
CVE-2026-71204-PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

Vulnerability Research

Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)

PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4).

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

PoC — cross-origin proxy abuse of configured provider API keys in PasteGuard (GHSA-q94x-p9rc-q89f, CVE-2026-86998, CVSS 7.6).

CVE-2026-39154, Stored XSS in CometChat JS SDK

A static + runtime security scanner for MCP (Model Context Protocol) servers

Burp Plugin for Secret Matching

mcp-remote exposed to OS command injection

CVE-2026-31816 - Budibase Authentication Bypass to RCE

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.