CVE-2026-18000 to CVE-2026-18999
149 CVEs with public proof-of-concept exploits.
- CVE-2026-180301 PoCBricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms
- CVE-2026-180311 PoCTabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback
- CVE-2026-180321 PoCWP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass
- CVE-2026-180351 PoCUser Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
- CVE-2026-180371 PoCCreate by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication
- CVE-2026-180381 PoCnextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
- CVE-2026-180391 PoCEssential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
- CVE-2026-180441 PoCEstatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch
- CVE-2026-180461 PoCCookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update
- CVE-2026-180481 PoCWP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal
- CVE-2026-180491 PoCWP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo
- CVE-2026-180501 PoCEvents Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads
- CVE-2026-180511 PoCW3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key
- CVE-2026-180521 PoCManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned Auto-Login Parameters
- CVE-2026-180571 PoCEvents Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection
- CVE-2026-180801 PoCERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect…
- CVE-2026-182001 PoCFoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update
- CVE-2026-182021 PoCJetEngine < 3.8.14 - Author+ Stored XSS via SVG Upload
- CVE-2026-182161 PoCBackup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
- CVE-2026-182201 PoCBinutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing
- CVE-2026-182301 PoCWP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter
- CVE-2026-182311 PoCWP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_user
- CVE-2026-182331 PoCMStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion
- CVE-2026-182341 PoCMStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet
- CVE-2026-182521 PoCInclusion of Functionality from Untrusted Control Sphere in GitLab
- CVE-2026-183151 PoCTrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id'…
- CVE-2026-183561 PoCLimit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Account Email
- CVE-2026-183571 PoCWPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure
- CVE-2026-183663 PoCsEvents Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
- CVE-2026-183911 PoCWooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection
- CVE-2026-183951 PoCChild Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes
- CVE-2026-184011 PoCjackson-core: Number length constraint bypass in non-blocking (async) JSON parser leads to potential denial of service
- CVE-2026-184312 PoCsAvada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
- CVE-2026-184331 PoCIncorrect Authorization in GitLab
- CVE-2026-184641 PoCWP Maps Pro < 6.1.3 - Unauthenticated Denial of Service
- CVE-2026-184651 PoCWP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion
- CVE-2026-184661 PoCWP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation
- CVE-2026-184681 PoCLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address…
- CVE-2026-184691 PoCLogin & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Code Brute Force
- CVE-2026-184701 PoCLogin & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password Response
- CVE-2026-184731 PoCWP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter
- CVE-2026-184741 PoCWP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category
- CVE-2026-185041 PoCfastify vulnerable to schema validation bypass via root primitive coercion mismatch
- CVE-2026-185772 PoCsKEVIncomplete patch leads to administrative account takeover
- CVE-2026-185811 PoCggml-org llama.cpp Jinja Minja Template parser.cpp assertion
- CVE-2026-185821 PoCmz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap
- CVE-2026-185831 PoCmz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of-bounds
- CVE-2026-185911 PoCMeesho Online Shopping App com.meesho.supply cleartext storage
- CVE-2026-185921 PoCosCommerce Email Template Configuration EmailController.php EmailController sql injection
- CVE-2026-185981 PoCGL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection
- CVE-2026-185991 PoCGL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection
- CVE-2026-186001 PoCGL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection
- CVE-2026-186011 PoCGL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection
- CVE-2026-186021 PoCGL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection
- CVE-2026-186031 PoCCancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure via Reorder AJAX Actions
- CVE-2026-186041 PoCtextPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components
- CVE-2026-186051 PoCCheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search path
- CVE-2026-186061 PoCRazer RzUpdateService Named Pipe RzUpdateService.exe privileges management
- CVE-2026-186071 PoCWavlink NU516 lighttpd upload.cgi strcpy stack-based overflow
- CVE-2026-186101 PoCNewType WebEIP EIP_Com_FileList.aspx improper authentication
- CVE-2026-186121 PoCGL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection
- CVE-2026-186131 PoCGL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
- CVE-2026-186141 PoCGL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection
- CVE-2026-186151 PoCGL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection
- CVE-2026-186161 PoCGL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection
- CVE-2026-186311 PoCjeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization
- CVE-2026-186321 PoClanggenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine
- CVE-2026-186411 PoCSangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os…
- CVE-2026-186441 PoCdanpros HTMLy Delete Username Endpoint htmly.php unlink path traversal
- CVE-2026-186451 PoCdanpros HTMLy Admin Content Endpoint admin.php add_content path traversal
- CVE-2026-186461 PoCdanpros HTMLy Author Name htmly.php path traversal
- CVE-2026-186471 PoCjina-ai reader Crawler/Puppeteer crawler.ts isValidTLD server-side request forgery
- CVE-2026-186481 PoCBlix Email Blue Mail Calendar App react-native-receive-sharing-intent FileDirectory.getFileFromUri path traversal
- CVE-2026-186491 PoCGst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
- CVE-2026-186531 PoCWP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter
- CVE-2026-186661 PoCLibrary Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
- CVE-2026-186821 PoCOpenAkita File Upload API upload cross site scripting
- CVE-2026-186841 PoCGL.iNet GL-MT3000 modem.so glc remove_profile command injection
- CVE-2026-186851 PoCGL.iNet GL-MT3000 modem.so glc set_upgrade command injection
- CVE-2026-186861 PoCGL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
- CVE-2026-187181 PoCGhidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
- CVE-2026-187201 PoCkalcaddle kodbox msgWarning Plugin action improper authorization
- CVE-2026-187211 PoCkalcaddle kodbox SSO API Login apiLogin redirect
- CVE-2026-187221 PoCdiaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authorization
- CVE-2026-187231 PoCdiaowen DWSurvey Survey Status up-survey-status.do improper authorization
- CVE-2026-187291 PoCLangflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
- CVE-2026-187411 PoCWorksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Location and Description Fields
- CVE-2026-187661 PoCchetans9 core-php-admin-panel customers.php sql injection
- CVE-2026-187731 PoCNousResearch hermes-agent Quick run.py _check_slash_access authorization
- CVE-2026-187741 PoCNousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgery
- CVE-2026-187751 PoCNousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot server-side request forgery
- CVE-2026-187761 PoCTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions
- CVE-2026-187771 PoCTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_status
- CVE-2026-187781 PoCTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX Actions
- CVE-2026-187791 PoCTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked
- CVE-2026-187811 PoCDrag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via Control Character Filename Bypass
- CVE-2026-187841 PoCo6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-based overflow
- CVE-2026-187851 PoCo6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after free
- CVE-2026-187861 PoCCheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass
- CVE-2026-187871 PoCGL.iNet AX1800 RPC Endpoint oui-rpc.lua remove_rule command injection
- CVE-2026-187882 PoCsTrippo ResponsiveFilemanager dialog.php unrestricted upload
- CVE-2026-187891 PoCEzoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes
- CVE-2026-187901 PoCSysterel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-bounds
- CVE-2026-188071 PoCECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers
- CVE-2026-188111 PoCH3C NX15 esps add command injection
- CVE-2026-188121 PoCH3C NX15 esps esps.ipv6.wan command injection
- CVE-2026-188131 PoCH3C NX15 esps delete command injection
- CVE-2026-188141 PoCH3C NX15 esps reload.reload_config command injection
- CVE-2026-188191 PoCRackTables cross-site request forgery
- CVE-2026-188521 PoCepsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition
- CVE-2026-188531 PoCZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal
- CVE-2026-188541 PoCShandong Hoteam PDM Product Data Management System DataService GetStoredClassByFilter sql injection
- CVE-2026-188591 PoCESAFENET CDG usbkey;logindojojs sql injection
- CVE-2026-188951 PoCUTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow
- CVE-2026-188961 PoClavkush-maurya Student-Registration-System changepass.php sql injection
- CVE-2026-188971 PoCUTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow
- CVE-2026-188981 PoCUTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflow
- CVE-2026-189001 PoCH3C NX15 Backend RPC esps file.exec os command injection
- CVE-2026-189011 PoCH3C NX15 Web API esps service.add routine
- CVE-2026-189021 PoCH3C NX15 esps repeaterproc command injection
- CVE-2026-189031 PoCyeqifu warehouse FileController.java path traversal
- CVE-2026-189071 PoCPathTravelsal Vulnerability in com.talpa.hibrowser
- CVE-2026-189271 PoCimranrisal-dev Student-Management-System Shared Upload Helper student_profile_pic.php storeProfileImage unrestricted upload
- CVE-2026-189341 PoCRSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post Deletion
- CVE-2026-189371 PoCBroken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection
- CVE-2026-189431 PoCWPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure
- CVE-2026-189451 PoCWP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation
- CVE-2026-189461 PoCContact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable Filename
- CVE-2026-189531 PoCImproper limitation of a pathname to a restricted directory in aws-transform-mcp-server
- CVE-2026-189581 PoCimranrisal-dev Student-Management-System Login loginCheckTest.php sql injection
- CVE-2026-189591 PoCyushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal
- CVE-2026-189601 PoCBlock User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords
- CVE-2026-189621 PoCWP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authorization
- CVE-2026-1896312 PoCsKeycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2026-189681 PoCttttonyhe OBlog tags.php cross site scripting
- CVE-2026-189691 PoCRongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted upload
- CVE-2026-189701 PoCRongzhitong Visual Integrated Command and Dispatch Platform findAll sql injection
- CVE-2026-189731 PoCheshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery
- CVE-2026-189741 PoCheshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure
- CVE-2026-189761 PoCNousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment
- CVE-2026-189801 PoCnearai ironclaw shell.rs classify_command_risk command injection
- CVE-2026-189901 PoCletta-ai LettaBot API Status Route server.ts missing authentication
- CVE-2026-189911 PoCnanocoai NanoClaw send_file core.ts path traversal
- CVE-2026-189921 PoCzhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization
- CVE-2026-189931 PoCNousResearch hermes-agent Memory Toolset model_tools.py access control
- CVE-2026-189951 PoCnetease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure
- CVE-2026-189961 PoCcosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.checkShellCommand privileges assignment
- CVE-2026-189971 PoCcosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization
- CVE-2026-189981 PoCcosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization