CVE-2026-32000 to CVE-2026-32999
112 CVEs with public proof-of-concept exploits.
- CVE-2026-320631 PoCOpenClaw 2026.2.19-2 < 2026.2.21 - Command Injection via Newline in systemd Unit Generation
- CVE-2026-320941 PoCShescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash
- CVE-2026-320961 PoCPlunk has SSRF via unvalidated AWS SNS SubscriptionConfirmation in POST /webhooks/sns
- CVE-2026-321021 PoCOliveTin Unauthorized Action Output Disclosure via EventStream
- CVE-2026-321031 PoCStudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation
- CVE-2026-321101 PoCSiYuan has a Full-Read SSRF via /api/network/forwardProxy
- CVE-2026-321271 PoCSQL Injection Vulnerability in ajax graphs library (OpenEMR)
- CVE-2026-321362 PoCsAdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication Bypass
- CVE-2026-321941 PoCMicrosoft Bing Images Remote Code Execution Vulnerability
- CVE-2026-322011 PoCKEVMicrosoft SharePoint Server Spoofing Vulnerability
- CVE-2026-322024 PoCsKEVWindows Shell Spoofing Vulnerability
- CVE-2026-322231 PoCWindows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability
- CVE-2026-322302 PoCsUptime Kuma is Missing Authorization Checks on Ping Badge Endpoint, Leaks Ping times of monitors without needing to be on a status page
- CVE-2026-322311 PoCZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload data
- CVE-2026-322381 PoCOpenEMR has Remote Code Execution in backup functionality
- CVE-2026-322451 PoCTinyauth's OIDC authorization codes are not bound to client on token exchange
- CVE-2026-322461 PoCTinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
- CVE-2026-322471 PoCGraphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
- CVE-2026-322541 PoCKube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS
- CVE-2026-322552 PoCsKan is Vulnerable to Unauthenticated SSRF via Attachment Download Endpoint
- CVE-2026-322671 PoCCraft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
- CVE-2026-323011 PoCCentrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL
- CVE-2026-323021 PoCOpenClaw: Untrusted web origins can obtain authenticated operator.admin access in trusted-proxy mode
- CVE-2026-323131 PoCxmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
- CVE-2026-323151 PoCmotionEye: World-Readable Configuration File Exposes Admin Password Hash
- CVE-2026-323211 PoCClipBucket v5 has time-based Blind SQL Injection in ajax.php that leads to Data Exfiltration
- CVE-2026-324511 PoCWordPress Fusion Builder plugin < 3.15.0 - Broken Access Control vulnerability
- CVE-2026-324521 PoCWordPress Fusion Builder plugin < 3.15.0 - Broken Access Control vulnerability
- CVE-2026-324754 PoCsWordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
- CVE-2026-324881 PoCWordPress User Registration plugin <= 4.4.9 - Privilege Escalation vulnerability
- CVE-2026-325421 PoCWordPress Fusion Builder plugin < 3.15.0 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2026-325831 PoCWordPress Modern Events Calendar plugin <= 7.29.0 - Broken Access Control vulnerability
- CVE-2026-325951 PoCTraefik: BasicAuth Middleware Timing Attack Allows Username Enumeration
- CVE-2026-325962 PoCsGlances exposes the REST API without authentication
- CVE-2026-325981 PoCOneUptime: Password Reset Token Logged at INFO Level
- CVE-2026-326001 PoCxml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
- CVE-2026-326041 PoCSpinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
- CVE-2026-326061 PoCIncusOS has a LUKS encryption bypass due to insufficient TPM policy
- CVE-2026-326081 PoCGlances has a Command Injection via Process Names in Action Command Templates
- CVE-2026-326091 PoCGlances has Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials
- CVE-2026-326101 PoCGlances's Default CORS Configuration Allows Cross-Origin Credential Theft
- CVE-2026-326111 PoCGlances has a SQL Injection in DuckDB Export via Unparameterized DDL Statements
- CVE-2026-326131 PoCSpinnaker vulnerable to RCE via expression parsing due to unrestricted context handling
- CVE-2026-326211 PoCApollo Federation has prototype pollution via incomplete key sanitization
- CVE-2026-326291 PoCphpMyFAQ: Stored XSS via Unsanitized Email Field in Admin FAQ Editor
- CVE-2026-326301 PoCfile-type affected by ZIP Decompression Bomb DoS via [Content_Types].xml entry
- CVE-2026-326321 PoCGlances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding
- CVE-2026-326331 PoCGlances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`
- CVE-2026-326341 PoCGlances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers
- CVE-2026-326381 PoCStudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
- CVE-2026-326461 PoCGardyn Cloud API Missing Authentication for Critical Function
- CVE-2026-326622 PoCsGardyn Cloud API Active Debug Code
- CVE-2026-326861 PoCUnbounded exponent in decimal enables unauthenticated DoS
- CVE-2026-326931 PoCUnauthorized access to Kubernetes secrets in Juju
- CVE-2026-326951 PoCTraefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
- CVE-2026-326991 PoCFacturaScripts unauthorized modification of immutable nick field via EditUser controller
- CVE-2026-327041 PoCSiYuan renderSprig: missing admin check allows any user to read full workspace DB
- CVE-2026-327071 PoCPX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop
- CVE-2026-327111 PoCpydicom: Path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root
- CVE-2026-327141 PoCSciTokens vulnerable to SQL Injection in KeyCache
- CVE-2026-327222 PoCsMemray-generated HTML reports vulnerable to Stored XSS via unescaped command-line metadata
- CVE-2026-327231 PoCSandboxJS timers have an execution-quota bypass (cross-sandbox currentTicks race)
- CVE-2026-327271 PoCSciTokens: Authorization Bypass via Path Traversal in Scope Validation
- CVE-2026-327301 PoCApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
- CVE-2026-327312 PoCsApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction
- CVE-2026-327432 PoCsPX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling
- CVE-2026-327468 PoCstelnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because…
- CVE-2026-327471 PoCSiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets
- CVE-2026-327491 PoCSiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
- CVE-2026-327501 PoCSiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
- CVE-2026-327551 PoCAdmidio is Missing CSRF Protection on Role Membership Date Changes
- CVE-2026-327561 PoCAdmidio: Unrestricted File Upload via CSRF Token Validation Bypass in Documents & Files Module
- CVE-2026-327571 PoCAdmidio: HTMLPurifier Bypass in eCard Message Allows HTML Email Injection
- CVE-2026-327581 PoCFile Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter
- CVE-2026-327591 PoCFile Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely
- CVE-2026-327601 PoCFile Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin
- CVE-2026-327611 PoCFile Browser has an Authorization Policy Bypass in its Public Share Download Flow
- CVE-2026-327631 PoCSQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.
- CVE-2026-327671 PoCSiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API
- CVE-2026-327711 PoCMonitoring is vulnerable to Archive Slip due to missing checks in sanitization
- CVE-2026-327941 PoCApache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
- CVE-2026-328051 PoCRomeo is vulnerable to Archive Slip due to missing checks in sanitization
- CVE-2026-328111 PoCHeimdall: Path received via Envoy gRPC corrupted when containing query string
- CVE-2026-328121 PoCAdmidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint
- CVE-2026-328131 PoCAdmidio: Second-Order SQL Injection via List Configuration (lsc_special_field, lsc_sort, lsc_filter)
- CVE-2026-328161 PoCAdmidio has Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions
- CVE-2026-328171 PoCAdmidio is Missing Authorization and CSRF Protection on Document and Folder Deletion
- CVE-2026-328181 PoCAdmidio is Missing Authorization on Forum Topic and Post Deletion
- CVE-2026-328341 PoCEasy PayPal Events & Tickets < 1.4 Authentication Bypass via QR Code Scanning
- CVE-2026-328361 PoCmackron / dr_libs dr_flac.h Excessive Memory Allocation in PICTURE Metadata Parsing
- CVE-2026-328451 PoCjkuhlmann / cgltf <= 1.15 Sparse Accessor Validation Integer Overflow
- CVE-2026-328481 PoCNetBSD cryptodev Race Condition Double-Free via cryptodev_op()
- CVE-2026-328491 PoCNetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c
- CVE-2026-328501 PoCMailEnable < 10.55 Reflected XSS via ManageShares.aspx SelectedIndex Parameter
- CVE-2026-328511 PoCMailEnable < 10.55 Reflected XSS via FreeBusy.aspx StartDate Parameter
- CVE-2026-328521 PoCMailEnable < 10.55 Reflected XSS via FreeBusy.aspx StartDate Parameter
- CVE-2026-328711 PoCFastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
- CVE-2026-328731 PoCewe: Loop with Unreachable Exit Condition ('Infinite Loop')
- CVE-2026-328811 PoCewe has an Overly Permissive List of Allowed Inputs
- CVE-2026-328851 PoCDDEV has ZipSlip path traversal in tar and zip archive extraction
- CVE-2026-328871 PoCEffect Bug: `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPC
- CVE-2026-328891 PoCtinytag: Denial of Service via non-terminating SYLT frame parsing loop
- CVE-2026-329131 PoCOpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects
- CVE-2026-329331 PoCAutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion
- CVE-2026-329361 PoCCoreDNS DoH GET path missing size validation causes CPU and memory amplification
- CVE-2026-329401 PoCSiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)
- CVE-2026-329411 PoCSliver Vulnerable to Authenticated OOM via Memory Exhaustion in mTLS/WireGuard Transports
- CVE-2026-329451 PoCPJSIP is vulnerable to Heap-based Buffer Overflow through DNS parser
- CVE-2026-329811 PoCRay Dashboard <= 2.8.0 Path Traversal Leading to Local File Disclosure
- CVE-2026-329852 PoCsXerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
- CVE-2026-329861 PoCTextpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection
- CVE-2026-329891 PoCPrecurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file upload