CVE-2026-33000 to CVE-2026-33999
194 CVEs with public proof-of-concept exploits.
- CVE-2026-330061 PoCApache HTTP Server: mod_auth_digest timing attack
- CVE-2026-3301728 PoCsKEVLangflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
- CVE-2026-330261 PoCnginx-ui Backup Restore Allows Tampering with Encrypted Backups
- CVE-2026-330271 PoCNginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory
- CVE-2026-330281 PoCNginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse
- CVE-2026-330291 PoCNginx UI: DoS via Negative Integer Input in Logrotate Interval
- CVE-2026-330301 PoCNginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys
- CVE-2026-330324 PoCsNginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
- CVE-2026-330331 PoCPotential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload
- CVE-2026-330351 PoCUnauthenticated Reflected XSS via innerHTML in AVideo
- CVE-2026-330381 PoCAVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
- CVE-2026-330391 PoCAVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
- CVE-2026-330431 PoCAVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
- CVE-2026-330441 PoCHome Assistant has stored XSS in Map-card through malicious device name
- CVE-2026-330451 PoCHome Assistant has stored XSS in history-graphs
- CVE-2026-330541 PoCMesop: Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion
- CVE-2026-330551 PoCtar-rs incorrectly ignores PAX size headers if header size is nonzero
- CVE-2026-330572 PoCsMesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py
- CVE-2026-330601 PoCCKAN MCP Server: SSRF via base_url allows access to internal networks
- CVE-2026-330661 PoCSiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
- CVE-2026-330672 PoCsSiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata
- CVE-2026-331171 PoCAzure SDK for Java Security Feature Bypass Vulnerability
- CVE-2026-331281 PoCh3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields
- CVE-2026-331371 PoCXWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
- CVE-2026-331391 PoCPySpector: Plugin Sandbox Bypass leads to Arbitrary Code Execution
- CVE-2026-331431 PoCOneUptime: WhatsApp Webhook Missing Signature Verification
- CVE-2026-331461 PoCDocmost's Public Share Search Exposes Metadata of Restricted Children
- CVE-2026-331491 PoCTandoor Recipes Vulnerable to Host Header Injection
- CVE-2026-331541 PoCdynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver
- CVE-2026-331551 PoCDeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT
- CVE-2026-331591 PoCCraft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users
- CVE-2026-331661 PoCAllure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers)
- CVE-2026-331861 PoCgRPC-Go has an authorization bypass via missing leading slash in :path
- CVE-2026-332031 PoCSiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass
- CVE-2026-332041 PoCSimpleJWT has an Unauthenticated Denial of Service via JWE header tampering
- CVE-2026-332261 PoCBudibase Unrestricted Server-Side Request Forgery (SSRF) via REST Datasource Query Preview
- CVE-2026-332291 PoCXWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API
- CVE-2026-332301 PoCnltk Vulnerable to Cross-site Scripting
- CVE-2026-332311 PoCNLTK has unauthenticated remote shutdown in nltk.app.wordnet_app
- CVE-2026-332361 PoCNLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
- CVE-2026-332421 PoCSalvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway Bypass
- CVE-2026-332671 PoCApache Traffic Server: Untrusted @ headers can spoof ATS internal metadata
- CVE-2026-332851 PoCLiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash
- CVE-2026-332871 PoCLiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern
- CVE-2026-332921 PoCAVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Videos
- CVE-2026-332931 PoCAVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter
- CVE-2026-332941 PoCAVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network Resources
- CVE-2026-332951 PoCAVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php
- CVE-2026-332961 PoCAVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php
- CVE-2026-332971 PoCAVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.php
- CVE-2026-333091 PoCLangflow has an Arbitrary File Write (RCE) via v2 API
- CVE-2026-333102 PoCsIntake has a Command Injection via shell() Expansion in Parameter Defaults
- CVE-2026-333121 PoCRead-only Vikunja users can delete project background images via broken object-level authorization
- CVE-2026-333141 PoCpyload-ng: Improper Authentication and Origin Validation Error
- CVE-2026-333151 PoCVikunja has a 2FA Bypass via Caldav Basic Auth
- CVE-2026-333171 PoCOP-TEE: PKCS#11 TA out-of-bounds read and memory disclosure
- CVE-2026-333181 PoCActual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
- CVE-2026-333191 PoCAVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command
- CVE-2026-333201 PoCDasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
- CVE-2026-333311 PoCoRPC: Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify
- CVE-2026-333402 PoCsLoLLMs WEBUI has unauthenticated Server-Side Request Forgery (SSRF) in /api/proxy endpoint
- CVE-2026-333441 PoCDagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG
- CVE-2026-333491 PoCfast-xml-parser: Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation
- CVE-2026-333521 PoCAVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)
- CVE-2026-333531 PoCSoft Serve: Authenticated repo import can clone server-local private repositories
- CVE-2026-333541 PoCAVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
- CVE-2026-334331 PoCTraefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
- CVE-2026-334394 PoCsPre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
- CVE-2026-334421 PoCKysely has a MySQL SQL Injection via Backslash Escape Bypass in non-type-safe usage of JSON path keys.
- CVE-2026-334533 PoCsApache Camel: CoAP URI Query Parameter to Exchange Header Injection in camel-coap Allows Single-Packet Pre-Auth Remote Code Execution
- CVE-2026-334541 PoCApache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection…
- CVE-2026-334681 PoCKysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string…
- CVE-2026-334762 PoCsSiYuan has an Unauthenticated Arbitrary File Read via Path Traversal
- CVE-2026-334781 PoCAVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
- CVE-2026-334791 PoCAVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin
- CVE-2026-334801 PoCAVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
- CVE-2026-334821 PoCAVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()
- CVE-2026-334831 PoCAVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php
- CVE-2026-334851 PoCAVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Parameter
- CVE-2026-334861 PoCRoadiz has Server-Side Request Forgery (SSRF) in roadiz/documents
- CVE-2026-334871 PoCgoxmldsig has validateSignature Loop Variable Capture Signature Bypass
- CVE-2026-334881 PoCAVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl Plugin
- CVE-2026-334901 PoCh3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
- CVE-2026-334921 PoCAVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
- CVE-2026-334931 PoCAVideo has a Path Traversal in import.json.php that Allows Private Video Theft and Arbitrary File Read/Deletion via fileURI Parameter
- CVE-2026-334972 PoCsLangflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
- CVE-2026-334991 PoCAVideo has Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPage.php
- CVE-2026-335001 PoCAVideo Vulnerable to Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWithLinks Sanitization
- CVE-2026-335021 PoCAVideo has Unauthenticated SSRF via plugin/Live/test.php
- CVE-2026-335071 PoCAVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
- CVE-2026-335091 PoCpyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration
- CVE-2026-335121 PoCAVideo has an unauthenticated decrypt oracle leaking any ciphertext
- CVE-2026-335131 PoCAVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)
- CVE-2026-335281 PoCGoDoxy has a Path Traversal Vulnerability in its File API
- CVE-2026-335331 PoCGlances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
- CVE-2026-335343 PoCsEspoCRM has authenticated SSRF via internal-host validation bypass using alternative IPv4 notation
- CVE-2026-335401 PoCDistribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
- CVE-2026-335421 PoCIncus does not verify combined fingerprint when downloading images from simplestreams servers
- CVE-2026-335442 PoCsTinyauth has OAuth account confusion via shared mutable state on singleton service instances
- CVE-2026-335451 PoCMobSF has SQL Injection in its SQLite Database Viewer Utils
- CVE-2026-335521 PoCNorthern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.
- CVE-2026-335551 PoCAn issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously…
- CVE-2026-336191 PoCPinchTab has Unauthenticated Blind SSRF in Task Scheduler via Unvalidated callbackUrl
- CVE-2026-336201 PoCPinchTab: API Bearer Token Exposed in URL Query Parameter via Server Logs and Intermediary Systems
- CVE-2026-336211 PoCPinchTab: Unapplied Rate Limiting Middleware Allows Unbounded Brute-Force of API Token
- CVE-2026-336221 PoCA PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution
- CVE-2026-336231 PoCPinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command Execution
- CVE-2026-336262 PoCsLMDeploy Vulnerable to Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
- CVE-2026-336281 PoCInvoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items
- CVE-2026-336341 PoCKEVTrivy ecosystem supply chain briefly compromised
- CVE-2026-336351 PoCiCalendar has ICS injection via unsanitized URI property values
- CVE-2026-336371 PoCFaraday: Protocol-relative URI objects still bypass host scoping (possible incomplete fix for GHSA-33mh-2634-fwr2)
- CVE-2026-336412 PoCsGlances Vulnerable to Command Injection via Dynamic Configuration Values
- CVE-2026-336461 PoCmise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
- CVE-2026-336471 PoCAVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload
- CVE-2026-336481 PoCAVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path
- CVE-2026-336491 PoCAVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification
- CVE-2026-336501 PoCAVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion
- CVE-2026-336511 PoCAVideo has a Blind SQL Injection in Live Schedule Reminder via Unsanitized live_schedule_id in Scheduler_commands::getAllActiveOrToRepeat()
- CVE-2026-336561 PoCEspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user
- CVE-2026-336571 PoCEspoCRM: Stored HTML injection in email notifications about stream notes via unescaped post field
- CVE-2026-336611 PoCWeChat Pay callback signature verification bypassed when Host header is localhost
- CVE-2026-336681 PoCVikunja Allows Disabled/Locked User Accounts to Authenticate via API Tokens, CalDAV, and OpenID Connect
- CVE-2026-336711 PoCPicomatch has a ReDoS vulnerability via extglob quantifiers
- CVE-2026-336751 PoCVikunja has SSRF via Todoist/Trello Migration File Attachment URLs that Allows Reading Internal Network Resources
- CVE-2026-336761 PoCVikunja has Cross-Project Information Disclosure via Task Relations — Missing Authorization Check on Related Task Read
- CVE-2026-336771 PoCWebhook BasicAuth Credentials Exposed to Read-Only Project Collaborators via API
- CVE-2026-336781 PoCVikunja has IDOR in Task Attachment ReadOne Allows Cross-Project File Access and Deletion
- CVE-2026-336791 PoCVikunja has SSRF via OpenID Connect Avatar Download that Bypasses Webhook SSRF Protections
- CVE-2026-336801 PoCVikunja Vulnerable to Link Share Hash Disclosure via ReadAll Endpoint Enables Permission Escalation
- CVE-2026-336811 PoCAVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin Name
- CVE-2026-336831 PoCAVideo vulnerable to Stored XSS via html_entity_decode() Reversing xss_esc() Sanitization in Channel About Field
- CVE-2026-336901 PoCAVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()
- CVE-2026-336932 PoCsLemmy's Activitypub-Federation has SSRF via 0.0.0.0 bypass in activitypub-federation-rust v4_is_invalid()
- CVE-2026-337011 PoCOpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution
- CVE-2026-337111 PoCIncus vulnerable to local privilege escalation through VM screenshot path
- CVE-2026-337121 PoCTypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls
- CVE-2026-337151 PoCChamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action
- CVE-2026-337161 PoCAVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php
- CVE-2026-337171 PoCAVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with Resolution Validation Abort
- CVE-2026-337181 PoCOpenHands is Vulnerable to Command Injection through its Git Diff Handler
- CVE-2026-337191 PoCAVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment in status.json.php
- CVE-2026-337231 PoCAVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subscribe.php
- CVE-2026-337251 PoCMetabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import
- CVE-2026-337311 PoCAVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
- CVE-2026-337431 PoCIncus vulnerable to denial of source through crafted bucket backup file
- CVE-2026-337441 PoCBentoML has Dockerfile Command Injection via system_packages in bentofile.yaml
- CVE-2026-337522 PoCsRedirect-based SSRF leading to internal network access in curl_cffi (with TLS impersonation bypass)
- CVE-2026-337531 PoCImproper Certificate Validation in rfc3161-client
- CVE-2026-337591 PoCAVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents
- CVE-2026-337601 PoCLangflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
- CVE-2026-337631 PoCAVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean Oracle
- CVE-2026-337641 PoCAVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcriptions
- CVE-2026-337661 PoCAVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints
- CVE-2026-337671 PoCAVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into Query
- CVE-2026-337681 PoCAstro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
- CVE-2026-337691 PoCAstro: Remote allowlist bypass via unanchored matchPathname wildcard
- CVE-2026-337701 PoCAVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Variables
- CVE-2026-338051 PoC@fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers
- CVE-2026-338061 PoCfastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header
- CVE-2026-338071 PoC@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes
- CVE-2026-338081 PoC@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
- CVE-2026-338242 PoCsKEVWindows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
- CVE-2026-338254 PoCsKEVMicrosoft Defender Elevation of Privilege Vulnerability
- CVE-2026-338261 PoCWindows Active Directory Remote Code Execution Vulnerability
- CVE-2026-338271 PoCWindows TCP/IP Remote Code Execution Vulnerability
- CVE-2026-338292 PoCsWindows Snipping Tool Spoofing Vulnerability
- CVE-2026-338651 PoCStored XSS via unsafe YAML parsing in MLflow
- CVE-2026-338661 PoCAuthorization Bypass in MLflow AJAX Endpoint
- CVE-2026-338681 PoCMastodon has a GET-Based Open Redirect via '/web/%2F<domain>'
- CVE-2026-338701 PoCNetty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
- CVE-2026-338771 PoCApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
- CVE-2026-338881 PoCApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
- CVE-2026-338891 PoCApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context
- CVE-2026-338911 PoCForge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
- CVE-2026-338941 PoCForge has signature forgery in RSA-PKCS due to ASN.1 extra field
- CVE-2026-338951 PoCForge has signature forgery in Ed25519 due to missing S > L check
- CVE-2026-338961 PoCForge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
- CVE-2026-339171 PoCOpenEMR has SQL Injection in CAMOS Form
- CVE-2026-339362 PoCspython-ecdsa: Denial of Service via improper DER length validation in crafted private keys
- CVE-2026-339375 PoCsHandlebars.js has JavaScript Injection via AST Type Confusion
- CVE-2026-339381 PoCHandlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
- CVE-2026-339391 PoCHandlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
- CVE-2026-339401 PoCHandlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
- CVE-2026-339411 PoCHandlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
- CVE-2026-339431 PoCHappy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
- CVE-2026-339461 PoCMCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
- CVE-2026-339491 PoC@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
- CVE-2026-339501 PoCsignalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
- CVE-2026-339801 PoCAzure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
- CVE-2026-339811 PoCChangedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
- CVE-2026-339921 PoCpyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
- CVE-2026-339931 PoCLocutus has Prototype Pollution via __proto__ Key Injection in unserialize()
- CVE-2026-339941 PoCLocutus Prototype Pollution due to incomplete fix for CVE-2026-25521