CVE-2026-43000 to CVE-2026-43999
54 CVEs with public proof-of-concept exploits.
- CVE-2026-430742 PoCseventpoll: defer struct eventpoll free to RCU grace period
- CVE-2026-4328424 PoCsxfrm: esp: avoid in-place decrypt on shared skb frags
- CVE-2026-434491 PoCnvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set
- CVE-2026-434944 PoCsnet/rds: reset op_nents when zerocopy page pin fails
- CVE-2026-43499113 PoCsrtmutex: Use waiter::task instead of current in remove_waiter()
- CVE-2026-4350013 PoCsrxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
- CVE-2026-435012 PoCsipv6: rpl: reserve mac_len headroom when recompressed SRH grows
- CVE-2026-435039 PoCsnet: skbuff: propagate shared-frag marker through frag-transfer helpers
- CVE-2026-435121 PoCApache Tomcat: Digest authenticator will authenticate any unknown user
- CVE-2026-435151 PoCApache Tomcat: Security constraints not correctly applied
- CVE-2026-436331 PoCHestiaCP 1.9.0-1.9.4 Deserialization RCE via Web Terminal
- CVE-2026-436341 PoCHestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header
- CVE-2026-436371 PoCCornac < 2.6.0 Path Traversal via _extract_archive() in download.py
- CVE-2026-436381 PoCBitwarden Server < 2026.4.1 Missing Authorization via Organization Cipher Import
- CVE-2026-436391 PoCBitwarden Server < 2026.4.0 Missing Authorization via Provider Clients
- CVE-2026-436401 PoCBitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key
- CVE-2026-436441 PoCpodinfo 6.11.2 Reflected XSS via /echo Endpoint
- CVE-2026-436551 PoCAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS…
- CVE-2026-437001 PoCA cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and…
- CVE-2026-437231 PoCA path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS…
- CVE-2026-437351 PoCThe issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS…
- CVE-2026-437601 PoCAn access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may…
- CVE-2026-438131 PoCA validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS…
- CVE-2026-438651 PoCApache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution
- CVE-2026-438661 PoCApache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder
- CVE-2026-438671 PoCApache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream…
- CVE-2026-438731 PoCWWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the…
- CVE-2026-438741 PoCWWBN AVideo: Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']`…
- CVE-2026-438751 PoCWWBN AVideo: Password Hash Leaked in MobileManager OAuth Redirect URL Enables Account Takeover
- CVE-2026-438761 PoCWWBN AVideo: HTML Injection in notifySubscribers.json.php Enables Platform-Branded Phishing Emails to Channel Subscribers
- CVE-2026-438771 PoCWWBN AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Any Logged-in User's Profile Photo with Arbitrary Bytes
- CVE-2026-438781 PoCWWBN AVideo: Reflected XSS in plugin/Meet/iframe.php via Unescaped `user`/`pass` Parameters Reflected into JavaScript String Literal
- CVE-2026-438791 PoCWWBN AVideo: Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect Bypass
- CVE-2026-438801 PoCWWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From Address
- CVE-2026-438821 PoCWWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing
- CVE-2026-438831 PoCWWBN AVideo: IDOR in PayPalYPT agreementCancel.json.php Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements
- CVE-2026-438841 PoCWWBN AVideo: SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()
- CVE-2026-438851 PoCWWBN AVideo: Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization
- CVE-2026-438911 PoCchangedetection.io: Arbitrary Local File Read via crafted backup restore
- CVE-2026-438931 PoCexiftool-vendored: Argument injection via newline characters in tag names
- CVE-2026-439141 PoCVaultwarden: Brute-force protection bypass vulnerability
- CVE-2026-439291 PoCssrfcheck: Server-Side Request Forgery (SSRF) and Incomplete List of Disallowed Inputs
- CVE-2026-439371 PoCYAF.NET: Pre-Handler Authorization Bypass on Admin Pages Enabling Blind SQL Execution via `/Admin/RunSql`
- CVE-2026-439381 PoCYAF.NET: Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
- CVE-2026-439391 PoCYAF.NET: Stored XSS in Forum Thread Posts/Replies Allowing Arbitrary JavaScript Execution for All Thread Viewers
- CVE-2026-439451 PoCFUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
- CVE-2026-439471 PoCFUXA Vulnerable to Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass
- CVE-2026-439481 PoCwger: cross-tenant password reset and plaintext disclosure via gym=None bypass
- CVE-2026-439771 PoCwger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API
- CVE-2026-439781 PoCwger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers
- CVE-2026-439791 PoCLocal Deep Research: HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
- CVE-2026-439951 PoCFlowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
- CVE-2026-439981 PoCvm2: NodeVM require.root bypass via symlink traversal allows sandbox escape
- CVE-2026-439991 PoCvm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape