CVE-2026-12000 to CVE-2026-12999
166 CVEs with public proof-of-concept exploits.
- CVE-2026-120451 PoCpgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
- CVE-2026-120531 PoCInsertion of Sensitive Information into Log File in GitLab
- CVE-2026-120651 PoCGroww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
- CVE-2026-120661 PoCPbootCMS Password MemberController.php retrieve password recovery
- CVE-2026-120811 PoCDatabase for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field
- CVE-2026-120821 PoCPraison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
- CVE-2026-120831 PoCAdmin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Restoration via reset-for Parameter
- CVE-2026-121291 PoCCodeAstro Human Resource Management System Dashboard add_tod cross site scripting
- CVE-2026-121301 PoCCodeAstro Human Resource Management System Projects Management Add_Projects cross site scripting
- CVE-2026-121311 PoCCodeAstro Human Resource Management System Payroll Invoice Payroll.php sql injection
- CVE-2026-121431 PoCform-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
- CVE-2026-121661 PoCCVE-2026-12166
- CVE-2026-121671 PoCCVE-2026-12167
- CVE-2026-121681 PoCCVE-2026-12168
- CVE-2026-121741 PoCD-Link DCS-935L HTTP rhea snprintf format string
- CVE-2026-121751 PoCCodeAstro Student Attendance Management System createStudents.php sql injection
- CVE-2026-121832 PoCsNefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
- CVE-2026-121861 PoCGL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection
- CVE-2026-121871 PoCGL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection
- CVE-2026-121881 PoCGrit42 Grit GritEntityController grit_entity_controller.rb sql injection
- CVE-2026-121891 PoCMoovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
- CVE-2026-121911 PoCComma AI Openpilot Pickle modeld.py pickle.loads deserialization
- CVE-2026-121932 PoCsVS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
- CVE-2026-121941 PoCPHPIPAM Authenticated LFI
- CVE-2026-121951 PoCmyVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary commands as a part…
- CVE-2026-121961 PoCHestiaCP Admin Takeover
- CVE-2026-121971 PoCRuijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection
- CVE-2026-121981 PoCMicroweber API Endpoint thumbnail_img userfiles_path path traversal
- CVE-2026-122001 PoCRitlabs TinyWeb Server Header libeay32.dll.html stack-based overflow
- CVE-2026-122011 PoCIObit Malware Fighter DLL permission
- CVE-2026-122021 PoCIntelliants Subrion CMS Blocks Endpoint cross site scripting
- CVE-2026-122031 PoCHKUDS AI-Trader Research Export agents.csv information disclosure
- CVE-2026-122041 PoCShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization
- CVE-2026-122061 PoCGrit42 Grit data_table_entity.rb DataTableEntity sql injection
- CVE-2026-122071 PoCmedkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource injection
- CVE-2026-122081 PoCjsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution
- CVE-2026-122091 PoCRubyLouvre avalon Template Filter index.js prototype pollution
- CVE-2026-122102 PoCsuniversal-tool-calling-protocol python-utcp utcp-gql/utcp-websocket server-side request forgery
- CVE-2026-122111 PoCIntelbras iNVU 7016 FT Web syslog path traversal
- CVE-2026-122141 PoCQihoo 360 Total Security Nucleus Engine Monitoring Logic RpcStringBindingComposeW protection mechanism
- CVE-2026-122161 PoCsvaarala duktape duk_api_bytecode.c memory corruption
- CVE-2026-122171 PoCDVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
- CVE-2026-122181 PoCYealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflow
- CVE-2026-122191 PoCYealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection
- CVE-2026-122201 PoCYealink SIP-T46U Firmware Chunk Upload handler accupgradebychunk mod_upgrade.SparePartsUpload stack-based overflow
- CVE-2026-122211 PoCYealink SIP-T46U Firmware Chunk Upload upgrade sprintf stack-based overflow
- CVE-2026-122221 PoCYealink SIP-T46U Web FastCGI Service bttest mod_webd.BlueToothTest stack-based overflow
- CVE-2026-122231 PoCYealink SIP-T46U Web FastCGI Service tftpuploadiperf mod_webd.TFTPUploadIperf command injection
- CVE-2026-122511 PoCUltimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Selection Field
- CVE-2026-122551 PoCMainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration
- CVE-2026-122701 PoCEverest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endpoints
- CVE-2026-122711 PoCTutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
- CVE-2026-122731 PoCTutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
- CVE-2026-122741 PoCTutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
- CVE-2026-122751 PoCTutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration
- CVE-2026-122761 PoCLA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration
- CVE-2026-122772 PoCsFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal
- CVE-2026-122811 PoCShibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
- CVE-2026-122951 PoCSandbox escape in the DOM: Navigation component
- CVE-2026-123521 PoCIncorrect Authorization
- CVE-2026-123751 PoCUncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
- CVE-2026-123761 PoCAcademy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint
- CVE-2026-123781 PoCBookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
- CVE-2026-123931 PoCWPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation via IDOR
- CVE-2026-123942 PoCsMemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator
- CVE-2026-123951 PoCWP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter
- CVE-2026-123961 PoCWP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rejection
- CVE-2026-123971 PoCWP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
- CVE-2026-124001 PoCFlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API…
- CVE-2026-124151 PoCInvoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
- CVE-2026-124162 PoCsInvoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter
- CVE-2026-124321 PoCStripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId'…
- CVE-2026-124361 PoCImproperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
- CVE-2026-124851 PoCGeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command
- CVE-2026-124921 PoCHappy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user
- CVE-2026-124931 PoCClover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order
- CVE-2026-124971 PoCProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection
- CVE-2026-125001 PoCWP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
- CVE-2026-125011 PoCWP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification
- CVE-2026-125101 PoCAI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR
- CVE-2026-125111 PoCAI Engine < 3.5.5 - Editor+ Arbitrary File Write via Path Traversal
- CVE-2026-125121 PoCQuotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter
- CVE-2026-125131 PoCShared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
- CVE-2026-125141 PoCShared Files < 1.7.70 - Unauthenticated Limited File Upload
- CVE-2026-125161 PoCFediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy
- CVE-2026-125171 PoCFediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint
- CVE-2026-125251 PoCRedux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
- CVE-2026-125261 PoCAdvanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Administrator Account Takeover via Front-End User Update Action
- CVE-2026-125361 PoCAvada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title
- CVE-2026-125821 PoCLibrary Management System < 3.5.8 - Unauthenticated SQL Injection via book_id
- CVE-2026-125831 PoCNewsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field
- CVE-2026-125841 PoCPayment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback
- CVE-2026-125851 PoCAbandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
- CVE-2026-125861 PoCLenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset
- CVE-2026-125921 PoCSlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header
- CVE-2026-126731 PoCLiquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin…
- CVE-2026-126841 PoCCustomer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
- CVE-2026-126851 PoCEscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor
- CVE-2026-126871 PoCProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID
- CVE-2026-126881 PoCProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery
- CVE-2026-126891 PoCProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization
- CVE-2026-126901 PoCProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization
- CVE-2026-126951 PoCminiOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret
- CVE-2026-126961 PoCwpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
- CVE-2026-126971 PoCwpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR
- CVE-2026-126981 PoCwpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment
- CVE-2026-127131 PoCWPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number
- CVE-2026-127201 PoCKirki < 6.0.13 - Unauthenticated PHP Object Injection
- CVE-2026-127211 PoCKirki < 6.0.13 - Unauthenticated SQL Injection
- CVE-2026-127231 PoCKirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library
- CVE-2026-127241 PoCKirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password
- CVE-2026-127701 PoCBerriAI litellm Admin Key key_management_endpoints.py improper authorization
- CVE-2026-127711 PoCBerriAI litellm M2M JWT user_api_key_auth.py improper authorization
- CVE-2026-127721 PoCBerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration
- CVE-2026-127731 PoCBerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
- CVE-2026-127741 PoCBerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery
- CVE-2026-127751 PoCMontodel House-Rental-Management login.php sql injection
- CVE-2026-127761 PoCMontodel House-Rental-Management index.php houses sql injection
- CVE-2026-127781 PoCAOMEI Partition Assistant Kernel Driver ampa10.sys access control
- CVE-2026-127791 PoCAOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access control
- CVE-2026-127801 PoCAOMEI Backupper Kernel Driver amwrtdrv.sys access control
- CVE-2026-127811 PoCEaseUS Partition Master Kernel Driver epmntdrv.sys access control
- CVE-2026-127821 PoCEaseUS Partition Master Kernel Driver EUEDKEPM.sys access control
- CVE-2026-127841 PoCIM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access control
- CVE-2026-127861 PoCEzbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access control
- CVE-2026-127871 PoCzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnection Endpoint deserialization
- CVE-2026-127881 PoCzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
- CVE-2026-127951 PoCBerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
- CVE-2026-127961 PoCBerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
- CVE-2026-127971 PoCBerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
- CVE-2026-127981 PoCBerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_openapi_spec_async server-side request forgery
- CVE-2026-127991 PoCBerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
- CVE-2026-128051 PoCOFFIS DCMTK ofxml.cc parseFile heap-based overflow
- CVE-2026-128061 PoCEdimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow
- CVE-2026-128071 PoCEdimax BR-6478AC V2 POST Request setWAN command injection
- CVE-2026-128081 PoCEdimax BR-6478AC V2 POST Request stainfo command injection
- CVE-2026-128091 PoCEdimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection
- CVE-2026-128101 PoCEdimax BR-6478AC V2 POST Request mp command injection
- CVE-2026-128111 PoCkortix-ai suna Auth Endpoint page.tsx router.push cross site scripting
- CVE-2026-128131 PoCactivepieces File URL file.ts handleUrlFile server-side request forgery
- CVE-2026-128231 PoCBrowserbase Skills Autobrowse Trace Artifact default permission
- CVE-2026-128651 PoCPhoto Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged Parameters
- CVE-2026-128691 PoCHeader Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import
- CVE-2026-128721 PoCWebinfos <= 1.2 - Unauthenticated Arbitrary File Upload
- CVE-2026-128771 PoCSoftware Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter
- CVE-2026-128982 PoCsAll-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal
- CVE-2026-129011 PoCGetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification
- CVE-2026-129061 PoCRTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure
- CVE-2026-129071 PoCRTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation
- CVE-2026-129401 PoCLangflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
- CVE-2026-129481 PoCStored Cross-Site Scripting (XSS)
- CVE-2026-129651 PoCSuper Store Finder < 7.11 - Unauthenticated SQL Injection via ssf_tracking
- CVE-2026-129661 PoCDirect Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions
- CVE-2026-129681 PoCProduct Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload
- CVE-2026-129701 PoCLearnPress < 4.4.1 - Reflected XSS via c_search
- CVE-2026-129711 PoCLearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
- CVE-2026-129721 PoCPayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering
- CVE-2026-129731 PoCPayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification
- CVE-2026-129761 PoCLearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant
- CVE-2026-129781 PoCFunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form
- CVE-2026-129791 PoCFunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer
- CVE-2026-129811 PoCCAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset
- CVE-2026-129821 PoCDocument Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery
- CVE-2026-129831 PoCDinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection
- CVE-2026-129871 PoCEvents Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking Registration
- CVE-2026-129881 PoCWP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding