CVE-2026-42000 to CVE-2026-42999
136 CVEs with public proof-of-concept exploits.
- CVE-2026-420271 PoCApache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader
- CVE-2026-420311 PoCCKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
- CVE-2026-420331 PoCAxios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
- CVE-2026-420341 PoCAxios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0
- CVE-2026-420351 PoCAxios: Header Injection via Prototype Pollution
- CVE-2026-420361 PoCAxios: HTTP adapter streamed responses bypass maxContentLength
- CVE-2026-420371 PoCAxios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
- CVE-2026-420381 PoCAxios: no_proxy bypass via IP alias allows SSRF
- CVE-2026-420391 PoCAxios: unbounded recursion in toFormData causes DoS via deeply nested request data
- CVE-2026-420401 PoCAxios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
- CVE-2026-420421 PoCAxios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
- CVE-2026-420441 PoCAxios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
- CVE-2026-420451 PoCLobeHub: Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE)
- CVE-2026-420481 PoCLangflow: Path Traversal in Langflow Knowledge Bases API
- CVE-2026-420551 PoCNGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
- CVE-2026-420721 PoCNornicdb: Improper Network Binding in NornicDB Bolt Server allows unauthorized remote access
- CVE-2026-420731 PoCOpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
- CVE-2026-420741 PoCOpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
- CVE-2026-420751 PoCEvolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write
- CVE-2026-420761 PoCEvolver: Command Injection via `execSync` in `_extractLLM()` function allows Remote Code Execution
- CVE-2026-420771 PoCEvolver: Prototype Pollution via `Object.assign()` in mailbox store operations
- CVE-2026-420811 PoCfree5GC: UE Security Capability bypass on NGAP PathSwitchRequest
- CVE-2026-420821 PoCfree5GC: Missing Concurrent NAS SMC Validation During NGAP Handover
- CVE-2026-420831 PoCfree5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of…
- CVE-2026-420861 PoCOpenC3 COSMOS: Self-XSS in the Command Sender
- CVE-2026-420891 PoCyeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation
- CVE-2026-420961 PoCBroken Access Control in Sparx Pro Cloud Server
- CVE-2026-420971 PoCAuthentication Bypass in Sparx Pro Cloud Server
- CVE-2026-421411 PoCXibo: Authenticated Server-Side Request Forgery (SSRF) in Library Upload via URL functionality
- CVE-2026-421541 PoCPrometheus: remote read endpoint allows denial of service via crafted snappy payload
- CVE-2026-421679 PoCsmod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of…
- CVE-2026-421801 PoCLemmy: SSRF in /api/v3/post via Webmention dispatch
- CVE-2026-421811 PoCLemmy: SSRF and internal image disclosure in post link metadata via unvalidated og:image
- CVE-2026-421831 PoCArgo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)
- CVE-2026-421841 PoCTauri: Origin Confusion Allows Remote Pages to Invoke Local-Only IPC Commands
- CVE-2026-421881 PoCGeyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL
- CVE-2026-421911 PoCOpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local blob injection for OTLP Exporter
- CVE-2026-421941 PoCIncomplete fix for CVE-2026-32812: SSRF in admidio
- CVE-2026-421991 PoCGrid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior
- CVE-2026-422031 PoCLiteLLM: Server-Side Template Injection in /prompts/test endpoint
- CVE-2026-422051 PoCAvo: Broken Access Control: Unauthorized Execution of Arbitrary Action Classes Across Resources
- CVE-2026-422084 PoCsKEVLiteLLM: SQL injection in Proxy API key verification
- CVE-2026-422151 PoCGitPython: Command injection via Git options bypass
- CVE-2026-422201 PoCnginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and…
- CVE-2026-422211 PoCnginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
- CVE-2026-422221 PoCnginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
- CVE-2026-422231 PoCnginx-ui: Settings API Exposes Protected Secrets
- CVE-2026-422281 PoCn8n: Hijacking of Unauthenticated Chat Execution
- CVE-2026-422311 PoCn8n: Prototype Pollution in XML Webhook Body Parser Leads to RCE
- CVE-2026-422391 PoCBudibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
- CVE-2026-422641 PoCAxios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
- CVE-2026-422713 PoCsKEVLiteLLM: Authenticated command execution via MCP stdio test endpoints
- CVE-2026-422813 PoCsMagicMirror²: Unauthenticated SSRF via /cors endpoint
- CVE-2026-422841 PoCGitPython: Unsafe option check validates multi_options before shlex.split transforms it
- CVE-2026-422941 PoCArgo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor
- CVE-2026-422951 PoCArgo Workflows: Exposure of artifact repository credentials
- CVE-2026-422961 PoCArgo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing…
- CVE-2026-423041 PoCTwisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
- CVE-2026-423121 PoCpyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification
- CVE-2026-423131 PoCpyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy
- CVE-2026-423141 PoCpyLoad: Path Traversal via Package Folder Name
- CVE-2026-423151 PoCpyLoad: Path Traversal via Package Folder Name in set_package_data
- CVE-2026-423331 PoCquarkus-openapi-generator has overly broad path-parameter matching that sends authentication headers to unintended operations
- CVE-2026-423381 PoCip-address: XSS in Address6 HTML-emitting methods
- CVE-2026-423391 PoCNew API: SSRF Filter Bypass via 0.0.0.0
- CVE-2026-424252 PoCsOpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery
- CVE-2026-424611 PoCArcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets)
- CVE-2026-424711 PoCUnsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) calls unserialize()…
- CVE-2026-425271 PoCApache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
- CVE-2026-425303 PoCsNGINX Open-Source ngx_http_v3_module vulnerability
- CVE-2026-425339 PoCsNGINX Map directive and Regex matching vulnerability
- CVE-2026-425441 PoCGranian: Unauthenticated DoS via WebSocket subprotocol header panic
- CVE-2026-425451 PoCGranian: DoS via WSGI response header panic
- CVE-2026-425481 PoCFlight: Reflected XSS via unvalidated JSONP callback in Flight::jsonp()
- CVE-2026-425491 PoCFlight: Path traversal in `make:controller` CLI creates arbitrary directories outside project root
- CVE-2026-425501 PoCFlight: SQL Injection via unvalidated identifiers in SimplePdo::insert / update / delete
- CVE-2026-425511 PoCFlight: HTTP method override enabled by default enables CSRF escalation and middleware bypass in flightphp/core
- CVE-2026-425521 PoCFlight: Sensitive information disclosure via default error handler in flightphp/core
- CVE-2026-425551 PoCValtimo: SpEL injection via StandardEvaluationContext allows Remote Code Execution by admin users
- CVE-2026-425601 PoCauth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
- CVE-2026-425683 PoCsYamcs Vulnerable to LDAP Injection in LdapAuthModule
- CVE-2026-425692 PoCsphpvms: /importer authorization bypass causing full database wipe
- CVE-2026-425781 PoCNetty: HTTP Header Injection via HttpProxyHandler Disabled Validation
- CVE-2026-425791 PoCNetty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
- CVE-2026-425801 PoCNetty: HTTP Request Smuggling due to incorrect chunk size parsing
- CVE-2026-425811 PoCNetty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
- CVE-2026-425821 PoCNetty: HTTP/3 QPACK literal unbounded allocation
- CVE-2026-425831 PoCNetty: Lz4FrameDecoder resource exhaustion
- CVE-2026-425851 PoCNetty: HTTP Request Smuggling due to malformed Transfer-Encoding
- CVE-2026-425861 PoCNetty: CRLF Injection in Netty Redis Codec Encoder
- CVE-2026-425871 PoCNetty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS
- CVE-2026-425883 PoCsApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
- CVE-2026-425892 PoCsGotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
- CVE-2026-425911 PoCGotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8
- CVE-2026-425921 PoCGotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
- CVE-2026-425931 PoCGotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
- CVE-2026-425941 PoCGotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
- CVE-2026-425951 PoCGotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
- CVE-2026-425962 PoCsGotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
- CVE-2026-425971 PoCGotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme
- CVE-2026-426011 PoCArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
- CVE-2026-426021 PoCazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
- CVE-2026-426051 PoCAzuraCast: Path Traversal in `currentDirectory` Parameter Enables Remote Code Execution via Media Upload
- CVE-2026-426072 PoCsGrav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
- CVE-2026-426081 PoCGrav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.
- CVE-2026-426101 PoCGrav: Sensitive Information Disclosure via Accounts Service Bypass
- CVE-2026-426111 PoCGrav: Stored XSS via Tag Injection
- CVE-2026-426121 PoCGrav: Publisher-Level Stored XSS via Unquoted Event Attributes
- CVE-2026-426131 PoCGrav: Privilege Escalation via Missing Server-Side Validation of groups/access
- CVE-2026-426471 PoCWordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability
- CVE-2026-427581 PoCWordPress WebinarIgnition plugin < 4.08.253 - Privilege Escalation vulnerability
- CVE-2026-427781 PoCApache MINA: CWE-502 Deserialization of Untrusted Data (take 2)
- CVE-2026-427791 PoCApache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE (take 2)
- CVE-2026-427852 PoCsOpenKM 6.3.12 Remote Code Execution via Administrative Scripting
- CVE-2026-427962 PoCsArelle < 2.39.10 Unauthenticated RCE via /rest/configure
- CVE-2026-428091 PoCApache Polaris: staged table creation could vend storage credentials for unvalidated locations
- CVE-2026-428261 PoCAzure DevOps Information Disclosure Vulnerability
- CVE-2026-428411 PoCGrav: Stored XSS via Markdown media attribute() action in Grav CMS
- CVE-2026-428431 PoCgrav-plugin-api: Grav API Privilege Escalation to Super Admin
- CVE-2026-428441 PoCGrav: Low-privileged API users can create super-admin accounts via blueprint-upload
- CVE-2026-428451 PoCGrav: Anonymous Page Content Overwrite via Form File Upload filename Override
- CVE-2026-428531 PoC@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input
- CVE-2026-428601 PoCOpen edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint
- CVE-2026-428611 PoCFlowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment
- CVE-2026-428621 PoCFlowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment
- CVE-2026-428631 PoCFlowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment
- CVE-2026-428771 PoCFacturaScripts: Stored XSS via product reference in sales/purchases
- CVE-2026-428782 PoCsFacturaScripts: Unauthenticated phpinfo() Disclosure via Installer Endpoint in FacturaScripts
- CVE-2026-428791 PoCFacturaScripts: Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images
- CVE-2026-428802 PoCsArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
- CVE-2026-429311 PoCDenial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
- CVE-2026-429344 PoCsNGINX ngx_http_charset_module vulnerability
- CVE-2026-4294526 PoCsNGINX ngx_http_rewrite_module vulnerability
- CVE-2026-429464 PoCsNGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
- CVE-2026-429781 PoCWindows Push Notifications Elevation of Privilege Vulnerability
- CVE-2026-429801 PoCNT OS Kernel Elevation of Privilege Vulnerability