CVE-2026-34000 to CVE-2026-34999
154 CVEs with public proof-of-concept exploits.
- CVE-2026-340051 PoCIn Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell…
- CVE-2026-340363 PoCsDolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php
- CVE-2026-340381 PoCCoolify authenticated remote command injection leading to RCE and secret exfiltration
- CVE-2026-340401 PoCMoby: AuthZ plugin bypass with oversized request body
- CVE-2026-340411 PoCact: Unrestricted set-env and add-path command processing enables environment injection
- CVE-2026-340481 PoCCoolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team servers
- CVE-2026-340701 PoCLangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
- CVE-2026-340841 PoCPhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load
- CVE-2026-340961 PoCGuardian Language-System XSS via name Parameter in designer.php
- CVE-2026-340971 PoCGuardian Language-System XSS via id Parameter in text_file.php
- CVE-2026-340981 PoCGuardian Language-System XSS via id Parameter in media.php
- CVE-2026-340991 PoCGuardian Language-System Unauthenticated SQL Injection via id Parameter in job_info.php
- CVE-2026-341001 PoCGuardian Language-System SQL Injection via id Parameter in media.php
- CVE-2026-341011 PoCGuardian Language-System SQL Injection via id Parameter in text_file.php
- CVE-2026-341021 PoCGuardian Language-System SQL Injection via id Parameter in job_info_get.php
- CVE-2026-341031 PoCGuardian Language-System SQL Injection via id Parameter in subtitles.php
- CVE-2026-341041 PoCGuardian Language-System SQL Injection via name Parameter in designer.php
- CVE-2026-341051 PoCGuardian Language-System SQL Injection via id Parameter in translate_text.php
- CVE-2026-341061 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.php
- CVE-2026-341071 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in translate.php
- CVE-2026-341081 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in text.php
- CVE-2026-341091 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in speech.php
- CVE-2026-341101 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php
- CVE-2026-341111 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac_text.php
- CVE-2026-341121 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
- CVE-2026-341131 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in speech_text.php
- CVE-2026-341141 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.php
- CVE-2026-341151 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php
- CVE-2026-341161 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe.php
- CVE-2026-341171 PoCGuardian Language-System Unauthenticated OS Command Injection via id Parameter in text_to_subtitles.php
- CVE-2026-341481 PoCFedify affected by resource exhaustion caused by unbounded redirect following during remote key/document resolution
- CVE-2026-341564 PoCsNocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
- CVE-2026-341591 PoCllama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend
- CVE-2026-341601 PoCChamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
- CVE-2026-341661 PoCLiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter
- CVE-2026-341771 PoCVM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
- CVE-2026-341781 PoCImporting a crafted backup leads to project restriction bypass
- CVE-2026-341791 PoCUpdate of type field in restricted TLS certificate allows privilege escalation to cluster admin
- CVE-2026-3419715 PoCsKEVApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
- CVE-2026-342001 PoCNhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network Port
- CVE-2026-342071 PoCTypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
- CVE-2026-342121 PoCDocmost page content has stored XSS via unsanitized attachment URLs
- CVE-2026-342131 PoCDocmost has cross-page attachment overwrite via flawed attachmentId overwrite validation
- CVE-2026-342201 PoCMikroORM is vulnerable to SQL Injection via specially crafted object
- CVE-2026-342221 PoCOpen WebUI has Broken Access Control in Tool Valves
- CVE-2026-342251 PoCOpen WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
- CVE-2026-342261 PoCHappy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
- CVE-2026-342271 PoCSliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface
- CVE-2026-343081 PoCVulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are…
- CVE-2026-343441 PoCWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2026-343481 PoCWindows Event Logging Service Information Disclosure Vulnerability
- CVE-2026-343591 PoCHAPI FHIR: Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect in HAPI FHIR Core
- CVE-2026-343601 PoCHAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
- CVE-2026-343611 PoCHAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
- CVE-2026-343751 PoCAVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Payment Page
- CVE-2026-343821 PoCAdmidio: Missing CSRF Protection on Custom List Deletion in mylist_function.php
- CVE-2026-343841 PoCAdmidio: Missing CSRF Protection on Registration Approval Actions
- CVE-2026-343941 PoCAVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking
- CVE-2026-343961 PoCAVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel
- CVE-2026-344031 PoCNginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
- CVE-2026-344133 PoCsXerte Online Toolkits Missing Authentication via connector.php
- CVE-2026-344142 PoCsXerte Online Toolkits Path Traversal via connector.php
- CVE-2026-344152 PoCsXerte Online Toolkits File Upload RCE via elfinder Connector
- CVE-2026-344161 PoCOSCAL-GUI Reflected XSS via project parameter in oscal.php
- CVE-2026-344171 PoCOSCAL-GUI Reflected XSS via project parameter in oscal-forms.php
- CVE-2026-344291 PoCVvveb < 1.0.8.1 Stored XSS via Media Upload and Rename
- CVE-2026-344442 PoCsLupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
- CVE-2026-344471 PoCONNX: External Data Symlink Traversal
- CVE-2026-344481 PoCSiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop client
- CVE-2026-344491 PoCSiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
- CVE-2026-344532 PoCsSiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked…
- CVE-2026-344722 PoCsUnauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated…
- CVE-2026-344732 PoCsUnauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N,…
- CVE-2026-344742 PoCsSensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to the router web…
- CVE-2026-344869 PoCsKEVApache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
- CVE-2026-345221 PoCSillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
- CVE-2026-345231 PoCSillyTavern: Path traversal allows file existence oracle
- CVE-2026-345241 PoCSillyTavern: Path traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
- CVE-2026-345261 PoCSillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6
- CVE-2026-345291 PoCFile Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file
- CVE-2026-345301 PoCFile Browser is vulnerable to Stored Cross-Site Scripting via text/template branding injection
- CVE-2026-345431 PoCOpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)
- CVE-2026-345441 PoCOpenEXR: integer overflow to OOB write in uncompress_b44_impl()
- CVE-2026-345571 PoCCI4MS: Permissions Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345581 PoCCI4MS: Methods Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345591 PoCCI4MS: Blogs Tags Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345601 PoCCI4MS: Logs Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345611 PoCCI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via…
- CVE-2026-345621 PoCCI4MS: System Settings (Company Information) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via…
- CVE-2026-345631 PoCCI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
- CVE-2026-345641 PoCCI4MS: Menu Management (Pages) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345651 PoCCI4MS: Menu Management (Posts) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345661 PoCCI4MS: Pages Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345671 PoCCI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345681 PoCCI4MS: Blogs Posts Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345691 PoCCI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-345711 PoCCI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account…
- CVE-2026-345851 PoCSiYuan: Stored XSS in imported .sy.zip content leads to arbitrary command execution
- CVE-2026-345881 PoCOpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
- CVE-2026-345891 PoCOpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
- CVE-2026-345931 PoCAsh Framework: Ash.Type.Module.cast_input/2 atom exhaustion via unchecked Module.concat allows BEAM VM crash
- CVE-2026-345981 PoCYesWiki has Persistant Blind XSS at "/?BazaR&vue=consulter"
- CVE-2026-346011 PoCxmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
- CVE-2026-346052 PoCsSiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )
- CVE-2026-346111 PoCAVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users
- CVE-2026-346131 PoCAVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins
- CVE-2026-346216 PoCsKEVAcrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
- CVE-2026-346221 PoCAcrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
- CVE-2026-346261 PoCAcrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
- CVE-2026-347151 PoCewe Has Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response Splitting)
- CVE-2026-347161 PoCAVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification
- CVE-2026-347241 PoCZammad has a server-side template injection leading to RCE via AI Agent
- CVE-2026-347251 PoCdbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration
- CVE-2026-347261 PoCCopier `_subdirectory` allows template root escape via parent-directory traversal
- CVE-2026-347271 PoCVikunja ahs a TOTP Two-Factor Authentication Bypass via OIDC Login Path
- CVE-2026-347281 PoCphpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController
- CVE-2026-347291 PoCphpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes()
- CVE-2026-347301 PoCCopier `_external_data` allows path traversal and absolute-path local file read without unsafe mode
- CVE-2026-347311 PoCAVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php
- CVE-2026-347321 PoCAVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints
- CVE-2026-347331 PoCAVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard
- CVE-2026-347371 PoCAVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
- CVE-2026-347381 PoCAVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter
- CVE-2026-347391 PoCAVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php
- CVE-2026-347401 PoCAVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation
- CVE-2026-347461 PoCPayload has Authenticated SSRF via Upload Functionality
- CVE-2026-347471 PoCPayload has an SQL Injection via Query Handling
- CVE-2026-347481 PoC@payloadcms/next has Stored XSS in Admin Panel
- CVE-2026-347491 PoCPayload has a CSRF Protection Bypass in Authentication Flow
- CVE-2026-347501 PoCPayload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints
- CVE-2026-347511 PoCPayload has Unvalidated Input in Password Recovery Endpoints
- CVE-2026-347531 PoCvLLM affected by Server-Side Request Forgery (SSRF) in `download_bytes_from_url `
- CVE-2026-347831 PoCFerret has a Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
- CVE-2026-348241 PoCMesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service
- CVE-2026-348251 PoCNocoBase Has SQL Injection via template variable substitution in workflow SQL node
- CVE-2026-348282 PoCslistmonk: Active sessions remain valid after password reset and password change
- CVE-2026-348381 PoCGroup-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in `AbstractSettingsCollection`
- CVE-2026-348391 PoCGlances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
- CVE-2026-348471 PoChoppscotch: Open redirect via `/enter?redirect=`
- CVE-2026-348851 PoCWordPress Media LIbrary Assistant plugin <= 3.34 - SQL Injection vulnerability
- CVE-2026-349084 PoCsKEVA malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make…
- CVE-2026-349094 PoCsKEVA malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the…
- CVE-2026-349105 PoCsKEVA malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute…
- CVE-2026-349262 PoCsKEVA directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key…
- CVE-2026-349341 PoCPraisonAI: Second-Order SQL Injection in `get_all_user_threads`
- CVE-2026-349402 PoCsKubeAI has an OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model pods
- CVE-2026-349501 PoCfast-jwt has an incomplete fix for CVE-2023-48223: JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key
- CVE-2026-349651 PoCCockpit CMS Authenticated Remote Code Execution via Collections
- CVE-2026-349741 PoCphpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding leads to Stored XSS and Privilege Escalation
- CVE-2026-349751 PoCPlunk has a CRLF Email Header Injection in raw MIME message construction allows authenticated API user to inject arbitrary email headers
- CVE-2026-349762 PoCsDgraph Affected by Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
- CVE-2026-349801 PoCOpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
- CVE-2026-349891 PoCCI4MS affected by Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
- CVE-2026-349901 PoCOpenPrinting CUPS: Local print admin token disclosure using temporary printers