CVE-2026-23000 to CVE-2026-23999
85 CVEs with public proof-of-concept exploits.
- CVE-2026-230011 PoCmacvlan: fix possible UAF in macvlan_forward_source()
- CVE-2026-230021 PoClib/buildid: use __kernel_read() for sleepable context
- CVE-2026-230031 PoCip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()
- CVE-2026-230041 PoCdst: fix races in rt6_uncached_list_del() and rt_del_uncached_list()
- CVE-2026-230051 PoCx86/fpu: Clear XSTATE_BV[i] in guest XSAVE state whenever XFD[i]=1
- CVE-2026-230061 PoCASoC: tlv320adcx140: fix null pointer
- CVE-2026-230071 PoCblock: zero non-PI portion of auto integrity buffer
- CVE-2026-230081 PoCdrm/vmwgfx: Fix KMS with 3D on HW version 10
- CVE-2026-230091 PoCxhci: sideband: don't dereference freed ring when removing sideband endpoint
- CVE-2026-230101 PoCipv6: Fix use-after-free in inet6_addr_del().
- CVE-2026-231119 PoCsnetfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate()
- CVE-2026-232311 PoCnetfilter: nf_tables: fix use-after-free in nf_tables_addchain()
- CVE-2026-233982 PoCsicmp: fix NULL pointer dereference in icmp_tag_validation()
- CVE-2026-234151 PoCfutex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy()
- CVE-2026-234161 PoCmm/mseal: update VMA end correctly on merge
- CVE-2026-234791 PoCredis-server use-after-free in unblock client flow may allow remote code execution
- CVE-2026-234821 PoCBlinko: Unauthorized Arbitrary File Read - /api/file/temp
- CVE-2026-234831 PoCBlinko: Unauthorized Arbitrary File Read - /plugins
- CVE-2026-234861 PoCBlinko: Unauthorized User Information Leak
- CVE-2026-234891 PoCFields GLPI plugin vulnerable to RCE in dropdown generation
- CVE-2026-234901 PoCpyasn1 has a DoS vulnerability in decoder
- CVE-2026-234912 PoCsInvoicePlane has Unauthenticated Path Traversal in Guest Controller
- CVE-2026-234921 PoCPimcore has a Blind SQL Injection in Admin Search Find API due to an incomplete fix for CVE-2023-30848
- CVE-2026-234981 PoCShopware Improper Control of Generation of Code in Twig rendered views
- CVE-2026-234991 PoCSaleor vulnerable to stored XSS via Unrestricted File Upload
- CVE-2026-235002 PoCsDolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
- CVE-2026-235151 PoCRCE - Command Injection in Signal K set-system-time plugin
- CVE-2026-235191 PoCRustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz
- CVE-2026-235203 PoCsArcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE
- CVE-2026-235221 PoCLobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion
- CVE-2026-235242 PoCsLaravel Redis Horizontal Scaling Insecure Deserialization
- CVE-2026-235361 PoCFeast: unauthenticated arbitrary file read
- CVE-2026-235507 PoCsWordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
- CVE-2026-235521 PoCApache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy
- CVE-2026-236031 PoCBlind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
- CVE-2026-236221 PoCCSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover
- CVE-2026-236313 PoCsredis-server Lua use-after-free may allow remote code execution
- CVE-2026-236441 PoCesm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packages
- CVE-2026-236451 PoCSiYuan Vulnerable to Stored Cross-Site Scripting (XSS) via Unrestricted SVG File Upload
- CVE-2026-236963 PoCsWindmill < 1.603.3 File Ownership Handling SQLi RCE
- CVE-2026-236972 PoCsVtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
- CVE-2026-236982 PoCsVtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
- CVE-2026-237231 PoCWeGIA has a Critical SQL Injection in Atendido_ocorrenciaControle via id_memorando parameter
- CVE-2026-237331 PoCLobe Chat has Cross-Site Scripting (XSS) issue that may escalate to Remote Code Execution (RCE)
- CVE-2026-237351 PoCConcurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in graphql-modules
- CVE-2026-2374444 PoCsREC in MCPJam inspector due to HTTP Endpoint exposes
- CVE-2026-237453 PoCsnode-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
- CVE-2026-237472 PoCsGolioth Firmware SDK < 0.22.0 Payload Utils Stack-based Buffer Overflow
- CVE-2026-237481 PoCGolioth Firmware SDK < 0.22.0 LightDB State Out-of-Bounds Read
- CVE-2026-237491 PoCGolioth Firmware SDK < 0.22.0 Blockwise Transfer Path Out-of-Bounds Read
- CVE-2026-237501 PoCGolioth Pouch (prior to commit 1b2219a1) BLE GATT Heap-based Buffer Overflow
- CVE-2026-237512 PoCsKofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting
- CVE-2026-237603 PoCsKEVSmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
- CVE-2026-237611 PoCVB-Audio Voicemeeter & Matrix Drivers DoS via Improper FILE_OBJECT FsContext Initialization
- CVE-2026-237621 PoCVB-Audio Voicemeeter & Matrix Drivers DoS via MmMapLockedPagesSpecifyCache
- CVE-2026-237631 PoCVB-Audio Matrix Drivers Local Privilege Escalation via Kernel Memory Exposure
- CVE-2026-237641 PoCVB-Audio Voicemeeter & Matrix Drivers DoS via Corrupted IoAllocateMdl Length
- CVE-2026-238131 PoCAuthentication Bypass in Web Interface allows Unauthenticated Admin Password Reset
- CVE-2026-238294 PoCsMailpit has SMTP Header Injection via Regex Bypass
- CVE-2026-238301 PoCSandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
- CVE-2026-238422 PoCsChatterBot has Denial of Service via Database Connection Pool Exhaustion
- CVE-2026-238451 PoCMailpit Vulnerable to Server-Side Request Forgery (SSRF) via HTML Check API
- CVE-2026-238471 PoCSiYuan Vulnerable to Reflected Cross-Site Scripting (XSS) via /api/icon/getDynamicIcon
- CVE-2026-238491 PoCFile Browser vulnerable to Username Enumeration via Timing Attack in /api/login
- CVE-2026-238501 PoCSiYuan vulnerable to arbitrary file read
- CVE-2026-238692 PoCsA denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel,…
- CVE-2026-238771 PoCDirectory Traversal & Filesystem can be accessed by a non-admin user
- CVE-2026-238791 PoCpy7zr: Arbitrary File Write Vulnerability
- CVE-2026-238811 PoCKyverno Denial of Service via Context Variable Amplification in Policy Engine
- CVE-2026-238852 PoCsAlchemyCMS has Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
- CVE-2026-238881 PoCpnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
- CVE-2026-238891 PoCpnpm has Windows-specific tarball Path Traversal
- CVE-2026-238901 PoCpnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
- CVE-2026-239071 PoCApache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
- CVE-2026-2391810 PoCsApache HTTP Server: http2: double free and possible RCE on early reset
- CVE-2026-239471 PoCOrval MCP client is vulnerable to code injection via unsanitized x-enum-descriptions in enum generation
- CVE-2026-239491 PoCjaraco.context Has a Path Traversal Vulnerability
- CVE-2026-239501 PoCnode-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
- CVE-2026-239531 PoCIncus container environment configuration newline injection
- CVE-2026-239541 PoCIncus container image templating arbitrary host file read and write
- CVE-2026-239581 PoCDataEase Vulnerable to Brute-Force Attack on Admin JWT Secret Derived from Password that Enables Full Account Takeover
- CVE-2026-239601 PoCArgo Workflows affected by stored XSS in the artifact directory listing
- CVE-2026-239801 PoCApache Superset: Improper Neutralization of Special Elements used in a SQL Command
- CVE-2026-239891 PoCREVA Public Link Exploit
- CVE-2026-239971 PoCFacturaScripts has a Stored Cross-Site Scripting (XSS) in "Observations" field via History View