CVE-2026-31000 to CVE-2026-31999
37 CVEs with public proof-of-concept exploits.
- CVE-2026-311561 PoCA path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from…
- CVE-2026-312662 PoCsCraft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).
- CVE-2026-312801 PoCAn issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause a Denial of…
- CVE-2026-312811 PoCTotara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all…
- CVE-2026-312821 PoCTotara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form.…
- CVE-2026-312831 PoCIn Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used…
- CVE-2026-313091 PoCImproper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated…
- CVE-2026-314021 PoCnfsd: fix heap overflow in NFSv4.0 LOCK replay cache
- CVE-2026-314131 PoCbpf: Fix unsound scalar forking in maybe_fork_scalars() for BPF_OR
- CVE-2026-314291 PoCnet: skb: fix cross-cache free of KFENCE-allocated skb head
- CVE-2026-31431234 PoCsKEVcrypto: algif_aead - Revert to operating out-of-place
- CVE-2026-315251 PoCbpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN
- CVE-2026-316353 PoCsrxrpc: fix oversized RESPONSE authenticator length check
- CVE-2026-316942 PoCsfuse: reject oversized dirents in page cache
- CVE-2026-317171 PoCksmbd: validate owner of durable handle on reconnect
- CVE-2026-317871 PoCxen/privcmd: fix double free via VMA splitting
- CVE-2026-318011 PoCzot create-only policy allows overwrite attempts of existing latest tag (update permission not required)
- CVE-2026-318022 PoCsnode-tar Symlink Path Traversal via Drive-Relative Linkpath
- CVE-2026-318072 PoCsSiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS
- CVE-2026-318092 PoCsSiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
- CVE-2026-318121 PoCQuinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
- CVE-2026-318151 PoCdjango-unicorn affected by component state manipulation via unvalidated attribute access
- CVE-2026-318164 PoCsBudibase Universal Auth Bypass via Webhook Query Param Injection
- CVE-2026-318171 PoCOliveTin's unsafe parsing of UniqueTrackingId can be used to write files
- CVE-2026-318291 PoCFlowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access
- CVE-2026-318311 PoCTautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint
- CVE-2026-318421 PoCTinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling
- CVE-2026-318441 PoCAuthenticated SQL Injection in Koha displayby parameter of suggestion.pl
- CVE-2026-318601 PoCUnhead has a XSS bypass in `useHeadSafe` via attribute name injection and case-sensitive protocol check
- CVE-2026-318731 PoCUnhead has a Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity
- CVE-2026-318821 PoCDagu SSE Authentication Bypass in Basic Auth Mode
- CVE-2026-318861 PoCDagu has a Path Traversal via `dagRunId` in Inline DAG Execution
- CVE-2026-318921 PoCWorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
- CVE-2026-318992 PoCsCairoSVG vulnerable to Exponential DoS via recursive <use> element amplification
- CVE-2026-319081 PoCApache APISIX: forward auth plugin allows header injection
- CVE-2026-319751 PoCCloud CLI WebSocket shell injection
- CVE-2026-319781 PoCmotionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint