CVE-2026-1000 to CVE-2026-1999
279 CVEs with public proof-of-concept exploits.
- CVE-2026-10101 PoCStored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege Escalation
- CVE-2026-10481 PoCLigeroSmart index.pl cross site scripting
- CVE-2026-10491 PoCLigeroSmart index.pl cross site scripting
- CVE-2026-10501 PoCrisesoft-y9 Digital-Infrastructure REST Authenticate Endpoint Y9PlatformUtil.java sql injection
- CVE-2026-10561 PoCSnow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal
- CVE-2026-10591 PoCFeMiner wms chkuser.php sql injection
- CVE-2026-10611 PoCxiweicheng TMS FileController.java upload unrestricted upload
- CVE-2026-10621 PoCxiweicheng TMS HtmlUtil.java summary server-side request forgery
- CVE-2026-10631 PoCbastillion-io Bastillion Public Key Management System AuthKeysKtrl.java command injection
- CVE-2026-10641 PoCbastillion-io Bastillion System Management SystemKtrl.java command injection
- CVE-2026-10661 PoCkalcaddle kodbox Compression zip command injection
- CVE-2026-10691 PoCUncontrolled Recursion in GitLab
- CVE-2026-10801 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-10901 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-10921 PoCImproper Validation of Specified Quantity in Input in GitLab
- CVE-2026-10941 PoCImproper Validation of Unsafe Equivalence in Input in GitLab
- CVE-2026-11011 PoCImproper Validation of Specified Quantity in Input in GitLab
- CVE-2026-11051 PoCEasyCMS UserAction.class.php sql injection
- CVE-2026-11061 PoCChamilo LMS Legal Consent SocialController.php deleteLegal improper authorization
- CVE-2026-11072 PoCsEyouCMS Member Avatar Diyajax.php check_userinfo unrestricted upload
- CVE-2026-11112 PoCsSanluan PublicCMS Task Template Management TaskTemplateAdminController.java save path traversal
- CVE-2026-11121 PoCSanluan PublicCMS Trade Address Deletion Endpoint TradeAddressController.java delete improper authorization
- CVE-2026-11151 PoCStored XSS in parisneo/lollms
- CVE-2026-11181 PoCitsourcecode Society Management System add_activity.php sql injection
- CVE-2026-11191 PoCitsourcecode Society Management System delete_activity.php sql injection
- CVE-2026-11201 PoCYonyou KSOA HTTP GET Parameter del_work.jsp sql injection
- CVE-2026-11211 PoCYonyou KSOA HTTP GET Parameter del_workplan.jsp sql injection
- CVE-2026-11221 PoCYonyou KSOA HTTP GET Parameter work_info.jsp sql injection
- CVE-2026-11231 PoCYonyou KSOA HTTP GET Parameter work_mod.jsp sql injection
- CVE-2026-11241 PoCYonyou KSOA HTTP GET Parameter work_report.jsp sql injection
- CVE-2026-11251 PoCD-Link DIR-823X set_wifidog_settings sub_412E7C command injection
- CVE-2026-11261 PoClwj flow SVG File FormResource.java uploadFile unrestricted upload
- CVE-2026-11281 PoCWP eCommerce <= 3.15.1 - Coupon Deletion via CSRF
- CVE-2026-11291 PoCYonyou KSOA HTTP GET Parameter worksadd.jsp sql injection
- CVE-2026-11301 PoCYonyou KSOA HTTP GET Parameter worksadd_plan.jsp sql injection
- CVE-2026-11311 PoCYonyou KSOA HTTP GET Parameter save_catalog.jsp sql injection
- CVE-2026-11321 PoCYonyou KSOA HTTP GET Parameter edit_folder.jsp sql injection
- CVE-2026-11331 PoCYonyou KSOA HTTP GET Parameter folder.jsp sql injection
- CVE-2026-11341 PoCitsourcecode Society Management System expenses.php cross site scripting
- CVE-2026-11351 PoCitsourcecode Society Management System activity.php cross site scripting
- CVE-2026-11361 PoClcg0124 BootDo ContentController save cross site scripting
- CVE-2026-11371 PoCUTT 进取 520W formWebAuthGlobalConfig strcpy buffer overflow
- CVE-2026-11381 PoCUTT 进取 520W ConfigExceptQQ strcpy buffer overflow
- CVE-2026-11391 PoCUTT 进取 520W ConfigExceptMSN strcpy buffer overflow
- CVE-2026-11401 PoCUTT 进取 520W ConfigExceptAli strcpy buffer overflow
- CVE-2026-11411 PoCPHPGurukul News Portal Add Sub-Admin add-subadmins.php improper authorization
- CVE-2026-11421 PoCPHPGurukul News Portal cross-site request forgery
- CVE-2026-11431 PoCTOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg buffer overflow
- CVE-2026-11441 PoCquickjs-ng quickjs Atomics Ops quickjs.c use after free
- CVE-2026-11451 PoCquickjs-ng quickjs quickjs.c js_typed_array_constructor_ta heap-based overflow
- CVE-2026-11491 PoCTotolink LR350 POST Request cstecgi.cgi setDiagnosisCfg command injection
- CVE-2026-11501 PoCTotolink LR350 POST Request cstecgi.cgi setTracerouteCfg command injection
- CVE-2026-11511 PoCtechnical-laohu mpay User Center cross site scripting
- CVE-2026-11521 PoCtechnical-laohu mpay QR Code Image unrestricted upload
- CVE-2026-11531 PoCtechnical-laohu mpay cross-site request forgery
- CVE-2026-11541 PoCSourceCodester E-Learning System Lesson index.php cross site scripting
- CVE-2026-11551 PoCTotolink LR350 cstecgi.cgi setWiFiEasyGuestCfg buffer overflow
- CVE-2026-11561 PoCTotolink LR350 cstecgi.cgi setWiFiBasicCfg buffer overflow
- CVE-2026-11571 PoCTotolink LR350 cstecgi.cgi setWiFiEasyCfg buffer overflow
- CVE-2026-11581 PoCTotolink LR350 POST Request cstecgi.cgi setWizardCfg buffer overflow
- CVE-2026-11591 PoCitsourcecode Online Frozen Foods Ordering System order_online.php sql injection
- CVE-2026-11601 PoCPHPGurukul Directory Management System Search index.php sql injection
- CVE-2026-11611 PoCpbrong hrms recruitment.go UpdateRecruitmentById cross site scripting
- CVE-2026-11621 PoCUTT HiPER 810 setSysAdm strcpy buffer overflow
- CVE-2026-11691 PoCbirkir prime cross-site request forgery
- CVE-2026-11701 PoCbirkir prime GraphQL API graphql information disclosure
- CVE-2026-11711 PoCbirkir prime GraphQL Field graphql denial of service
- CVE-2026-11721 PoCbirkir prime GraphQL Directive graphql denial of service
- CVE-2026-11731 PoCbirkir prime GraphQL Array Based Query Batch graphql denial of service
- CVE-2026-11741 PoCbirkir prime GraphQL Alias graphql resource consumption
- CVE-2026-11751 PoCbirkir prime GraphQL Directive graphql information exposure
- CVE-2026-11761 PoCitsourcecode School Management System index.php sql injection
- CVE-2026-11771 PoCYonyou KSOA HTTP GET Parameter save_folder.jsp sql injection
- CVE-2026-11781 PoCYonyou KSOA HTTP GET Parameter select.jsp sql injection
- CVE-2026-11791 PoCYonyou KSOA HTTP GET Parameter user_popedom.jsp sql injection
- CVE-2026-11821 PoCImproper Removal of Sensitive Information Before Storage or Transfer in GitLab
- CVE-2026-11841 PoCDeserialization of Untrusted Data in GitLab
- CVE-2026-11921 PoCTosei Online Store Management System ネット店舗管理システム imode_alldata.php command injection
- CVE-2026-11931 PoCMineAdmin View view improper authorization
- CVE-2026-11941 PoCMineAdmin Swagger information disclosure
- CVE-2026-11951 PoCMineAdmin JWT Token refresh data authenticity
- CVE-2026-11961 PoCMineAdmin getFileInfoById information disclosure
- CVE-2026-11971 PoCMineAdmin downloadById information disclosure
- CVE-2026-12021 PoCCRMEB LoginController.php appleLogin improper authentication
- CVE-2026-12031 PoCCRMEB JSON Token LoginServices.php remoteRegister improper authentication
- CVE-2026-12072 PoCsPotential SQL injection via raster lookups on PostGIS
- CVE-2026-12081 PoCFriendly Functions for Welcart <= 1.2.5 - Cross-Site Request Forgery to Settings Update
- CVE-2026-12181 PoCBjskzy Zhiyou ERP com.artery.richclient.RichClientService RichClientService.class initRCForm xml external entity reference
- CVE-2026-12301 PoCUse of Incorrectly-Resolved Name or Reference in GitLab
- CVE-2026-12321 PoCAnti-Tamper Bypass in BeyondTrust Privilege Management for Windows
- CVE-2026-12351 PoCWP eCommerce <= 3.15.1 - Unauthenticated PHP Object Injection
- CVE-2026-12771 PoCURL Shortify <= 1.12.1 - Unauthenticated Open Redirect via 'redirect_to' Parameter
- CVE-2026-12813 PoCsKEVA code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2026-12821 PoCImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
- CVE-2026-12961 PoCFrontend Post Submission Manager Lite <= 1.2.7 - Unauthenticated Open Redirect via 'requested_page' Parameter
- CVE-2026-13062 PoCsmidi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action
- CVE-2026-13122 PoCsPotential SQL injection via QuerySet.order_by and FilteredRelation
- CVE-2026-13141 PoC3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated…
- CVE-2026-13221 PoCBusiness Logic Errors in GitLab
- CVE-2026-13241 PoCSangfor Operation and Maintenance Management System SSH Protocol session SessionController os command injection
- CVE-2026-13251 PoCSangfor Operation and Maintenance Security Management System edit_pwd_mall password recovery
- CVE-2026-13261 PoCTotolink NR1800X POST Request cstecgi.cgi setWanCfg command injection
- CVE-2026-13271 PoCTotolink NR1800X POST Request cstecgi.cgi setTracerouteCfg command injection
- CVE-2026-13281 PoCTotolink NR1800X POST Request cstecgi.cgi setWizardCfg buffer overflow
- CVE-2026-13291 PoCTenda AX1803 WifiGuestSet fromGetWifiGuestBasic stack-based overflow
- CVE-2026-13372 PoCsInsufficient escaping of unicode characters in query log
- CVE-2026-13381 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-13403 PoCsKEVA code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2026-135716 PoCsMigration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
- CVE-2026-13682 PoCsVideo Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature Generation
- CVE-2026-13691 PoCConditional CAPTCHA <= 4.0.0 - Open Redirect
- CVE-2026-13751 PoCTutor LMS <= 3.9.5 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion
- CVE-2026-13871 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-13881 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2026-14021 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-14052 PoCsSlider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
- CVE-2026-14061 PoClcg0124 BootDo Host Header AccessControlFilter.java redirectToLogin
- CVE-2026-14071 PoCBeetel 777VR1 UART information disclosure
- CVE-2026-14081 PoCBeetel 777VR1 UART weak password
- CVE-2026-14091 PoCBeetel 777VR1 UART excessive authentication
- CVE-2026-14101 PoCBeetel 777VR1 UART missing authentication
- CVE-2026-14111 PoCBeetel 777VR1 UART access control
- CVE-2026-14121 PoCSangfor Operation and Maintenance Security Management System HTTP POST Request get_clip_img command injection
- CVE-2026-14131 PoCSangfor Operation and Maintenance Security Management System HTTP POST Request port_validate portValidate command injection
- CVE-2026-14141 PoCSangfor Operation and Maintenance Security Management System HTTP POST Request get_Information getInformation command injection
- CVE-2026-14151 PoCGPAC media_export.c gf_media_export_webvtt_metadata null pointer dereference
- CVE-2026-14161 PoCGPAC filedump.c DumpMovieInfo null pointer dereference
- CVE-2026-14171 PoCGPAC filedump.c dump_isom_rtp null pointer dereference
- CVE-2026-14181 PoCGPAC SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds write
- CVE-2026-14191 PoCD-Link DCS700l Web Form setDayNightMode command injection
- CVE-2026-14201 PoCTenda AC23 WifiExtraSet buffer overflow
- CVE-2026-14211 PoCcode-projects Online Examination System Add Pages cross site scripting
- CVE-2026-14221 PoCcode-projects Online Examination System Login Page index.php sql injection
- CVE-2026-14231 PoCcode-projects Online Examination System admin_pic.php unrestricted upload
- CVE-2026-14241 PoCPHPGurukul News Portal Profile Pic unrestricted upload
- CVE-2026-14301 PoCWP Lightbox 2 < 3.0.7 - Admin+ Stored XSS
- CVE-2026-14341 PoCReflected XSS in Omega-PSIR
- CVE-2026-14421 PoCUnitree UPK files Hard-Coded Key
- CVE-2026-14431 PoCcode-projects Online Music Site AdminDeleteUser.php sql injection
- CVE-2026-14441 PoCiJason-Liu Books_Manager add_book_check.php cross site scripting
- CVE-2026-14451 PoCiJason-Liu Books_Manager upload_bookCover.php unrestricted upload
- CVE-2026-14481 PoCD-Link DIR-615 Web Management wiz_policy_3_machine.php os command injection
- CVE-2026-14491 PoCHisense TransTech Smart Bus Management System TireMng.aspx Page_Load sql injection
- CVE-2026-14561 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-14571 PoCAuthenticated RCE Vulnerability Due to Buffer Overflow on TP-Link VIGI C385
- CVE-2026-14581 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-14591 PoCA post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware…
- CVE-2026-14925 PoCsUser Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
- CVE-2026-15001 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-15051 PoCD-Link DIR-615 URL Filter set_temp_nodes.php os command injection
- CVE-2026-15061 PoCD-Link DIR-615 MAC Filter Configuration adv_mac_filter.php os command injection
- CVE-2026-15081 PoCCourt Reservation < 1.10.9 - Event Deletion via CSRF
- CVE-2026-15091 PoCAvada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution
- CVE-2026-15161 PoCImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2026-15201 PoCrethinkdb Secondary Index cross site scripting
- CVE-2026-15211 PoCOpen5GS SGWC s5c-handler.c denial of service
- CVE-2026-15221 PoCOpen5GS SGWC s5c-handler.c sgwc_s5c_handle_modify_bearer_response denial of service
- CVE-2026-15293 PoCsOrg.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validation
- CVE-2026-15321 PoCD-Link DCS-700L Music File Upload Service setUploadMusic uploadmusic path traversal
- CVE-2026-15331 PoCcode-projects Online Music Site AdminAddCategory.php sql injection
- CVE-2026-15341 PoCcode-projects Online Music Site AdminEditUser.php sql injection
- CVE-2026-15351 PoCcode-projects Online Music Site AdminReply.php sql injection
- CVE-2026-15401 PoCSpam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution
- CVE-2026-15411 PoCAvada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference
- CVE-2026-15421 PoCSuper Stage WP <= 1.0.1 - Unauthenticated PHP Object Injection
- CVE-2026-15431 PoCAvada (Fusion) Builder <= 3.15.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Shortcodes
- CVE-2026-15441 PoCD-Link DIR-823X set_mode sub_41E2A0 os command injection
- CVE-2026-15451 PoCitsourcecode School Management System index.php sql injection
- CVE-2026-15461 PoCjishenghua jshERP com.jsh.erp.datasource.mappers.DepotItemMapperEx importItemExcel getBillItemByParam sql injection
- CVE-2026-15471 PoCTotolink A7000R cstecgi.cgi setUnloadUserData command injection
- CVE-2026-15481 PoCTotolink A7000R cstecgi.cgi CloudACMunualUpdateUserdata command injection
- CVE-2026-15491 PoCjishenghua jshERP PluginController uploadPluginConfigFile path traversal
- CVE-2026-15502 PoCsPHPGurukul Hospital Management System Admin Dashboard adminviews.py improper authorization
- CVE-2026-15511 PoCitsourcecode School Management System controller.php sql injection
- CVE-2026-15521 PoCSEMCMS SEMCMS_Info.php sql injection
- CVE-2026-15553 PoCsWebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
- CVE-2026-15571 PoCWP Responsive Images <= 1.0 - Unauthenticated Path Traversal to Arbitrary File Read via src
- CVE-2026-15601 PoCCustom Block Builder – Lazy Blocks <= 4.2.0 - Authenticated (Contributor+) Remote Code Execution
- CVE-2026-15811 PoCwpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection
- CVE-2026-15861 PoCOpen5GS SGWC s11-handler.c ogs_gtp2_f_teid_to_ip denial of service
- CVE-2026-15871 PoCOpen5GS SGWC s11-handler.c sgwc_s11_handle_modify_bearer_request denial of service
- CVE-2026-15881 PoCjishenghua jshERP installByPath install path traversal
- CVE-2026-15891 PoCitsourcecode School Management System index.php sql injection
- CVE-2026-15901 PoCitsourcecode School Management System index.php sql injection
- CVE-2026-15931 PoCitsourcecode Society Management System edit_expenses_query.php sql injection
- CVE-2026-15941 PoCitsourcecode Society Management System add_expenses.php sql injection
- CVE-2026-15951 PoCitsourcecode Society Management System edit_student_query.php sql injection
- CVE-2026-15961 PoCD-Link DWR-M961 formLtefotaUpgradeQuectel sub_419920 command injection
- CVE-2026-15972 PoCsBdtask SalesERP Administrative Endpoint improper authorization
- CVE-2026-15981 PoCBdtask Bhojon All-In-One Restaurant Management System User Information profile cross site scripting
- CVE-2026-15992 PoCsBdtask Bhojon All-In-One Restaurant Management System Checkout placeorder logic error
- CVE-2026-16002 PoCsBdtask Bhojon All-In-One Restaurant Management System Add-to-Cart Submission Endpoint addtocart logic error
- CVE-2026-16011 PoCTotolink A7000R cstecgi.cgi setUploadUserData command injection
- CVE-2026-16031 PoCKEVAn authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific…
- CVE-2026-16061 PoCImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2026-16101 PoCTenda AX12 Pro V2 Telnet Service hard-coded credentials
- CVE-2026-16231 PoCTotolink A7000R cstecgi.cgi setUpgradeFW command injection
- CVE-2026-16241 PoCD-Link DWR-M961 formLtefotaUpgradeFibocom command injection
- CVE-2026-16251 PoCD-Link DWR-M961 SMS Message formSmsManage sub_4250E0 command injection
- CVE-2026-16311 PoCFeeds for YouTube < 2.6.4 - Subscriber+ License Data Deletion
- CVE-2026-16371 PoCTenda AC21 AdvSetMacMtuWan fromAdvSetMacMtuWan stack-based overflow
- CVE-2026-16381 PoCTenda AC21 mDMZSetCfg command injection
- CVE-2026-16572 PoCsEventPrime <= 4.2.8.4 - Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint
- CVE-2026-16591 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-16601 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-16621 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-16631 PoCMissing Authorization in GitLab
- CVE-2026-16681 PoCInput Validation Vulnerability on Multiple Omada Switches
- CVE-2026-16691 PoCArbitrary File Read in Keras via HDF5 External Datasets
- CVE-2026-16801 PoCLocal Privilege Escalation in Local Admin Service
- CVE-2026-16821 PoCFree5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereference
- CVE-2026-16831 PoCFree5GC SMF PFCP handler.go HandlePfcpSessionReportRequest denial of service
- CVE-2026-16851 PoCD-Link DIR-823X Login sub_40AC74 excessive authentication
- CVE-2026-16861 PoCTotolink A3600R app.so setAppEasyWizardConfig buffer overflow
- CVE-2026-16871 PoCTenda HG10 Boa Webserver formSamba command injection
- CVE-2026-16881 PoCitsourcecode Directory Management System index.php sql injection
- CVE-2026-16891 PoCTenda HG10 Login formLogin checkUserFromLanOrWan command injection
- CVE-2026-16901 PoCTenda HG10 formSysCmd system command injection
- CVE-2026-16911 PoCbolo-solo SnakeYAML BackupService.java importMarkdownsSync deserialization
- CVE-2026-17001 PoCprojectworlds House Rental and Property Listing sms.php cross site scripting
- CVE-2026-17011 PoCitsourcecode School Management System index.php sql injection
- CVE-2026-17021 PoCSourceCodester Pet Grooming Management Software User Management user.php improper authorization
- CVE-2026-17051 PoCD-Link DSL-6641K Web ad_virtual_server_vdsl cross site scripting
- CVE-2026-17241 PoCMissing Authentication for Critical Function in GitLab
- CVE-2026-17251 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-17291 PoCAdForest <= 6.0.12 - Authentication Bypass
- CVE-2026-17315 PoCsKEVRemote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
- CVE-2026-17321 PoCImproper Removal of Sensitive Information Before Storage or Transfer in GitLab
- CVE-2026-17331 PoCZhong Bang CRMEB :uni tidyOrder improper authorization
- CVE-2026-17341 PoCZhong Bang CRMEB crontab Endpoint CrontabController.php authorization
- CVE-2026-17351 PoCYealink MeetingBar A30 Diagnostic command injection
- CVE-2026-17361 PoCOpen5GS SGWC s11-handler.c assertion
- CVE-2026-17371 PoCOpen5GS CreateBearerRequest s5c-handler.c sgwc_s5c_handle_create_bearer_request assertion
- CVE-2026-17381 PoCOpen5GS SGWC context.c sgwc_tunnel_add assertion
- CVE-2026-17391 PoCFree5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereference
- CVE-2026-17401 PoCEFM ipTIME A8004T Hidden Hiddenloginsetup timepro.cgi httpcon_check_session_url improper authentication
- CVE-2026-17411 PoCEFM ipTIME A8004T Debug d.cgi httpcon_check_session_url backdoor
- CVE-2026-17421 PoCEFM ipTIME A8004T VPN Service timepro.cgi commit_vpncli_file_upload unrestricted upload
- CVE-2026-17431 PoCDJI Mavic Mini/Air/Spark/Mini SE Enhanced Wi-Fi Pairing authentication replay
- CVE-2026-17441 PoCD-Link DSL-6641K sp_pppoe_user.js doSubmitPPP cross site scripting
- CVE-2026-17451 PoCSourceCodester Medical Certificate Generator App cross-site request forgery
- CVE-2026-17461 PoCJeecgBoot Online Report API loadDictItemByKeyword sql injection
- CVE-2026-17471 PoCAuthentication Bypass Using an Alternate Path or Channel in GitLab
- CVE-2026-17511 PoCMissing Authorization in GitLab
- CVE-2026-17521 PoCIncorrect Authorization in GitLab
- CVE-2026-17531 PoCGutena Forms < 1.6.1 - Contributor+ Arbitrary Limited Options Update
- CVE-2026-17791 PoCUser Registration & Membership <= 5.1.2 - Authentication Bypass
- CVE-2026-18021 PoCZiroom ZHOME A0101 zrMacClone.lua macAddrClone command injection
- CVE-2026-18031 PoCZiroom ZHOME A0101 Dropbear SSH Service default credentials
- CVE-2026-18101 PoCbolo-blog bolo-solo ZIP File BackupService.java unpackFilteredZip path traversal
- CVE-2026-18111 PoCbolo-blog bolo-solo Filename BackupService.java importFromMarkdown path traversal
- CVE-2026-18121 PoCbolo-blog bolo-solo Filename BackupService.java importFromCnblogs path traversal
- CVE-2026-18131 PoCbolo-blog bolo-solo FreeMarker Template PicUploadProcessor.java unrestricted upload
- CVE-2026-18142 PoCsRapid7 Nexpose Insecure Java Keystore Password Generation
- CVE-2026-18302 PoCsQuick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload
- CVE-2026-18351 PoClcg0124 BootDo cross-site request forgery
- CVE-2026-18441 PoCPixelYourSite PRO <= 12.4.0.2 - Unauthenticated Stored Cross-Site Scripting
- CVE-2026-18671 PoCWP Front User Submit < 5.0.6 - Unauthenticated Sensitive Information Exposure
- CVE-2026-18791 PoCHarvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted upload
- CVE-2026-18801 PoCAn Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation…
- CVE-2026-18841 PoCZenTao Webhook model.php fetchHook server-side request forgery
- CVE-2026-18902 PoCsLeadConnector < 3.0.22 - Unauthenticated Rest Call
- CVE-2026-19001 PoCLink Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update
- CVE-2026-19371 PoCYayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action
- CVE-2026-19691 PoCThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload
- CVE-2026-19701 PoCEdimax BR-6258n formStaDrvSetup redirect
- CVE-2026-19711 PoCEdimax BR-6288ACL wiz_WISP24gmanual.asp wiz_WISP24gmanual cross site scripting
- CVE-2026-19721 PoCEdimax BR-6208AC auth_check_userpass2 default credentials
- CVE-2026-19731 PoCFree5GC SMF establishPfcpSession null pointer dereference
- CVE-2026-19741 PoCFree5GC SMF datapath.go ResolveNodeIdToIp denial of service
- CVE-2026-19751 PoCFree5GC pfcp_reports.go identityTriggerType null pointer dereference
- CVE-2026-19761 PoCFree5GC SMF SessionDeletionResponse null pointer dereference
- CVE-2026-19771 PoCisaacwasserman mcp-vegalite-server visualize_data eval code injection
- CVE-2026-19781 PoCkalyan02 NanoCMS User Information pagesdata.txt direct request
- CVE-2026-19791 PoCmruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free
- CVE-2026-19801 PoCWPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure
- CVE-2026-19901 PoCoatpp Type.hpp ObjectWrapper null pointer dereference
- CVE-2026-19911 PoClibuvc UVC Descriptor device.c uvc_scan_streaming null pointer dereference
- CVE-2026-19981 PoCmicropython runtime.c mp_import_all memory corruption