CVE-2026-15000 to CVE-2026-15999
230 CVEs with public proof-of-concept exploits.
- CVE-2026-150132 PoCsSAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
- CVE-2026-150321 PoCwpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion
- CVE-2026-150341 PoCflask-dashboard Flask-MonitoringDashboard cross-site request forgery
- CVE-2026-150351 PoCbentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
- CVE-2026-150361 PoCHarness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization
- CVE-2026-150382 PoCsInfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
- CVE-2026-150391 PoCGift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload
- CVE-2026-150451 PoCWallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount
- CVE-2026-150461 PoCLitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeover via CSRF
- CVE-2026-150471 PoCs2Member < 260805 - Contributor+ Stored XSS via Shortcode
- CVE-2026-150481 PoCGeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat History
- CVE-2026-150491 PoCDepicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import
- CVE-2026-150541 PoCBit Form < 3.1.2 - Unauthenticated Inactive Form Submission
- CVE-2026-150941 PoCWP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
- CVE-2026-151051 PoCdavenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-bounds write
- CVE-2026-151341 PoCCodeAstro Simple Online Leave Management System index.php sql injection
- CVE-2026-151351 PoCcode-projects Online Food Order System edit_food_items.php sql injection
- CVE-2026-151371 PoCcode-projects Interview Management System View.php sql injection
- CVE-2026-151381 PoCtumf mcp-text-editor text_editor.py _validate_file_path path traversal
- CVE-2026-151471 PoCFive Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
- CVE-2026-151481 PoCWP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR
- CVE-2026-151491 PoCWP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
- CVE-2026-151501 PoCmyCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCRED
- CVE-2026-151511 PoCFive Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications
- CVE-2026-151521 PoCWP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass
- CVE-2026-151531 PoCWP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search
- CVE-2026-151581 PoCBlocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
- CVE-2026-151821 PoCGNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
- CVE-2026-151841 PoCGNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
- CVE-2026-151851 PoCGPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds
- CVE-2026-151871 PoCenquirer Public Package API Enquirer.set prototype pollution
- CVE-2026-151881 PoCmanjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmployeeProfileAPIView access control
- CVE-2026-151901 PoCSourceCodester Simple and Nice Shopping Cart Script login.php sql injection
- CVE-2026-151911 PoCmettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization
- CVE-2026-151921 PoCmettle sendportal APIv1 Webhooks mailjet missing authentication
- CVE-2026-151931 PoCAidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
- CVE-2026-151941 PoCOpen5GS AMF context.c amf_context_final use after free
- CVE-2026-152021 PoCYzmCMS Header yzmphp.php get_url cross site scripting
- CVE-2026-152051 PoCPaymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup
- CVE-2026-152061 PoCSMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile
- CVE-2026-152081 PoCRegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
- CVE-2026-152091 PoCJS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR
- CVE-2026-152101 PoCLogin/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force
- CVE-2026-152111 PoCSubscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Capture Token
- CVE-2026-152131 PoCWelcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback
- CVE-2026-152141 PoCSubscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDOR
- CVE-2026-152151 PoCSubscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation
- CVE-2026-152161 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-152171 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-152291 PoCPinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price Manipulation
- CVE-2026-152301 PoCYayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
- CVE-2026-152311 PoCTaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
- CVE-2026-152321 PoCAppointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Deletion
- CVE-2026-152331 PoCNested Pages < 3.2.15 - Editor+ Stored XSS via Post Title
- CVE-2026-152341 PoCCodeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
- CVE-2026-152351 PoCHotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
- CVE-2026-152361 PoCGallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure
- CVE-2026-152371 PoCHotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint
- CVE-2026-152381 PoCHotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR
- CVE-2026-152391 PoCSimple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key
- CVE-2026-152401 PoCCustomer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator Resolution
- CVE-2026-152411 PoCChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
- CVE-2026-152441 PoCHUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
- CVE-2026-152451 PoCBNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
- CVE-2026-152461 PoCRealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass
- CVE-2026-152481 PoCMeta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
- CVE-2026-152491 PoCPatterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link
- CVE-2026-152501 PoCLatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funnel
- CVE-2026-152521 PoCSearch Atlas SEO < 2.6.12 - Subscriber+ Google Indexing API Access
- CVE-2026-152531 PoCEasy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title
- CVE-2026-152541 PoCSimply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode
- CVE-2026-152551 PoCRegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR
- CVE-2026-152561 PoCNinja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
- CVE-2026-152571 PoCRegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification
- CVE-2026-152581 PoCProduct Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter
- CVE-2026-152601 PoCGeo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR
- CVE-2026-152621 PoCAdmin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column
- CVE-2026-152701 PoCD-link DIR-823G Web boa.conf least privilege violation
- CVE-2026-152741 PoClo48576 fbxcel Node Header parser.rs denial of service
- CVE-2026-152761 PoCpdeljanov Symphonia Metadata denial of service
- CVE-2026-152821 PoCInstant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
- CVE-2026-153111 PoCNousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
- CVE-2026-153171 PoCSipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery
- CVE-2026-153181 PoCSipeed PicoClaw MQTT Channel mqtt.go authorization
- CVE-2026-153191 PoCSipeed PicoClaw Launcher access_control.go IPAllowlist access control
- CVE-2026-153201 PoCSipeed PicoClaw pico.go rt.ReloadConfig authorization
- CVE-2026-153211 PoCMyEMS Admin Backend svg.py on_post cross site scripting
- CVE-2026-153261 PoChalo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal
- CVE-2026-153291 PoCzhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosure
- CVE-2026-153301 PoCzhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side request forgery
- CVE-2026-153321 PoCzhayujie CowAgent Message Endpoint channel.py authorization
- CVE-2026-153591 PoCTemplately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite
- CVE-2026-153601 PoCAjax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
- CVE-2026-153611 PoCContent Views < 4.5 - Subscriber+ SQL Injection via preview_request
- CVE-2026-153681 PoCProfile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration
- CVE-2026-153721 PoCWP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
- CVE-2026-153731 PoCEleveo Call Recording Software userAddAction.do improper authorization
- CVE-2026-153741 PoCEleveo Call Recording Software Group roleAddAction.do improper authorization
- CVE-2026-153751 PoCEleveo Call Recording Software LDAP User users_ldap.jsp improper authorization
- CVE-2026-153761 PoCEleveo Call Recording Software statisticReportAction.do improper authorization
- CVE-2026-153771 PoCEleveo Call Recording Software sendlogfile improper authorization
- CVE-2026-153811 PoCWP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter
- CVE-2026-153821 PoCUltimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts
- CVE-2026-153831 PoCBlog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
- CVE-2026-153841 PoCManual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR
- CVE-2026-153851 PoCRT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS
- CVE-2026-153861 PoCMeow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text
- CVE-2026-153871 PoCAcceptance of Extraneous Untrusted Data With Trusted Data in GitLab
- CVE-2026-153881 PoCCookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure
- CVE-2026-154098 PoCsKEVA Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote…
- CVE-2026-154103 PoCsKEVPost-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance…
- CVE-2026-154131 PoCLink Factory - Backdoor
- CVE-2026-154231 PoCIncorrect Authorization in GitLab
- CVE-2026-154301 PoCCVE-2026-15430
- CVE-2026-154701 PoCEleveo Call Recording Software group.jsp improper authorization
- CVE-2026-154711 PoCEleveo Call Recording Software pci_dss_status.jsp improper authorization
- CVE-2026-154721 PoCEleveo Call Recording Software composeEmailAction.do improper authorization
- CVE-2026-154731 PoCEleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization
- CVE-2026-154741 PoCEleveo Call Recording Software audio.jsp improper authorization
- CVE-2026-154751 PoCMiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control
- CVE-2026-154761 PoCQILING Disk Master Kernel Driver diskbckp.sys access control
- CVE-2026-154781 PoCIceHRM UserReport Endpoint EmployeeAttendanceReport.php sql injection
- CVE-2026-154791 PoCH3C NX15 Administrator Password Modification Endpoint modify change_passwd password recovery
- CVE-2026-154801 PoCTrendnet TEW-635BRM Web Service rc start_httpd stack-based overflow
- CVE-2026-154811 PoCTrendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
- CVE-2026-154941 PoCAMTT Hotel Broadband Operation System switch_status.php sql injection
- CVE-2026-154951 PoCSonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
- CVE-2026-154961 PoCSonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection
- CVE-2026-154971 PoCSonicCloudOrg sonic-agent JWT Authentication Filter ExchangeController.java code injection
- CVE-2026-154991 PoCAstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization
- CVE-2026-155001 PoCAstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery
- CVE-2026-155011 PoCAstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery
- CVE-2026-155062 PoCsSecureAge CatchPulse Driver saappctl.sys heap-based overflow
- CVE-2026-155071 PoCcoollabsio Coolify Policy Policies authorization
- CVE-2026-155081 PoCHelicone ai-gateway AWS Metadata Service service.rs build_target_url server-side request forgery
- CVE-2026-155091 PoCLeantime JSON-RPC Endpoint addUser improper authorization
- CVE-2026-155101 PoCLeantime API saveSetting improper authorization
- CVE-2026-155111 PoCComfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection
- CVE-2026-155121 PoCpig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection
- CVE-2026-155131 PoCWavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
- CVE-2026-155141 PoCMetasoft 美特软件 MetaCRM PHPRPC Remote Call rpc.jsp RPCService.query sql injection
- CVE-2026-155151 PoCTencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
- CVE-2026-155161 PoCMacCMS Pro Installation Index.php step5 authorization
- CVE-2026-155171 PoCJinher OA PlanGiveOut.aspx sql injection
- CVE-2026-155181 PoCAREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
- CVE-2026-155201 PoCGNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
- CVE-2026-155211 PoCmakafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
- CVE-2026-155221 PoCtugcantopaloglu godot-mcp run_project index.js validatePath path traversal
- CVE-2026-155231 PoCCodeAstro Simple Online Leave Management System dashboard.php sql injection
- CVE-2026-155241 PoCalioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal
- CVE-2026-155251 PoCkLOsk adloop write.py _validate_urls server-side request forgery
- CVE-2026-155261 PoCaugmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProjectDeps path traversal
- CVE-2026-155271 PoCbetter-auth better-icons scan_project_icons/sync_icon path traversal
- CVE-2026-155281 PoClamaalrajih kicad-mcp path_validator.py protection mechanism
- CVE-2026-155301 PoCWuzhiCMS Attachment API index.php listimage information disclosure
- CVE-2026-155311 PoCyashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserialization
- CVE-2026-155321 PoCSourceCodester Online Book Store System User Management cross site scripting
- CVE-2026-155331 PoCDedeCMS Column Management search.php code injection
- CVE-2026-155351 PoCAkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization
- CVE-2026-155361 PoCitsourcecode Hospital Management System patviewprescription.php sql injection
- CVE-2026-155371 PoCSourceCodester Online Book Store System login.php sql injection
- CVE-2026-155391 PoCSourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload
- CVE-2026-155401 PoCSourceCodester Online Book Store System Administrative index.php php file inclusion
- CVE-2026-155431 PoCTenda CH22 CertListInfo formCertListInfo buffer overflow
- CVE-2026-155441 PoCShibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow
- CVE-2026-155451 PoCShibby Tomato apcupsd tomatodata.cgi main out-of-bounds write
- CVE-2026-155461 PoCShibby Tomato start_jffs2 sub_2D568 os command injection
- CVE-2026-155471 PoCShibby Tomato CIFS Mount sub_2D048 os command injection
- CVE-2026-155571 PoCwaooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight improper authentication
- CVE-2026-155581 PoCCodeAstro Simple Online Leave Management System deletemp.php sql injection
- CVE-2026-155591 PoCCodeAstro Simple Online Leave Management System POST accept.php sql injection
- CVE-2026-155801 PoCPassPortal browser extension: vault token disclosure via unvalidated postMessage
- CVE-2026-155831 PoCSSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
- CVE-2026-155941 PoCwaooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization
- CVE-2026-155951 PoCSourceCodester Class and Exam Timetabling System forsubject.php cross site scripting
- CVE-2026-155961 PoCSourceCodester Class and Exam Timetabling System subject.php cross site scripting
- CVE-2026-155971 PoCSourceCodester Class and Exam Timetabling System edit_exam2.php sql injection
- CVE-2026-155981 PoCantv layout object.js setNestedValue prototype pollution
- CVE-2026-156071 PoCtanstack db Alias Path select.ts select prototype pollution
- CVE-2026-156181 PoCmosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection mechanism
- CVE-2026-156191 PoCmosaxiv clawlet IPv4 tool_web_fetch.go web_fetch server-side request forgery
- CVE-2026-156201 PoCmosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery
- CVE-2026-156221 PoCpoco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
- CVE-2026-156241 PoCnextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDownloadVideo server-side request forgery
- CVE-2026-156251 PoCnextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist
- CVE-2026-156261 PoCnextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile path traversal
- CVE-2026-156271 PoCnextlevelbuilder GoClaw tool.go handleNavigate information disclosure
- CVE-2026-156281 PoCzhayujie chatgpt-on-wechat CowAgent Vision Tool vision.py Vision._download_to_data_url server-side request forgery
- CVE-2026-156291 PoClouisho5 picobot Workspace filesystem.go GetSkill link following
- CVE-2026-156681 PoClouisho5 picobot web Tool web.go WebTool.Execute server-side request forgery
- CVE-2026-156691 PoClouisho5 picobot exec Tool exec.go ExecTool.Execute os command injection
- CVE-2026-156721 PoCitsourcecode Electronic Judging System add_judges.php sql injection
- CVE-2026-156751 PoCcode-projects Online Job Portal EditUser.php sql injection
- CVE-2026-156761 PoCcode-projects Online Job Portal DeleteUser.php sql injection
- CVE-2026-156771 PoCcode-projects Online Job Portal JobSeekerInsert.php unrestricted upload
- CVE-2026-156781 PoCcode-projects Online Job Portal DetailJob.php cross site scripting
- CVE-2026-156901 PoCopen62541 Shared Client ua_client_connect.c responseReadNamespacesArray null pointer dereference
- CVE-2026-156911 PoCTenda BE12 Pro SafeClientFilter fromSafeClientFilter stack-based overflow
- CVE-2026-156921 PoCTenda BE12 Pro SafeUrlFilter fromSafeUrlFilter stack-based overflow
- CVE-2026-156931 PoCTenda BE12 Pro SafeMacFilter fromSafeMacFilter stack-based overflow
- CVE-2026-156941 PoCTenda BE12 Pro SetIpBind fromSetIpBind stack-based overflow
- CVE-2026-156951 PoCTenda BE12 Pro DhcpListClient fromDhcpListClient stack-based overflow
- CVE-2026-156961 PoCTenda BE12 Pro VirtualSer fromVirtualSer stack-based overflow
- CVE-2026-156991 PoCspencermountain compromise Public Root API extend.js nlp.extend prototype pollution
- CVE-2026-157001 PoCDedeCMS Album Publishing Feature zip.class.php ExtractFile path traversal
- CVE-2026-157011 PoCTotolink NR1800X lighttpd formLogout.htm Form_Logout stack-based overflow
- CVE-2026-157031 PoCSourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.php sql injection
- CVE-2026-157061 PoCMissing Authentication for Critical Function in Management API in Baylan Water Meters's BMS
- CVE-2026-157151 PoCSourceCodester Class and Exam Timetabling System exam.php cross site scripting
- CVE-2026-157181 PoCInvalid pointer in the JavaScript: WebAssembly component
- CVE-2026-157321 PoCWGDashboard Server-Side Request Forgery Vulnerability
- CVE-2026-157332 PoCsWGDashboard Remote Code Execution vulnerability
- CVE-2026-157341 PoCWGDashboard Server-Side Template Injection vulnerability
- CVE-2026-157483 PoCsForminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
- CVE-2026-157491 PoCmastergo-design mastergo-magic-mcp mcp__C2d get-c2d.ts execute path traversal
- CVE-2026-157501 PoCmastergo-design mastergo-magic-mcp mcp__getComponentLink get-component-link.ts z.string server-side request forgery
- CVE-2026-157511 PoCmastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workflow.md execute path traversal
- CVE-2026-157521 PoCzhinianboke xianyu-auto-reply Backend User Endpoint users authorization
- CVE-2026-157531 PoCzhinianboke xianyu-auto-reply review approve trusting http permission methods on the server side
- CVE-2026-157761 PoCInappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a…
- CVE-2026-158262 PoCsUser Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username'…
- CVE-2026-159031 PoCOut of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a…
- CVE-2026-159071 PoCH3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
- CVE-2026-159301 PoCSimple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision
- CVE-2026-159311 PoCSimple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name
- CVE-2026-159321 PoCSupport Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal
- CVE-2026-159391 PoCSimple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API
- CVE-2026-159581 PoCEasy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX
- CVE-2026-159641 PoCSingle Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
- CVE-2026-159811 PoCSAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter