CVE-2026-25000 to CVE-2026-25999
133 CVEs with public proof-of-concept exploits.
- CVE-2026-250381 PoCGitea private organization labels are visible to unauthorized users
- CVE-2026-250401 PoCBudibase Vulnerable to Privilege Escalation via API Abuse – Creator Can Invite Users with Admin/Any Role
- CVE-2026-250473 PoCsdeepHas vulnerable to Prototype Pollution via constructor.prototype
- CVE-2026-250481 PoCxgrammar: Multi-layer nesting causes DoS
- CVE-2026-250491 PoCn8n Has an Expression Escape Vulnerability Leading to RCE
- CVE-2026-250501 PoCVendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy
- CVE-2026-250531 PoCn8n is Vulnerable to OS Command Injection in Git Node
- CVE-2026-250591 PoCOpenList affected by Path Traversal in file copy and remove handlers
- CVE-2026-250691 PoCSunFounder Pironman Dashboard <= 1.3.13 Path Traversal Arbitrary File Read/Deletion
- CVE-2026-250752 PoCsstrongSwan 4.5.0 < 6.0.5 EAP-TTLS AVP Parsing Integer Underflow
- CVE-2026-250893 PoCsKEVA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0…
- CVE-2026-250992 PoCsRemote Code Execution via Unrestricted File Upload in Bludit
- CVE-2026-251191 PoCGogs: Authentication Bypass via Unvalidated Reverse Proxy Headers
- CVE-2026-251261 PoCPolarLearn's unvalidated vote direction allows vote count manipulation
- CVE-2026-251281 PoCfast-xml-parser has RangeError DoS Numeric Entities Bug
- CVE-2026-251291 PoCPsySH has Local Privilege Escalation via CWD .psysh.php auto-load
- CVE-2026-251301 PoCCybersecurity AI vulnerable to command Injection through argument injection in find_file Agent tool
- CVE-2026-251361 PoCRucio WebUI has a Reflected Cross-site Scripting Vulnerability
- CVE-2026-251381 PoCRucio WebUI has Username Enumeration via Login Error Message
- CVE-2026-251611 PoCAlist vulnerable to Path Traversal in multiple file operation handlers
- CVE-2026-251721 PoCWindows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2026-251731 PoCWindows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2026-251772 PoCsActive Directory Domain Services Elevation of Privilege Vulnerability
- CVE-2026-251941 PoCOut-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a…
- CVE-2026-251971 PoCGardyn Cloud API Authorization Bypass Through User-Controlled Key
- CVE-2026-252111 PoCLlama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
- CVE-2026-252121 PoCAn issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker…
- CVE-2026-252281 PoCSignalK Server has Path Traversal leading to information disclosure
- CVE-2026-252311 PoCFileRise affected by an Unauthenticated File Read Due to Insufficient Access Control
- CVE-2026-252321 PoCGogs has a Protected Branch Deletion Bypass in Web Interface
- CVE-2026-252421 PoCGogs allows unauthenticated file uploads
- CVE-2026-252434 PoCsredis-server RESTORE invalid memory access may allow remote code execution
- CVE-2026-252538 PoCsOpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket…
- CVE-2026-254721 PoCWordPress Fusion Builder plugin <= 3.14.1 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-254751 PoCOpenClaw Vulnerable to Local File Inclusion via MEDIA: Path Extraction
- CVE-2026-254781 PoCLitestar has a CORS origin allowlist bypass due to unescaped regex metacharacters in allowed origins
- CVE-2026-254791 PoCLitestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patterns
- CVE-2026-254811 PoCLangroid has WAF Bypass Leading to RCE in TableChatAgent
- CVE-2026-254821 PoCCraft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget)
- CVE-2026-254831 PoCCraft Commerce has Stored XSS via Order Status Message with potential database exfiltration
- CVE-2026-254841 PoCCraft Commerce has Stored XSS in Product Type Name
- CVE-2026-254851 PoCCraft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation
- CVE-2026-254861 PoCCraft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation
- CVE-2026-254871 PoCCraft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation
- CVE-2026-254881 PoCCraft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation
- CVE-2026-254891 PoCCraft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation
- CVE-2026-254901 PoCCraft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation
- CVE-2026-254911 PoCCraft has a Stored XSS in Entry Types Name
- CVE-2026-254931 PoCCraft has a SSRF in GraphQL Asset Mutation via HTTP Redirect
- CVE-2026-254941 PoCCraft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation
- CVE-2026-254951 PoCCraft has a SQL Injection in Element Indexes via criteria[orderBy]
- CVE-2026-254961 PoCCraft has a stored XSS in Number Prefix & Suffix Fields
- CVE-2026-255051 PoCBambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication
- CVE-2026-255091 PoCCI4MS Vulnerable to User Email Enumeration via Password Reset Flow
- CVE-2026-255101 PoCCI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor
- CVE-2026-255123 PoCsGroup-Office is vulnerable to RCE due to Command Injection via TNEF Attachment Handler
- CVE-2026-255131 PoCFacturaScripts has SQL Injection vulnerability in API ORDER BY Clause
- CVE-2026-255141 PoCFacturaScripts has SQL Injection vulnerability in Autocomplete Actions
- CVE-2026-255201 PoCSandboxJS has a Sandbox Escape
- CVE-2026-255211 PoCLocutus is vulnerable to Prototype Pollution
- CVE-2026-255221 PoCCraft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation
- CVE-2026-255241 PoCOpenMage LTS's Phar Deserialization leads to Remote Code Execution
- CVE-2026-255261 PoCJinJava Bypass through ForTag leads to Arbitrary Java Execution
- CVE-2026-255272 PoCschangedetection.io vulnerable to unauthenticated static path traversal
- CVE-2026-255331 PoCEnclave has a sandbox escape via infinite recursion and error objects
- CVE-2026-255371 PoCjsonwebtoken has Type Confusion that leads to potential authorization bypass
- CVE-2026-255391 PoCSiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE
- CVE-2026-255421 PoCTekton Pipelines: VerificationPolicy regex pattern bypass via substring matching
- CVE-2026-255443 PoCsPayload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
- CVE-2026-255452 PoCsAstro has Full-Read SSRF in error rendering via Host: header injection
- CVE-2026-255461 PoCGodot MCP is vulnerable to Command Injection via unsanitized projectPath
- CVE-2026-255471 PoCUncontrolled Resource Consumption in @isaacs/brace-expansion
- CVE-2026-255481 PoCInvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning
- CVE-2026-255501 PoCSeagull Software BarTender Unauthenticated RCE via .NET Remoting Service
- CVE-2026-255511 PoCSeagull Software BarTender Deserialization Privilege Escalation via .NET Remoting Service
- CVE-2026-255552 PoCsOpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
- CVE-2026-255571 PoCEvoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter
- CVE-2026-255591 PoCOpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint
- CVE-2026-255741 PoCPayload Affected by Cross-Collection IDOR in payload-preferences Access Control (Multi-Auth Environments)
- CVE-2026-255771 PoCEmmett has an Unhandled CookieError Exception Causing Denial of Service
- CVE-2026-255781 PoCNavidrome is vulnerable to XSS via comment from song metadata
- CVE-2026-255791 PoCNavidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>`…
- CVE-2026-255811 PoCSCEditor affected by DOM XSS via emoticon URL/HTML injection
- CVE-2026-255892 PoCsRedisBloom RESTORE invalid memory access may allow remote code execution
- CVE-2026-255911 PoCNew API has an SQL LIKE Wildcard Injection DoS via Token Search
- CVE-2026-255941 PoCInvoicePlane has Stored XSS via Family Name in Product Form
- CVE-2026-255951 PoCInvoicePlane has Stored XSS via Invoice Number in Invoice View and Dashboard
- CVE-2026-255961 PoCInvoicePlane has Stored XSS via Product Unit Name in Invoice Item List
- CVE-2026-256041 PoCApache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
- CVE-2026-256161 PoCBlesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.
- CVE-2026-256281 PoCQdrant affected by arbitrary file write via `/logger` endpoint
- CVE-2026-256321 PoCEPyT-Flow has unsafe JSON deserialization (__type__)
- CVE-2026-256391 PoCAxios affected by Denial of Service via __proto__ Key in mergeConfig
- CVE-2026-256433 PoCsFrigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
- CVE-2026-256761 PoCThe installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic…
- CVE-2026-257311 PoCCalibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export
- CVE-2026-257323 PoCsNiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
- CVE-2026-257461 PoCOpenEMR has SQL Injection Vulnerability
- CVE-2026-257472 PoCsApache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDB
- CVE-2026-257581 PoCSpree allows unauthenticated users can access all guest addresses
- CVE-2026-257601 PoCWebsite Path Traversal / Arbitrary File Read (Authenticated) in Sliver
- CVE-2026-257661 PoCEcho has a Windows path traversal via backslash in middleware.Static default filesystem
- CVE-2026-257692 PoCsWazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization
- CVE-2026-257701 PoCWazuh has Privilege Escalation to Root via Cluster Protocol File Write
- CVE-2026-258541 PoCApache Tomcat: Occasionally open redirect
- CVE-2026-258551 PoCOpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload
- CVE-2026-258561 PoCOpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface
- CVE-2026-258572 PoCsTenda G300-F Command Injection via formSetWanDiag
- CVE-2026-258602 PoCsOpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
- CVE-2026-258721 PoCJUNG Smart Panel 5.1 KNX Unauthenticated Path Traversal
- CVE-2026-258731 PoCOmniGen2-RL Reward Server Unsafe Deserialization RCE
- CVE-2026-258741 PoCLeRobot Unsafe Deserialization Remote Code Execution via gRPC
- CVE-2026-258791 PoCLangroid has Prompt to SQL Injection, Leading to RCE
- CVE-2026-258811 PoC@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)
- CVE-2026-258821 PoCFiber has a Denial of Service Vulnerability via Route Parameter Overflow
- CVE-2026-258871 PoCChartbrew: Remote Code Execution (RCE) via MongoDB Dataset Query
- CVE-2026-258891 PoCFile Browser has an Authentication Bypass in User Password Update
- CVE-2026-258902 PoCsFile Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
- CVE-2026-258923 PoCsAdminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint
- CVE-2026-258953 PoCsFUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
- CVE-2026-258961 PoCfast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names
- CVE-2026-259161 PoCRoundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
- CVE-2026-259241 PoCKanboard is Missing Access Control on Plugin Installation leading to Administrative RCE
- CVE-2026-259381 PoCFUXA Unauthenticated Remote Code Execution in Node-RED Integration
- CVE-2026-259391 PoCFUXA Unauthenticated Remote Arbitrary Scheduler Write
- CVE-2026-259401 PoCjsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
- CVE-2026-259491 PoCTraefik: TCP readTimeout bypass via STARTTLS on Postgres
- CVE-2026-259611 PoCSumatraPDF Update MITM -> Arbitrary Code Execution
- CVE-2026-259641 PoCTandoor Recipes Affected by Authenticated Local File Disclosure (LFD) via Recipe Import leads to Arbitrary File Read
- CVE-2026-259911 PoCTandoor Recipes affected by Blind SSRF with Internal Network Access via Recipe Import
- CVE-2026-259921 PoCSiYuan has a File Read Interface Case Bypass Vulnerability
- CVE-2026-259942 PoCsPJSIP has a heap buffer overflow in ICE with long username
- CVE-2026-259961 PoCInspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode