CVE-2026-35000 to CVE-2026-35999
74 CVEs with public proof-of-concept exploits.
- CVE-2026-350293 PoCsLiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
- CVE-2026-350302 PoCsLiteLLM has an authentication bypass via OIDC userinfo cache key collision
- CVE-2026-350311 PoCJellyfin: Potential RCE via subtitle upload path traversal + .strm chain
- CVE-2026-350361 PoCEch0 Affected by Unauthenticated Server-Side Request Forgery in Website Preview Feature
- CVE-2026-350373 PoCsEch0 affected by unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata
- CVE-2026-350381 PoCsignalk-server: Arbitrary Prototype Read via `from` Field Bypass
- CVE-2026-350391 PoCfast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
- CVE-2026-350401 PoCfast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
- CVE-2026-350421 PoCfast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
- CVE-2026-350441 PoCBentoML has a Server-Side Template Injection via unsandboxed Jinja2 Environment in Dockerfile generation
- CVE-2026-350451 PoCTandoor Recipes Affected by Private Recipe Exposure and Unauthorized Modification
- CVE-2026-350511 PoCTraefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth
- CVE-2026-350571 PoCXenForo Stored Cross-Site Scripting via Structured Text Mentions
- CVE-2026-351681 PoCOpenSTAManager: SQL Injection via Aggiornamenti Module
- CVE-2026-351721 PoCDistribution has stale blob access resurrection via repo-scoped redis descriptor cache invalidation
- CVE-2026-351791 PoCWWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php
- CVE-2026-351811 PoCWWBN AVideo Affected by CSRF on Player Skin Configuration via admin/playerUpdate.json.php
- CVE-2026-351871 PoCpyLoad has SSRF in parse_urls API endpoint via unvalidated URL parameter
- CVE-2026-351961 PoCChamilo LMS has OS Command Injection via export_all_certificates action
- CVE-2026-352011 PoCDiscount has an Out-of-bounds Read in rdiscount
- CVE-2026-352041 PoCHelm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
- CVE-2026-352161 PoCBudibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation Step
- CVE-2026-352501 PoCVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is…
- CVE-2026-352735 PoCsKEVVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported…
- CVE-2026-353391 PoCuutils coreutils chmod False Success Exit Code in Recursive Mode
- CVE-2026-353731 PoCuutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenames
- CVE-2026-353921 PoCgoshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload
- CVE-2026-353931 PoCImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload
- CVE-2026-353941 PoCMobile Next has Arbitrary Android Intent Execution via mobile_open_url
- CVE-2026-353972 PoCsjupyter-server path traversal allows access to sibling directories sharing root_dir name prefix
- CVE-2026-354051 PoClibp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
- CVE-2026-354141 PoCOpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with…
- CVE-2026-354501 PoCWWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php
- CVE-2026-354521 PoCWWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php
- CVE-2026-354531 PoCPhpSpreadsheet XSS via number format text substitution in HTML Writer
- CVE-2026-354551 PoCimmich has Stored XSS via OCR Text in 360° Panorama Viewer
- CVE-2026-354581 PoCGotenberg has a ReDoS via extraHttpHeaders scope feature
- CVE-2026-354591 PoCpyLoad has SSRF fix bypass via HTTP redirect
- CVE-2026-354711 PoCImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs
- CVE-2026-354901 PoCchangedetection.io has an Authentication Bypass via Decorator Ordering
- CVE-2026-354921 PoCKedro-Datasets has a path traversal vulnerability in PartitionedDataset allows arbitrary file write
- CVE-2026-355331 PoCmise has a local settings bypass config trust checks
- CVE-2026-355691 PoCApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
- CVE-2026-355702 PoCsOpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal
- CVE-2026-355821 PoCEmissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
- CVE-2026-355841 PoCFreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration
- CVE-2026-355851 PoCFile Browser has a Command Injection via Hook Runner
- CVE-2026-355861 PoCAuthorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng
- CVE-2026-355871 PoCGlances IP Plugin has SSRF via public_api that leads to credential leakage
- CVE-2026-355881 PoCGlances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
- CVE-2026-355921 PoCpyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass
- CVE-2026-355951 PoCVikunja Affected by Privilege Escalation via Project Reparenting
- CVE-2026-355961 PoCVikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
- CVE-2026-355971 PoCVikunja Affected by TOTP Brute-Force Due to Non-Functional Account Lockout
- CVE-2026-355981 PoCVikunja has Missing Authorization on CalDAV Task Read
- CVE-2026-355991 PoCVikunja has an Algorithmic Complexity DoS in Repeating Task Handler
- CVE-2026-356001 PoCVikunja has HTML Injection via Task Titles in Overdue Email Notifications
- CVE-2026-356011 PoCVikunja has an iCalendar Property Injection via CRLF in CalDAV Task Output
- CVE-2026-356021 PoCVikunja has a File Size Limit Bypass via Vikunja Import
- CVE-2026-356041 PoCFile Browser share links remain accessible after Share/Download permissions are revoked
- CVE-2026-356051 PoCFile Browser has an access rule bypass via HasPrefix without trailing separator in path matching
- CVE-2026-356061 PoCFile Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check
- CVE-2026-356071 PoCFile Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
- CVE-2026-356151 PoCPraisonAI has a Path Traversal in FileTools
- CVE-2026-356166 PoCsKEVA improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute…
- CVE-2026-356321 PoCOpenClaw <= 2026.2.22 - Symlink Traversal via IDENTITY.md appendFile in agents.create/update
- CVE-2026-356531 PoCOpenClaw < 2026.3.24 - Incorrect Authorization in POST /reset-profile via browser.request
- CVE-2026-356651 PoCOpenClaw < 2026.3.24 - Denial of Service via Feishu Webhook Pre-Auth Body Parsing
- CVE-2026-356671 PoCOpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.ts
- CVE-2026-356681 PoCOpenClaw < 2026.3.24 - Sandbox Media Root Bypass via Unnormalized mediaUrl and fileUrl Parameters
- CVE-2026-356711 PoCphpMyFAQ - Insecure Direct Object Reference in User Password API
- CVE-2026-356721 PoCphpMyFAQ - Authentication Bypass via Empty API Token
- CVE-2026-356751 PoCphpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/update
- CVE-2026-356761 PoCphpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint