CVE-2026-3000 to CVE-2026-3999
336 CVEs with public proof-of-concept exploits.
- CVE-2026-30011 PoCGutenverse <= 3.4.6 - Reflected Cross-Site Scripting via 's' Parameter
- CVE-2026-30081 PoCVulnerability in Notepad++
- CVE-2026-30151 PoCUTT HiPER 810G formPolicyRouteConf strcpy buffer overflow
- CVE-2026-30161 PoCUTT HiPER 810G formP2PLimitConfig strcpy buffer overflow
- CVE-2026-30181 PoCNewsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parameter
- CVE-2026-30261 PoCerzhongxmu JEEWMS UEditor getRemoteImage.jsp server-side request forgery
- CVE-2026-30271 PoCerzhongxmu JEEWMS UEditor getContent.jsp cross site scripting
- CVE-2026-30281 PoCerzhongxmu JEEWMS JeecgListDemoController.java doAdd cross site scripting
- CVE-2026-30351 PoCAuthentication Bypass Using an Alternate Path or Channel in GitLab
- CVE-2026-30401 PoCDrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection
- CVE-2026-30411 PoCxingfuggz BaykeShop Article Sidebar custom.html cross site scripting
- CVE-2026-30421 PoCitsourcecode Event Management System index.php sql injection
- CVE-2026-30431 PoCitsourcecode Event Management System navbar.php cross site scripting
- CVE-2026-30441 PoCTenda AC8 Httpd Service UploadCfg webCgiGetUploadFile stack-based overflow
- CVE-2026-30461 PoCitsourcecode E-Logbook with Health Monitoring System for COVID-19 check_profile_old.php sql injection
- CVE-2026-30491 PoChorilla-opensource horilla Query Parameter global_search.py get redirect
- CVE-2026-30501 PoChorilla-opensource horilla Leads global.js cross site scripting
- CVE-2026-30511 PoCDataLinkDC dinky Project Name GitRepository.java getProjectDir path traversal
- CVE-2026-30521 PoCDataLinkDC dinky Flink Proxy Controller FlinkProxyController.java proxyUba server-side request forgery
- CVE-2026-30531 PoCDataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authentication
- CVE-2026-30555 PoCsKEVInsufficient input validation leading to memory overread
- CVE-2026-30571 PoCa54552239 pearProjectApi Backend Task.php dateTotalForProject sql injection
- CVE-2026-30591 PoCCVE-2026-3059
- CVE-2026-30601 PoCCVE-2026-3060
- CVE-2026-30641 PoCHummerRisk Cloud Task Scheduler ResourceCreateService.java command injection
- CVE-2026-30651 PoCHummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult command injection
- CVE-2026-30661 PoCHummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection
- CVE-2026-30671 PoCHummerRisk Archive Extraction CommandUtils.java extractZip path traversal
- CVE-2026-30681 PoCitsourcecode Document Management System deluser.php sql injection
- CVE-2026-30691 PoCitsourcecode Document Management System edtlbls.php sql injection
- CVE-2026-30701 PoCSourceCodester Modern Image Gallery App upload.php cross site scripting
- CVE-2026-30731 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-30741 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-30791 PoCLearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter
- CVE-2026-30931 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-31011 PoCIntelbras TIP 635G Ping os command injection
- CVE-2026-31021 PoCexiftool PNG File MacOS.pm SetMacOSTags os command injection
- CVE-2026-31331 PoCitsourcecode Document Management System Login loging.php sql injection
- CVE-2026-31341 PoCitsourcecode News Portal Project edit-category.php sql injection
- CVE-2026-31351 PoCitsourcecode News Portal Project add-category.php sql injection
- CVE-2026-31371 PoCCodeAstro Food Ordering System food_ordering.exe stack-based overflow
- CVE-2026-31471 PoClibvips csvload.c vips_foreign_load_csv_build heap-based overflow
- CVE-2026-31481 PoCSourceCodester Simple and Nice Shopping Cart Script signup.php sql injection
- CVE-2026-31491 PoCitsourcecode College Management System asign-single-student-subjects.php sql injection
- CVE-2026-31501 PoCitsourcecode College Management System display-teacher.php sql injection
- CVE-2026-31511 PoCitsourcecode College Management System login.php sql injection
- CVE-2026-31521 PoCitsourcecode College Management System teacher-salary.php sql injection
- CVE-2026-31531 PoCitsourcecode Document Management System register.php sql injection
- CVE-2026-31601 PoCUnintended Proxy or Intermediary ('Confused Deputy') in GitLab
- CVE-2026-31631 PoCSourceCodester Website Link Extractor URL file_get_contents server-side request forgery
- CVE-2026-31641 PoCitsourcecode News Portal Project contactus.php sql injection
- CVE-2026-31651 PoCTenda F453 httpd AdvSetWrlsafeset fromSetWifiGusetBasic buffer overflow
- CVE-2026-31661 PoCTenda F453 httpd RouteStatic fromRouteStatic buffer overflow
- CVE-2026-31671 PoCTenda F453 httpd webtypelibrary formWebTypeLibrary buffer overflow
- CVE-2026-31681 PoCTenda F453 httpd NatStaticSetting fromNatStaticSetting buffer overflow
- CVE-2026-31691 PoCTenda F453 httpd SafeEmailFilter fromSafeEmailFilter buffer overflow
- CVE-2026-31701 PoCSourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System patient-search.php cross site scripting
- CVE-2026-31711 PoCSourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System queue.php cross site scripting
- CVE-2026-31761 PoCMissing Authorization in GitLab
- CVE-2026-31803 PoCsContest Gallery <= 28.1.4 - Unauthenticated SQL Injection
- CVE-2026-31851 PoCfeiyuchuixue sz-boot-parent API Endpoint sys-message authorization
- CVE-2026-31861 PoCfeiyuchuixue sz-boot-parent Password Reset password default password
- CVE-2026-31871 PoCfeiyuchuixue sz-boot-parent API Endpoint upload unrestricted upload
- CVE-2026-31881 PoCfeiyuchuixue sz-boot-parent API templates path traversal
- CVE-2026-31921 PoCChia Blockchain RPC Credential rpc_server_base.py _authenticate improper authentication
- CVE-2026-31931 PoCChia Blockchain send_transaction cross-site request forgery
- CVE-2026-31941 PoCChia Blockchain RPC Server Master Passphrase get_private_key missing authentication
- CVE-2026-32001 PoCz-9527 admin user.js getUsers sql injection
- CVE-2026-32091 PoCfosrl Pangolin Role verifyApiKeyRoleAccess access control
- CVE-2026-32201 PoCMultiple Plugins - Unauthenticated Stored XSS via Minify Library
- CVE-2026-32221 PoCWP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter
- CVE-2026-32271 PoCAuthenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
- CVE-2026-32281 PoCNextScripts: Social Networks Auto-Poster <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nxs_fbembed' Shortcode
- CVE-2026-32541 PoCImproper Restriction of Rendered UI Layers or Frames in GitLab
- CVE-2026-32611 PoCitsourcecode School Management System Setting index.php sql injection
- CVE-2026-32621 PoCgo2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect
- CVE-2026-32641 PoCgo2ismail Free-CRM Administrative redirect
- CVE-2026-32651 PoCgo2ismail Free-CRM Security API improper authorization
- CVE-2026-32681 PoCpsi-probe PSI Probe Session Attribute RemoveSessAttributeController.java access control
- CVE-2026-32691 PoCpsi-probe PSI Probe Session ExpireSessionsController.java handleRequestInternal denial of service
- CVE-2026-32701 PoCpsi-probe PSI Probe Whois Whois.java lookup server-side request forgery
- CVE-2026-32711 PoCTenda F453 httpd P2pListFilterof fromP2pListFilter buffer overflow
- CVE-2026-32721 PoCTenda F453 httpd DhcpListClient fromDhcpListClient buffer overflow
- CVE-2026-32731 PoCTenda F453 httpd AdvSetWrlsafeset formWrlsafeset buffer overflow
- CVE-2026-32741 PoCTenda F453 httpd L7Prot frmL7ProtForm buffer overflow
- CVE-2026-32751 PoCTenda F453 httpd addressNat fromAddressNat buffer overflow
- CVE-2026-32811 PoClibvips bandrank.c vips_bandrank_build heap-based overflow
- CVE-2026-32821 PoClibvips unpremultiply.c vips_unpremultiply_build out-of-bounds
- CVE-2026-32831 PoClibvips extract.c vips_extract_band_build out-of-bounds
- CVE-2026-32841 PoClibvips extract.c vips_extract_area_build integer overflow
- CVE-2026-32851 PoCberry-lang berry be_lexer.c scan_string out-of-bounds
- CVE-2026-32861 PoCitwanger paicoding Image Save Endpoint ImageRestController.java save server-side request forgery
- CVE-2026-32871 PoCyoulaitech youlai-mall App-side Product Pagination Endpoint SpuController.java listPagedSpuForApp sql injection
- CVE-2026-32891 PoCSanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path traversal
- CVE-2026-32921 PoCjizhiCMS Batch Model.php findAll sql injection
- CVE-2026-32931 PoCsnowflakedb snowflake-jdbc JDBC URL SdkProxyRoutePlanner.java SdkProxyRoutePlanner redos
- CVE-2026-32962 PoCsEverest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata
- CVE-2026-33003 PoCsEverest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
- CVE-2026-33011 PoCTotolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection
- CVE-2026-33021 PoCSourceCodester Doctor Appointment System Sign Up register.php cross site scripting
- CVE-2026-33262 PoCsXStore < 9.7.3 - Unauthenticated SQLi
- CVE-2026-33331 PoCMinhNhut Link Gateway <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
- CVE-2026-33351 PoCCanto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload
- CVE-2026-33591 PoCForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs'
- CVE-2026-33761 PoCTenda F453 SafeMacFilter fromSafeMacFilter buffer overflow
- CVE-2026-33771 PoCTenda F453 SafeUrlFilter fromSafeUrlFilter buffer overflow
- CVE-2026-33781 PoCTenda F453 qossetting fromqossetting buffer overflow
- CVE-2026-33791 PoCTenda F453 SetIpBind fromSetIpBind buffer overflow
- CVE-2026-33801 PoCTenda F453 L7Im frmL7ImForm buffer overflow
- CVE-2026-33821 PoCChaiScript boxed_number.hpp get_as memory corruption
- CVE-2026-33831 PoCChaiScript boxed_number.hpp go divide by zero
- CVE-2026-33841 PoCChaiScript chaiscript_eval.hpp Function_Push_Pop recursion
- CVE-2026-33851 PoCwren-lang wren wren_compiler.c resolveLocal recursion
- CVE-2026-33861 PoCwren-lang wren wren_compiler.c emitOp out-of-bounds
- CVE-2026-33871 PoCwren-lang wren wren_compiler.c getByteCountForArguments null pointer dereference
- CVE-2026-33881 PoCSquirrel sqcompiler.cpp UnaryOP recursion
- CVE-2026-33891 PoCSquirrel sqstdrex.cpp sqstd_rex_newnode null pointer dereference
- CVE-2026-33901 PoCFascinatedBox lily Error Reporting lily_build_error.c patch_line_end out-of-bounds
- CVE-2026-33911 PoCFascinatedBox lily lily_emitter.c clear_storages out-of-bounds
- CVE-2026-33921 PoCFascinatedBox lily lily_emitter.c eval_tree null pointer dereference
- CVE-2026-33931 PoCjarikomppa soloud Audio File soloud_wav.cpp loadflac heap-based overflow
- CVE-2026-33941 PoCjarikomppa soloud WAV File soloud_wav.cpp loadwav memory corruption
- CVE-2026-33952 PoCsMaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
- CVE-2026-33961 PoCWCAPF – WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection
- CVE-2026-33981 PoCTenda F453 httpd AdvSetWan fromAdvSetWan buffer overflow
- CVE-2026-33991 PoCTenda F453 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow
- CVE-2026-34001 PoCTenda AC15 TextEditingConversion stack-based overflow
- CVE-2026-34011 PoCSourceCodester Web-based Pharmacy Product Management System session expiration
- CVE-2026-34021 PoCPHPGurukul Student Record Management System edit-course.php cross site scripting
- CVE-2026-34031 PoCPHPGurukul Student Record Management System edit-subject.php cross site scripting
- CVE-2026-34041 PoCthinkgem JeeSite Endpoint CasOutHandler.java xml external entity reference
- CVE-2026-34051 PoCthinkgem JeeSite Connection path traversal
- CVE-2026-34061 PoCprojectworlds Online Art Gallery Shop Registration registration.php sql injection
- CVE-2026-34071 PoCYosysHQ yosys BLIF File rtlil.h set heap-based overflow
- CVE-2026-34081 PoCOpen Babel CDXML File atom.cpp GetExplicitValence null pointer dereference
- CVE-2026-34092 PoCseosphoros-ai db-gpt Flow Import Endpoint import importlib.machinery.SourceFileLoader.exec_module code injection
- CVE-2026-34101 PoCitsourcecode Society Management System check_studid.php sql injection
- CVE-2026-34111 PoCitsourcecode University Management System admin_single_student_update.php sql injection
- CVE-2026-34121 PoCitsourcecode University Management System att_single_view.php cross site scripting
- CVE-2026-34131 PoCitsourcecode University Management System admin_single_student.php sql injection
- CVE-2026-34301 PoCCreative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
- CVE-2026-34561 PoCGeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation <= 1.2.0 - Unauthenticated SQL Injection via 'attributekey'
- CVE-2026-34621 PoCFrisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
- CVE-2026-34631 PoCxlnt-community xlnt Compound Document binary.hpp append heap-based overflow
- CVE-2026-34651 PoCTuya App/SDK JSON Data Point denial of service
- CVE-2026-34851 PoCD-Link DIR-868L SSDP Service sub_1BF84 os command injection
- CVE-2026-34861 PoCitsourcecode College Management System student-fee.php sql injection
- CVE-2026-34871 PoCitsourcecode College Management System class-result.php sql injection
- CVE-2026-35022 PoCsKEVTrueConf Client Update Integrity Verification Bypass
- CVE-2026-35531 PoCIncorrect Authorization in GitLab
- CVE-2026-35764 PoCsPlanyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
- CVE-2026-35841 PoCKali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
- CVE-2026-35891 PoCWooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF
- CVE-2026-35981 PoCRustDesk Server Generates Config Strings Using Reversible Encoding (Base64 + Reverse) Instead of Encryption
- CVE-2026-36061 PoCEttercap etterfilter ef_output.c add_data_segment out-of-bounds
- CVE-2026-36071 PoCAccess Control Check Implemented After Asset is Accessed in GitLab
- CVE-2026-36092 PoCsXIGNCODE3 xhunter1.sys kernel driver contains a Privilege Escalation Vulnerability
- CVE-2026-36101 PoCHSC Cybersecurity Mailinspector URL mliUserValidation.php cross site scripting
- CVE-2026-36121 PoCWavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection
- CVE-2026-36131 PoCWavlink WL-NU516U1 login.cgi sub_401A0C stack-based overflow
- CVE-2026-36161 PoCDefaultFuction Jeson Customer Relationship Management System edit.php sql injection
- CVE-2026-36611 PoCWavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection
- CVE-2026-36621 PoCWavlink WL-NU516U1 adm.cgi usb_p910 command injection
- CVE-2026-36631 PoCxlnt-community xlnt XLSX File compound_document.cpp xsgetn out-of-bounds
- CVE-2026-36641 PoCxlnt-community xlnt Encrypted XLSX File compound_document.cpp read_directory out-of-bounds
- CVE-2026-36651 PoCxlnt-community xlnt XLSX File xlsx_consumer.cpp read_office_document null pointer dereference
- CVE-2026-36671 PoCFreedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppService improper authorization
- CVE-2026-36681 PoCFreedom Factory dGEN1 org.ethosmobile.webpwaemul AndroidEthereum access control
- CVE-2026-36691 PoCFreedom Factory dGEN1 com.dgen.alarm AlarmService improper authorization
- CVE-2026-36701 PoCFreedom Factory dGEN1 com.dgen.alarm improper authorization
- CVE-2026-36711 PoCFreedom Factory dGEN1 org.ethereumphone.walletmanager.testing123 TokenBalanceContentProvider improper authorization
- CVE-2026-36721 PoCJeecgBoot getDictItems isExistSqlInjectKeyword sql injection
- CVE-2026-36741 PoCFreedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppProvider improper authorization
- CVE-2026-36751 PoCFreedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppReceiver improper authorization
- CVE-2026-36771 PoCTenda FH451 setcfm fromSetCfm stack-based overflow
- CVE-2026-36781 PoCTenda FH451 AdvSetWan sub_3C434 stack-based overflow
- CVE-2026-36791 PoCTenda FH451 QuickIndex formQuickIndex stack-based overflow
- CVE-2026-36801 PoCRyuzakiShinji biome-mcp-server biome-mcp-server.ts command injection
- CVE-2026-36811 PoCwelovemedia FFmate webhook.go fireWebhook server-side request forgery
- CVE-2026-36821 PoCwelovemedia FFmate ffmpeg.go Execute argument injection
- CVE-2026-36831 PoCbufanyun HotGo Endpoint upload.go ImageTransferStorage server-side request forgery
- CVE-2026-36931 PoCShy2593666979 AgentChat User Endpoint user.py update_user_info resource injection
- CVE-2026-36951 PoCSourceCodester Modern Image Gallery App delete.php path traversal
- CVE-2026-36961 PoCTotolink N300RH CGI cstecgi.cgi setWiFiWpsConfig os command injection
- CVE-2026-36981 PoCUTT HiPER 810G NTP strcpy buffer overflow
- CVE-2026-36991 PoCUTT HiPER 810G formRemoteControl strcpy buffer overflow
- CVE-2026-37001 PoCUTT HiPER 810G formConfigDnsFilterGlobal strcpy buffer overflow
- CVE-2026-37011 PoCH3C Magic B1 aspForm Edit_BasicSSID_5G buffer overflow
- CVE-2026-37021 PoCSourceCodester Loan Management System index.php cross site scripting
- CVE-2026-37031 PoCWavlink NU516U1 login.cgi sub_401A10 out-of-bounds write
- CVE-2026-37041 PoCWavlink NU516U1 Incomplete Fix CVE-2025-10959 firewall.cgi sub_405B2C command injection
- CVE-2026-37051 PoCcode-projects Simple Flight Ticket Booking System Adminsearch.php sql injection
- CVE-2026-37071 PoCMrNanko webp4j gif_decoder.c DecodeGifFromMemory integer overflow
- CVE-2026-37081 PoCcode-projects Simple Flight Ticket Booking System login.php sql injection
- CVE-2026-37091 PoCcode-projects Simple Flight Ticket Booking System register.php sql injection
- CVE-2026-37101 PoCcode-projects Simple Flight Ticket Booking System Adminadd.php sql injection
- CVE-2026-37111 PoCcode-projects Simple Flight Ticket Booking System Adminupdate.php sql injection
- CVE-2026-37131 PoCpnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow
- CVE-2026-37151 PoCWavlink WL-WN579X3-C firewall.cgi sub_40139C stack-based overflow
- CVE-2026-37161 PoCWavlink WL-WN579X3-C adm.cgi sub_401AD4 cross site scripting
- CVE-2026-37191 PoCTsinghua Unigroup Electronic Archives System downLoad path traversal
- CVE-2026-37201 PoC1024-lab/lab1024 SmartAdmin Notice notice-form-drawer.vue cross site scripting
- CVE-2026-37211 PoC1024-lab/lab1024 SmartAdmin Help Documentation HelpDocAddForm.java cross site scripting
- CVE-2026-37231 PoCcode-projects Simple Flight Ticket Booking System Admindelete.php sql injection
- CVE-2026-37241 PoCSourceCodester Patients Waiting Area Queue Management System checkin.php improper authorization
- CVE-2026-37251 PoC1024-lab/lab1024 SmartAdmin FreeMarker Template MailService.java freemarkerResolverContent special elements used in a template engine
- CVE-2026-37261 PoCTenda F453 webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow
- CVE-2026-37271 PoCTenda F453 QuickIndex sub_3C6C0 stack-based overflow
- CVE-2026-37281 PoCTenda F453 setcfm fromSetCfm stack-based overflow
- CVE-2026-37291 PoCTenda F453 PPTPDClient fromPptpUserAdd stack-based overflow
- CVE-2026-37301 PoCitsourcecode Free Hotel Reservation System index.php sql injection
- CVE-2026-37321 PoCTenda F453 exeCommand strcpy stack-based overflow
- CVE-2026-37331 PoCxuxueli xxl-job JobInfoController.java server-side request forgery
- CVE-2026-37341 PoCSourceCodester Client Database Management System Endpoint fetch_manager_details.php improper authorization
- CVE-2026-37351 PoCcode-projects Simple Flight Ticket Booking System SearchResultOneway.php sql injection
- CVE-2026-37361 PoCcode-projects Simple Flight Ticket Booking System SearchResultRoundtrip.php sql injection
- CVE-2026-37371 PoCSourceCodester Pet Grooming Management Software User Creation add_user.php improper authorization
- CVE-2026-37381 PoCSourceCodester Pet Grooming Management Software Financial Report improper authorization
- CVE-2026-37391 PoCsuitenumerique messages ThreadAccess serializers.py ThreadAccessSerializer improper authentication
- CVE-2026-37401 PoCitsourcecode University Management System admin_search_student.php sql injection
- CVE-2026-37411 PoCYiFang CMS D_friendLink.php update cross site scripting
- CVE-2026-37421 PoCYiFang CMS D_singlePage.php update cross site scripting
- CVE-2026-37431 PoCYiFang CMS D_singlePageGroup.php update cross site scripting
- CVE-2026-37441 PoCcode-projects Student Web Portal signup.php valreg_passwdation sql injection
- CVE-2026-37451 PoCcode-projects Student Web Portal profile.php sql injection
- CVE-2026-37461 PoCSourceCodester Simple Responsive Tourism Website Login Login.php sql injection
- CVE-2026-37471 PoCitsourcecode University Management System add_result.php sql injection
- CVE-2026-37481 PoCBytedesk SVG File UploadRestController.java uploadFile unrestricted upload
- CVE-2026-37491 PoCBytedesk SVG File UploadRestService.java handleFileUpload unrestricted upload
- CVE-2026-37501 PoCContiNew Admin Storage Management S3ClientFactory.java URI.create server-side request forgery
- CVE-2026-37511 PoCSourceCodester Employee Task Management System GET Parameter daily-attendance-report.php sql injection
- CVE-2026-37521 PoCSourceCodester Employee Task Management System GET Parameter daily-task-report.php sql injection
- CVE-2026-37531 PoCSourceCodester Sales and Inventory System add_sales_print.php sql injection
- CVE-2026-37541 PoCSourceCodester Sales and Inventory System add_stock.php sql injection
- CVE-2026-37551 PoCSourceCodester Sales and Inventory System POST check_customer_details.php sql injection
- CVE-2026-37561 PoCSourceCodester Sales and Inventory System check_item_details.php sql injection
- CVE-2026-37571 PoCprojectworlds Online Art Gallery Shop pass sql injection
- CVE-2026-37581 PoCprojectworlds Online Art Gallery Shop adminHome.php sql injection
- CVE-2026-37591 PoCprojectworlds Online Art Gallery Shop adminHome.php sql injection
- CVE-2026-37601 PoCitsourcecode University Management System view_result.php sql injection
- CVE-2026-37611 PoCSourceCodester Client Database Management System Endpoint superadmin_user_delete.php improper authorization
- CVE-2026-37621 PoCSourceCodester Client Database Management System Endpoint superadmin_delete_manager.php improper authorization
- CVE-2026-37631 PoCcode-projects Simple Flight Ticket Booking System showhistory.php cross site scripting
- CVE-2026-37641 PoCSourceCodester Client Database Management System superadmin_user_update.php improper authorization
- CVE-2026-37651 PoCitsourcecode University Management System att_single_view.php sql injection
- CVE-2026-37661 PoCSourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site scripting
- CVE-2026-37671 PoCitsourcecode sanitize or validate this input teacher-attendance.php sql injection
- CVE-2026-37681 PoCTenda F453 WrlExtraSet formWrlExtraSet stack-based overflow
- CVE-2026-37691 PoCTenda F453 WrlclientSet stack-based overflow
- CVE-2026-37701 PoCSourceCodester Computer Laboratory Management System cross-site request forgery
- CVE-2026-37711 PoCSourceCodester/janobe Resort Reservation System accomodation.php sql injection
- CVE-2026-37751 PoCFoxit PDF Editor/Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
- CVE-2026-37801 PoCFoxit PDF Editor/Reader Installer Uncontrolled Search Path Privilege Escalation
- CVE-2026-37851 PoCEasyCMS Request Parameter RbacnodeAction.class.php sql injection
- CVE-2026-37862 PoCsEasyCMS Request Parameter RbacuserAction.class.php sql injection
- CVE-2026-37881 PoCBytedesk SpringAIOpenrouterRestController SpringAIOpenrouterRestService.java getModels server-side request forgery
- CVE-2026-37891 PoCBytedesk SpringAIGiteeRestController SpringAIGiteeRestService.java getModels server-side request forgery
- CVE-2026-37901 PoCSourceCodester Sales and Inventory System POST Parameter check_supplier_details.php sql injection
- CVE-2026-37911 PoCSourceCodester Sales and Inventory System Search dashboard.php sql injection
- CVE-2026-37921 PoCSourceCodester Sales and Inventory System GET Parameter purchase_invoice.php sql injection
- CVE-2026-37931 PoCSourceCodester Sales and Inventory System GET Parameter sales_invoice1.php sql injection
- CVE-2026-37962 PoCsQi-ANXIN QAX Virus Removal Mini Filter Driver QKSecureIO_Imp.sys ZwTerminateProcess access control
- CVE-2026-37971 PoCTiandy Video Surveillance System 视频监控平台 CLS_REST_File.java uploadFile unrestricted upload
- CVE-2026-37981 PoCComfast CF-AC100 Request Path mbox-config sub_44AC14 command injection
- CVE-2026-37991 PoCTenda i3 setcfm formSetCfm stack-based overflow
- CVE-2026-38001 PoCSourceCodester/janobe Resort Reservation System controller.php doInsert unrestricted upload
- CVE-2026-38011 PoCTenda i3 setAutoPing formSetAutoPing stack-based overflow
- CVE-2026-38021 PoCTenda i3 exeCommand formexeCommand stack-based overflow
- CVE-2026-38031 PoCTenda i3 WifiMacFilterGet formWifiMacFilterGet stack-based overflow
- CVE-2026-38041 PoCTenda i3 WifiMacFilterSet formWifiMacFilterSet stack-based overflow
- CVE-2026-38051 PoCuse after free in SMB connection reuse
- CVE-2026-38061 PoCSourceCodester/janobe Resort Reservation System room_rates.php sql injection
- CVE-2026-38071 PoCTenda FH1202 AdvSetWrlsafeset formWrlsafeset stack-based overflow
- CVE-2026-38081 PoCTenda FH1202 webtypelibrary formWebTypeLibrary stack-based overflow
- CVE-2026-38091 PoCTenda FH1202 NatSaticSetting fromNatStaticSetting stack-based overflow
- CVE-2026-38101 PoCTenda FH1202 DhcpListClient fromDhcpListClient stack-based overflow
- CVE-2026-38111 PoCTenda FH1202 P2pListFilter fromP2pListFilter stack-based overflow
- CVE-2026-38121 PoCitsourcecode Payroll Management System manage_employee_allowances.php cross site scripting
- CVE-2026-38131 PoCopencc JFlow WF_CCForm.java Calculate injection
- CVE-2026-38141 PoCUTT HiPER 810G getOneApConfTempEntry strcpy buffer overflow
- CVE-2026-38151 PoCUTT HiPER 810G formApMail strcpy buffer overflow
- CVE-2026-38161 PoCOWASP DefectDojo SonarQubeParser/MSDefenderParser parser.py input_zip.read denial of service
- CVE-2026-38171 PoCSourceCodester Patients Waiting Area Queue Management System patient-search.php improper authorization
- CVE-2026-38181 PoCTiandy Easy7 CMS Windows GetDBData.jsp sql injection
- CVE-2026-38191 PoCSourceCodester Resort Reservation System Reservation Management page cross site scripting
- CVE-2026-38301 PoCProduct Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQLi
- CVE-2026-38431 PoCSQL Injection in Nefteprodukttekhnika BUK TS-G Allows Remote Code Execution
- CVE-2026-38449 PoCsBreeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
- CVE-2026-38543 PoCsRemote code execution via git push option injection in GitHub Enterprise Server
- CVE-2026-38571 PoCCross-Site Request Forgery (CSRF) in GitLab
- CVE-2026-38811 PoCPerformance Monitor <= 1.0.6 - Unauthenticated Blind SSRF
- CVE-2026-38887 PoCsLocal Privilege Escalation in snapd
- CVE-2026-389110 PoCsPix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
- CVE-2026-39061 PoCWordPress 6.9 - 6.9.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Note Creation via REST API
- CVE-2026-39091 PoCKEVOut of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a…
- CVE-2026-39101 PoCKEVInappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a…
- CVE-2026-39431 PoCH3C ACG1000-AK230 aaa_portal_auth_local_submit command injection
- CVE-2026-39441 PoCitsourcecode University Management System att_add.php sql injection
- CVE-2026-39461 PoCPHPEMS index.php cross site scripting
- CVE-2026-39491 PoCstrukturag libheif HEIF File decoder_vvdec.cc vvdec_push_data2 out-of-bounds
- CVE-2026-39501 PoCstrukturag libheif stsz/stts track.cc load out-of-bounds
- CVE-2026-39511 PoCLockerProject Locker Error Response registry.js authIsAwesome cross site scripting
- CVE-2026-39541 PoCOpenBMB XAgent workspace.py workspace path traversal
- CVE-2026-39551 PoCelecV2P jsfile Endpoint wbjs.js runJSFile code injection
- CVE-2026-39561 PoCxierongwkhd weimai-wetapp Admin_AdminUserController.java getAdmins sql injection
- CVE-2026-39571 PoCxierongwkhd weimai-wetapp Endpoint HomeController.java getLikeMovieList sql injection
- CVE-2026-39581 PoCWoahai321 ListSync JSON api_server.py requests.post server-side request forgery
- CVE-2026-39591 PoC0xKoda WireMCP Tshark CLI index.js server.tool os command injection
- CVE-2026-39611 PoCzyddnys manga-image-translator Translate Endpoints request_extraction.py to_pil_image server-side request forgery
- CVE-2026-39621 PoCJcharis Machine-Learning-Web-Apps Jinja2 Template app.py render_template cross site scripting
- CVE-2026-39631 PoCperfree go-fastdfs-web Apache Shiro RememberMe ShiroConfig.java rememberMeManager hard-coded key
- CVE-2026-39641 PoCOpenAkita Chat API Endpoint shell.py run os command injection
- CVE-2026-39652 PoCswhyour qinglong API express.ts protection mechanism
- CVE-2026-39661 PoC648540858 wvp-GB28181-pro IP Address ABLMediaNodeServerService.java getDownloadFilePath server-side request forgery
- CVE-2026-39671 PoCAlfresco Activiti Process Variable Serialization System SerializableType.java createObjectInputStream deserialization
- CVE-2026-39681 PoCAutohomeCorp frostmourne Oracle Nashorn JavaScript ExpressionRule.java scriptEngine.eval code injection
- CVE-2026-39691 PoCFeMiner wms Basic Organizational Structure depart_add_bg.php sql injection
- CVE-2026-39701 PoCTenda i3 wifiSSIDget formwrlSSIDget stack-based overflow
- CVE-2026-39711 PoCTenda i3 wifiSSIDset formwrlSSIDset stack-based overflow
- CVE-2026-39721 PoCTenda W3 HTTP setcfm formSetCfm stack-based overflow
- CVE-2026-39731 PoCTenda W3 POST Parameter setAutoPing formSetAutoPing stack-based overflow
- CVE-2026-39741 PoCTenda W3 HTTP exeCommand formexeCommand stack-based overflow
- CVE-2026-39751 PoCTenda W3 POST Parameter WifiMacFilterGet formWifiMacFilterGet stack-based overflow
- CVE-2026-39761 PoCTenda W3 POST Parameter WifiMacFilterSet formWifiMacFilterSet stack-based overflow
- CVE-2026-39781 PoCD-Link DIR-513 formEasySetupWizard3 stack-based overflow
- CVE-2026-39791 PoCquickjs-ng quickjs quickjs.c js_iterator_concat_return use after free
- CVE-2026-39801 PoCitsourcecode Online Doctor Appointment System patient_action.php sql injection
- CVE-2026-39811 PoCitsourcecode Online Doctor Appointment System doctor_action.php sql injection
- CVE-2026-39821 PoCitsourcecode University Management System view_result.php cross site scripting
- CVE-2026-39831 PoCCampcodes Division Regional Athletic Meet Game Result Matrix System save-games.php cross site scripting
- CVE-2026-39841 PoCCampcodes Division Regional Athletic Meet Game Result Matrix System save_up_athlete.php cross site scripting
- CVE-2026-39881 PoCInefficient Algorithmic Complexity in GitLab
- CVE-2026-39901 PoCCesiumGS CesiumJS standalone.html cross site scripting
- CVE-2026-39921 PoCCodeGenieApp serverless-express Users Endpoint dynamodb.ts injection
- CVE-2026-39931 PoCitsourcecode Payroll Management System manage_employee_deductions.php cross site scripting
- CVE-2026-39941 PoCrui314 mold Object File input-files.cc initialize_sections heap-based overflow