CVE-2026-39000 to CVE-2026-39999
63 CVEs with public proof-of-concept exploits.
- CVE-2026-390311 PoCLansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An…
- CVE-2026-390472 PoCsBuffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service…
- CVE-2026-391071 PoCA Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly…
- CVE-2026-392921 PoCFalco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that…
- CVE-2026-393051 PoCArbitrary File Write / Path Traversal in Action Orchestrator
- CVE-2026-393061 PoCPraisonAI recipe registry pull path traversal writes files outside the chosen output directory
- CVE-2026-393071 PoCPraisonAI has an Arbitrary File Write (Zip Slip) in Templates Extraction
- CVE-2026-393081 PoCPraisonAI recipe registry publish path traversal allows out-of-root file write
- CVE-2026-393201 PoCSignal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths
- CVE-2026-393241 PoCRack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
- CVE-2026-393391 PoCChurchCRM has an API Authentication Bypass
- CVE-2026-393521 PoCFrappe has an Arbitrary File Read via Path Traversal in render_include
- CVE-2026-393601 PoCRustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration
- CVE-2026-393635 PoCsVite Affected by Arbitrary File Read via Vite Dev Server WebSocket
- CVE-2026-393641 PoCVite has a `server.fs.deny` bypass with queries
- CVE-2026-393652 PoCsVite has a Path Traversal in Optimized Deps `.map` Handling
- CVE-2026-393671 PoCWWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page
- CVE-2026-393681 PoCWWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services
- CVE-2026-393691 PoCWWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs
- CVE-2026-393701 PoCWWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete…
- CVE-2026-393731 PoCJWCrypto: JWE ZIP decompression bomb
- CVE-2026-393762 PoCsFastFeedParser has an infinite redirect loop DoS via meta-refresh chain
- CVE-2026-393871 PoCBoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter
- CVE-2026-393891 PoCCI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
- CVE-2026-393901 PoCCI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting
- CVE-2026-393911 PoCCI4MS has Stored XSS via Unescaped Blacklist Note in Admin User List
- CVE-2026-393921 PoCCI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization
- CVE-2026-393931 PoCPost-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms
- CVE-2026-393941 PoCCI4MS has an .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
- CVE-2026-393961 PoCOpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
- CVE-2026-393971 PoC@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered…
- CVE-2026-394121 PoCLiquidJS has an ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel
- CVE-2026-394131 PoCLightRAG has a JWT Algorithm Confusion Vulnerability in LightRAG API
- CVE-2026-396361 PoCWordPress Livemesh Addons for Elementor plugin <= 9.0 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-396761 PoCWordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability
- CVE-2026-398031 PoCHTTP/1 chunked body reader ignores length cap in bandit
- CVE-2026-398041 PoCWebSocket permessage-deflate inflate has no output-size cap in bandit
- CVE-2026-398061 PoCHTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit
- CVE-2026-398071 PoCClient-supplied URI scheme trusted without transport verification in bandit
- CVE-2026-398087 PoCsKEVA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0…
- CVE-2026-398132 PoCsA path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow…
- CVE-2026-398162 PoCsApache NiFi: Missing Execute Code Required Permission on TinkerpopClientService
- CVE-2026-398461 PoCSiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
- CVE-2026-398581 PoCTraefik: Forwarded alias spoofing top pre-auth decision bypass
- CVE-2026-398591 PoCLiquidJS has a renderFile() / parseFile() bypass configured root and allow arbitrary file read
- CVE-2026-398661 PoCLawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml
- CVE-2026-398851 PoCFrontMCP Affected by SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications
- CVE-2026-398881 PoCPraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
- CVE-2026-398901 PoCPraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition Loading
- CVE-2026-399041 PoCGophish 0.12.1 Denial of Service via Office Document Upload
- CVE-2026-399061 PoCUnisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via .NET Remoting
- CVE-2026-399071 PoCUnisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via WCF SOAP
- CVE-2026-399081 PoCOpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source
- CVE-2026-399122 PoCsv2board / Xboard Authentication Token Exposure via loginWithMailLink
- CVE-2026-399201 PoCBridgeHead FileStore < 24A Apache Axis2 Default Credentials RCE
- CVE-2026-399311 PoCOpenEMR Authenticated SQL Injection via backup.php Import Feature
- CVE-2026-399321 PoCOpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection
- CVE-2026-399382 PoCsCacti: Unauthenticated RCE on Graph Image
- CVE-2026-399631 PoCSerendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain
- CVE-2026-399641 PoCTypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers
- CVE-2026-399731 PoCApktool: Path Traversal to Arbitrary File Write
- CVE-2026-399831 PoCFTP Command Injection via CRLF in basic-ftp
- CVE-2026-3998723 PoCsKEVmarimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass