CVE-2026-2000 to CVE-2026-2999
388 CVEs with public proof-of-concept exploits.
- CVE-2026-20001 PoCDCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection
- CVE-2026-20021 PoCForminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
- CVE-2026-20054 PoCsPostgreSQL pgcrypto heap buffer overflow executes arbitrary code
- CVE-2026-20081 PoCabhiphile fermat-mcp eqn_chart.py eqn_chart code injection
- CVE-2026-20091 PoCSourceCodester Gas Agency Management System createUser.php access control
- CVE-2026-20101 PoCSanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization
- CVE-2026-20111 PoCitsourcecode Student Management System controller.php sql injection
- CVE-2026-20121 PoCitsourcecode Student Management System index.php sql injection
- CVE-2026-20131 PoCitsourcecode Student Management System index.php sql injection
- CVE-2026-20141 PoCitsourcecode Student Management System index.php sql injection
- CVE-2026-20151 PoCPortabilis i-Educar Final Status Import FinalStatusImportService.php improper authorization
- CVE-2026-20161 PoChappyfish100 libfastcommon base64.c base64_decode stack-based overflow
- CVE-2026-20171 PoCIP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow
- CVE-2026-20181 PoCitsourcecode School Management System controller.php sql injection
- CVE-2026-20201 PoCJS Archive List <= 6.1.7 - Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute
- CVE-2026-20252 PoCsMail Mint < 1.19.5 - Unauthenticated Emails Disclosure
- CVE-2026-20541 PoCD-Link DIR-605L/DIR-619L Wifi Setting information disclosure
- CVE-2026-20551 PoCD-Link DIR-605L/DIR-619L DHCP Client Information information disclosure
- CVE-2026-20561 PoCD-Link DIR-605L/DIR-619L DHCP Connection Status wan_connection_status.asp information disclosure
- CVE-2026-20571 PoCSourceCodester Medical Center Portal Management System login.php sql injection
- CVE-2026-20582 PoCsmathurvishal CloudClassroom-PHP-Project Post Query Details postquerypublic.php sql injection
- CVE-2026-20591 PoCSourceCodester Medical Center Portal Management System emp_edit1.php sql injection
- CVE-2026-20601 PoCcode-projects Simple Blood Donor Management System editcampaignform.php sql injection
- CVE-2026-20611 PoCD-Link DIR-823X set_ipv6 sub_424D20 os command injection
- CVE-2026-20621 PoCOpen5GS PGW S5U Address sgwc_sxa_handle_session_modification_response null pointer dereference
- CVE-2026-20631 PoCD-Link DIR-823X Web Management set_ac_server os command injection
- CVE-2026-20641 PoCPortabilis i-Educar User Data meusdadod.php cross site scripting
- CVE-2026-20651 PoCFlycatcher Toys smART Pixelator Bluetooth Low Energy missing authentication
- CVE-2026-20661 PoCUTT 进取 520W formIpGroupConfig strcpy buffer overflow
- CVE-2026-20671 PoCUTT 进取 520W formTimeGroupConfig strcpy buffer overflow
- CVE-2026-20681 PoCUTT 进取 520W formSyslogConf strcpy buffer overflow
- CVE-2026-20691 PoCggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflow
- CVE-2026-20701 PoCUTT 进取 520W formPolicyRouteConf strcpy buffer overflow
- CVE-2026-20711 PoCUTT 进取 520W formP2PLimitConfig strcpy buffer overflow
- CVE-2026-20731 PoCitsourcecode School Management System index.php sql injection
- CVE-2026-20741 PoCO2OA HTTP POST Request check xml external entity reference
- CVE-2026-20751 PoCyeqifu warehouse Role-Permission Binding RoleController.java saveRolePermission access control
- CVE-2026-20761 PoCyeqifu warehouse User Management Endpoint UserController.java deleteUser improper authorization
- CVE-2026-20771 PoCyeqifu warehouse Role Management RoleController.java deleteRole improper authorization
- CVE-2026-20781 PoCyeqifu warehouse Permission Management PermissionController.java deletePermission improper authorization
- CVE-2026-20791 PoCyeqifu warehouse Menu Management MenuController.java deleteMenu improper authorization
- CVE-2026-20801 PoCUTT HiPER 810 formUser setSysAdm command injection
- CVE-2026-20811 PoCD-Link DIR-823X set_password os command injection
- CVE-2026-20821 PoCD-Link DIR-823X set_mac_clone os command injection
- CVE-2026-20831 PoCcode-projects Social Networking Site delete_post.php sql injection
- CVE-2026-20841 PoCD-Link DIR-823X set_language os command injection
- CVE-2026-20851 PoCD-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection
- CVE-2026-20861 PoCUTT HiPER 810G Management formFireWall strcpy buffer overflow
- CVE-2026-20871 PoCSourceCodester Online Class Record System login.php sql injection
- CVE-2026-20881 PoCPHPGurukul Beauty Parlour Management System accepted-appointment.php sql injection
- CVE-2026-20891 PoCSourceCodester Online Class Record System controller.php sql injection
- CVE-2026-20901 PoCSourceCodester Online Class Record System search.php sql injection
- CVE-2026-21041 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-21051 PoCyeqifu warehouse Department Management DeptController.java deleteDept improper authorization
- CVE-2026-21061 PoCyeqifu warehouse Notice Management NoticeController.java batchDeleteNotice improper authorization
- CVE-2026-21071 PoCyeqifu warehouse Log Info LoginfoController.java batchDeleteLoginfo improper authorization
- CVE-2026-21081 PoCjsbroks COCO Annotator Endpoint long_task denial of service
- CVE-2026-21091 PoCjsbroks COCO Annotator Delete Category undo improper authorization
- CVE-2026-21101 PoCTasin1025 SwiftBuy login.php excessive authentication
- CVE-2026-21111 PoCJeecgBoot Retrieval-Augmented Generation edit path traversal
- CVE-2026-21132 PoCsyuan1994 tpadmin WebUploader preview.php deserialization
- CVE-2026-21141 PoCitsourcecode Society Management System edit_admin.php sql injection
- CVE-2026-21151 PoCitsourcecode Society Management System delete_expenses.php sql injection
- CVE-2026-21161 PoCitsourcecode Society Management System edit_expenses.php sql injection
- CVE-2026-21171 PoCitsourcecode Society Management System edit_activity.php sql injection
- CVE-2026-21181 PoCUTT HiPER 810 rehttpd formReleaseConnect sub_4407D4 command injection
- CVE-2026-21201 PoCD-Link DIR-823X Configuration Parameter set_server_settings os command injection
- CVE-2026-21221 PoCXiaopi Panel WAF Firewall demo.php sql injection
- CVE-2026-21291 PoCD-Link DIR-823X set_ac_status os command injection
- CVE-2026-21311 PoCXixianLiang HarmonyOS-mcp-server input_text os command injection
- CVE-2026-21321 PoCcode-projects Online Music Site AdminUpdateCategory.php sql injection
- CVE-2026-21331 PoCcode-projects Online Music Site AdminUpdateCategory.php unrestricted upload
- CVE-2026-21341 PoCPHPGurukul Hospital Management System manage-doctors.php sql injection
- CVE-2026-21351 PoCUTT HiPER 810 formPdbUpConfig sub_43F020 command injection
- CVE-2026-21361 PoCprojectworlds Online Food Ordering System view-ticket.php sql injection
- CVE-2026-21371 PoCTenda TX3 SetIpMacBind buffer overflow
- CVE-2026-21381 PoCTenda TX9 SetStaticRouteCfg sub_42D03C buffer overflow
- CVE-2026-21391 PoCTenda TX9 fast_setting_wifi_set sub_432580 buffer overflow
- CVE-2026-21401 PoCTenda TX9 setMacFilterCfg sub_4223E0 buffer overflow
- CVE-2026-21411 PoCWuKongOpenSource WukongCRM URL PermissionServiceImpl.java improper authorization
- CVE-2026-21421 PoCD-Link DIR-823X set_qos sub_420688 os command injection
- CVE-2026-21431 PoCD-Link DIR-823X DDNS Service set_ddns os command injection
- CVE-2026-21451 PoCcym1102 nginxWebUI Web Management check cross site scripting
- CVE-2026-21461 PoCguchengwuyue yshopmall co.yixiang.utils.FileUtil updateAvatar unrestricted upload
- CVE-2026-21471 PoCTenda AC21 Web Management DownloadLog information disclosure
- CVE-2026-21481 PoCTenda AC21 Web Management DownloadFlash information disclosure
- CVE-2026-21491 PoCSourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System appointments.php cross site scripting
- CVE-2026-21501 PoCSourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System checkin.php cross site scripting
- CVE-2026-21511 PoCD-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection
- CVE-2026-21521 PoCD-Link DIR-615 Web Configuration adv_routing.php os command injection
- CVE-2026-21531 PoCmwielgoszewski doorman views.py is_safe_url redirect
- CVE-2026-21541 PoCSourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System Patient Registration registration.php cross site scripting
- CVE-2026-21551 PoCD-Link DIR-823X Configuration set_dmz sub_4208A0 os command injection
- CVE-2026-21561 PoCcode-projects Online Student Management System Announcement Management index.php cross site scripting
- CVE-2026-21571 PoCD-Link DIR-823X set_static_route_table sub_4175CC os command injection
- CVE-2026-21591 PoCSourceCodester Simple Responsive Tourism Website Registration Master.php cross site scripting
- CVE-2026-21601 PoCSourceCodester Simple Responsive Tourism Website Master.php cross site scripting
- CVE-2026-21611 PoCitsourcecode Directory Management System forget-password.php sql injection
- CVE-2026-21621 PoCitsourcecode News Portal Project aboutus.php sql injection
- CVE-2026-21631 PoCD-Link DIR-600 ssdp.cgi command injection
- CVE-2026-21641 PoCdetronetdip E-commerce addadhar.php unrestricted upload
- CVE-2026-21651 PoCdetronetdip E-commerce Account Creation Endpoint add_seller.php missing authentication
- CVE-2026-21661 PoCcode-projects Online Reviewer System Login index.php sql injection
- CVE-2026-21671 PoCTotolink WA300 cstecgi.cgi setAPNetwork os command injection
- CVE-2026-21681 PoCD-Link DWR-M921 formLtefotaUpgradeQuectel sub_419920 command injection
- CVE-2026-21691 PoCD-Link DWR-M921 formLtefotaUpgradeFibocom command injection
- CVE-2026-21751 PoCD-Link DIR-823X set_upnp sub_420618 os command injection
- CVE-2026-21771 PoCSourceCodester Prison Management System Login session fixiation
- CVE-2026-21781 PoCr-huijts xcode-mcp-server run_lldb index.ts registerXcodeTools command injection
- CVE-2026-21791 PoCPHPGurukul Hospital Management System manage-users.php sql injection
- CVE-2026-21801 PoCTenda RX3 fast_setting_wifi_set stack-based overflow
- CVE-2026-21811 PoCTenda RX3 openSchedWifi stack-based overflow
- CVE-2026-21821 PoCUTT 进取 521G setSysAdm doSystem command injection
- CVE-2026-21851 PoCTenda RX3 MAC Filtering Configuration Endpoint setBlackRule set_device_name stack-based overflow
- CVE-2026-21861 PoCTenda RX3 SetIpMacBind fromSetIpMacBind stack-based overflow
- CVE-2026-21871 PoCTenda RX3 formSetQosBand set_qosMib_list stack-based overflow
- CVE-2026-21881 PoCUTT 进取 521G formPdbUpConfig sub_446B18 os command injection
- CVE-2026-21891 PoCitsourcecode School Management System index.php sql injection
- CVE-2026-21901 PoCitsourcecode School Management System controller.php sql injection
- CVE-2026-21911 PoCTenda AC9 formGetDdosDefenceList stack-based overflow
- CVE-2026-21921 PoCTenda AC9 formGetRebootTimer stack-based overflow
- CVE-2026-21941 PoCD-Link DI-7100G C1 start_proxy_client_email command injection
- CVE-2026-21951 PoCcode-projects Online Reviewer System questions-view.php sql injection
- CVE-2026-21961 PoCcode-projects Online Reviewer System exam-update.php sql injection
- CVE-2026-21971 PoCcode-projects Online Reviewer System exam-delete.php sql injection
- CVE-2026-21981 PoCcode-projects Online Reviewer System loaddata.php sql injection
- CVE-2026-21991 PoCcode-projects Online Reviewer System user-delete.php sql injection
- CVE-2026-22001 PoCheyewei JFinalCMS API Endpoint save cross site scripting
- CVE-2026-22011 PoCZeroWdd studentmanager LeaveController.java addLeave cross site scripting
- CVE-2026-22021 PoCTenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow
- CVE-2026-22031 PoCTenda AC8 Embedded Httpd Service fast_setting_wifi_set buffer overflow
- CVE-2026-22101 PoCD-Link DIR-823X set_filtering sub_4211C8 os command injection
- CVE-2026-22111 PoCcode-projects Online Music Site AdminDeleteCategory.php sql injection
- CVE-2026-22121 PoCcode-projects Online Music Site AdminEditCategory.php sql injection
- CVE-2026-22131 PoCcode-projects Online Music Site AdminAddAlbum.php unrestricted upload
- CVE-2026-22141 PoCcode-projects for Plugin AdminAddAlbum.php cross site scripting
- CVE-2026-22151 PoCrachelos WeRSS we-mp-rss JWT auth.py default key
- CVE-2026-22161 PoCrachelos WeRSS we-mp-rss tools.py download_export_file path traversal
- CVE-2026-22171 PoCitsourcecode Event Management System manage_user.php sql injection
- CVE-2026-22181 PoCD-Link DCS-933L alphapd setSystemAdmin command injection
- CVE-2026-22201 PoCcode-projects Online Reviewer System btn_functions.php sql injection
- CVE-2026-22211 PoCcode-projects Online Reviewer System Login index.php sql injection
- CVE-2026-22222 PoCscode-projects Online Reviewer System btn_functions.php cross site scripting
- CVE-2026-22231 PoCcode-projects Online Reviewer System index.php sql injection
- CVE-2026-22241 PoCcode-projects Online Reviewer System btn_functions.php cross site scripting
- CVE-2026-22251 PoCitsourcecode News Portal Project Administrator Login index.php sql injection
- CVE-2026-22261 PoCDouPHP ZIP File file.php unrestricted upload
- CVE-2026-22271 PoCD-Link DCS-931L setSystemAdmin doSystem command injection
- CVE-2026-22381 PoCMissing Authorization in GitLab
- CVE-2026-22401 PoCjanet-lang janet compile.c janetc_pop_funcdef out-of-bounds
- CVE-2026-22411 PoCjanet-lang janet os.c os_strftime out-of-bounds
- CVE-2026-22421 PoCjanet-lang janet specials.c janetc_if out-of-bounds
- CVE-2026-22451 PoCCCExtractor MPEG-TS File ts_tables.c parse_PMT out-of-bounds
- CVE-2026-22461 PoCAprilRobotics apriltag apriltag.c apriltag_detector_detect memory corruption
- CVE-2026-22563 PoCsCommand injection vulnerability in ModelScope's ms-agent
- CVE-2026-22581 PoCaardappel lobster wfc.h WaveFunctionCollapse memory corruption
- CVE-2026-22591 PoCaardappel lobster Parsing parser.h ParseStatements memory corruption
- CVE-2026-22601 PoCD-Link DCS-931L setSysAdmin os command injection
- CVE-2026-22621 PoCEasy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST API
- CVE-2026-22911 PoCCVE-2026-2291
- CVE-2026-23291 PoCGrandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
- CVE-2026-23321 PoCHTTP Request Smuggling via Chunked Extension Quoted-String Parsing
- CVE-2026-23431 PoCPeproDev Ultimate Invoice <= 2.2.5 - Unauthenticated Invoice Archive Download
- CVE-2026-23701 PoCImproper Handling of Parameters in GitLab
- CVE-2026-23911 PoCqs's arrayLimit bypass in comma parsing allows denial of service
- CVE-2026-23951 PoCSQLi in Xpoda Türkiye Informatics Technology's No Code Platform
- CVE-2026-24061 PoCIDOR in Universe Software's Online Registration and Workflow Management System
- CVE-2026-24133 PoCsAlly – Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path
- CVE-2026-24161 PoCGeo Mashup <= 1.13.17 - Unauthenticated SQL Injection via 'sort' Parameter
- CVE-2026-24181 PoCLogin with Salesforce <= 1.0.2 - Unauthenticated Authentication Bypass
- CVE-2026-24418 PoCsKEVUse after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
- CVE-2026-24461 PoCPowerpack for LearnDash < 1.3.0 - Unauthenticated Arbitrary Option Update
- CVE-2026-24611 PoCMissing authorization check allows unauthorized modification of other users' comments on a board
- CVE-2026-24661 PoCDukaPress <= 3.2.4 - Reflected XSS
- CVE-2026-24722 PoCsStored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization
- CVE-2026-25161 PoCUnidocs ezPDF DRM Reader/ezPDF Reader SHFOLDER.dll uncontrolled search path
- CVE-2026-25171 PoCOpen5GS SMF types.c ogs_gtp2_parse_tft denial of service
- CVE-2026-25211 PoCOpen5GS SGW-C sgwc_s5c_handle_create_session_response memory corruption
- CVE-2026-25221 PoCOpen5GS MME esm-build.c memory corruption
- CVE-2026-25231 PoCOpen5GS SMF gn-handler.c smf_gn_handle_create_pdp_context_request assertion
- CVE-2026-25241 PoCOpen5GS MME mme_s11_handle_create_session_response denial of service
- CVE-2026-25251 PoCFree5GC PFCP UDP Endpoint denial of service
- CVE-2026-25261 PoCWavlink WL-WN579A3 wireless.cgi multi_ssid command injection
- CVE-2026-25271 PoCWavlink WL-WN579A3 login.cgi command injection
- CVE-2026-25281 PoCWavlink WL-WN579A3 wireless.cgi Delete_Mac_list command injection
- CVE-2026-25301 PoCWavlink WL-WN579A3 wireless.cgi AddMac command injection
- CVE-2026-25311 PoCMindsDB File Upload security.py clear_filename server-side request forgery
- CVE-2026-25331 PoCTosei Self-service Washing Machine tosei_datasend.php command injection
- CVE-2026-25341 PoCComfast CF-N1 V2 mbox-config sub_44AC4C command injection
- CVE-2026-25351 PoCComfast CF-N1 V2 mbox-config sub_44AB9C command injection
- CVE-2026-25361 PoCopencc JFlow Workflow WF_Admin_AttrFlow.java Imp_Done xml external entity reference
- CVE-2026-25371 PoCComfast CF-E4 HTTP POST Request mbox-config command injection
- CVE-2026-25451 PoCLigeroSmart index.pl cross site scripting
- CVE-2026-25461 PoCLigeroSmart index.pl cross site scripting
- CVE-2026-25471 PoCLigeroSmart index.pl AgentDashboard cross site scripting
- CVE-2026-25491 PoCzhanghuanhao LibrarySystem 图书馆管理系统 BookController.java access control
- CVE-2026-25501 PoCEFM iptime A6004MX timepro.cgi commit_vpncli_file_upload unrestricted upload
- CVE-2026-25511 PoCZenTao Backup control.php delete path traversal
- CVE-2026-25531 PoCtushar-2223 Hotel-Management-System HTTP POST Request home.php sql injection
- CVE-2026-25561 PoCcskefu Endpoint MediaController.java server-side request forgery
- CVE-2026-25571 PoCcskefu File Upload MediaController.java upload cross site scripting
- CVE-2026-25581 PoCGeekAI net_handler.go Download server-side request forgery
- CVE-2026-25601 PoCkalcaddle kodbox Media File Preview Plugin VideoResize.class.php run os command injection
- CVE-2026-25611 PoCJingDong JD Cloud Box AX6600 jdcweb_rpc jdcapi web_get_ddns_uptime privileges management
- CVE-2026-25621 PoCJingDong JD Cloud Box AX6600 jdcweb_rpc jdcapi cast_streen privileges management
- CVE-2026-25631 PoCJingDong JD Cloud Box AX6600 jdcapp_rpc controlDevice get_status privileges management
- CVE-2026-25651 PoCWavlink WL-NU516U1 adm.cgi sub_40785C stack-based overflow
- CVE-2026-25661 PoCWavlink WL-NU516U1 adm.cgi sub_406194 stack-based overflow
- CVE-2026-25671 PoCWavlink WL-NU516U1 nas.cgi sub_401218 stack-based overflow
- CVE-2026-25761 PoCBusiness Directory Plugin <= 6.4.21 - Unauthenticated SQL Injection via payment Parameter
- CVE-2026-25862 PoCsAn authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the…
- CVE-2026-25871 PoCA critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish…
- CVE-2026-26001 PoCElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget
- CVE-2026-26011 PoCMissing Authorization in GitLab
- CVE-2026-26141 PoCArbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow
- CVE-2026-26151 PoCWavlink WL-NU516U1 firewall.cgi singlePortForwardDelete command injection
- CVE-2026-26161 PoCBeetel 777VR1 Web Management hard-coded credentials
- CVE-2026-26171 PoCBeetel 777VR1 Telnet Service/SSH Service insecure default initialization of resource
- CVE-2026-26181 PoCBeetel 777VR1 SSH Service risky encryption
- CVE-2026-26191 PoCIncorrect Authorization in GitLab
- CVE-2026-26201 PoCHuace Monitoring and Early Warning System ProjectRole.aspx sql injection
- CVE-2026-26211 PoCSciyon Koyuan Thermoelectricity Heat Network Management System AsyncTreeProxy.aspx sql injection
- CVE-2026-26221 PoCBlossom Article Title ArticleController.java content cross site scripting
- CVE-2026-26231 PoCBlossom File Upload BLOSManager.java put path traversal
- CVE-2026-26241 PoCAuthentication Bypass in ePati's Antikor NGFW
- CVE-2026-26261 PoCDivi Booster < 5.0.2 - Unauthenticated PHP Object Injection
- CVE-2026-26271 PoCSoftland FBackup Backup/Restore HID.dll link following
- CVE-2026-26291 PoCjishi node-sonos-http-api TTS Provider mac-os.js Promise os command injection
- CVE-2026-26312 PoCsDatalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege Escalation
- CVE-2026-26362 PoCsDenial of Service in Microsoft OS
- CVE-2026-26411 PoCuniversal-ctags V Language v.c parseExprList recursion
- CVE-2026-26421 PoCggreer the_silver_searcher search.c search_stream null pointer dereference
- CVE-2026-26441 PoCniklasso minisat DIMACS File SolverTypes.h value out-of-bounds
- CVE-2026-26521 PoCAuthentication Bypass in mlflow/mlflow
- CVE-2026-26531 PoCadmesh normals.c stl_check_normal_vector heap-based overflow
- CVE-2026-26541 PoChuggingface smolagents LocalPythonExecutor requests.post server-side request forgery
- CVE-2026-26551 PoCChaiScript chaiscript_defines.hpp operator use after free
- CVE-2026-26561 PoCChaiScript type_info.hpp bare_equal use after free
- CVE-2026-26571 PoCwren-lang wren Error Message wren_compiler.c printError stack-based overflow
- CVE-2026-26581 PoCnewbee-ltd newbee-mall Multiple Endpoints cross-site request forgery
- CVE-2026-26591 PoCSquirrel sqfuncstate.cpp PopTarget out-of-bounds
- CVE-2026-26601 PoCFascinatedBox lily lily_symtab.c shorthash_for_name use after free
- CVE-2026-26611 PoCSquirrel sqobject.h operator heap-based overflow
- CVE-2026-26621 PoCFascinatedBox lily lily_emitter.c count_transforms out-of-bounds
- CVE-2026-26651 PoChuanzi-qch base-admin JSP Parser SysFileController.java upload unrestricted upload
- CVE-2026-26661 PoCmingSoft MCMS Template Archive uploadTemplate.do unrestricted upload
- CVE-2026-26671 PoCRongzhitong Visual Integrated Command and Dispatch Platform api access control
- CVE-2026-26681 PoCRongzhitong Visual Integrated Command and Dispatch Platform User add access control
- CVE-2026-26691 PoCRongzhitong Visual Integrated Command and Dispatch Platform User delete access control
- CVE-2026-26702 PoCsAdvantech WISE-6610 Background Management openvpn_apply os command injection
- CVE-2026-26721 PoCTsinghua Unigroup Electronic Archives System downLoad download path traversal
- CVE-2026-26761 PoCGoogTech sms-ssm API LoginInterceptor.java preHandle improper authorization
- CVE-2026-26821 PoCTsinghua Unigroup Electronic Archives System prinReport.html sql injection
- CVE-2026-26831 PoCTsinghua Unigroup Electronic Archives System downLoad.html path traversal
- CVE-2026-26841 PoCTsinghua Unigroup Electronic Archives System uploadFile.html unrestricted upload
- CVE-2026-26861 PoCSECCN Dingcheng G10 session_login.cgi qq os command injection
- CVE-2026-26871 PoCReading progressbar < 1.3.1 - Admin+ Stored XSS
- CVE-2026-26881 PoCCM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass
- CVE-2026-26891 PoCitsourcecode Event Management System manage_booking.php sql injection
- CVE-2026-26901 PoCitsourcecode Event Management System Admin Login ajax.php sql injection
- CVE-2026-26911 PoCitsourcecode Event Management System manage_register.php sql injection
- CVE-2026-26961 PoCExport All URLs < 5.1 - Unauthenticated Sensitive Data Exposure
- CVE-2026-26993 PoCsEAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)
- CVE-2026-27021 PoCBeetel 777VR1 WPA2 PSK hard-coded credentials
- CVE-2026-27031 PoCxlnt-community xlnt Encrypted XLSX File base64.cpp decode_base64 off-by-one
- CVE-2026-27041 PoCOpen Babel CIF File transform3d.cpp DescribeAsString out-of-bounds
- CVE-2026-27051 PoCOpen Babel MOL2 File atom.h SetFormalCharge out-of-bounds
- CVE-2026-27061 PoCcode-projects Patient Record Management System fecalysis_not.php sql injection
- CVE-2026-27091 PoCbusy Callback app.js redirect
- CVE-2026-27111 PoCzhutoutoutousan worldquant-miner URL ssrf_proxy.py server-side request forgery
- CVE-2026-27261 PoCIncorrect Authorization in GitLab
- CVE-2026-27282 PoCsLibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful…
- CVE-2026-27451 PoCAuthentication Bypass Using an Alternate Path or Channel in GitLab
- CVE-2026-27481 PoCS/MIME Certificate Subject Whitespace
- CVE-2026-27631 PoCUse-after-free in the JavaScript Engine component
- CVE-2026-27641 PoCJIT miscompilation, use-after-free in the JavaScript Engine: JIT component
- CVE-2026-27661 PoCUse-after-free in the JavaScript Engine: JIT component
- CVE-2026-27962 PoCsJIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-28111 PoCAjaxify Comments < 3.2 - Unauthenticated HTTP Header Injection
- CVE-2026-28201 PoCFujian Smart Integrated Management Platform System XAccessPermissionPlus.ashx sql injection
- CVE-2026-28211 PoCFujian Smart Integrated Management Platform System XCamera.ashx sql injection
- CVE-2026-28221 PoCJeecgBoot Backend airag_app,1,create_by sql injection
- CVE-2026-28231 PoCComfast CF-E7 webmggnt mbox-config sub_41ACCC command injection
- CVE-2026-28241 PoCComfast CF-E7 webmggnt mbox-config sub_441CF4 command injection
- CVE-2026-28251 PoCrachelos WeRSS we-mp-rss Article fix.py fix_html cross site scripting
- CVE-2026-28461 PoCUTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection
- CVE-2026-28471 PoCUTT HiPER 520 Web Management formReleaseConnect sub_44EFB4 os command injection
- CVE-2026-28481 PoCSourceCodester Simple Responsive Tourism Website Registration Master.php sql injection
- CVE-2026-28491 PoCyeqifu warehouse Cache Sync CacheController.java syncCache access control
- CVE-2026-28501 PoCyeqifu warehouse Customer Endpoint CustomerController.java deleteCustomer access control
- CVE-2026-28511 PoCyeqifu warehouse Inport Endpoint InportController.java deleteInport access control
- CVE-2026-28521 PoCyeqifu warehouse Sales Endpoint SalesController.java deleteSales access control
- CVE-2026-28531 PoCD-Link DWR-M960 System Log Configuration Endpoint formSysLog sub_462E14 stack-based overflow
- CVE-2026-28541 PoCD-Link DWR-M960 NTP Configuration Endpoint formNtp sub_4611CC stack-based overflow
- CVE-2026-28551 PoCD-Link DWR-M960 DDNS Settings formDdns sub_4648F0 stack-based overflow
- CVE-2026-28561 PoCD-Link DWR-M960 Filter Configuration Endpoint formFilter sub_424AFC stack-based overflow
- CVE-2026-28571 PoCD-Link DWR-M960 Port Forwarding Configuration Endpoint formPortFw sub_423E00 stack-based overflow
- CVE-2026-28581 PoCwren-lang wren Source File wren_compiler.c peekChar out-of-bounds
- CVE-2026-28601 PoCfeng_ha_ha/megagao ssm-erp/production_ssm EmployeeController.java improper authorization
- CVE-2026-28631 PoCfeng_ha_ha/megagao ssm-erp/production_ssm FileServiceImpl.java deleteFile path traversal
- CVE-2026-28641 PoCfeng_ha_ha/megagao ssm-erp/production_ssm PictureController.java pictureDelete path traversal
- CVE-2026-28651 PoCitsourcecode Agri-Trading Online Shopping System HTTP POST Request productcontroller.php sql injection
- CVE-2026-28671 PoCitsourcecode Vehicle Management System billaction.php sql injection
- CVE-2026-28691 PoCjanet-lang janet handleattr specials.c janetc_varset out-of-bounds
- CVE-2026-28701 PoCTenda A21 formSetQosBand set_qosMib_list stack-based overflow
- CVE-2026-28711 PoCTenda A21 SetIpMacBind fromSetIpMacBind stack-based overflow
- CVE-2026-28721 PoCTenda A21 MAC Filtering Configuration Endpoint setBlackRule set_device_name stack-based overflow
- CVE-2026-28731 PoCTenda A21 openSchedWifi setSchedWifi stack-based overflow
- CVE-2026-28741 PoCTenda A21 fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow
- CVE-2026-28761 PoCTenda A18 setBlackRule parse_macfilter_rule stack-based overflow
- CVE-2026-28771 PoCTenda A18 Httpd Service WifiExtraSet strcpy stack-based overflow
- CVE-2026-28811 PoCD-Link DWR-M960 Advanced Firewall Configuration Endpoint formFirewallAdv sub_425FF8 stack-based overflow
- CVE-2026-28821 PoCD-Link DWR-M960 formDosCfg sub_46385C stack-based overflow
- CVE-2026-28831 PoCD-Link DWR-M960 formIpQoS sub_427D74 stack-based overflow
- CVE-2026-28841 PoCD-Link DWR-M960 WAN Interface Setting formWanConfigSetup sub_41914C stack-based overflow
- CVE-2026-28851 PoCD-Link DWR-M960 formIpv6Setup sub_469104 stack-based overflow
- CVE-2026-28861 PoCTenda A21 SetOnlineDevName set_device_name stack-based overflow
- CVE-2026-28871 PoCaardappel lobster idents.h TypeName recursion
- CVE-2026-28891 PoCCCExtractor mp4.c processmp4 use after free
- CVE-2026-28941 PoCfunadmin forget.html getMember information disclosure
- CVE-2026-28951 PoCfunadmin Member.php repass password recovery
- CVE-2026-28961 PoCfunadmin Configuration Ajax.php setConfig improper authorization
- CVE-2026-28971 PoCfunadmin Backend index.html cross site scripting
- CVE-2026-28982 PoCsfunadmin Backend Endpoint AuthCloudService.php getMember deserialization
- CVE-2026-29001 PoCMissing Authorization in GitLab
- CVE-2026-29031 PoCskvadrik re2c ast.cc check_and_merge_special_rules null pointer dereference
- CVE-2026-29041 PoCUTT HiPER 810G ConfigExceptAli strcpy buffer overflow
- CVE-2026-29051 PoCTenda HG9 Wireless Configuration Endpoint formWlanSetup stack-based overflow
- CVE-2026-29061 PoCTenda HG9 Samba Configuration Endpoint formSamba stack-based overflow
- CVE-2026-29071 PoCTenda HG9 GPON Configuration Endpoint formgponConf stack-based overflow
- CVE-2026-29081 PoCTenda HG9 Loopback Detection Configuration Endpoint formLoopBack stack-based overflow
- CVE-2026-29091 PoCTenda HG9 Diagnostic Ping Endpoint formPing stack-based overflow
- CVE-2026-29101 PoCTenda HG9 formPing6 stack-based overflow
- CVE-2026-29111 PoCTenda FH451 GstDhcpSetSer buffer overflow
- CVE-2026-29121 PoCcode-projects Online Reviewer System studentresult-view.php sql injection
- CVE-2026-29131 PoClibvips source.c vips_source_read_to_memory heap-based overflow
- CVE-2026-29251 PoCD-Link DWR-M960 Bridge VLAN Configuration Endpoint formBridgeVlan sub_42B5A0 stack-based overflow
- CVE-2026-29261 PoCD-Link DWR-M960 LTE Configuration Endpoint formLteSetup sub_4237AC stack-based overflow
- CVE-2026-29271 PoCD-Link DWR-M960 Operation Mode Configuration Endpoint formOpMode sub_462590 stack-based overflow
- CVE-2026-29281 PoCD-Link DWR-M960 WLAN Encryption Configuration Endpoint formWlEncrypt sub_452CCC stack-based overflow
- CVE-2026-29291 PoCD-Link DWR-M960 Wireless Access Control Endpoint formWlAc sub_453140 stack-based overflow
- CVE-2026-29301 PoCTenda A18 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflow
- CVE-2026-29321 PoCYiFang CMS Extended Management D_adPosition.php update cross site scripting
- CVE-2026-29331 PoCYiFang CMS Extended Management D_adManage.php update cross site scripting
- CVE-2026-29341 PoCYiFang CMS Extended Management D_friendLinkGroup.php update cross site scripting
- CVE-2026-29351 PoCUTT HiPER 810G ConfigExceptMSN strcpy buffer overflow
- CVE-2026-29381 PoCSourceCodester Student Result Management System update_smtp.php access control
- CVE-2026-29391 PoCitsourcecode Student Management System Add Student add_student cross site scripting
- CVE-2026-29401 PoCZaher1307 tiny_web_server URL tiny.c out-of-bounds write
- CVE-2026-29421 PoCProSolution WP Client <= 1.9.9 - Unauthenticated Arbitrary File Upload via proSol_fileUploadProcess
- CVE-2026-29431 PoCSapneshNaik Student Management System index.php cross site scripting
- CVE-2026-29441 PoCTosei Online Store Management System ネット店舗管理システム HTTP POST Request monitor.php system os command injection
- CVE-2026-29451 PoCJeecgBoot uploadImgByHttp server-side request forgery
- CVE-2026-29461 PoCrymcu forest Article Content/Comments/Portfolio XssUtils.java XssUtils.replaceHtmlCode cross site scripting
- CVE-2026-29471 PoCrymcu forest User Profile UserInfoController.java updateUserInfo cross site scripting
- CVE-2026-29521 PoCVaelsys HTTP POST Request tree_server.php os command injection
- CVE-2026-29531 PoCDromara UJCMS Template WebFileTemplateController.delete deleteDirectory path traversal
- CVE-2026-29541 PoCDromara UJCMS ImportDataController import-channel importChanel injection
- CVE-2026-29561 PoCqinming99 dst-admin restore revertBackup command injection
- CVE-2026-29571 PoCqinming99 dst-admin File BackupController.java deleteBackup denial of service
- CVE-2026-29581 PoCD-Link DWR-M960 formWsc sub_457C5C stack-based overflow
- CVE-2026-29591 PoCD-Link DWR-M960 formNewSchedule sub_44E0F8 stack-based overflow
- CVE-2026-29601 PoCD-Link DWR-M960 formDhcpv6s sub_468D64 stack-based overflow
- CVE-2026-29611 PoCD-Link DWR-M960 VPN Configuration Endpoint formVpnConfigSetup sub_4196C4 stack-based overflow
- CVE-2026-29621 PoCD-Link DWR-M960 Scheduled Reboot Configuration Endpoint formDateReboot sub_460F30 stack-based overflow
- CVE-2026-29631 PoCJinher OA C6 OfficeSupplyTypeRight.aspx sql injection
- CVE-2026-29651 PoC07FLYCMS/07FLY-CMS/07FlyCRM System Extension edit.html cross site scripting
- CVE-2026-29661 PoCCesanta Mongoose DNS Transaction ID dns.c mg_sendnsreq random values
- CVE-2026-29671 PoCCesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source
- CVE-2026-29681 PoCCesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verification
- CVE-2026-29691 PoCdatapizza-labs datapizza-ai Jinja2 Template prompt.py ChatPromptTemplate special elements used in a template engine
- CVE-2026-29701 PoCdatapizza-labs datapizza-ai cache.py RedisCache deserialization
- CVE-2026-29711 PoCa466350665 Smart-SSO Login login.html cross site scripting
- CVE-2026-29721 PoCa466350665 Smart-SSO Role Edit UserController.java save cross site scripting
- CVE-2026-29731 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-29741 PoCAliasVault App Backup aliasvault.xml backup
- CVE-2026-29751 PoCFastApiAdmin Custom Documentation Endpoint init_app.py reset_api_docs information disclosure
- CVE-2026-29761 PoCFastApiAdmin Download Endpoint controller.py download_controller information disclosure
- CVE-2026-29771 PoCFastApiAdmin Scheduled Task API controller.py upload_controller unrestricted upload
- CVE-2026-29781 PoCFastApiAdmin Scheduled Task API controller.py upload_file_controller unrestricted upload
- CVE-2026-29791 PoCFastApiAdmin Scheduled Task API controller.py user_avatar_upload_controller unrestricted upload
- CVE-2026-29801 PoCUTT HiPER 810G setSysAdm strcpy buffer overflow
- CVE-2026-29811 PoCUTT HiPER 810G formTaskEdit_ap strcpy buffer overflow
- CVE-2026-29831 PoCSourceCodester Student Result Management System Bulk Import import_users.php access control
- CVE-2026-29841 PoCSourceCodester Student Result Management System drop_user.php denial of service
- CVE-2026-29851 PoCTiandy Video Surveillance System 视频监控平台 CLSBODownLoad.java downloadImage server-side request forgery
- CVE-2026-29913 PoCsKiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token
- CVE-2026-29951 PoCImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab