CVE-2026-29000 to CVE-2026-29999
61 CVEs with public proof-of-concept exploits.
- CVE-2026-2900020 PoCspac4j-jwt JwtAuthenticator Authentication Bypass
- CVE-2026-290021 PoCCouchCMS Privilege Escalation via f_k_levels_list Parameter
- CVE-2026-290041 PoCBusyBox DHCPv6 Client Heap Buffer Overflow via DNS_SERVERS
- CVE-2026-290071 PoCU-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c
- CVE-2026-290081 PoCU-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()
- CVE-2026-290091 PoCU-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
- CVE-2026-290142 PoCsMetInfo CMS Unauthenticated PHP Code Injection RCE
- CVE-2026-290221 PoCmackron / dr_libs dr_wav.h Heap Buffer Overflow via WAV File
- CVE-2026-290381 PoCchangedetection.io: Reflected XSS in RSS Tag Error Response
- CVE-2026-290391 PoCchangedetection.io: XPath - Arbitrary File Read via unparsed-text()
- CVE-2026-290411 PoCChamilo: Authenticated Remote Code Execution via Unrestricted File Upload
- CVE-2026-290421 PoCNuclio Shell Runtime Command Injection Leading to Privilege Escalation
- CVE-2026-290534 PoCsGhost Vulnerable to Remote Code Execution via Malicious Themes
- CVE-2026-290571 PoCNext.js: HTTP request smuggling in rewrites
- CVE-2026-290581 PoCAVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.php
- CVE-2026-290592 PoCsWindmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly
- CVE-2026-290631 PoCImmutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in immutable
- CVE-2026-290641 PoCZarf: Symlink targets in archives are not validated against destination directory
- CVE-2026-290651 PoCchangedetection.io: Zip Slip vulnerability in the backup restore functionality
- CVE-2026-290662 PoCsArbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI
- CVE-2026-290701 PoCOpen WebUI has unauthorized deletion of knowledge files
- CVE-2026-290711 PoCOpen WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
- CVE-2026-290731 PoCSiYuan: Direct SQL Query API accessible to Reader-level users enables unauthorized database access
- CVE-2026-290741 PoCSVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
- CVE-2026-290801 PoCRucio SQL Injection in FilterEngine Oracle JSON Path via DID Search API
- CVE-2026-290911 PoCLocutus: Remote Code Execution (RCE) in locutus call_user_func_array due to Code Injection
- CVE-2026-291141 PoCA vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed…
- CVE-2026-291151 PoCA vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet,…
- CVE-2026-291161 PoCA vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet,…
- CVE-2026-291454 PoCsApache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
- CVE-2026-291461 PoCApache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
- CVE-2026-291721 PoCCraft Commerce has a SQL Injection in Commerce Purchasables Table Sorting
- CVE-2026-291731 PoCCraft Commerce has Stored XSS while updating Order Status from Orders Table
- CVE-2026-291741 PoCCraft Commerce has a SQL Injection in Commerce Inventory Table Sorting
- CVE-2026-291751 PoCMultiple Stored XSS in Commerce Inventory Page Leading to Session Hijacking
- CVE-2026-291761 PoCCraft Commerce has Stored XSS in Inventory Location Name
- CVE-2026-291771 PoCCraft Commerce has Stored XSS in Craft Commerce Order Details Slideout
- CVE-2026-291811 PoCOpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
- CVE-2026-291832 PoCsSiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrary JavaScript execution
- CVE-2026-291881 PoCFile Browser: TUS Delete Endpoint Bypasses Delete Permission Check
- CVE-2026-291981 PoCIn Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account…
- CVE-2026-292041 PoCInsufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s…
- CVE-2026-295141 PoCNetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin
- CVE-2026-295191 PoCLucee CFML Server Reflected XSS via URL Path Parsing
- CVE-2026-295971 PoCDDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged user can access…
- CVE-2026-295981 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allow…
- CVE-2026-296091 PoCOpenClaw < 2026.2.14 - Denial of Service via Unbounded URL-backed Media Fetch
- CVE-2026-296281 PoCA stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of…
- CVE-2026-297721 PoCAstro: Memory exhaustion DoS due to missing request body size limit in Server Islands
- CVE-2026-297771 PoCTraefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
- CVE-2026-297802 PoCseml_parser: Path Traversal in Official Example Script Leading to Arbitrary File Write
- CVE-2026-297811 PoCSliver: Authenticated Nil-Pointer Dereference in Handlers
- CVE-2026-297821 PoCOpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2
- CVE-2026-297831 PoCGitHub Copilot CLI allows for dangerous shell expansion patterns that enable arbitrary command execution
- CVE-2026-297863 PoCsnode-tar: Hardlink Path Traversal via Drive-Relative Linkpath
- CVE-2026-297941 PoCVikunja has Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
- CVE-2026-298611 PoCPHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.
- CVE-2026-299233 PoCsThe pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL…
- CVE-2026-299541 PoCIn KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field…
- CVE-2026-299551 PoCThe `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses…
- CVE-2026-299711 PoCA reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. User-controlled…