CVE-2026-27000 to CVE-2026-27999
109 CVEs with public proof-of-concept exploits.
- CVE-2026-270181 PoCGotenberg: Chromium deny-list bypass via case-insensitive URL scheme
- CVE-2026-270221 PoCRediSearch Query Injection in @langchain/langgraph-checkpoint-redis
- CVE-2026-271141 PoCNanaZip has ROMFS Archive Infinite Loop
- CVE-2026-271161 PoCVikunja has Reflected HTML Injection via filter Parameter in Projects Module
- CVE-2026-271201 PoCLeaf-kit html escaping does not work on characters that are part of extended grapheme cluster
- CVE-2026-271241 PoCFastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities
- CVE-2026-271261 PoCCraft CMS has Stored XSS in Table Field via "HTML" Column Type
- CVE-2026-271291 PoCCloud Metadata SSRF Protection Bypass via IPv6 Resolution
- CVE-2026-271451 PoCInefficient candidate hostname parsing in crypto/x509
- CVE-2026-271671 PoCGradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
- CVE-2026-271721 PoCApache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from…
- CVE-2026-271743 PoCsMajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
- CVE-2026-271751 PoCMajorDoMo Command Injection in rc/index.php via Race Condition
- CVE-2026-271761 PoCMajorDoMo Reflected Cross-Site Scripting in command.php
- CVE-2026-271791 PoCMajorDoMo Unauthenticated SQL Injection in Commands Module
- CVE-2026-271802 PoCsMajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning
- CVE-2026-271821 PoCSaturn Remote Mouse Server UDP Command Injection RCE
- CVE-2026-271991 PoCWerkzeug safe_join() allows Windows special device names
- CVE-2026-272121 PoCSwiper has a Prototype Pollution Vulnerability
- CVE-2026-272801 PoCDNG SDK | Out-of-bounds Write (CWE-787)
- CVE-2026-273441 PoCWordPress inseri core plugin <= 1.0.5 - Broken Access Control vulnerability
- CVE-2026-273841 PoCWordPress W3 Total Cache plugin <= 2.9.1 - Arbitrary Code Execution vulnerability
- CVE-2026-274702 PoCsZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cause Fields
- CVE-2026-274721 PoCSPIP < 4.4.9 Blind Server-Side Request Forgery via Syndicated Sites
- CVE-2026-274741 PoCSPIP < 4.4.9 Cross-Site Scripting in Private Area (Incomplete Fix)
- CVE-2026-274751 PoCSPIP < 4.4.9 Insecure Deserialization
- CVE-2026-274761 PoCRustFly 2.0.0 Command Injection via UDP Remote Control
- CVE-2026-274821 PoCRay: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
- CVE-2026-274834 PoCsMindsDB has Path Traversal in /api/files Leading to Remote Code Execution
- CVE-2026-274951 PoCn8n has a Sandbox Escape in its JavaScript Task Runner
- CVE-2026-275071 PoCBinardat 10G08-0800GSM Network Switch Hard-coded Credentials
- CVE-2026-275091 PoCUnitree Go2 Missing DDS Authentication Enables Adjacent RCE
- CVE-2026-275101 PoCUnitree Go2 Mobile Program Tampering Enables Root RCE
- CVE-2026-275401 PoCWordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability
- CVE-2026-275422 PoCsWordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability
- CVE-2026-275671 PoCPayload has Server-Side Request Forgery (SSRF) in External File URL Uploads
- CVE-2026-275742 PoCsOneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE
- CVE-2026-275751 PoCVijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
- CVE-2026-275771 PoCn8n: Expression Sandbox Escape Leads to RCE
- CVE-2026-275792 PoCsCollabPlatform : CORS Misconfiguration Allows Arbitrary Origin With Credentials Leading to Authenticated Account Data Exposure
- CVE-2026-275841 PoCActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints
- CVE-2026-275851 PoCCaddy's improper sanitization of glob characters in file matcher may lead to bypassing security protections
- CVE-2026-275861 PoCCaddy's mTLS client authentication silently fails open when CA certificate file is missing or malformed
- CVE-2026-275871 PoCCaddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth bypass
- CVE-2026-275881 PoCCaddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth bypass
- CVE-2026-275892 PoCsCaddy vulnerable to cross-origin config application via local admin API /load (caddy)
- CVE-2026-275901 PoCCaddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_INFO confusion) in FastCGI transport
- CVE-2026-275972 PoCs@enclave-vm/core is vulnerable to Sandbox Escape
- CVE-2026-275981 PoCDagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directory
- CVE-2026-275991 PoCCI4MS: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored…
- CVE-2026-276061 PoCRollup 4 has Arbitrary File Write via Path Traversal
- CVE-2026-276111 PoCFileBrowser Quantum: Password Protection Not Enforced on Shared File Links
- CVE-2026-276141 PoCBugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace rendering
- CVE-2026-276161 PoCVikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upload Leading to Token Exposure
- CVE-2026-276211 PoCTypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload
- CVE-2026-276221 PoCOpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write
- CVE-2026-276262 PoCsOliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checks
- CVE-2026-276361 PoCFreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache
- CVE-2026-276381 PoCActualBudget missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
- CVE-2026-276411 PoCFlask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection
- CVE-2026-276452 PoCschangedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response
- CVE-2026-276543 PoCsNGINX ngx_http_dav_module vulnerability
- CVE-2026-276951 PoCzae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
- CVE-2026-276961 PoCchangedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs
- CVE-2026-277021 PoCBudibase Vulnerable to Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)
- CVE-2026-277281 PoCOneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in traceroute exec()
- CVE-2026-277301 PoCesm.sh has SSRF localhost/private-network bypass in `/http(s)` module route
- CVE-2026-277341 PoCBeszel Vulnerable to Docker API Path Traversal via Unsanitized Container ID
- CVE-2026-277431 PoCSPIP referer_spam < 1.3.0 Unauthenticated SQL Injection
- CVE-2026-277441 PoCSPIP tickets < 4.3.3 Unauthenticated RCE
- CVE-2026-277451 PoCSPIP interface_traduction_objets < 2.2.2 Authenticated RCE
- CVE-2026-277461 PoCSPIP jeux < 4.1.1 Reflected XSS via index Parameters
- CVE-2026-277471 PoCSPIP interface_traduction_objets < 2.2.2 Authenticated SQL Injection
- CVE-2026-277603 PoCsOpenCATS PHP Code Injection via installer AJAX endpoint
- CVE-2026-277713 PoCsGitea Composer package source links use insufficient permission checks
- CVE-2026-277751 PoCGitea pre-receive hook permission cache allows full repository write access
- CVE-2026-277781 PoCePower epower.ie Improper Restriction of Excessive Authentication Attempts
- CVE-2026-277961 PoCHomarr: Unauthenticated Information Disclosure (Integration Metadata Leak)
- CVE-2026-278011 PoCVaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement
- CVE-2026-278021 PoCVaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager
- CVE-2026-278031 PoCVaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager Role
- CVE-2026-278081 PoCMailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API
- CVE-2026-278221 PoCRust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
- CVE-2026-278252 PoCsMCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in…
- CVE-2026-278261 PoCMCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
- CVE-2026-278291 PoCAstro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
- CVE-2026-278311 PoCrldns Vulnerable to Heap-based Out-of-Bounds Read
- CVE-2026-278331 PoCPiwigo: Unauthenticated Information Disclosure via pwg.history.search API
- CVE-2026-278351 PoCwger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
- CVE-2026-278381 PoCwger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
- CVE-2026-278761 PoCRCE on Grafana via sqlExpressions
- CVE-2026-278841 PoCNetExec vulnerable to arbitrary file write via path traversal in spider_plus module
- CVE-2026-278862 PoCsStrapi may leak sensitive data via relational filtering due to lack of query sanitization
- CVE-2026-278891 PoCNATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
- CVE-2026-279031 PoCminimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
- CVE-2026-279041 PoCminimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions
- CVE-2026-279051 PoCBentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction
- CVE-2026-279125 PoCsWindows Kerberos Elevation of Privilege Vulnerability
- CVE-2026-279321 PoCjoserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)
- CVE-2026-279401 PoCllama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation — Bypass of CVE-2025-53630 Fix
- CVE-2026-279448 PoCsNginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
- CVE-2026-279531 PoCormar has a Pydantic Validation Bypass via Kwargs Injection in Model Constructor
- CVE-2026-279591 PoCKoa has Host Header Injection via `ctx.hostname`
- CVE-2026-279621 PoCAuthlib JWS JWK Header Injection: Signature Verification Bypass
- CVE-2026-279641 PoCFacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
- CVE-2026-279662 PoCsLangflow has Remote Code Execution in CSV Agent
- CVE-2026-279712 PoCsQwik affected by unauthenticated RCE via server$ Deserialization
- CVE-2026-279771 PoCNext.js: null origin can bypass dev HMR websocket CSRF checks
- CVE-2026-279782 PoCsNext.js: null origin can bypass Server Actions CSRF checks