CVE-2026-22000 to CVE-2026-22999
93 CVEs with public proof-of-concept exploits.
- CVE-2026-220021 PoCVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are…
- CVE-2026-220031 PoCVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions…
- CVE-2026-220041 PoCVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45,…
- CVE-2026-220051 PoCVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are…
- CVE-2026-220061 PoCVulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported…
- CVE-2026-220071 PoCVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:…
- CVE-2026-220081 PoCVulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to…
- CVE-2026-220091 PoCVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are…
- CVE-2026-220101 PoCVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications…
- CVE-2026-220131 PoCVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:…
- CVE-2026-220141 PoCVulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported…
- CVE-2026-220151 PoCVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected…
- CVE-2026-220161 PoCVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:…
- CVE-2026-220171 PoCVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are…
- CVE-2026-220181 PoCVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component:…
- CVE-2026-220191 PoCVulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search). The supported…
- CVE-2026-220311 PoCFastify Middie Middleware Path Bypass
- CVE-2026-220331 PoCLabel Studio vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
- CVE-2026-220371 PoC@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
- CVE-2026-220381 PoCAutoGPT's API Keys and Secrets Logged in Plaintext in Stagehand Integration Blocks
- CVE-2026-220391 PoCKyverno Cross-Namespace Privilege Escalation via Policy apiCall
- CVE-2026-220421 PoCRustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
- CVE-2026-220431 PoCRustFS has IAM deny_only Short-Circuit that Allows Privilege Escalation via Service Account Minting
- CVE-2026-221841 PoCzlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()
- CVE-2026-221852 PoCsOpenLDAP LMDB mdb_load Heap Buffer Underflow in readline()
- CVE-2026-221861 PoCBio-Formats <= 8.3.0 XXE in Leica XLEF Metadata Parser
- CVE-2026-221872 PoCsBio-Formats <= 8.3.0 Memoizer Unsafe Deserialization via .bfmemo Cache Files
- CVE-2026-221881 PoCPanda3D <= 1.10.16 Deploy-Stub Stack Exhaustion via Unbounded alloca()
- CVE-2026-221891 PoCPanda3D <= 1.10.16 egg-mkfont Stack Buffer Overflow
- CVE-2026-221901 PoCPanda3D <= 1.10.16 egg-mkfont Format String Information Disclosure
- CVE-2026-221912 PoCsBeghelli Sicuro24 SicuroWeb AngularJS Template Injection
- CVE-2026-222005 PoCsosTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read
- CVE-2026-222081 PoCOpenS100 Portrayal Engine Unrestricted Lua Standard Library Access
- CVE-2026-222111 PoCTinyOS <= 2.1.2 Global Buffer Overflow in printfUART
- CVE-2026-222121 PoCTinyOS <= 2.1.2 Stack-Based Buffer Overflow in mcp2200gpio
- CVE-2026-222131 PoCRIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in tapslip6 Utility
- CVE-2026-222141 PoCRIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in ethos Serial Frame Parser
- CVE-2026-222181 PoCChainlit < 2.9.4 Arbitrary File Read via /project/element
- CVE-2026-222191 PoCChainlit < 2.9.4 SQLAlchemy Data Layer SSRF via /project/element
- CVE-2026-222261 PoCCommand Injection Vulnerability on TP-Link Archer BE230 and AX73
- CVE-2026-222413 PoCsOpen eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
- CVE-2026-222421 PoCCoreShop Vulnerable to SQL Injection via Admin Reports
- CVE-2026-222432 PoCsEGroupware has SQL Injection in Nextmatch Filter Processing
- CVE-2026-222531 PoCSoft Serve is missing an authorization check in LFS lock deletion
- CVE-2026-222561 PoCSalvo is vulnerable to reflected XSS in the list_html function
- CVE-2026-222571 PoCSalvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names
- CVE-2026-223561 PoCWordPress Jetpack CRM plugin <= 6.7.0 - Local File Inclusion vulnerability
- CVE-2026-224442 PoCsApache Solr: Insufficient file-access checking in standalone core-creation requests
- CVE-2026-225531 PoCInSAT MasterSCADA BUK-TS OS Command Injection
- CVE-2026-225551 PoCGitea organization forks can expose organization secrets without create permission
- CVE-2026-225574 PoCsA malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access…
- CVE-2026-225881 PoCSpree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
- CVE-2026-225921 PoCGogs is Vulnerable to Denial of Service
- CVE-2026-225941 PoCGhost has Staff 2FA bypass
- CVE-2026-226081 PoCFickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
- CVE-2026-226101 PoCAngular has XSS Vulnerability via Unsanitized SVG Script Attributes
- CVE-2026-226121 PoCFickling vulnerable to detection bypass due to "builtins" blindness
- CVE-2026-226662 PoCsDolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()
- CVE-2026-226793 PoCsWeaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint
- CVE-2026-226833 PoCsWindmill < 1.615.0 Operator Role Missing Authorization Checks RCE
- CVE-2026-226863 PoCsSandbox Escape via Host Error Prototype Chain in enclave-vm
- CVE-2026-226871 PoCWeKnora vulnerable to SQL Injection
- CVE-2026-226881 PoCWeKnora has Command Injection in MCP stdio test
- CVE-2026-226891 PoCMailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails
- CVE-2026-226921 PoCOctober CMS: Twig Sandbox Bypass via Collection Methods
- CVE-2026-226981 PoCRustCrypto SM2-PKE has 32-bit Biased Nonce Vulnerability
- CVE-2026-226991 PoCRustCrypto SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()
- CVE-2026-227001 PoCRustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKE
- CVE-2026-227031 PoCCosign verification accepts any valid Rekor entry under certain conditions
- CVE-2026-227041 PoCHAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
- CVE-2026-227221 PoCVMware Workstation for Windows null pointer dereference may allow an authenticated user to trigger a crash
- CVE-2026-227281 PoCsealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template annotations
- CVE-2026-227301 PoCCVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter
- CVE-2026-227322 PoCsUnder Some Conditions Spring Security HTTP Headers Are not Written
- CVE-2026-227382 PoCsSpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution
- CVE-2026-227391 PoCSpring Cloud Config Profile Substitution Can Allow Unintended Access To Files And Enable SSRF Attacks
- CVE-2026-227471 PoCUnauthorized User Impersonation when Using X.509 Client Certificates
- CVE-2026-227721 PoCFulcio vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass
- CVE-2026-227772 PoCsComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler
- CVE-2026-227781 PoCvLLM leaks a heap address when PIL throws an error
- CVE-2026-227821 PoCRustFS RPC signature verification logs shared secret
- CVE-2026-227851 PoCorval MCP client is vulnerable to a code injection attack.
- CVE-2026-227941 PoCAccount Takeover Vulnerability in Appsmith
- CVE-2026-228041 PoCTermix has a Stored XSS in File Manager leading to Local File Inclusion (LFI) in Electron and Session Hijacking in Browser
- CVE-2026-228071 PoCvLLM affected by RCE via auto_map dynamic module loading during model initialization
- CVE-2026-228101 PoCJoplin: Path traversal in OneNote importer allows overwriting arbitrary files
- CVE-2026-228129 PoCsOpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
- CVE-2026-228131 PoCMalicious website can execute commands on the local system through XSS in the OpenCode web UI
- CVE-2026-228201 PoCOutray cli is vulnerable to race conditions in tunnels creation
- CVE-2026-228491 PoCSaleor lacks proper HTML sanitization in rich text fields
- CVE-2026-228621 PoCgo-ethereum has a DoS via malicious p2p message
- CVE-2026-228631 PoCDeno node:crypto doesn't finalize cipher
- CVE-2026-228742 PoCsGitea webhook and migration allow-list filtering permits SSRF