CVE-2026-30000 to CVE-2026-30999
76 CVEs with public proof-of-concept exploits.
- CVE-2026-300481 PoCA stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly…
- CVE-2026-300821 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server…
- CVE-2026-302231 PoCOliveTin: JWT Audience Validation Bypass in Local Key and HMAC Modes
- CVE-2026-302241 PoCOliveTin: Session Fixation - Logout Fails to Invalidate Server-Side Session
- CVE-2026-302251 PoCOliveTin: RestartAction always runs actions as guest
- CVE-2026-302271 PoCMimeKit: CRLF Injection in Quoted Local-Part Enables SMTP Command Injection and Email Forgery
- CVE-2026-302331 PoCOliveTin: View permission not being checked when returning dashboards
- CVE-2026-302461 PoCgithub.com/gofiber/fiber/v3 cache middleware can mix responses across query parameters
- CVE-2026-302471 PoCWeKnora: SSRF via Redirection
- CVE-2026-302512 PoCsA reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0…
- CVE-2026-302521 PoCMultiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0…
- CVE-2026-303321 PoCA Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to…
- CVE-2026-303451 PoCA zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside…
- CVE-2026-303681 PoCA client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by…
- CVE-2026-304801 PoCA Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated…
- CVE-2026-304981 PoCA Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.
- CVE-2026-306231 PoCLiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to…
- CVE-2026-306911 PoCCross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via…
- CVE-2026-306951 PoCA Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access control devices,…
- CVE-2026-307411 PoCA remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a…
- CVE-2026-307831 PoCRustDesk Client Can Orphan API Channel to Ignore All Admin Commands and ACL Policies
- CVE-2026-307851 PoCRustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2026-307891 PoCRustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
- CVE-2026-307911 PoCRustDesk Client Accepts Pseudo-Encrypted Config Strings Without Cryptographic Validation
- CVE-2026-307921 PoCRustDesk Client Blindly Merges Unauthenticated Strategy Payloads, Bypassing Local Security Settings
- CVE-2026-307931 PoCRustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
- CVE-2026-307951 PoCRustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure
- CVE-2026-307961 PoCRustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat Sync
- CVE-2026-307971 PoCRustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled Server
- CVE-2026-307981 PoCRustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload
- CVE-2026-308201 PoCFlowise Authorization Bypass via Spoofed x-request-from Header
- CVE-2026-308211 PoCFlowise: Arbitrary File Upload via MIME Spoofing
- CVE-2026-308231 PoCFlowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration
- CVE-2026-308243 PoCsFlowise: Missing Authentication on NVIDIA NIM Endpoints
- CVE-2026-308271 PoCexpress-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting (all IPv4 clients share one bucket on dual-stack servers)
- CVE-2026-308301 PoCDefuddle: XSS via unescaped string interpolation in _findContentBySchemaText image tag
- CVE-2026-308321 PoCSoft Serve: SSRF via unvalidated LFS endpoint in repo import
- CVE-2026-308341 PoCPinchTab: SSRF with Full Response Exfiltration via Download Handler
- CVE-2026-308371 PoCElysia has a string URL format redos
- CVE-2026-308492 PoCsMantisBT SOAP API has an authentication bypass vulnerability on MySQL
- CVE-2026-308521 PoCCaddy: vars_regexp double-expands user input, leaking env vars and files
- CVE-2026-308551 PoCWeKnora: Broken Access Control in Tenant Management
- CVE-2026-308561 PoCWeKnora: Tool Execution Hijacking via Ambigous Naming Convention In MCP client and Indirect Prompt Injection
- CVE-2026-308571 PoCWeKnora: Unauthorized Cross‑Tenant Knowledge Base Cloning
- CVE-2026-308581 PoCWeKnora: DNS Rebinding Vulnerability in web_fetch Tool Allows SSRF to Internal Resources
- CVE-2026-308591 PoCWeKnora: Broken Access Control - Cross-Tenant Data Exposure
- CVE-2026-308601 PoCWeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
- CVE-2026-308611 PoCWeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation
- CVE-2026-308621 PoCCritical Stored XSS & Privilege Escalation in Appsmith
- CVE-2026-308631 PoCParse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
- CVE-2026-308691 PoCSiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage
- CVE-2026-308781 PoCbaserCMS: Mail Form Acceptance Bypass via Public API
- CVE-2026-308851 PoCWWBN AVideo - Unauthenticated IDOR - Playlist Information Disclosure
- CVE-2026-308861 PoCNew API: IDOR in VideoProxy allows cross-user video content access via missing ownership check
- CVE-2026-308871 PoCOneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE
- CVE-2026-309131 PoCflarum/nickname: Display name injection in notification emails (autolink & markdown)
- CVE-2026-309201 PoCOneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
- CVE-2026-309211 PoCOneUptime Synthetic Monitor RCE via exposed Playwright browser object
- CVE-2026-309221 PoCpyasn1 Vulnerable to Denial of Service via Unbounded Recursion
- CVE-2026-309261 PoCSiYuan Note publish service authorization bypass allows low-privilege users to modify notebook content
- CVE-2026-309282 PoCsGlances Exposes Unauthenticated Configuration Secrets
- CVE-2026-309301 PoCGlances has SQL Injection via Process Names in TimescaleDB Export
- CVE-2026-309321 PoCFroxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API
- CVE-2026-309331 PoCFileBrowser Quantum Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info
- CVE-2026-309341 PoCFileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)
- CVE-2026-309443 PoCsStudioCMS Affected by Privilege Escalation via Insecure API Token Generation
- CVE-2026-309452 PoCsStudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service
- CVE-2026-309501 PoCAutoGPT has Authenticated Session Hijacking via IDOR
- CVE-2026-309512 PoCsSequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
- CVE-2026-309521 PoCliquidjs has a path traversal fallback vulnerability
- CVE-2026-309571 PoCOneUptime Synthetic Monitor RCE via exposed Playwright browser object
- CVE-2026-309581 PoCOneUptime: Path Traversal — Arbitrary File Read (No Auth)
- CVE-2026-309591 PoCOneUptime has WhatsApp Resend Verification Authorization Bypass
- CVE-2026-309631 PoCCapsule Namespace Hijacking via subresource
- CVE-2026-309641 PoCWebauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation
- CVE-2026-309651 PoCParse Server session token exfiltration via `redirectClassNameForKey` query parameter