CVE-2026-26000 to CVE-2026-26999
71 CVEs with public proof-of-concept exploits.
- CVE-2026-260101 PoCLeaky JWTs in OpenMetadata exposing highly-privileged bot users
- CVE-2026-260121 PoCvaultwarden has Full Cipher Enumeration Ignoring Organization Collection Permissions
- CVE-2026-260211 PoCPrototype pollution in set-in
- CVE-2026-260221 PoCGogs: Stored XSS via data URI in issue comments
- CVE-2026-260261 PoCGLPI has a Server-Side Template Injection via Double-Compilation
- CVE-2026-260281 PoCCryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSS
- CVE-2026-260301 PoCMicrosoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
- CVE-2026-260551 PoCUnauthenticated Admission Webhook Endpoints in Yoke ATC
- CVE-2026-260561 PoCArbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC
- CVE-2026-261111 PoCWindows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- CVE-2026-261141 PoCMicrosoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2026-261192 PoCsWindows Admin Center Elevation of Privilege Vulnerability
- CVE-2026-261281 PoCWindows SMB Server Elevation of Privilege Vulnerability
- CVE-2026-261572 PoCsBusybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitization
- CVE-2026-261581 PoCBusybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entries
- CVE-2026-261791 PoCWindows Kernel Elevation of Privilege Vulnerability
- CVE-2026-261881 PoCSolspace Freeform plugin affected by Stored Cross-Site Scripting (XSS) in Freeform Craft Plugin CP UI (builder/integrations)
- CVE-2026-261902 PoCsMilvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
- CVE-2026-261983 PoCsormar is vulnerable to SQL Injection through aggregate functions min() and max()
- CVE-2026-262101 PoCKTransformers Unsafe Deserialization RCE via balance_serve
- CVE-2026-262111 PoCEkushey Project Manager CRM 5.0 Stored XSS via System Name Field
- CVE-2026-262141 PoCXiaomi Galaxy FDS Android SDK <= 3.0.8 TLS Hostname Verification Disabled Enables MITM
- CVE-2026-262152 PoCsmanga-image-translator Shared API Unsafe Deserialization RCE
- CVE-2026-262161 PoCCrawl4AI < 0.8.0 Docker API Unauthenticated Remote Code Execution via Hooks Parameter
- CVE-2026-262171 PoCCrawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling
- CVE-2026-262201 PoCLightLLM <= 1.1.0 PD Mode Unsafe Deserialization RCE
- CVE-2026-262211 PoCHyland OnBase Timer Service Unauthenticated .NET Remoting RCE
- CVE-2026-262241 PoCIntego Log Reporter TOCTOU Local Privilege Escalation
- CVE-2026-262251 PoCIntego Personal Backup Task File Privilege Escalation
- CVE-2026-262261 PoCbeautiful-mermaid < 0.1.3 SVG Attribute Injection
- CVE-2026-262311 PoCGitea maintainer-edit permissions allow unauthorized commits to readable repositories
- CVE-2026-262352 PoCsJUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing Authentication
- CVE-2026-262681 PoCCursor sandbox escape via Git hooks
- CVE-2026-262731 PoCKnown affected by Account Takeover via Password Reset Token Leakage
- CVE-2026-262791 PoCFroxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection
- CVE-2026-262821 PoCNanaZip has DotNet Single file OOB Heap Read
- CVE-2026-263111 PoCEnvoy HTTP: filter chain execution on reset streams causing UAF crash
- CVE-2026-263291 PoCOpenClaw has a path traversal in browser upload allows local file read
- CVE-2026-263311 PoCyt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option
- CVE-2026-263352 PoCsCalero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE
- CVE-2026-263361 PoCHyland Alfresco Improper Authorization Arbitrary File Read
- CVE-2026-263401 PoCTattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticated RTSP Stream Disclosure
- CVE-2026-263412 PoCsTattile Smart+ / Vega / Basic <= 1.181.5 Default Credentials
- CVE-2026-263421 PoCTattile Smart+ / Vega / Basic <= 1.181.5 Insufficient Session Token Expiration
- CVE-2026-263991 PoCA stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a…
- CVE-2026-264161 PoCAn authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate…
- CVE-2026-264171 PoCA broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows…
- CVE-2026-264181 PoCMissing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to…
- CVE-2026-264781 PoCA shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a…
- CVE-2026-267171 PoCAn issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC…
- CVE-2026-267181 PoCA Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform…
- CVE-2026-267191 PoCCross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET…
- CVE-2026-267201 PoCAn issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
- CVE-2026-267401 PoCBuffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension…
- CVE-2026-267441 PoCA user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd…
- CVE-2026-267461 PoCOpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read…
- CVE-2026-268011 PoCServer-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain…
- CVE-2026-268291 PoCA NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows attackers to cause a…
- CVE-2026-268301 PoCpdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and…
- CVE-2026-268991 PoCAn issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in…
- CVE-2026-269561 PoCvm2: WASM Sandbox Escape (Node 25 only)
- CVE-2026-269601 PoCnode-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction
- CVE-2026-269806 PoCsGhost has a SQL Injection in its Content API
- CVE-2026-269811 PoCOpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
- CVE-2026-269882 PoCsLibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream
- CVE-2026-269891 PoCLibreNMS has Stored XSS in Alert Rule
- CVE-2026-269901 PoCLibreNMS has Time-Based Blind SQL Injection in address-search.inc.php
- CVE-2026-269911 PoCLibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-groups name
- CVE-2026-269921 PoCLibreNMS has Stored Cross-Site Scripting via unsanitized /port-groups name
- CVE-2026-269961 PoCminimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
- CVE-2026-269981 PoCTraefik: unbounded io.ReadAll on auth server response body causes OOM denial of service(DOS)