CVE-2026-0 to CVE-2026-999
115 CVEs with public proof-of-concept exploits.
- CVE-2026-00063 PoCsIn multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code…
- CVE-2026-00132 PoCsIn setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This…
- CVE-2026-00231 PoCIn createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing…
- CVE-2026-00471 PoCIn dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing…
- CVE-2026-00491 PoCIn onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could…
- CVE-2026-00591 PoCIn multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could…
- CVE-2026-007314 PoCsIn adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code.…
- CVE-2026-00921 PoCIn Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local…
- CVE-2026-01631 PoCIn multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of…
- CVE-2026-02271 PoCPAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal
- CVE-2026-02578 PoCsKEVPAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
- CVE-2026-02651 PoCPAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
- CVE-2026-02731 PoCPAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI
- CVE-2026-03007 PoCsKEVPAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
- CVE-2026-05421 PoCRemote Code Execution in ServiceNow AI Platform
- CVE-2026-05441 PoCitsourcecode School Management System index.php sql injection
- CVE-2026-05451 PoCMissing Authentication for Critical Function in mlflow/mlflow
- CVE-2026-05461 PoCcode-projects Content Management System search.php sql injection
- CVE-2026-05472 PoCsPHPGurukul Online Course Registration Student Registration edit-student-profile.php unrestricted upload
- CVE-2026-05581 PoCUnauthenticated File Upload in parisneo/lollms
- CVE-2026-05601 PoCServer-Side Request Forgery (SSRF) in parisneo/lollms
- CVE-2026-05651 PoCcode-projects Content Management System delete.php sql injection
- CVE-2026-05661 PoCcode-projects Content Management System edit_posts.php unrestricted upload
- CVE-2026-05671 PoCcode-projects Content Management System pages.php sql injection
- CVE-2026-05681 PoCcode-projects Online Music Site ViewSongs.php sql injection
- CVE-2026-05691 PoCcode-projects Online Music Site AlbumByCategory.php sql injection
- CVE-2026-05701 PoCcode-projects Online Music Site Feedback.php sql injection
- CVE-2026-05711 PoCyeqifu warehouse AppFileUtils.java createResponseEntity path traversal
- CVE-2026-05741 PoCyeqifu warehouse Request UserController.java saveUserRole improper authorization
- CVE-2026-05751 PoCcode-projects Online Product Reservation System Administrator Login adminlogin.php sql injection
- CVE-2026-05761 PoCcode-projects Online Product Reservation System Parameter prod.php sql injection
- CVE-2026-05771 PoCcode-projects Online Product Reservation System prod.php unrestricted upload
- CVE-2026-05781 PoCcode-projects Online Product Reservation System delete.php sql injection
- CVE-2026-05791 PoCcode-projects Online Product Reservation System POST Parameter edit.php sql injection
- CVE-2026-05811 PoCTenda AC1206 httpd BehaviorManager formBehaviorManager command injection
- CVE-2026-05821 PoCitsourcecode Society Management System edit_activity_query.php sql injection
- CVE-2026-05831 PoCcode-projects Online Product Reservation System User Login login.php sql injection
- CVE-2026-05841 PoCcode-projects Online Product Reservation System left_cart.php sql injection
- CVE-2026-05851 PoCcode-projects Online Product Reservation System GET Parameter order_view.php sql injection
- CVE-2026-05861 PoCcode-projects Online Product Reservation System prod.php cross site scripting
- CVE-2026-05891 PoCcode-projects Online Product Reservation System Administration Backend improper authentication
- CVE-2026-05901 PoCcode-projects Online Product Reservation System POST Parameter delete.php sql injection
- CVE-2026-05911 PoCcode-projects Online Product Reservation System Cart Update update.php sql injection
- CVE-2026-05921 PoCcode-projects Online Product Reservation System User Registration register_code.php sql injection
- CVE-2026-05942 PoCsList Site Contributors <= 1.1.8 - Reflected Cross-Site Scripting via alpha
- CVE-2026-05951 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-05961 PoCCommand Injection in mlflow/mlflow
- CVE-2026-05971 PoCCampcodes Supplier Management System edit_profile.php sql injection
- CVE-2026-06021 PoCAuthentication Bypass Using an Alternate Path or Channel in GitLab
- CVE-2026-06031 PoCOrg.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
- CVE-2026-06051 PoCcode-projects Online Music Site login.php sql injection
- CVE-2026-06061 PoCcode-projects Online Music Site Albums.php sql injection
- CVE-2026-06071 PoCcode-projects Online Music Site AdminViewSongs.php sql injection
- CVE-2026-06282 PoCsInsufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to…
- CVE-2026-06401 PoCTenda AC23 PowerSaveSet sscanf buffer overflow
- CVE-2026-06411 PoCTOTOLINK WA300 cstecgi.cgi sub_401510 command injection
- CVE-2026-06421 PoCprojectworlds House Rental and Property Listing complaint.php cross site scripting
- CVE-2026-06431 PoCprojectworlds House Rental and Property Listing Signup register.php unrestricted upload
- CVE-2026-06491 PoCinvoiceninja Migration Import Import.php copy server-side request forgery
- CVE-2026-06501 PoCOpenFlagr <= 1.1.18 Authentication Bypass via Prefix Whitelist Path Normalization
- CVE-2026-06511 PoCPath Traversal on TP-Link Tapo D235, C211, C520WS and C260 via Local https
- CVE-2026-06521 PoCRemote Code Execution on TP-Link Tapo C260 by Guest User
- CVE-2026-06531 PoCInsecure Access Control on TP-Link Tapo D235 and C260
- CVE-2026-06581 PoCFive Star Restaurant Reservations < 2.7.9 - Arbitrary Bookings Deletion via CSRF
- CVE-2026-06971 PoCcode-projects Intern Membership Management System edit_admin.php sql injection
- CVE-2026-06981 PoCcode-projects Intern Membership Management System edit_students.php sql injection
- CVE-2026-06991 PoCcode-projects Intern Membership Management System edit_activity.php sql injection
- CVE-2026-07001 PoCcode-projects Intern Membership Management System check_admin.php sql injection
- CVE-2026-07011 PoCcode-projects Intern Membership Management System add_admin.php sql injection
- CVE-2026-07091 PoCSome Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers…
- CVE-2026-07171 PoCLottieFiles – Lottie block for Gutenberg <= 3.0.0 - Unauthenticated Sensitive Information Exposure
- CVE-2026-07231 PoCUnchecked Return Value in GitLab
- CVE-2026-07281 PoCcode-projects Intern Membership Management System delete_admin.php sql injection
- CVE-2026-07291 PoCcode-projects Intern Membership Management System add_activity.php sql injection
- CVE-2026-07301 PoCPHPGurukul Staff Leave Management System SVG File adminviews.py UPDATE_STAFF cross site scripting
- CVE-2026-07311 PoCTOTOLINK WA1200 HTTP Request cstecgi.cgi null pointer dereference
- CVE-2026-07321 PoCD-Link DI-8200G upgrade_filter.asp command injection
- CVE-2026-07331 PoCPHPGurukul Online Course Registration System manage-students.php sql injection
- CVE-2026-07409 PoCsNinja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
- CVE-2026-07431 PoCWP Content Permission <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ohmem-message' Parameter
- CVE-2026-07452 PoCsUser Language Switch <= 1.6.10 - Authenticated (Administrator+) Server-Side Request Forgery via 'info_language' Parameter
- CVE-2026-07521 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-07682 PoCsLangflow code Code Injection Remote Code Execution Vulnerability
- CVE-2026-07691 PoCLangflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability
- CVE-2026-077010 PoCsKEVLangflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
- CVE-2026-07761 PoCDiscord Client Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
- CVE-2026-08031 PoCPHPGurukul Online Course Registration System enroll.php sql injection
- CVE-2026-08211 PoCquickjs-ng quickjs quickjs.c js_typed_array_constructor heap-based overflow
- CVE-2026-08221 PoCquickjs-ng quickjs quickjs.c js_typed_array_sort heap-based overflow
- CVE-2026-08241 PoCquestdb ui Web Console cross site scripting
- CVE-2026-08261 PoCPoly Voice – Possible Remote Control of Certain Poly Devices
- CVE-2026-08271 PoCDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in…
- CVE-2026-08283 PoCsKernel driver vulnerability in Safetica Endpoint Client
- CVE-2026-08292 PoCsFrontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email Sending
- CVE-2026-08341 PoCLogic Vulnerability on TP-Link Archer C20, Archer AX53 and TL-WR841N v13
- CVE-2026-08361 PoCUTT 进取 520W formConfigFastDirectionW strcpy buffer overflow
- CVE-2026-08371 PoCUTT 进取 520W formFireWall strcpy buffer overflow
- CVE-2026-08381 PoCUTT 进取 520W ConfigWirelessBase strcpy buffer overflow
- CVE-2026-08391 PoCUTT 进取 520W APSecurity strcpy buffer overflow
- CVE-2026-08401 PoCUTT 进取 520W formConfigNoticeConfig strcpy buffer overflow
- CVE-2026-08411 PoCUTT 进取 520W formPictureUrl strcpy buffer overflow
- CVE-2026-08421 PoCFlycatcher Toys smART Sketcher Bluetooth Low Energy missing authentication
- CVE-2026-08431 PoCjiujiujia/victor123/wxw850227 jjjfood/jjjshop_food index sql injection
- CVE-2026-08471 PoCPath Traversal in nltk/nltk
- CVE-2026-08482 PoCsArbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR Loading
- CVE-2026-08501 PoCcode-projects Intern Membership Management System delete_activity.php sql injection
- CVE-2026-08511 PoCcode-projects Online Music Site AdminAddUser.php sql injection
- CVE-2026-08521 PoCcode-projects Online Music Site AdminUpdateUser.php sql injection
- CVE-2026-09111 PoCHustle <= 7.8.9.2 - Authenticated (Subscriber+) Arbitrary File Upoload via Module Import
- CVE-2026-09205 PoCsLA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via…
- CVE-2026-09263 PoCsProdigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]
- CVE-2026-09291 PoCRegistrationMagic < 6.0.7.2 - Subscriber+ Form Creation
- CVE-2026-09341 PoCIncorrect Authorization in GitLab
- CVE-2026-09581 PoCInterpretation Conflict in GitLab
- CVE-2026-09611 PoCOut-of-bounds Write in Wireshark