PoC Archive PoC Archive

tag

Prompt-Injection

Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966) EPSS 34%
CVE-2026-27966 (GHSA-3645-fxcv-hqr4) web Patched
CVE-2026-27966webCRITICAL 9.8Patched2026-07-06Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030 misc Patched
CVE-2026-26030miscCRITICALPatched2026-07-05Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316
CVE-2026-54316 (GHSA-fg94-h982-f3mm) misc Patched
CVE-2026-54316miscMEDIUMPatched2026-07-05adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
CVE-2026-33980 web Patched
CVE-2026-33980webHIGH 8.8Patched2026-07-05Firefox Smart Window Private URL Exfiltration
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webHIGHUnverified2026-07-03