CVE-2026-11000 to CVE-2026-11999
187 CVEs with public proof-of-concept exploits.
- CVE-2026-110571 PoCUninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to…
- CVE-2026-111011 PoCUninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a…
- CVE-2026-111021 PoCInappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary…
- CVE-2026-111031 PoCInappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level…
- CVE-2026-111041 PoCUninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to…
- CVE-2026-111051 PoCInsufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised…
- CVE-2026-111061 PoCInappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a…
- CVE-2026-111071 PoCInappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a…
- CVE-2026-111081 PoCInappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege…
- CVE-2026-111091 PoCUninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML…
- CVE-2026-111101 PoCUninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML…
- CVE-2026-111121 PoCInsufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who…
- CVE-2026-111131 PoCInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised…
- CVE-2026-111141 PoCUse after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer…
- CVE-2026-111151 PoCUse after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege…
- CVE-2026-111161 PoCUse after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious…
- CVE-2026-111171 PoCUse after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a…
- CVE-2026-111181 PoCUse after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via…
- CVE-2026-111191 PoCInappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the…
- CVE-2026-111201 PoCInsufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who…
- CVE-2026-113121 PoCbytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
- CVE-2026-113331 PoCtittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
- CVE-2026-113341 PoCtittuvarghese CollegeManagementSystem fetch.php sql injection
- CVE-2026-113351 PoCtittuvarghese CollegeManagementSystem login-form.php session_start session fixiation
- CVE-2026-113361 PoCtittuvarghese CollegeManagementSystem Admin admin_page.php improper authorization
- CVE-2026-113371 PoCtittuvarghese CollegeManagementSystem fetch.php cross site scripting
- CVE-2026-113381 PoCSourceCodester Ship Ferry Ticket Reservation System manage_user cross site scripting
- CVE-2026-113391 PoCD-Link DWR-M920 formUSSDSetup sub_41CF20 command injection
- CVE-2026-113411 PoCD-Link DWR-M920 formIMEISetup sub_412DA0 os command injection
- CVE-2026-113421 PoCcode-projects Hotel and Tourism Reservation System details.php sql injection
- CVE-2026-113442 PoCscode-projects Vehicle Management System New Driver Registration Form newdriver.php unrestricted upload
- CVE-2026-113492 PoCsModern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more
- CVE-2026-113511 PoCShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosure
- CVE-2026-113611 PoCFormidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
- CVE-2026-113661 PoCMonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass
- CVE-2026-113711 PoCBetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection
- CVE-2026-113872 PoCsSMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
- CVE-2026-114052 PoCsHidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
- CVE-2026-114061 PoCGL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection
- CVE-2026-114081 PoCvertex-app vertex Log Viewer Endpoint LogMod.js os command injection
- CVE-2026-114111 PoCiAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal
- CVE-2026-114121 PoCJinher OA GetFormSn.aspx sql injection
- CVE-2026-114131 PoCJingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow
- CVE-2026-114341 PoCFluentCMS Blocks Plugin blocks cross site scripting
- CVE-2026-114351 PoCJinher OA nextselectplan.aspx sql injection
- CVE-2026-114361 PoCMage AI Sign-in Flow index.tsx useMutation cross site scripting
- CVE-2026-114371 PoCperfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery
- CVE-2026-114471 PoCGL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injection
- CVE-2026-114501 PoCGL.iNet GL-MT3000 Path Normalization dlopen command injection
- CVE-2026-114511 PoCGL.iNet GL-MT3000 FTP Protocol glc snprintf command injection
- CVE-2026-114521 PoCGL.iNet GL-MT3000 SET_USER_PWD glc FUN_0042e200 command injection
- CVE-2026-114531 PoCTiobon Employee Self-Service System Login Endpoint BlogSearch.aspx sql injection
- CVE-2026-114551 PoCFoundationAgents MetaGPT common.py check_cmd_exists command injection
- CVE-2026-114561 PoCChanjet CRM HTTP GET Request jxf_dump_systable.php sql injection
- CVE-2026-114571 PoCerzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection
- CVE-2026-114581 PoCerzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosure
- CVE-2026-114592 PoCsSecureAge CatchPulse IOCTL saappctl.sys information disclosure
- CVE-2026-114601 PoCBoost Serialization improper validation of specified type of input
- CVE-2026-114611 PoCNousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization
- CVE-2026-114621 PoCChengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
- CVE-2026-114631 PoCUSCiLab Cereal Shared Pointer type confusion
- CVE-2026-114641 PoCJeecgBoot User List Endpoint SysUserController.java queryPageList information disclosure
- CVE-2026-114651 PoCsongquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic error
- CVE-2026-114661 PoCzilliztech deep-searcher collection_router.py CollectionRouter.invoke access control
- CVE-2026-114671 PoCjishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal
- CVE-2026-114681 PoCSourceCodester Hospitals Patient Records Management System page room_types cross site scripting
- CVE-2026-114691 PoCjishenghua jshERP platformConfig Add Endpoint PlatformConfigService.java insertPlatformConfig server-side request forgery
- CVE-2026-114701 PoChs-web hsweb-framework File Upload FileUploadProperties.java denied path traversal
- CVE-2026-114711 PoCSourceCodester Class and Exam Timetabling System index2.php sql injection
- CVE-2026-114721 PoCSourceCodester Class and Exam Timetabling System index1.php sql injection
- CVE-2026-114741 PoCKushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload
- CVE-2026-114751 PoCKushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection
- CVE-2026-114761 PoCKushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization
- CVE-2026-114771 PoChs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect
- CVE-2026-114781 PoCkokke tiny-regex-c Pattern re.c matchstar redos
- CVE-2026-114791 PoCyoanbernabeu grepai Qdrant Backend chunker.go weak hash
- CVE-2026-114801 PoCChengdu Everbrite Network Technology BeikeShop Admin Design Builder Endpoint admin.php sql injection
- CVE-2026-114811 PoCyoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
- CVE-2026-114821 PoCSourceCodester Class and Exam Timetabling System archive5.php sql injection
- CVE-2026-114831 PoCSourceCodester Class and Exam Timetabling System archive4.php sql injection
- CVE-2026-114841 PoCSourceCodester Class and Exam Timetabling System archive3.php sql injection
- CVE-2026-114851 PoCSourceCodester Class and Exam Timetabling System archive2.php sql injection
- CVE-2026-114861 PoCSourceCodester Class and Exam Timetabling System archive1.php sql injection
- CVE-2026-114871 PoCNeovim View Branch secure.lua M.read command injection
- CVE-2026-114881 PoCcode-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection
- CVE-2026-114891 PoCcode-projects Online Music Site AdminDeleteAlbum.php sql injection
- CVE-2026-114901 PoCcode-projects Online Music Site Search.php sql injection
- CVE-2026-114911 PoCCodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
- CVE-2026-114921 PoCD-Link DIR-823G vsftpd vsftpd.conf least privilege violation
- CVE-2026-114931 PoCTenda AC15 Samba smb.conf weak password
- CVE-2026-114941 PoCTOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation
- CVE-2026-114951 PoCCodeAstro Ingredients Stock Management System add_stock.php sql injection
- CVE-2026-114971 PoCD-Link DCS-5615 Boa Webserver boa.conf least privilege violation
- CVE-2026-114991 PoCTenda HG7HG9/HG10 formDOMAINBLK stack-based overflow
- CVE-2026-115001 PoCWeaviate Static API Key client.go validateConfig authorization
- CVE-2026-115011 PoCSourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection
- CVE-2026-115021 PoCJeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect
- CVE-2026-115031 PoCTenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow
- CVE-2026-115041 PoCTenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based overflow
- CVE-2026-115061 PoCCodeAstro Leave Management System search_staff_for_deletion.php sql injection
- CVE-2026-115071 PoCCodeAstro Leave Management System delete_leave_type.php sql injection
- CVE-2026-115081 PoCCodeAstro Leave Management System search_staff_to_assign_pc.php sql injection
- CVE-2026-115101 PoCCodeAstro Leave Management System add_leave.php sql injection
- CVE-2026-115121 PoCitsourcecode Hospital Management System billing.php cross site scripting
- CVE-2026-115131 PoCitsourcecode Hospital Management System adminaccount.php sql injection
- CVE-2026-115141 PoCitsourcecode Hospital Management System addpatient.php sql injection
- CVE-2026-115161 PoCUTT HiPER 2610G formNatStaticMap strcpy buffer overflow
- CVE-2026-115171 PoCUTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow
- CVE-2026-115182 PoCsSourceCodester Inventory System User Management users.php cross site scripting
- CVE-2026-115211 PoCMohammed-eid35 bank-management-system-springboot Transaction Endpoint TransactionController.java improper authorization
- CVE-2026-115221 PoCTenda W20E setPortMirror formSetPortMirror stack-based overflow
- CVE-2026-115231 PoCTenda W20E Web Management PortalAuth formPortalAuth stack-based overflow
- CVE-2026-115241 PoCTenda W20E Web Management modifyWifiFilterRules stack-based overflow
- CVE-2026-115281 PoCTenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow
- CVE-2026-115291 PoCdesigncomputer mysql-mcp-server mysql URI server.py read_resource sql injection
- CVE-2026-115301 PoCimvks786 student_management_system Login index.ph sql injection
- CVE-2026-115311 PoCimvks786 student_management_system Administrator Login Endpoint admin_login.php sql injection
- CVE-2026-115321 PoCimvks786 student_management_system Student Record add.php access control
- CVE-2026-115331 PoCimvks786 student_management_system Student Deletion Endpoint see.php improper authorization
- CVE-2026-115341 PoCimvks786 student_management_system add.php cross site scripting
- CVE-2026-115512 PoCsBranda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
- CVE-2026-115531 PoCTenda HG7HG9/HG10 formPPPEdit stack-based overflow
- CVE-2026-115541 PoCTOTOLINK CP450 vsftpd vsftpd.conf least privilege violation
- CVE-2026-115551 PoCD-Link DGS-1100-08PD Web boa.conf least privilege violation
- CVE-2026-115561 PoCTenda F451 Web Management WriteFacMac formWriteFacMac os command injection
- CVE-2026-115571 PoCTenda F451 Web Management Natlimit fromNatlimit stack-based overflow
- CVE-2026-115581 PoCCodeAstro Payroll System home_salary.php sql injection
- CVE-2026-115591 PoCCodeAstro Payroll System view_account.php sql injection
- CVE-2026-115621 PoCWS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update
- CVE-2026-115631 PoCWord Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via Path Traversal
- CVE-2026-115651 PoCAdvanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_fma_ui
- CVE-2026-115671 PoCSureForms < 2.11.1 - Unauthenticated Payment Amount Bypass
- CVE-2026-115681 PoCProduct Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
- CVE-2026-115701 PoCUser Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name
- CVE-2026-115711 PoCEverest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts
- CVE-2026-115751 PoCPhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback
- CVE-2026-115781 PoCFluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via IDOR
- CVE-2026-115791 PoCKali Forms < 2.4.17 - Unauthenticated Media Upload
- CVE-2026-115801 PoCKali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
- CVE-2026-115811 PoCKali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption
- CVE-2026-115821 PoCCodeAstro Student Attendance Management System index.php sql injection
- CVE-2026-115831 PoCCodeAstro Student Attendance Management System createClass.php sql injection
- CVE-2026-115841 PoCCodeAstro Student Attendance Management System createClass.php edit sql injection
- CVE-2026-115851 PoCCodeAstro Student Attendance Management System createClassArms.php sql injection
- CVE-2026-115881 PoCEONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Creation
- CVE-2026-115891 PoCWP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File Upload
- CVE-2026-115901 PoCWP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array Keys
- CVE-2026-116181 PoCDTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authentication
- CVE-2026-116201 PoCTOTOLINK EX200 vsftpd vsftpd.conf least privilege violation
- CVE-2026-116211 PoCDcat-Admin User Setting upload editorMDUpload unrestricted upload
- CVE-2026-116231 PoCtmux image.c image_free use after free
- CVE-2026-116453 PoCsKEVOut of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a…
- CVE-2026-117171 PoCAn authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.…
- CVE-2026-117181 PoCAn authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.…
- CVE-2026-117661 PoCUltimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile Fields
- CVE-2026-117671 PoCCRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact Form
- CVE-2026-117791 PoCPayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access
- CVE-2026-117811 PoCAdminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global Search AJAX
- CVE-2026-117821 PoCPoints and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR
- CVE-2026-117841 PoCOptimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via…
- CVE-2026-117941 PoCAdvanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
- CVE-2026-118011 PoCWPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via classifieds-types REST Endpoint
- CVE-2026-118271 PoCInsufficiently Protected Credentials in GitLab
- CVE-2026-118341 PoCUnauthenticated Command Injection via DHCP Option Handling in Multiple TP-Link Routers
- CVE-2026-118551 PoCSimple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version
- CVE-2026-118661 PoCLatePoint < 5.6.3 - Multiple Privileged Actions via CSRF
- CVE-2026-118671 PoCFrontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization
- CVE-2026-118681 PoCWP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation
- CVE-2026-118691 PoCWP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subject Access Request
- CVE-2026-118701 PoCHide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass
- CVE-2026-118721 PoCClever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via save_clever_menu_item
- CVE-2026-118751 PoCWP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access via Session Cookie Forgery
- CVE-2026-118801 PoCFluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR
- CVE-2026-118811 PoCFluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
- CVE-2026-118821 PoCBuilderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes
- CVE-2026-118831 PoCWebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass
- CVE-2026-118871 PoCSalon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass
- CVE-2026-119121 PoCSimple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
- CVE-2026-119612 PoCsUser Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
- CVE-2026-119621 PoCFileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File Operations
- CVE-2026-119631 PoCUser Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier Modification via IDOR
- CVE-2026-119641 PoCUser Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation
- CVE-2026-119651 PoCUser Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass
- CVE-2026-119661 PoCUser Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler
- CVE-2026-119741 PoCMedia folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download
- CVE-2026-119761 PoCMonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
- CVE-2026-119981 PoCAngularJS XSS via SCE resource URL sanitization bypass