CVE-2026-38000 to CVE-2026-38999
25 CVEs with public proof-of-concept exploits.
- CVE-2026-381651 PoCA Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows…
- CVE-2026-383601 PoCDirectory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code…
- CVE-2026-383611 PoCMultiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler…
- CVE-2026-384221 PoCBuffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the…
- CVE-2026-384261 PoCBuffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the…
- CVE-2026-384271 PoCAn issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffer overflow. The…
- CVE-2026-384651 PoCA Stored XSS vulnerability in the donor avatar mouse-over text feature in GazellePW (GazellePosterWall) commit…
- CVE-2026-384661 PoCA Stored XSS vulnerability in the torrent remaster custom title feature in GazellePW (GazellePosterWall) commit…
- CVE-2026-384671 PoCA SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows…
- CVE-2026-384681 PoCA SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall) commit…
- CVE-2026-384691 PoCA Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) commit…
- CVE-2026-384701 PoCA Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit…
- CVE-2026-384721 PoCA Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449…
- CVE-2026-384731 PoCA Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449…
- CVE-2026-384741 PoCGazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP…
- CVE-2026-3852610 PoCsAn authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to…
- CVE-2026-385331 PoCAn improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the…
- CVE-2026-385771 PoCInsecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
- CVE-2026-387515 PoCsOpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality…
- CVE-2026-387631 PoCAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828
- CVE-2026-387641 PoCAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
- CVE-2026-387651 PoCAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
- CVE-2026-387661 PoCAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function
- CVE-2026-388121 PoCRuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may…
- CVE-2026-389451 PoCCommand injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted…