CVE-2026-20000 to CVE-2026-20999
36 CVEs with public proof-of-concept exploits.
- CVE-2026-200001 PoCitsourcecode Hospital Management System viewprescriptionrecord.php sql injection
- CVE-2026-200451 PoCKEVCisco Unified Communications Products Remote Code Execution Vulnerability
- CVE-2026-200793 PoCsCisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
- CVE-2026-201278 PoCsKEVCisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
- CVE-2026-201313 PoCsKEVCisco Secure Firewall Management Center Software Remote Code Execution Vulnerability
- CVE-2026-201691 PoCCisco IoT Field Network Director Command Injection Vulnerability
- CVE-2026-201801 PoCCisco Identity Services Engine Multiple Remote Code Execution Vulnerability
- CVE-2026-201825 PoCsKEVCisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
- CVE-2026-202231 PoCCisco Secure Workload Unauthorized API Access Vulnerability
- CVE-2026-202241 PoCCisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability
- CVE-2026-202302 PoCsKEVCisco Unified Communications Manager Server-Side Request Forgery Vulnerability
- CVE-2026-202453 PoCsKEVCisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
- CVE-2026-202511 PoCRemote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
- CVE-2026-202538 PoCsKEVUnauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
- CVE-2026-202622 PoCsKEVCisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
- CVE-2026-203031 PoCCisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
- CVE-2026-204041 PoCIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has…
- CVE-2026-204521 PoCIn wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code…
- CVE-2026-206131 PoCThe ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before…
- CVE-2026-206372 PoCsA use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and…
- CVE-2026-206431 PoCA cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security…
- CVE-2026-206601 PoCA path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and…
- CVE-2026-206851 PoCAn attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved…
- CVE-2026-206872 PoCsA use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and…
- CVE-2026-206981 PoCThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4,…
- CVE-2026-207003 PoCsKEVA memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3,…
- CVE-2026-207061 PoCGitea repository archive downloads bypass token scope checks
- CVE-2026-208052 PoCsKEVDesktop Window Manager Information Disclosure Vulnerability
- CVE-2026-208173 PoCsWindows Error Reporting Service Elevation of Privilege Vulnerability
- CVE-2026-208201 PoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2026-2084114 PoCsWindows Notepad App Remote Code Execution Vulnerability
- CVE-2026-208968 PoCsGitea Docker image trusts spoofable reverse-proxy headers by default
- CVE-2026-209291 PoCWindows HTTP.sys Elevation of Privilege Vulnerability
- CVE-2026-209801 PoCImproper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.
- CVE-2026-209811 PoCImproper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary…
- CVE-2026-209821 PoCPath traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.