CVE-2026-10000 to CVE-2026-10999
259 CVEs with public proof-of-concept exploits.
- CVE-2026-100361 PoCSpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.yaml Parsing
- CVE-2026-100501 PoCDigest authentication lossy encoding
- CVE-2026-100531 PoCImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2026-100601 PoCTRENDnet TEW-432BRP formSetRoute command injection
- CVE-2026-100611 PoCTRENDnet TEW-432BRP formWPS command injection
- CVE-2026-100621 PoCTRENDnet TEW-432BRP formSetRoute stack-based overflow
- CVE-2026-100631 PoCTRENDnet TEW-432BRP formWPS stack-based overflow
- CVE-2026-100641 PoCTRENDnet TEW-432BRP formSetPortTr stack-based overflow
- CVE-2026-100771 PoCYOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes
- CVE-2026-100811 PoCUnlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews Widget
- CVE-2026-100821 PoCAdvanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter
- CVE-2026-100831 PoCAPCu Manager < 4.5.0 - Unauthenticated Stored XSS via Cache Key Pollution
- CVE-2026-100861 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-100871 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-100971 PoCML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery
- CVE-2026-101041 PoCProduct Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter
- CVE-2026-101102 PoCscode-projects Student Details Management System index.php sql injection
- CVE-2026-101111 PoCsambitraj STUDENT-MANAGEMENT-SYSTEM Login Page sql injection
- CVE-2026-101121 PoCsambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting
- CVE-2026-101131 PoCOpen5GS Shared NF-profile nnrf-handler.c denial of service
- CVE-2026-101141 PoCOpen5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds write
- CVE-2026-101151 PoCOpen5GS Shared NF-profile nnrf-handler.c denial of service
- CVE-2026-101161 PoCOpen5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of service
- CVE-2026-101171 PoCOpen5GS nghttp2-server.c ogs_pool_id_calloc denial of service
- CVE-2026-101191 PoCTRENDnet TEW-432BRP formSetMACFilter stack-based overflow
- CVE-2026-101201 PoCTRENDnet TEW-432BRP formSetFirewallRule stack-based overflow
- CVE-2026-101211 PoCTRENDnet TEW-432BRP formSetUrlFilter stack-based overflow
- CVE-2026-101221 PoCTRENDnet TEW-432BRP formSetProtocolFilter stack-based overflow
- CVE-2026-101231 PoCTRENDnet TEW-432BRP formSetDomainFilter stack-based overflow
- CVE-2026-101241 PoCShibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflow
- CVE-2026-101251 PoCEdimax BR-6478AC POST Request formPPPoESetup stack-based overflow
- CVE-2026-101261 PoCEdimax BR-6478AC POST Request formQoS buffer overflow
- CVE-2026-101271 PoCEdimax BR-6478AC POST Request formStaDrvSetup command injection
- CVE-2026-101521 PoCTaleLin lin-cms-spring-boot book Endpoint BookController.java access control
- CVE-2026-101531 PoCwestboy CicadasCMS AbstractCacheManager.java search cross site scripting
- CVE-2026-101551 PoCBdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection
- CVE-2026-101561 PoCOpen5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption
- CVE-2026-101571 PoCOpen5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication
- CVE-2026-101581 PoCTRENDnet TEW-432BRP formPortFw stack-based overflow
- CVE-2026-101591 PoCTRENDnet TEW-432BRP formSysLog stack-based overflow
- CVE-2026-101601 PoCTRENDnet TEW-432BRP formSetEnableWizard stack-based overflow
- CVE-2026-101611 PoCTRENDnet TEW-432BRP formResetStatistic stack-based overflow
- CVE-2026-101621 PoCTRENDnet TEW-432BRP formSetPassword stack-based overflow
- CVE-2026-101631 PoCEdimax BR-6478AC POST Request formUSBAccount buffer overflow
- CVE-2026-101641 PoCEdimax BR-6478AC POST Request formUSBFolder buffer overflow
- CVE-2026-101651 PoCEdimax BR-6478AC POST Request formWanTcpipSetup stack-based overflow
- CVE-2026-101661 PoCEdimax BR-6478AC POST Request formWlbasic command injection
- CVE-2026-101671 PoCOUSL-GROUP-BrinaryBrains School Student Management System MY_Controller Login.php sign_auth_cookie improper authentication
- CVE-2026-101681 PoCOUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks resource injection
- CVE-2026-101691 PoCOUSL-GROUP-BrinaryBrains School Student Management System Forgot Password Endpoint Login.php ajax_forgot_password password recovery
- CVE-2026-101702 PoCscode-projects Visitor Management System phone_0.php sql injection
- CVE-2026-101711 PoCcode-projects Online Music Site AdminUpdateAlbum.php sql injection
- CVE-2026-101721 PoCBdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload
- CVE-2026-101731 PoCOrthanc Explorer 2 URL StudyList.vue cross site scripting
- CVE-2026-101741 PoCAider-AI Aider Pre-commit Hook args.py protection mechanism
- CVE-2026-101751 PoCAider-AI Aider Architect Mode auth.py editor_coder.run code injection
- CVE-2026-101761 PoCAider-AI Aider Code Generation Workflow sql injection
- CVE-2026-101771 PoCAider-AI Aider AWS EC2 Metadata Endpoint api_docs.py requests.get server-side request forgery
- CVE-2026-101781 PoCcode-projects Online Music Site AdminEditAlbum.php sql injection
- CVE-2026-101791 PoCTRENDnet TEW-432BRP formSetWlanEncrypt stack-based overflow
- CVE-2026-101801 PoCTRENDnet TEW-432BRP formSysCmd command injection
- CVE-2026-101811 PoCTRENDnet TEW-432BRP formSysCmd stack-based overflow
- CVE-2026-101821 PoCTRENDnet TEW-432BRP formWlanSetup command injection
- CVE-2026-101831 PoCTRENDnet TEW-432BRP formWlanSetup stack-based overflow
- CVE-2026-101841 PoCSourceCodester Hospitals Patient Records Management System Users.php delete sql injection
- CVE-2026-101851 PoCSourceCodester Hospitals Patient Records Management System Users.php save sql injection
- CVE-2026-101861 PoCcode-projects Online Hospital Management System patient.php sql injection
- CVE-2026-101872 PoCsTotolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow
- CVE-2026-101881 PoCTenda W12 httpd cgistaKickOff stack-based overflow
- CVE-2026-101891 PoCTenda W12 httpd cgiSysTimeInfoSet stack-based overflow
- CVE-2026-101901 PoCTenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service
- CVE-2026-101911 PoCTenda W12 httpd cgiWifiMacFilterSet stack-based overflow
- CVE-2026-101921 PoCTenda W12 httpd set_local_time_0 stack-based overflow
- CVE-2026-101931 PoCOFCMS ComnController ComnController.java query sql injection
- CVE-2026-101971 PoCAssimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference
- CVE-2026-101981 PoCAssimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference
- CVE-2026-101991 PoCAssimp glTF2Asset.h LazyDict null pointer dereference
- CVE-2026-102001 PoCAssimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflow
- CVE-2026-102011 PoCAssimp UV Channel FBXExporter.cpp WriteObjects divide by zero
- CVE-2026-102021 PoCOFCMS JSON Query SystemDictController.java query sql injection
- CVE-2026-102031 PoCOFCMS JSON Query SystemParamController.java query sql injection
- CVE-2026-102041 PoCOFCMS JSON Query SysUserController.java query sql injection
- CVE-2026-102051 PoCMetasoft 美特软件 MetaCRM upload.jsp unrestricted upload
- CVE-2026-102061 PoCD-Link DI-8400 dbsrv.asp stack-based overflow
- CVE-2026-102081 PoCcode-projects Online Hospital Management System login_1.php login_user sql injection
- CVE-2026-102091 PoCcode-projects Online Hospital Management System Appointment appointmentdetail.php sql injection
- CVE-2026-102101 PoCAstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection
- CVE-2026-102111 PoCAstrBotDevs AstrBot fs.py _normalize_rw_path authorization
- CVE-2026-102121 PoCAstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization
- CVE-2026-102131 PoCAstrBotDevs AstrBot API Endpoint delete path traversal
- CVE-2026-102141 PoCzhayujie chatgpt-on-wechat Bash Tool bash.py _get_safety_warning os command injection
- CVE-2026-102151 PoCDolibarr ERP CRM Leave Request REST API api_holidays.class.php checkUserAccessToObject improper authorization
- CVE-2026-102161 PoCunitedbyai droidclaw claim Endpoint pairing.ts excessive authentication
- CVE-2026-102171 PoCnextlevelbuilder GoClaw RoleAdmin Gateway tts_config.go handleSave privileges management
- CVE-2026-102181 PoCnextlevelbuilder GoClaw evolution_handlers.go auth improper authorization
- CVE-2026-102191 PoCnextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection
- CVE-2026-102201 PoCNousResearch hermes-agent skills_tool.py skill_view injection
- CVE-2026-102211 PoCNousResearch hermes-agent run_agent.py _compress_context injection
- CVE-2026-102221 PoCNousResearch hermes-agent config.py _sanitize_env_lines injection
- CVE-2026-102231 PoCNousResearch hermes-agent memory_tool.py _scan_memory_content injection
- CVE-2026-102241 PoCNousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption
- CVE-2026-102251 PoCraisulislamg4 student_management_system_by_php Login login_check.php sql injection
- CVE-2026-102261 PoCraisulislamg4 student_management_system_by_php delete.php sql injection
- CVE-2026-102271 PoCraisulislamg4 student_management_system_by_php User Creation add_user_check.php sql injection
- CVE-2026-102281 PoCraisulislamg4 student_management_system_by_php admission_form_check.php cross site scripting
- CVE-2026-102291 PoCAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflow
- CVE-2026-102301 PoCAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflow
- CVE-2026-102311 PoCAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based overflow
- CVE-2026-102321 PoCAssimp ASE File scene.cpp ~aiNode use after free
- CVE-2026-102331 PoCAssimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds
- CVE-2026-102341 PoCMettle sendportal Campaign webview cross site scripting
- CVE-2026-102351 PoCCodeAstro Ingredients Stock Management System stock_manager.php sql injection
- CVE-2026-102361 PoCSourceCodester Water Billing Management System User Management Endpoint Users.php save improper authorization
- CVE-2026-102371 PoCSourceCodester Water Billing Management System User Management manage_user sql injection
- CVE-2026-102391 PoCJeecgBoot edit WordUtil.addImage server-side request forgery
- CVE-2026-102401 PoCJeecgBoot test server-side request forgery
- CVE-2026-102411 PoCjeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet server-side…
- CVE-2026-102421 PoCitsourcecode Content Management System instructions.php sql injection
- CVE-2026-102432 PoCscode-projects Smart Parking System Admin Endpoint missing authentication
- CVE-2026-102441 PoCSourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scripting
- CVE-2026-102451 PoCSourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scripting
- CVE-2026-102461 PoCSourceCodester Pharmacy Sales and Inventory System main create_medicine_presentation cross site scripting
- CVE-2026-102471 PoCSourceCodester Pharmacy Sales and Inventory System main create_generic_name cross site scripting
- CVE-2026-102481 PoCSourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supplier csv injection
- CVE-2026-102491 PoCitsourcecode Online Blood Bank Management System viewrequest.php sql injection
- CVE-2026-102501 PoCitsourcecode Online Blood Bank Management System campsdetails.php sql injection
- CVE-2026-102511 PoCitsourcecode Online House Rental System ajax.php login sql injection
- CVE-2026-102521 PoCitsourcecode Online House Rental System manage_tenant.php sql injection
- CVE-2026-102531 PoCitsourcecode Online House Rental System manage_payment.php sql injection
- CVE-2026-102541 PoCSourceCodester Pet Grooming Management Software admin file information disclosure
- CVE-2026-102551 PoCSourceCodester Pharmacy Sales and Inventory System ShowForm.php sell_statement access control
- CVE-2026-102561 PoCitsourcecode Content Management System save_comment.php sql injection
- CVE-2026-102571 PoCitsourcecode Content Management System update_ss_img.php sql injection
- CVE-2026-102581 PoCitsourcecode Content Management System add_sub_topic.php sql injection
- CVE-2026-102591 PoCH3C Magic B0 aspForm SetMobileAPInfoById stack-based overflow
- CVE-2026-102601 PoCCodeAstro Online Job Portal delete-jobs.php sql injection
- CVE-2026-102611 PoCCodeAstro Online Job Portal application_status.php sql injection
- CVE-2026-102621 PoCcode-projects Real State Services Login loginuser.php sql injection
- CVE-2026-102631 PoCSourceCodester Computer Repair Shop Management System manage_product.php sql injection
- CVE-2026-102641 PoClharries whatsapp-mcp Send API Endpoint main.go SendMessageRequest path traversal
- CVE-2026-102651 PoCitsourcecode Content Management System edit_topic.php sql injection
- CVE-2026-102671 PoCjanet-lang janet debug.c doframe out-of-bounds
- CVE-2026-102681 PoCjanet-lang janet marsh.c unmarshal_one_fiber integer overflow
- CVE-2026-102701 PoCD-Link DI-7001 MINI API httpd_debug.asp sprintf stack-based overflow
- CVE-2026-102711 PoCa4m4 Student-Management-System Admin Endpoint admin redirect
- CVE-2026-102721 PoCa4m4 Student-Management-System deleteform.php improper authorization
- CVE-2026-102731 PoCphp-censor Webhook Endpoint GitBuild.php os command injection
- CVE-2026-102741 PoCindrasishbanerjee aem-mcp-server Axios Request Flow mcp-server.ts getAssetMetadata server-side request forgery
- CVE-2026-102751 PoCOpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow
- CVE-2026-102761 PoChekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
- CVE-2026-102771 PoCj3k0 mcp-google-workspace MCP Gmail Tool gmail.ts saveToDisk access control
- CVE-2026-102781 PoCishayoyo excel-mcp read_file/write_file index.ts path traversal
- CVE-2026-102791 PoChiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injection
- CVE-2026-102801 PoChorizon921 mcpilot MCP API Call Endpoint route.ts server-side request forgery
- CVE-2026-102811 PoCEnderfga claw-orchestrator API Endpoint embedded-server.ts EmbeddedServer missing authentication
- CVE-2026-102861 PoCCodeAstro Payroll System home_employee.php sql injection
- CVE-2026-102871 PoCSourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery
- CVE-2026-102882 PoCscode-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authentication
- CVE-2026-102892 PoCscode-projects Hotel and Tourism Reservation System tour.php cross site scripting
- CVE-2026-102902 PoCscode-projects Hotel and Tourism Reservation System GET Parameter tour.php sql injection
- CVE-2026-102921 PoCUTT HiPER 1200GW formTaskEdit strcpy stack-based overflow
- CVE-2026-102931 PoCUTT HiPER 1200GW formFireWall strcpy stack-based overflow
- CVE-2026-102941 PoCPackageKit API pk-transaction.c g_file_test improper authorization
- CVE-2026-102951 PoCSourceCodester Customer Review App review_app.py get_all_reviews denial of service
- CVE-2026-102961 PoCitsourcecode Fees Management System ajax.php sql injection
- CVE-2026-102971 PoCitsourcecode Fees Management System manage_course.php sql injection
- CVE-2026-102981 PoCggml-org whisper.cpp ggml.c whisper_model_load null pointer dereference
- CVE-2026-102991 PoCcode-projects Online Hospital Management System viewdoctortimings.php resource injection
- CVE-2026-103001 PoCSGLang Inference HTTP Endpoint lora_manager.py assertion
- CVE-2026-103011 PoCitsourcecode Fees Management System index.php cross site scripting
- CVE-2026-103021 PoCitsourcecode Fees Management System manage_fee.php sql injection
- CVE-2026-105141 PoC1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting
- CVE-2026-105209 PoCsKEVAn OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated…
- CVE-2026-105221 PoCSimple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator
- CVE-2026-105233 PoCsAn Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote…
- CVE-2026-105241 PoCCoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
- CVE-2026-105251 PoCNEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
- CVE-2026-105261 PoCEmbedPress < 4.6.1 - Unauthenticated Blind SSRF
- CVE-2026-105281 PoCOrthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow
- CVE-2026-105291 PoCwestboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
- CVE-2026-105301 PoCPie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
- CVE-2026-105311 PoCAI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortcode Attribute
- CVE-2026-105481 PoCNousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper…
- CVE-2026-105501 PoCelunez eladmin Application Deployment App.java command injection
- CVE-2026-105511 PoCBreeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library
- CVE-2026-105581 PoCSourceCodester Pizzafy Ecommerce System index.php file inclusion
- CVE-2026-105591 PoCSourceCodester Pizzafy Ecommerce System index.php file inclusion
- CVE-2026-105651 PoCOpen5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition
- CVE-2026-105661 PoCFoundationAgents MetaGPT schema.py Message.check_instruct_content deserialization
- CVE-2026-105671 PoC1Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross site scripting
- CVE-2026-105681 PoCitsourcecode Fees Management System manage_payment.php sql injection
- CVE-2026-105803 PoCsHippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
- CVE-2026-105831 PoCnextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import server-side request forgery
- CVE-2026-105991 PoCIntegrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
- CVE-2026-106161 PoCnextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization
- CVE-2026-106171 PoCnextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing authentication
- CVE-2026-106191 PoCsayan365 student-management-system improper authentication
- CVE-2026-106201 PoCcode-projects Student Admission System index.php sql injection
- CVE-2026-106241 PoCSourceCodester Human Resource Management Employee View detailview.php resource injection
- CVE-2026-106501 PoCwarmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
- CVE-2026-106611 PoCahujasid blender-mcp server.py open injection
- CVE-2026-106621 PoCahujasid blender-mcp ZIP File server.py requests.get server-side request forgery
- CVE-2026-106721 PoCUnterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)
- CVE-2026-106881 PoCahujasid blender-mcp server.py execute_blender_code code injection
- CVE-2026-106901 PoCwonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side request forgery
- CVE-2026-106911 PoCwonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos
- CVE-2026-106921 PoCjohnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
- CVE-2026-106931 PoCSourceCodester Online Boat Reservation System Administrative Endpoint improper authorization
- CVE-2026-106941 PoCSourceCodester Online Food Ordering System index.php include file inclusion
- CVE-2026-107024 PoCsJIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-107031 PoCEIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free
- CVE-2026-107041 PoCSourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection
- CVE-2026-107121 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-107221 PoCcilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
- CVE-2026-107241 PoCReviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews
- CVE-2026-107352 PoCsShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
- CVE-2026-107491 PoCPost Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData
- CVE-2026-107501 PoCRoyal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools
- CVE-2026-107531 PoCSite Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update
- CVE-2026-107551 PoCAll in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration
- CVE-2026-107661 PoCmlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash
- CVE-2026-107681 PoCLocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
- CVE-2026-107711 PoCcrmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery
- CVE-2026-107751 PoCsgl-project SGLang Cache data_hash denial of service
- CVE-2026-107771 PoCealpha072 Student-Management-System Administrative Backend config.php improper authentication
- CVE-2026-107831 PoCgradio-app gradio Audio Cache Key save_audio_to_cache weak hash
- CVE-2026-107952 PoCsUpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
- CVE-2026-108011 PoCmodelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
- CVE-2026-108021 PoCkeystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
- CVE-2026-108031 PoCMLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
- CVE-2026-108041 PoCStreamlit Palette hashing.py weak hash
- CVE-2026-108061 PoCmjperpinosa stumasy add_post.php unrestricted upload
- CVE-2026-108071 PoCmjperpinosa stumasy change_profile_image.php unrestricted upload
- CVE-2026-108081 PoCitsourcecode Fees Management System manage_student.php sql injection
- CVE-2026-108091 PoCitsourcecode Fees Management System manage_user.php sql injection
- CVE-2026-108101 PoCitsourcecode Fees Management System navbar.php cross site scripting
- CVE-2026-108111 PoCitsourcecode Fees Management System receipt.php sql injection
- CVE-2026-108121 PoCzilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
- CVE-2026-108131 PoCLMCache KV Cache utils.py hex_hash_to_int16 weak hash
- CVE-2026-108141 PoCmilvus-io milvus Grantee ID Hash kv_catalog.go weak hash
- CVE-2026-108151 PoCLakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
- CVE-2026-108181 PoCWPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
- CVE-2026-108201 PoCProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
- CVE-2026-108211 PoCYoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE
- CVE-2026-108232 PoCsYMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure
- CVE-2026-108241 PoCMasteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion
- CVE-2026-108271 PoCSpectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes
- CVE-2026-108301 PoCAllCoach < 1.0.2 - Unauthenticated Account Takeover
- CVE-2026-108341 PoCWP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_profile_image
- CVE-2026-108351 PoCSALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection
- CVE-2026-108701 PoCShibby Tomato Web UI rc start_dhcpc os command injection
- CVE-2026-108711 PoCShibby Tomato Web UI rc start_6rd_tunnel os command injection
- CVE-2026-108721 PoCShibby Tomato Web UI rc start_vpnserver os command injection
- CVE-2026-108731 PoCShibby Tomato Web UI rstats rstats_path os command injection
- CVE-2026-108741 PoCprojectworlds Online Art Gallery Shop Project adminHome.php sql injection
- CVE-2026-108751 PoCprojectworlds Online Art Gallery Shop Project adminHome.ph sql injection
- CVE-2026-108761 PoCSourceCodester Ship Ferry Ticket Reservation System admin improper authorization
- CVE-2026-108771 PoCSourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql injection
- CVE-2026-108781 PoCD-Link DWR-M920 formSmsManage sub_41C8E8 command injection