CVE-2026-40000 to CVE-2026-40999
113 CVEs with public proof-of-concept exploits.
- CVE-2026-400001 PoCPath Traversal Vulnerability in ZTE Blade A75 5G
- CVE-2026-400031 PoCUSB-based arbitrary memory write vulnerability in ZTE ZX297520V3 soc BootROM
- CVE-2026-400221 PoCApache Camel Platform HTTP Main: Authentication Bypass on Non-Root Context Paths in camel main runtime
- CVE-2026-400341 PoCgitoxide - Command Injection via Partial .gitmodules Override in gix-submodule
- CVE-2026-400361 PoCUnfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
- CVE-2026-400471 PoCApache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in…
- CVE-2026-400481 PoCApache Camel PQC: Unsafe Deserialization from FileBasedKeyLifecycleManager
- CVE-2026-400711 PoCpyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions
- CVE-2026-400721 PoCweb3.py affected by SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling
- CVE-2026-400831 PoCCacti: SQL Injection in managers.php
- CVE-2026-400881 PoCImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
- CVE-2026-400981 PoCOpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option disclosure and file-disclosure variant
- CVE-2026-401031 PoCVikunja's Scoped API tokens with projects.background permission can delete project backgrounds
- CVE-2026-401051 PoCXWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
- CVE-2026-401071 PoCSiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
- CVE-2026-401111 PoCPraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)
- CVE-2026-401121 PoCPraisonAI has Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
- CVE-2026-401131 PoCPraisonAI has an Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
- CVE-2026-401141 PoCPraisonAI has Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
- CVE-2026-401512 PoCsPraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
- CVE-2026-401541 PoCPraisonAI Affected by Untrusted Remote Template Code Execution
- CVE-2026-401571 PoCPraisonAI affected by arbitrary file write via path traversal in `praisonai recipe unpack`
- CVE-2026-401601 PoCPraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallback
- CVE-2026-401731 PoCDgraph: Unauthenticated pprof endpoint leaks admin auth token
- CVE-2026-401753 PoCsAxios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
- CVE-2026-401764 PoCsComposer is vulnerable to Command Injection via Malicious Perforce Repository
- CVE-2026-401791 PoCPrometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer
- CVE-2026-401801 PoCZip Slip Path Traversal in quarkus-openapi-generator ApicurioCodegenWrapper class
- CVE-2026-401861 PoCApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
- CVE-2026-401881 PoCgoshs is Missing Write Protection for Parametric Data Values
- CVE-2026-401891 PoCgoshs has a file-based ACL authorization bypass in goshs state-changing routes
- CVE-2026-401901 PoCLangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
- CVE-2026-401931 PoCMaddy Mail Server: LDAP Filter Injection via Unsanitized Username
- CVE-2026-401941 PoCphpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()
- CVE-2026-401951 PoCIncus nil-pointer dereference in storage bucket import allows denial of service
- CVE-2026-401971 PoCIncus nil-pointer dereference in custom volume import allows denial of service
- CVE-2026-402172 PoCsLiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
- CVE-2026-402421 PoCArcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
- CVE-2026-402451 PoCFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication
- CVE-2026-402461 PoCfree5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
- CVE-2026-402471 PoCfree5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
- CVE-2026-402481 PoCfree5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
- CVE-2026-402511 PoCIncus out-of-bounds panic in snapshot metadata handling allows denial of service
- CVE-2026-402591 PoCSiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView API
- CVE-2026-402612 PoCsComposer has Command Injection via Malicious Perforce Reference
- CVE-2026-402802 PoCsGotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-lists
- CVE-2026-402811 PoCGotenberg vulnerable to argument injection via newlines in ExifTool metadata values
- CVE-2026-402871 PoCPraisonAI has RCE via Automatic tools.py Import
- CVE-2026-402881 PoCPraisonAI: Critical RCE via `type: job` workflow YAML
- CVE-2026-402891 PoCPraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
- CVE-2026-402961 PoCPhpSpreadsheet vulnerable to XSS in HTML writer via custom number format codes
- CVE-2026-403082 PoCsMy Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog
- CVE-2026-403151 PoCPraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
- CVE-2026-403181 PoCSiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
- CVE-2026-403451 PoCdeepmerge-ts: Stack exhaustion when merging recursive object graphs
- CVE-2026-403696 PoCsWindows Kernel Elevation of Privilege Vulnerability
- CVE-2026-404531 PoCApache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies…
- CVE-2026-404662 PoCsApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
- CVE-2026-404732 PoCsApache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
- CVE-2026-404781 PoCImproper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
- CVE-2026-404811 PoCmonetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
- CVE-2026-404861 PoCKimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate
- CVE-2026-404871 PoCPostiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS
- CVE-2026-404911 PoCgdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall
- CVE-2026-405011 PoCCherry Studio RCE via SearchService nodeIntegration Misconfiguration
- CVE-2026-405171 PoCradare2 < 6.1.4 Command Injection via PDB Parser Symbol Names
- CVE-2026-405211 PoCFrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
- CVE-2026-405221 PoCFrontAccounting < 2.4.20 SQL Injection via rep601.php
- CVE-2026-405231 PoCFrontAccounting < 2.4.20 SQL Injection via reporting/rep710.php
- CVE-2026-405241 PoCFrontAccounting < 2.4.20 SQL Injection via get_gl_transactions()
- CVE-2026-405641 PoCApache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Kubernetes Operator
- CVE-2026-405761 PoCImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in excel-mcp-server
- CVE-2026-405941 PoCpyLoad: Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)
- CVE-2026-406101 PoCBentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
- CVE-2026-406111 PoCLego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
- CVE-2026-407014 PoCsNGINX ngx_http_ssl_module vulnerability
- CVE-2026-407751 PoCWordPress Royal MCP plugin <= 1.4.2 - Broken Access Control vulnerability
- CVE-2026-407761 PoCWordPress Eventin plugin <= 4.1.8 - Broken Access Control vulnerability
- CVE-2026-407911 PoCWordPress WP Time Slots Booking Form plugin <= 1.2.46 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-408581 PoCApache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
- CVE-2026-408591 PoCApache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is…
- CVE-2026-408602 PoCsApache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
- CVE-2026-408631 PoCPhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
- CVE-2026-408641 PoCJupyterHub: Cross-origin form POSTs bypass XSRF
- CVE-2026-408681 PoCkyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
- CVE-2026-408761 PoCSFTP root escape via prefix-based path validation in goshs
- CVE-2026-408781 PoCmailcow-dockerized Login Page has Reflected Parameter Injection / Wrong-Context XSS Escaping
- CVE-2026-408821 PoCOpenRemote has XXE in Velbus Asset Import
- CVE-2026-408831 PoCgoshs: CSRF in state-changing GET routes enables authenticated file deletion and directory creation
- CVE-2026-408841 PoCgoshs: Empty-username SFTP password authentication bypass in goshs
- CVE-2026-408851 PoCgoshs: Public collaborator feed leaks .goshs ACL credentials and enables unauthorized access
- CVE-2026-408861 PoCArgo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
- CVE-2026-408871 PoC@vendure/core has a SQL Injection vulnerability
- CVE-2026-408931 PoCGotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move
- CVE-2026-408971 PoCMath.js: Unsafe object property setter in mathjs
- CVE-2026-408991 PoCDataEase has an Arbitrary File Read Vulnerability
- CVE-2026-409001 PoCDataEase has SQL Injection via Stacked Queries
- CVE-2026-409011 PoCDataEase: Quartz Deserialization → Remote Code Execution
- CVE-2026-409021 PoCPhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
- CVE-2026-409071 PoCWWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth Tokens
- CVE-2026-409091 PoCWWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)
- CVE-2026-409101 PoCfrp: Authentication bypass in frp HTTP vhost routing when routeByHTTPUser is used for access control
- CVE-2026-409111 PoCWWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
- CVE-2026-409121 PoCTraefik: StripPrefixRegex auth bypass via Path/RawPath desync
- CVE-2026-409221 PoCSiYuan: Incomplete sanitization of bazaar README allows stored XSS via iframe srcdoc (incomplete fix for CVE-2026-33066)
- CVE-2026-409251 PoCWWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
- CVE-2026-409261 PoCWWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script)
- CVE-2026-409291 PoCWWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content…
- CVE-2026-409311 PoCComplete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing
- CVE-2026-409331 PoCFlowise: Authenticated RCE Via MCP Adapters
- CVE-2026-409351 PoCWWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
- CVE-2026-409761 PoCIn certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an…
- CVE-2026-409871 PoCRemote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization