CVE-2026-19000 to CVE-2026-19999
249 CVEs with public proof-of-concept exploits.
- CVE-2026-190001 PoCJeecgBoot Anonymous Chat Attachment send server-side request forgery
- CVE-2026-190051 PoCnanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent privileges management
- CVE-2026-190061 PoCmf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
- CVE-2026-190071 PoCmf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management
- CVE-2026-190081 PoCmf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
- CVE-2026-190091 PoCTinyAGI Message API Endpoint response.ts collectFiles file inclusion
- CVE-2026-190101 PoCTinyAGI Message API Endpoint index.ts processMessage authorization
- CVE-2026-190111 PoCTinyAGI agents.ts buildSystemPrompt file inclusion
- CVE-2026-190191 PoCpoco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
- CVE-2026-190201 PoCitsourcecode Hospital Management System servicetype.php sql injection
- CVE-2026-190211 PoCSourceCodester Computer Repair Shop Management System Master.php delete_product sql injection
- CVE-2026-190341 PoCShibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection
- CVE-2026-190351 PoCShibby Tomato qoslimit new_qoslimit_start os command injection
- CVE-2026-190361 PoCShibby Tomato wanoptions sub_40F88C os command injection
- CVE-2026-190371 PoCWonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral workflow
- CVE-2026-190491 PoCProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie
- CVE-2026-190501 PoCProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate
- CVE-2026-190521 PoCProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls
- CVE-2026-190531 PoCProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter
- CVE-2026-190551 PoCProSolution WP Client < 2.0.11 - Reflected XSS via Multiple Parameters
- CVE-2026-190561 PoCProSolution WP Client < 2.0.11 - Reflected XSS via 'page' Parameter
- CVE-2026-190581 PoCFoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection
- CVE-2026-190591 PoCFoundationAgents MetaGPT editor.py read path traversal
- CVE-2026-190601 PoCFoundationAgents MetaGPT code injection
- CVE-2026-190621 PoCchiuwingyan house selectall.action sql injection
- CVE-2026-190671 PoCitsourcecode Hospital Management System treatment.php sql injection
- CVE-2026-190681 PoCitsourcecode Hospital Management System treatmentdetail.php sql injection
- CVE-2026-190691 PoCitsourcecode Hospital Management System treatmentrecord.php sql injection
- CVE-2026-190701 PoCitsourcecode Hospital Management System viewadmin.php sql injection
- CVE-2026-190711 PoCitsourcecode Hospital Management System viewappointment.php sql injection
- CVE-2026-190731 PoCOrder Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure
- CVE-2026-190741 PoCAdvanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom Field Disclosure
- CVE-2026-190751 PoCAll-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Parameter
- CVE-2026-190771 PoCCopy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization
- CVE-2026-190841 PoCShared Files < 1.7.70 - Unauthenticated Arbitrary File Read
- CVE-2026-190851 PoCCopy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure
- CVE-2026-190881 PoCShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication
- CVE-2026-190891 PoCProduct Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload
- CVE-2026-190922 PoCsTutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing
- CVE-2026-190931 PoCTutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path
- CVE-2026-190941 PoCTutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters
- CVE-2026-191081 PoCMZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
- CVE-2026-191101 PoCDataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting
- CVE-2026-191161 PoCWP User Frontend < 4.3.11 - Subscriber+ PHP Object Injection via Frontend Post Edit Form
- CVE-2026-191891 PoCPower Sofware PowerISO Kernel Driver scdemu.sys privileges management
- CVE-2026-191901 PoCStableBit Scanner ScannerService Scanner.Service.exe permission
- CVE-2026-191911 PoCStableBit DrivePool DrivePoolService DrivePool.Service.exe permission
- CVE-2026-191921 PoCDeepCool DisplayService DeepCoolDisplayService.exe access control
- CVE-2026-191931 PoCJiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control
- CVE-2026-191951 PoCV-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control
- CVE-2026-191961 PoCSourceCodester Photo Share Website ajax.php login sql injection
- CVE-2026-192061 PoCMZ Automation libiec61850 ASDU Element sv_subscriber.c SVReceiver_stopThreadless heap-based overflow
- CVE-2026-192071 PoCPHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting
- CVE-2026-192081 PoCWonderTrader TraderDD.cpp queryTrades behavioral workflow
- CVE-2026-192091 PoCSourceCodester Photo Share Website index.php home cross site scripting
- CVE-2026-192101 PoCSourceCodester Photo Share Website ajax.php save_upload unrestricted upload
- CVE-2026-192111 PoCSourceCodester Photo Share Website ajax.php signup sql injection
- CVE-2026-192121 PoCWonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
- CVE-2026-192131 PoCWonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
- CVE-2026-192171 PoCRoyal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget
- CVE-2026-192201 PoCForminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalation
- CVE-2026-192211 PoCForminator Forms < 1.57.0.5 - Admin+ Network-Wide RCE via Hub Connector API Key on Multisite
- CVE-2026-192221 PoCForminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role Bypass
- CVE-2026-192231 PoCSmush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite
- CVE-2026-192251 PoCDefender Security < 6.2.0 - Admin+ Network-Wide RCE via Hub Connector on Multisite
- CVE-2026-192261 PoCRoyal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordion Widget Effect Settings
- CVE-2026-192291 PoCSourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
- CVE-2026-192301 PoCSourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting
- CVE-2026-192311 PoCSourceCodester Simple Doctors Appointment System ajax.php delete_appointment sql injection
- CVE-2026-192431 PoCHKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection
- CVE-2026-192441 PoCHKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control
- CVE-2026-192451 PoCHKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure
- CVE-2026-192461 PoCHKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery
- CVE-2026-192511 PoCUltimate Member < 2.13.0 - Unauthenticated Unapproved Comment Disclosure via Profile Activity
- CVE-2026-192591 PoCMZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_varAccessSpecToObjectReference heap-based overflow
- CVE-2026-192681 PoCabdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection
- CVE-2026-192861 PoCLangflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
- CVE-2026-192951 PoCLangflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
- CVE-2026-193411 PoCUTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow
- CVE-2026-193421 PoCcode-projects Task Management System Login index.php improper authentication
- CVE-2026-193431 PoCcode-projects Task Management System AdminLogin.php sql injection
- CVE-2026-193441 PoCcode-projects Task Management System comment_count_user.php sql injection
- CVE-2026-193451 PoCcode-projects Task Management System UpdateTaskStatus.php authorization
- CVE-2026-193461 PoCTenda CH22 CertListInfo formCertListInfo command injection
- CVE-2026-193471 PoCitsourcecode Hospital Management System viewdoctor.php sql injection
- CVE-2026-193481 PoCShenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection
- CVE-2026-193511 PoCdresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection
- CVE-2026-193521 PoCmifi lossless-cut Built-in HTTP API Service httpServer.ts server-side request forgery
- CVE-2026-193531 PoCDedeCMS Installation Wizard index.php _4_Setup file inclusion
- CVE-2026-193611 PoCmacrozheng mall mall-portal getAuthCode password recovery
- CVE-2026-193641 PoCitsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection
- CVE-2026-193751 PoCdmitriiweb article-scraper-mcp server.py fetch_article server-side request forgery
- CVE-2026-193761 PoCUasoft Badaso File API api.php class permission
- CVE-2026-193781 PoCcode-projects Task Management System CommentSave.php cross site scripting
- CVE-2026-193791 PoCEFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection
- CVE-2026-193801 PoCMullvad wireguard.sys IOCTL AdapterState reference count
- CVE-2026-193811 PoCKingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management
- CVE-2026-193821 PoCAlmico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak
- CVE-2026-193831 PoCsaithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload
- CVE-2026-193841 PoCSourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection
- CVE-2026-194061 PoCEasy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via REST Appointments Listing
- CVE-2026-194161 PoCKiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR
- CVE-2026-194171 PoCKiviCare < 4.5.4 - Patient+ Arbitrary Media Attachment Read via IDOR
- CVE-2026-194231 PoCUltimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Role Field on Profile Forms
- CVE-2026-194301 PoCCatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via download-all
- CVE-2026-194351 PoCCopy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure
- CVE-2026-194531 PoCJetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore Admin User Selection
- CVE-2026-194541 PoCJetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup Download
- CVE-2026-194789 PoCsImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2026-194901 PoCNetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
- CVE-2026-195001 PoCSureForms contains an uncontrolled resource consumption vulnerability
- CVE-2026-195011 PoCCVE-2026-19501
- CVE-2026-195986 PoCsPods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
- CVE-2026-196131 PoCECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source
- CVE-2026-196151 PoCAdmin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC
- CVE-2026-196262 PoCsRemote Code Execution
- CVE-2026-196323 PoCsTranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
- CVE-2026-196503 PoCsCross-Site Request Forgery (CSRF) in GitLab
- CVE-2026-196792 PoCsImproper Input Validation
- CVE-2026-196813 PoCsCommand Injection
- CVE-2026-196971 PoCGutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload
- CVE-2026-196981 PoCGutenKit < 2.5.1 - Contributor+ Stored CSS Injection
- CVE-2026-196991 PoCGutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure
- CVE-2026-197041 PoCComments – wpDiscuz < 7.6.66 - Unauthenticated Comment Disclosure via SQLi
- CVE-2026-197091 PoCMembership For WooCommerce < 3.1.2 - Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass
- CVE-2026-197101 PoCSourceCodester Simple Student Information System view_department.php sql injection
- CVE-2026-197111 PoCPremium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request
- CVE-2026-197121 PoCMasteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description
- CVE-2026-197141 PoCSimple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience Validation
- CVE-2026-197151 PoCWP OAuth Server < 6.3.1 - Unauthenticated OAuth Token and User Data Disclosure via Debug Log File
- CVE-2026-197171 PoCCatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API
- CVE-2026-197181 PoCBlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connection Key Recovery
- CVE-2026-197191 PoCSocial Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stored XSS via Post Title
- CVE-2026-197221 PoCWPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup Restore
- CVE-2026-197231 PoCSocial Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via Pin It Share Handler
- CVE-2026-197251 PoCWPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connect
- CVE-2026-197261 PoCVisualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure
- CVE-2026-197281 PoCExtra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileupload
- CVE-2026-197451 PoCCalix GigaSpire Web Management utilities_configurationsave.cgi denial of service
- CVE-2026-197501 PoCTenda CH/CP/TX3 SSH hard-coded password
- CVE-2026-197511 PoCEnzoVezzaro mcp-dominican-layer parse-csv tool index.ts axios.get server-side request forgery
- CVE-2026-197521 PoCEnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side request forgery
- CVE-2026-197531 PoCModel Context Protocol mcp-rdf-explorer MCP Server server.py explore_url server-side request forgery
- CVE-2026-197561 PoCDromara lamp-cloud Code Generator DefGenProjectController.java path traversal
- CVE-2026-197571 PoCDromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal
- CVE-2026-197581 PoCdromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal
- CVE-2026-197621 PoCDTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal
- CVE-2026-197641 PoCRaisecom Communication Command and Dispatch Management Platform getpwd.php sql injection
- CVE-2026-197651 PoCeyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource server-side request forgery
- CVE-2026-197671 PoCitsourcecode Hospital Management System viewdoctortimings.php sql injection
- CVE-2026-197701 PoCfeedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forgery
- CVE-2026-197821 PoCWPS Bidouille < 1.33.5 - Subscriber+ User Email Disclosure via wps_get_users
- CVE-2026-197841 PoCfrancoisjacquet RosarioSIS Referrals.php DBUpdate authorization
- CVE-2026-197871 PoCSourceCodester Air Cargo Management System Master.php save_cargo_type sql injection
- CVE-2026-197881 PoCTenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow
- CVE-2026-197891 PoCTenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow
- CVE-2026-197901 PoCTenda G0 httpd Web Management module formSetPortMirror stack-based overflow
- CVE-2026-197911 PoCTenda G0 httpd web management interface module addStaticRoute stack-based overflow
- CVE-2026-197921 PoCTenda G0 httpd web management interface module setPortMapping buffer overflow
- CVE-2026-198111 PoCTOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
- CVE-2026-198121 PoCTOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
- CVE-2026-198131 PoCTOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow
- CVE-2026-198141 PoCTOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow
- CVE-2026-198151 PoCTOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow
- CVE-2026-198211 PoCTenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow
- CVE-2026-198221 PoCTenda W20E QoS Edit editQos lstAdd stack-based overflow
- CVE-2026-198231 PoCTenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
- CVE-2026-198241 PoCTenda W20E addIpMacBind ipMacBindListStore stack-based overflow
- CVE-2026-198251 PoCSourceCodester Simple Client Management System Master.php save_service sql injection
- CVE-2026-198261 PoCalldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization
- CVE-2026-198271 PoCalldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal
- CVE-2026-198281 PoC648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal
- CVE-2026-198291 PoC648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal
- CVE-2026-198341 PoCWebkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization
- CVE-2026-198351 PoCWebkul Bagisto Customer Item Deletion Endpoint access control
- CVE-2026-198361 PoCWebkul Bagisto Backend Customer Detail Feature view authorization
- CVE-2026-198371 PoCWebkul Bagisto Customer Search search information disclosure
- CVE-2026-198381 PoCWebkul Bagisto Backend Reporting Endpoint sales authorization
- CVE-2026-198391 PoCSourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload
- CVE-2026-198421 PoCSAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite
- CVE-2026-198441 PoCTOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow
- CVE-2026-198451 PoCTOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow
- CVE-2026-198461 PoCTOTOLINK A800R firewall.so cstecgi.cgi setUrlFilterRules stack-based overflow
- CVE-2026-198471 PoCTOTOLINK A800R wps.so cstecgi.cgi setWiFiWpsConfig stack-based overflow
- CVE-2026-198481 PoCProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Display Name
- CVE-2026-198891 PoCServer-Side Request Forgery (SSRF) in GitLab AI Gateway
- CVE-2026-198941 PoCitsourcecode Hospital Management System viewmedicine.php sql injection
- CVE-2026-198951 PoCopensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive authentication
- CVE-2026-198961 PoCmangroup dtale Flask Session Cookie app.py build_secret_key random values
- CVE-2026-198971 PoCmangroup dtale Login Endpoint auth.py login excessive authentication
- CVE-2026-198981 PoCVictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authentication
- CVE-2026-198991 PoCSourceCodester Class and Exam Timetabling System edit_teacher.php sql injection
- CVE-2026-199002 PoCsLB-LINK X-PRO shadow hard-coded credentials
- CVE-2026-199011 PoCLB-LINK X-PRO easycwmp hard-coded credentials
- CVE-2026-199031 PoCSourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
- CVE-2026-199041 PoCSourceCodester Online Book Store System System Settings index.php site_settings cross site scripting
- CVE-2026-199051 PoCJinher OA attendance_out_approve.aspx sql injection
- CVE-2026-199121 PoCCVE-2026-19912
- CVE-2026-199131 PoCCVE-2026-19913
- CVE-2026-199141 PoCWelcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter
- CVE-2026-199161 PoCcode-projects Online Food Order System edit_food_items.php cross site scripting
- CVE-2026-199171 PoCcode-projects Online Food Order System delete_food_items1.php sql injection
- CVE-2026-199181 PoCSpaceX Starlink Router Gen 3 gRPC Management get_status access control
- CVE-2026-199191 PoCcode-projects Online Shopping System Login login.php sql injection
- CVE-2026-199201 PoCcode-projects Online Shopping System action.php sql injection
- CVE-2026-199211 PoCcode-projects Online Shopping System homeaction.php sql injection
- CVE-2026-199221 PoCcode-projects Online Shopping System checkout.php cross site scripting
- CVE-2026-199231 PoCcode-projects Online Shopping System checkout_process.php sql injection
- CVE-2026-199241 PoCTenda AC10 httpd R7WebsSecurityHandler improper authentication
- CVE-2026-199251 PoCSourceCodester Stock Management System Master.php delete_supplier sql injection
- CVE-2026-199261 PoCEvergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection
- CVE-2026-199271 PoCOpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery
- CVE-2026-199281 PoCOpenBoxes Role Interceptor RoleInterceptor.groovy needManager privileges management
- CVE-2026-199291 PoCOpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elements in template engine
- CVE-2026-199301 PoCDolibarr User Cloning card.php ldap injection
- CVE-2026-199321 PoCDefaultFuction Notice-System-Managent NoticeController execute GroovyShell.evaluate code injection
- CVE-2026-199331 PoCDefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflow
- CVE-2026-199341 PoCitsourcecode Hospital Management System vieworder.php sql injection
- CVE-2026-199551 PoCTrailDB TOC Validation tdb.c tdb_open out-of-bounds
- CVE-2026-199571 PoCgraphlit graphlit-mcp-server ssrf-test Endpoint tools.ts fetch server-side request forgery
- CVE-2026-199581 PoCiatsiuk pptr-mcp execute Tool vm-executor.ts executeCode code injection
- CVE-2026-199591 PoCEdimax EW-7478APC formWanTcpipSetup stack-based overflow
- CVE-2026-199601 PoCEdimax EW-7478APC formWlbasic command injection
- CVE-2026-199611 PoCEdimax EW-7478APC formWlSiteSurvey buffer overflow
- CVE-2026-199621 PoCEdimax EW-7478APC setWAN command injection
- CVE-2026-199631 PoCEdimax EW-7478APC stainfo command injection
- CVE-2026-199641 PoCJij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection
- CVE-2026-199651 PoCautomad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy
- CVE-2026-199661 PoCCodeCanyon TimeCamp Integration for CRM Contact Information Update save_contact authorization
- CVE-2026-199671 PoCOpen Asset Import Library Assimp File Compression.cpp decompressBlock heap-based overflow
- CVE-2026-199681 PoCOpen Asset Import Library Assimp 3DGS MDL7 Model LWOLoader.h ReadFaces_3DGS_MDL7 heap-based overflow
- CVE-2026-199691 PoCOpen Asset Import Library Assimp 3DGS MDL7 Model Output Mesh Generator MDLLoader.cpp GenerateOutputMeshes_3DGS_MDL7 buffer overflow
- CVE-2026-199701 PoCOpen Asset Import Library Assimp Node MDLLoader.cpp AddBonesToNodeGraph_3DGS_MDL7 heap-based overflow
- CVE-2026-199721 PoCitsourcecode Hospital Management System viewpatient.php sql injection
- CVE-2026-199731 PoCitsourcecode Hospital Management System viewpaymentreport.php sql injection
- CVE-2026-199761 PoCCOMFAST CF-N1-S mbox-config sub_44A968 command injection
- CVE-2026-199771 PoCEFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication
- CVE-2026-199781 PoCjiantao88 android-mcp-server Command Execution index.js child_process.exec os command injection
- CVE-2026-199841 PoCjkawamoto mcp-florence2 __init__.py get_images server-side request forgery
- CVE-2026-199861 PoCAdblock for Youtube Extension Event Listener contentscript.js updateDynamicRules improper authorization
- CVE-2026-199881 PoCAlaev SEO Tools Extension Popup UI popup.html addDiv cross site scripting
- CVE-2026-199921 PoCOrange View Limited DualSafe Password Manager & Digital Vault Extension postMessage-based Bridge information disclosure
- CVE-2026-199931 PoCWebkul Bagisto RMA State Validation update-status behavioral workflow
- CVE-2026-199941 PoCWebkul Bagisto Configuration Management execute authorization
- CVE-2026-199951 PoCWebkul Bagisto RMA Message send-message cross site scripting
- CVE-2026-199961 PoCWebkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management
- CVE-2026-199971 PoCWebkul Bagisto Backend Sales RMA Endpoint requests authorization
- CVE-2026-199981 PoCcode-projects Online Shopping System offersmail.php cross site scripting
- CVE-2026-199991 PoCOpen Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.cpp ParseBoneTrafoKeys_3DGS_MDL7 buffer overflow