CVE-2026-45000 to CVE-2026-45999
124 CVEs with public proof-of-concept exploits.
- CVE-2026-450081 PoCphpMyFAQ - Path Traversal in Client::deleteClientFolder via URL Parameter
- CVE-2026-450091 PoCphpMyFAQ - Insufficient Authorization Check in Admin API Endpoints
- CVE-2026-450111 PoCApostrophe has stored XSS via javascript: URL in Image Widget Link
- CVE-2026-450121 PoCApostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
- CVE-2026-450181 PoCChainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution
- CVE-2026-450191 PoCChainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access
- CVE-2026-450331 PoCGitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
- CVE-2026-450342 PoCsPhpSpreadsheet: File::prohibitWrappers bypass
- CVE-2026-450611 PoCBudibase: SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)
- CVE-2026-450621 PoCFrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
- CVE-2026-450671 PoCSymfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
- CVE-2026-450871 PoCDalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
- CVE-2026-450912 PoCssealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
- CVE-2026-451351 PoCCaddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
- CVE-2026-451371 PoCAnchor: Program<'info, System> is not properly validated
- CVE-2026-451381 PoCCI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
- CVE-2026-451391 PoCCI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
- CVE-2026-451471 PoCSiYuan: Broken access control in SiYuan `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk
- CVE-2026-451481 PoCSiYuan: Broken access control in SiYuan publish-mode Readers can enumerate metadata
- CVE-2026-451521 PoCuniget: Command Injection in tool.Check Leading to Arbitrary Code Execution
- CVE-2026-451561 PoCNextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC
- CVE-2026-451852 PoCsExim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is…
- CVE-2026-452331 PoCHTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave
- CVE-2026-452472 PoCsKEVMirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
- CVE-2026-452581 PoCMultiple vulnerabilities in the sound(4) mmap path
- CVE-2026-452601 PoCPimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling
- CVE-2026-452701 PoCCI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
- CVE-2026-452871 PoCOpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse
- CVE-2026-452982 PoCsDozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
- CVE-2026-453001 PoCasync-http-client: Cookie header not stripped on cross-origin redirect
- CVE-2026-453021 PoCPrototype Pollution in parse-nested-form-data via `__proto__` in FormData field names
- CVE-2026-453031 PoCOpen WebUI: Stored XSS via the HTML renedering view
- CVE-2026-453061 PoCpyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory
- CVE-2026-453091 PoCAsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
- CVE-2026-453101 PoCCodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool
- CVE-2026-453111 PoCCodeWhale: run_tests Tool Enables RCE via Malicious Repository Without Approval
- CVE-2026-453141 PoCOpen WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
- CVE-2026-453151 PoCOpen WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
- CVE-2026-453161 PoCOpen WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
- CVE-2026-453171 PoCOpen WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation
- CVE-2026-453181 PoCOpen WebUI: Stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
- CVE-2026-453213 PoCsKEVMalware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
- CVE-2026-453301 PoCDecidim: Verification admins can access supplied IDs from other organisations
- CVE-2026-453322 PoCsAutomad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint
- CVE-2026-453391 PoCOpen WebUI: API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
- CVE-2026-453461 PoCOpen WebUI: Stored Cross-Site Scripting in SVG Renderer
- CVE-2026-453471 PoCOpen WebUI: Blind server side request forgery (SSRF) via the PDF generate function
- CVE-2026-453481 PoCpyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template literal
- CVE-2026-453501 PoCOpen WebUI: Chat completion API allows tool restrictions to be bypassed
- CVE-2026-453571 PoCLiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)
- CVE-2026-453651 PoCOpen WebUI: Authenticated users can bypass model access control via exposed query parameter
- CVE-2026-453691 PoCpython-utcp: Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
- CVE-2026-453711 PoCSiYuan: SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs
- CVE-2026-453741 PoCCodeWhale: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
- CVE-2026-453751 PoCSiYuan: Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
- CVE-2026-453761 PoCDecidim: Admin user search allows SQL injection through similarity-based sorting
- CVE-2026-453771 PoCDecidim: Private exports can be downloaded through reusable links
- CVE-2026-453781 PoCDecidim: Verification documents can be downloaded through reusable links
- CVE-2026-453851 PoCOpen WebUI: An IDOR vulnerability exists in the update_message_by_id API endpoint
- CVE-2026-453861 PoCOpen WebUI: An IDOR vulnerability exists in the pin_channel_message API endpoint
- CVE-2026-453951 PoCOpen WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
- CVE-2026-453972 PoCsOpen WebUI: Unauthenticated RAG Configuration Disclosure
- CVE-2026-453981 PoCOpen WebUI: IDOR - Retrieval API Bypasses Knowledge Base Access Controls
- CVE-2026-454012 PoCsOpen WebUI: SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints
- CVE-2026-454021 PoCOpen WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
- CVE-2026-454041 PoCOpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
- CVE-2026-454472 PoCsHeap Use-After-Free in the PKCS7_verify() Function
- CVE-2026-455041 PoCMicrosoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2026-455391 PoCMicrosoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents…
- CVE-2026-455481 PoCBudibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation
- CVE-2026-455781 PoCWWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL
- CVE-2026-455801 PoCWWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute
- CVE-2026-455841 PoCMicrosoft Defender Remote Code Execution Vulnerability
- CVE-2026-455852 PoCsWindows BitLocker Security Feature Bypass Vulnerability
- CVE-2026-456101 PoCWWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a…
- CVE-2026-456171 PoCLiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
- CVE-2026-456181 PoCLiquidJS is Vulnerable to Remote Code Execution
- CVE-2026-456231 PoCPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
- CVE-2026-456591 PoCKEVMicrosoft SharePoint Remote Code Execution Vulnerability
- CVE-2026-456651 PoCOpen WebUI: Stored XSS in Banner Component via Improper Sanitization Order
- CVE-2026-456661 PoCOpen WebUI: Indirect Object Reference (IDOR) in user notes
- CVE-2026-456671 PoCOpen WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
- CVE-2026-456691 PoCNuxt: Reflected XSS in `navigateTo()` external redirect
- CVE-2026-456701 PoCNuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
- CVE-2026-456711 PoCOpen WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
- CVE-2026-456721 PoCOpen WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
- CVE-2026-456751 PoCOpen WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
- CVE-2026-456761 PoCOpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent
- CVE-2026-456781 PoCOpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
- CVE-2026-456791 PoCOpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
- CVE-2026-456801 PoCOpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
- CVE-2026-456811 PoCOpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size
- CVE-2026-456821 PoCOpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
- CVE-2026-456831 PoCOpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memory disclosure
- CVE-2026-456841 PoCOpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers
- CVE-2026-456851 PoCOpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
- CVE-2026-456861 PoCOpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI
- CVE-2026-456941 PoCLibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters
- CVE-2026-456951 PoCKopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used
- CVE-2026-457031 PoCPimcore: WordExport Authorization Bypass for Unauthorized Document Export
- CVE-2026-457041 PoCPimcore: CustomReports Share Bypass
- CVE-2026-457091 PoCMailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
- CVE-2026-457111 PoCMailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
- CVE-2026-457121 PoCMailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
- CVE-2026-457131 PoCMailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
- CVE-2026-457151 PoCBudibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration
- CVE-2026-457161 PoCBudibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration
- CVE-2026-457191 PoCBudibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API
- CVE-2026-457211 PoCAlgernon: handler.lua discovery walks parent directories above the server root
- CVE-2026-457251 PoCcompliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
- CVE-2026-457281 PoCAlgernon: Single-file mode unconditionally enables debug mode
- CVE-2026-457301 PoCNuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any project
- CVE-2026-457371 PoCArgo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
- CVE-2026-457381 PoCArgo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
- CVE-2026-457411 PoCGotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
- CVE-2026-457741 PoCcompliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
- CVE-2026-457811 PoCMCP Registry: OCI ownership validation fails open on upstream rate limits, allowing attacker-controlled package claims
- CVE-2026-457831 PoClibp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
- CVE-2026-457991 PoCWire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
- CVE-2026-458031 PoCgh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
- CVE-2026-458051 PoCPenpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
- CVE-2026-458061 PoCPenpot: Authenticated SSRF in remote image import via create-file-media-object-from-url
- CVE-2026-458292 PoCsA pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated…
- CVE-2026-458331 PoCA code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary…