CVE-2026-46000 to CVE-2026-46999
102 CVEs with public proof-of-concept exploits.
- CVE-2026-462155 PoCsdrm: Set old handle to NULL before prime swap in change_handle
- CVE-2026-462423 PoCseventpoll: fix ep_remove struct eventpoll / struct file UAF
- CVE-2026-462432 PoCssmb: client: reject userspace cifs.spnego descriptions
- CVE-2026-462751 PoCBluetooth: hci_uart: fix UAFs and race conditions in close and init paths
- CVE-2026-4630013 PoCsnet: skbuff: preserve shared-frag marker during coalescing
- CVE-2026-463162 PoCsKVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
- CVE-2026-4633110 PoCsnet/sched: fix pedit partial COW leading to page cache corruption
- CVE-2026-463335 PoCsptrace: slightly saner 'get_dumpable()' logic
- CVE-2026-463371 PoCWWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
- CVE-2026-463381 PoCPyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
- CVE-2026-463393 PoCs9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
- CVE-2026-463411 PoCApify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
- CVE-2026-463451 PoCcompliance-trestle - jinja has an Arbitrary File Write via Path Traversal
- CVE-2026-463571 PoCHAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Import Request
- CVE-2026-463591 PoCphpMyFAQ - SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token Fields
- CVE-2026-463601 PoCphpMyFAQ - Stored XSS via Entity Decoding Depth Limit Bypass in SVG Sanitizer
- CVE-2026-463611 PoCphpMyFAQ - Stored Cross-Site Scripting via raw Filter in search.twig
- CVE-2026-463621 PoCphpMyFAQ - Authorization Bypass in Admin Pages via Non-Terminating Permission Check
- CVE-2026-463631 PoCphpMyFAQ - Stored XSS in FAQ Question/Answer via Encode-Decode Bypass
- CVE-2026-463642 PoCsphpMyFAQ - SQL Injection via User-Agent Header in BuiltinCaptcha
- CVE-2026-463661 PoCphpMyFAQ - Unauthenticated Information Disclosure via getIdFromSolutionId Permission Bypass
- CVE-2026-463671 PoCphpMyFAQ - Stored XSS via Utils::parseUrl() in Comment Rendering
- CVE-2026-463682 PoCsluci-app-https-dns-proxy Authenticated Command Injection via setInitAction
- CVE-2026-463722 PoCsSillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
- CVE-2026-463761 PoCFreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface
- CVE-2026-463771 PoCDasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
- CVE-2026-463781 PoCDasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
- CVE-2026-463831 PoCMicrosoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
- CVE-2026-463851 PoCiskorotkov/avro: CPU Exhaustion in Avro Decoder
- CVE-2026-463911 PoCHAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
- CVE-2026-463931 PoCHAXcms createSite SSRF Enables Arbitrary File Read
- CVE-2026-463941 PoCHAX CMS Vulnerable to Command Injection using Git.php
- CVE-2026-463952 PoCsHAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
- CVE-2026-463961 PoCHAX CMS has a stored XSS via <iframe> that allows access to sensitive client-side data and account takeover
- CVE-2026-464031 PoCKlever-Go KVM read-only execution can commit contract delete and upgrade side effects
- CVE-2026-464201 PoCsetup-php: Command Injection in Repository-Derived PHP Version Resolution
- CVE-2026-464281 PoClettre has TLS hostname verification disabled when using Boring TLS backend
- CVE-2026-464301 PoCAlgernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
- CVE-2026-464311 PoCAlgernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
- CVE-2026-464321 PoCLMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
- CVE-2026-464391 PoCcompliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
- CVE-2026-464411 PoCFlowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment
- CVE-2026-464423 PoCsFlowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
- CVE-2026-464431 PoCFlowise: Credential Data Leak
- CVE-2026-464531 PoCApache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering,…
- CVE-2026-464541 PoCApache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing…
- CVE-2026-464551 PoCApache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the…
- CVE-2026-464561 PoCApache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a…
- CVE-2026-464571 PoCApache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a…
- CVE-2026-464751 PoCFlowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover
- CVE-2026-464761 PoCFlowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
- CVE-2026-464771 PoCFlowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover
- CVE-2026-464781 PoCFlowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover
- CVE-2026-464791 PoCFlowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
- CVE-2026-464801 PoCFlowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
- CVE-2026-464811 PoCOpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users
- CVE-2026-464902 PoCssamlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
- CVE-2026-464921 PoCmd-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
- CVE-2026-464961 PoCHAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
- CVE-2026-464971 PoCSSRF via sitemap-derived URLs in Crawlee for Python
- CVE-2026-465101 PoCPrototype pollution in form-data-objectizer via bracket-notation form keys
- CVE-2026-465111 PoCHAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
- CVE-2026-465191 PoCmcp-server-kubernetes Affected By Tool Access Control Bypass: Presentation-Layer Filtering Without Execution-Layer Enforcement
- CVE-2026-465221 PoCImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
- CVE-2026-465261 PoCLocal Deep Research: SSRF bypass in `safe_get`
- CVE-2026-465291 PoCPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
- CVE-2026-465521 PoCNocoDB: Shared-base link access can invite arbitrary users as persistent base members
- CVE-2026-465581 PoCPlane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane…
- CVE-2026-465621 PoCYamcs: Remote Code Execution via Mission Database algorithm override
- CVE-2026-465841 PoCApache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to…
- CVE-2026-465851 PoCApache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header…
- CVE-2026-465871 PoCApache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
- CVE-2026-465881 PoCApache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
- CVE-2026-465911 PoCApache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause…
- CVE-2026-465921 PoCApache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that…
- CVE-2026-466061 PoCGlances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
- CVE-2026-466071 PoCGlances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution
- CVE-2026-466081 PoCGlances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
- CVE-2026-466111 PoCGlances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
- CVE-2026-466211 PoCYamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
- CVE-2026-466251 PoCJavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
- CVE-2026-466401 PoCTwig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
- CVE-2026-466431 PoCSnappy: Binary path is never shell-escaped due to an inverted is_executable check
- CVE-2026-466702 PoCsYesWiki: Unauthenticated SQL Injection
- CVE-2026-466721 PoCActual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper
- CVE-2026-466731 PoCRussh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote…
- CVE-2026-466791 PoClibp2p: Memory DoS via subscription flood of unique topics
- CVE-2026-466801 PoCcontainerd user ID handling bypass allows runAsNonRoot evasion
- CVE-2026-466891 PoCKanidm: Unauthenticated process abort via SCIM filter stack exhaustion
- CVE-2026-466951 PoCBoxLite: Permission Bypass in boxlite Allows Modification of Read-Only Files
- CVE-2026-467001 PoCActual: Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
- CVE-2026-467011 PoCNetwork-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
- CVE-2026-467021 PoCRussh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
- CVE-2026-467031 PoCBoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Write on the Host
- CVE-2026-467051 PoCrussh server userauth state is not reset when authentication principal changes
- CVE-2026-467151 PoCFlask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
- CVE-2026-467161 PoCNezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
- CVE-2026-467171 PoCNezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
- CVE-2026-467251 PoCRemote Code Execution in extension "Content Element Selector" (ceselector)
- CVE-2026-467261 PoCApache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without…
- CVE-2026-468172 PoCsKEVVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are…
- CVE-2026-468581 PoCVulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics).…