CVE-2026-41000 to CVE-2026-41999
143 CVEs with public proof-of-concept exploits.
- CVE-2026-410422 PoCsApache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java…
- CVE-2026-410441 PoCApache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by…
- CVE-2026-410531 PoCOver-inclusive team membership expansion in GitHub App authentication provider for Rancher
- CVE-2026-410551 PoCAVideo has an incomplete fix for CVE-2026-33039 (SSRF)
- CVE-2026-410561 PoCAVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover
- CVE-2026-410571 PoCAVideo has CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) that Exposes Authenticated API Responses
- CVE-2026-410581 PoCAVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideo
- CVE-2026-410601 PoCAVideo's SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
- CVE-2026-410611 PoCWWBN AVideo Vulnerable to stored XSS via Unanchored Duration Regex in Video Encoder Receiver
- CVE-2026-410621 PoCWWBN/AVideo has an incomplete fix for a directory traversal bypass via query string in ReceiveImage downloadURL parameters
- CVE-2026-410631 PoCWWBN AVideo has incomplete fix for CVE-2026-33500 (XSS)
- CVE-2026-410641 PoCAVideo has an incomplete fix for CVE-2026-33502 (Command Injection)
- CVE-2026-410671 PoCAstro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass
- CVE-2026-410681 PoCKyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
- CVE-2026-410895 PoCsWindows Netlogon Remote Code Execution Vulnerability
- CVE-2026-410914 PoCsKEVMicrosoft Defender Elevation of Privilege Vulnerability
- CVE-2026-410963 PoCsWindows DNS Client Remote Code Execution Vulnerability
- CVE-2026-411301 PoCCraft CMS has a host header injection leading to SSRF via resource-js endpoint
- CVE-2026-411331 PoCpyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
- CVE-2026-411351 PoCfree5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service
- CVE-2026-411361 PoCfree5GC AMF missing default case in Content-Type switch in HTTPUEContextTransfer
- CVE-2026-411371 PoCFlowise: Code Injection in CSVAgent leads to Authenticated RCE
- CVE-2026-411381 PoCFlowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas.
- CVE-2026-411431 PoCYesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()
- CVE-2026-411661 PoCOpenRemote has Improper Access Control via updateUserRealmRoles function
- CVE-2026-411741 PoCTraefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
- CVE-2026-411762 PoCsRclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
- CVE-2026-411794 PoCsRClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
- CVE-2026-411801 PoCPsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restart
- CVE-2026-411811 PoCTraefik: Errors middleware forwards Authorization and Cookie headers to separate error page service
- CVE-2026-412001 PoCSTIG Manager has reflected XSS vulnerability in the Web App
- CVE-2026-412021 PoCci4ms Backup::restore is vulnerable to Zip Slip leading to RCE
- CVE-2026-412031 PoCci4ms Theme::upload is vulnerable to Zip Slip leading to RCE
- CVE-2026-412111 PoC`vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME`
- CVE-2026-412131 PoC@node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted…
- CVE-2026-412281 PoCFroxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution
- CVE-2026-412291 PoCFroxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
- CVE-2026-412301 PoCFroxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
- CVE-2026-412311 PoCFroxlor has Incomplete Symlink Validation in DataDump.add() that Allows Arbitrary Directory Ownership Takeover via Cron
- CVE-2026-412341 PoCFroxlor: BIND Zone File Injection via TXT Record Content
- CVE-2026-412351 PoCFroxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement
- CVE-2026-412361 PoCFroxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path
- CVE-2026-412371 PoCFroxlor has an incomplete fix for CVE-2026-30932
- CVE-2026-412382 PoCsDOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
- CVE-2026-412422 PoCsprotobufjs has an arbitrary code execution issue
- CVE-2026-412441 PoCMojic: Observable Timing Discrepancy in HMAC Verification
- CVE-2026-412491 PoCCoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration
- CVE-2026-412621 PoCFleet: Cross-Team Policy Data Exposure via Global Policy Read Endpoint
- CVE-2026-412641 PoCFlowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
- CVE-2026-412651 PoCFlowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
- CVE-2026-412661 PoCFlowise: Sensitive Data Leak in public-chatbotConfig
- CVE-2026-412671 PoCFlowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
- CVE-2026-412691 PoCFlowise: File Upload Validation Bypass in createAttachment
- CVE-2026-412701 PoCFlowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
- CVE-2026-412711 PoCFlowise: APIChain Prompt Injection SSRF in GET/POST API Chains
- CVE-2026-412741 PoCFlowise: Cypher Injection in GraphCypherQAChain
- CVE-2026-412751 PoCFlowise: Password Reset Link Sent Over Unsecured HTTP
- CVE-2026-412761 PoCFlowise: AccountService resetPassword Authentication Bypass Vulnerability
- CVE-2026-412771 PoCFlowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
- CVE-2026-412851 PoCIn OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option…
- CVE-2026-413031 PoCOpenClaw < 2026.3.28 - Authorization Bypass in Discord Text Approval Commands
- CVE-2026-413041 PoCWWBN AVideo vulnerable to RCE caused by clonesite plugin
- CVE-2026-413051 PoCPostCSS has XSS via Unescaped </style> in its CSS Stringify Output
- CVE-2026-413111 PoCLiquidJS is vulnerable to Denial of Service via circular block reference in layout
- CVE-2026-413161 PoCERB has an @_init deserialization guard bypass via def_module / def_method / def_class
- CVE-2026-413191 PoCMailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
- CVE-2026-413221 PoC@astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformed
- CVE-2026-413231 PoCKyverno: ServiceAccount token leaked to external servers via apiCall service URL
- CVE-2026-413241 PoCbasic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
- CVE-2026-413281 PoCDgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
- CVE-2026-414171 PoCNetty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri()
- CVE-2026-414322 PoCsNew API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
- CVE-2026-414522 PoCsKrayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup
- CVE-2026-414531 PoCKrayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter
- CVE-2026-414562 PoCsBludit CMS Reflected XSS via Search Plugin
- CVE-2026-414592 PoCsXerte Online Toolkits Path Disclosure via /setup
- CVE-2026-414623 PoCsProjeQtor < 12.4.4 Unauthenticated SQL Injection via Login
- CVE-2026-414632 PoCsProjeQtor < 12.4.4 ZipSlip Path Traversal via uploadPlugin.php
- CVE-2026-414642 PoCsProjeQtor < 12.4.4 Missing Authorization via objectDetail.php
- CVE-2026-414652 PoCsProjeQtor < 12.4.4 Path Traversal via dynamicDialog.php
- CVE-2026-414662 PoCsProjeQtor < 12.4.4 Stored XSS via checkValidHtmlText()
- CVE-2026-414672 PoCsProjeQtor < 12.4.4 Stored XSS via checkValidFileName()
- CVE-2026-414682 PoCsBeghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection
- CVE-2026-414692 PoCsBeghelli Sicuro24 SicuroWeb Missing Content Security Policy
- CVE-2026-414701 PoCLIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
- CVE-2026-414711 PoCEasy PayPal Events & Tickets < 1.4 Information Disclosure via QR Code Endpoint
- CVE-2026-414722 PoCsCyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard
- CVE-2026-414731 PoCCyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints
- CVE-2026-414791 PoCAuthlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type
- CVE-2026-414851 PoCKyverno Controller Denial of Service via forEach Mutation Panic
- CVE-2026-414901 PoCDagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
- CVE-2026-414922 PoCsUnauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in Dgraph
- CVE-2026-414971 PoCIncomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
- CVE-2026-414981 PoCKimai: Team API Missing Object-Level Authorization
- CVE-2026-415111 PoCOpenMcdf has an Infinite loop DoS via crafted CFB directory cycle
- CVE-2026-415511 PoCA vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user…
- CVE-2026-415671 PoCDocker: `PUT /containers/{id}/archive` executes container binary on the host
- CVE-2026-415711 PoCNote Mark: OIDC-registered users authenticated by submitting password "null"
- CVE-2026-415721 PoCNote Mark: Unauthenticated read of notes and assets in soft-deleted public books
- CVE-2026-415751 PoCth30d4y/IP: DOM-Based Cross-Site Scripting (XSS) Vulnerability
- CVE-2026-415861 PoCObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE
- CVE-2026-415871 PoCCI4MS: Unrestricted PHP File Upload via Theme Installation Leads to Authenticated Remote Code Execution
- CVE-2026-415911 PoCMarko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping
- CVE-2026-416402 PoCsNocoBase Vulnerable to SQL Injection via String Concatenation in Recursive Eager Loading
- CVE-2026-416411 PoCNocoBase Vulnerable to SQL Validation Bypass via `sqlCollection:update` Missing `checkSQL` Call
- CVE-2026-416421 PoCGoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute
- CVE-2026-416431 PoCGoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
- CVE-2026-416501 PoCfast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
- CVE-2026-4165110 PoCsPackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
- CVE-2026-416531 PoCBentoPDF: Stored XSS via Markdown Editor Leading to Persistent File Exfiltration
- CVE-2026-416561 PoCAdmidio: Path Traversal via Unvalidated `name` Parameter in Document Add Mode Enables Arbitrary Server File Read
- CVE-2026-416571 PoCAdmidio: Cross-Organization Member Data Exposure via Permission Check Mismatch in contacts_data.php
- CVE-2026-416581 PoCAdmidio: Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items
- CVE-2026-416601 PoCAdmidio: Inverted 2FA Reset Authorization Check Lets Group Leaders Strip Admin TOTP
- CVE-2026-416611 PoCAdmidio: Reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion
- CVE-2026-416621 PoCAdmidio: Missing Minimum Administrator Check in Role Membership Removal
- CVE-2026-416631 PoCAdmidio: CSRF on Admin Preferences Triggers Unauthorized Backup, .htaccess Write, and Email Send
- CVE-2026-416721 PoCxmldom: XML node injection through unvalidated comment serialization
- CVE-2026-416731 PoCxmldom: Denial of service via uncontrolled recursion in XML serialization
- CVE-2026-416741 PoCxmldom: XML injection through unvalidated DocumentType serialization
- CVE-2026-416751 PoCxmldom: XML node injection through unvalidated processing instruction serialization
- CVE-2026-416792 PoCsPaperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
- CVE-2026-416801 PoCMarked: OOM Denial of Service via Infinite Recursion in marked Tokenizer
- CVE-2026-416851 PoCIncus: Unbounded binary import disk exhaustion
- CVE-2026-417291 PoCSpring Data REST SpEL Injection via Map Key in JSON Patch
- CVE-2026-418881 PoCDistribution: Tag deletion bypasses `storage.delete.enabled` configuration
- CVE-2026-418931 PoCSignal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)
- CVE-2026-418951 PoCchangedetection.io: XXE vulnerability in the changedetection.io project
- CVE-2026-419001 PoCOpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
- CVE-2026-419011 PoCThymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressions
- CVE-2026-419172 PoCsOpenKM 6.3.12 Local File Inclusion via Admin Scripting
- CVE-2026-419221 PoCWDR201A WiFi Extender OS Command Injection via wireless.cgi
- CVE-2026-419231 PoCWDR201A WiFi Extender OS Command Injection via internet.cgi
- CVE-2026-419241 PoCWDR201A WiFi Extender OS Command Injection via makeRequest.cgi
- CVE-2026-419251 PoCWDR201A WiFi Extender OS Command Injection via adm.cgi (reboot_time)
- CVE-2026-419261 PoCWDR201A WiFi Extender OS Command Injection via firewall.cgi
- CVE-2026-419271 PoCWDR201A WiFi Extender Stack-Based Buffer Overflow via firewall.cgi
- CVE-2026-419391 PoCCare Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
- CVE-2026-4194055 PoCsKEVWebPros cPanel and WHM Authentication Bypass via Login Flow
- CVE-2026-419472 PoCsDify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints
- CVE-2026-419482 PoCsDify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
- CVE-2026-419492 PoCsDify < 1.14.2 Authorization Bypass via File Preview Endpoint
- CVE-2026-419502 PoCsDify < 1.14.0 Authorization Bypass via File UUID