CVE-2026-28000 to CVE-2026-28999
65 CVEs with public proof-of-concept exploits.
- CVE-2026-281341 PoCWordPress JetEngine plugin <= 3.7.2 - Remote Code Execution (RCE) vulnerability
- CVE-2026-282081 PoCJunrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtractor on Linux/Unix
- CVE-2026-282291 PoCArgo Workflows has unauthorized access to Argo Workflows Template
- CVE-2026-282311 PoCpillow_heif Has Integer Overflow in Encode Path Buffer Validation that Leads to Heap Out-of-Bounds Read
- CVE-2026-282771 PoCLangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loading
- CVE-2026-282861 PoCZimaOS: Unauthorized Creation of Files/Folders in Restricted System Directories via API
- CVE-2026-282881 PoCDify has a user enumeration issue
- CVE-2026-282892 PoCsFreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution
- CVE-2026-282911 PoCsimple-git has Command Execution via Option-Parsing Bypass
- CVE-2026-282921 PoCsimple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE
- CVE-2026-283181 PoCKEVSolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
- CVE-2026-283381 PoCPMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages
- CVE-2026-283421 PoCOliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint
- CVE-2026-283581 PoCNocoDB: User Enumeration via Password Reset Endpoint
- CVE-2026-283632 PoCsIn OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as…
- CVE-2026-283724 PoCstelnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support…
- CVE-2026-283931 PoCOpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal
- CVE-2026-284091 PoCWeGIA Vulnerable to Remote Code Execution (RCE) via OS Command Injection
- CVE-2026-284141 PoCGradio has Absolute Path Traversal on Windows with Python 3.13+
- CVE-2026-284161 PoCGradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing
- CVE-2026-284451 PoCTypebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview
- CVE-2026-284661 PoCOpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval Bypass
- CVE-2026-284921 PoCFile Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory
- CVE-2026-284961 PoCFOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
- CVE-2026-284991 PoCLeafKit's HTML escaping may be skipped for Collection values, enabling XSS
- CVE-2026-285011 PoCWWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
- CVE-2026-285071 PoCIdno: Remote Code Execution via Chained Import File Write and Template Path Traversal
- CVE-2026-285081 PoCIdno: Unauthenticated SSRF via URL Unfurl Endpoint
- CVE-2026-285131 PoCPocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchange
- CVE-2026-285153 PoCsopenDCIM <= 23.04 Missing Authorization in install.php
- CVE-2026-285163 PoCsopenDCIM <= 23.04 SQL Injection in Config::UpdateParameter
- CVE-2026-285173 PoCsopenDCIM <= 23.04 OS Command Injection via dot Configuration Parameter
- CVE-2026-285292 PoCscryptodev-linux <= 1.14 get_userbuf Use After Free LPE
- CVE-2026-286721 PoCApache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
- CVE-2026-286841 PoCpython-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
- CVE-2026-286851 PoCKimai: API invoice endpoint missing customer-level access control (IDOR)
- CVE-2026-286951 PoCCraft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
- CVE-2026-286961 PoCCraft affected by IDOR via GraphQL @parseRefs
- CVE-2026-286971 PoCCraft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates
- CVE-2026-286991 PoCGitea Basic Auth bypasses OAuth2 access token scopes
- CVE-2026-287371 PoCGitea 3D file viewer allows stored XSS through glTF extensionsRequired
- CVE-2026-287441 PoCGitea Git smart HTTP bypasses repository token scopes for bearer tokens
- CVE-2026-287661 PoCGardyn Cloud API Missing Authentication for Critical Function
- CVE-2026-287671 PoCGardyn Cloud API Missing Authentication for Critical Function
- CVE-2026-287811 PoCCraft Affected by Entries Authorship Spoofing via Mass Assignment
- CVE-2026-287821 PoCCraft has a Permission Bypass and IDOR in Duplicate Entry Action
- CVE-2026-287861 PoCOpen WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
- CVE-2026-287871 PoCOneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
- CVE-2026-287881 PoCOpen WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
- CVE-2026-287891 PoCOliveTin: Unauthenticated DoS via concurrent map writes in OAuth2 state handling
- CVE-2026-287901 PoCOliveTin: Unauthenticated Action Termination via KillAction When Guests Must Login
- CVE-2026-287911 PoCPath Traversal in Media Upload Handle in Tina
- CVE-2026-287921 PoCCross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
- CVE-2026-287931 PoCPath Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS
- CVE-2026-287941 PoCoRPC: Prototype Pollution in `@orpc/client` via `StandardRPCJsonSerializer` Deserialization
- CVE-2026-288021 PoCAuthlib: Setting `alg: none` and a blank signature appears to bypass signature verification
- CVE-2026-288051 PoCOpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter
- CVE-2026-288071 PoCPath Traversal in wisp.serve_static allows arbitrary file read
- CVE-2026-288151 PoCA remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path,…
- CVE-2026-288581 PoCA buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able…
- CVE-2026-288671 PoCThis issue was addressed with improved authentication. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4,…
- CVE-2026-289561 PoCA memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia…
- CVE-2026-289901 PoCThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5,…
- CVE-2026-289922 PoCsA memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and…
- CVE-2026-289951 PoCA logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5,…