CVE-2026-47000 to CVE-2026-47999
81 CVEs with public proof-of-concept exploits.
- CVE-2026-470661 PoCInfinite loop in Alt-Svc header parser in hackney
- CVE-2026-470741 PoCex_aws_sns SigningCertURL not validated in verify_message/1
- CVE-2026-471015 PoCsLiteLLM < 1.83.14 Privilege Escalation via API Key Generation
- CVE-2026-471024 PoCsLiteLLM < 1.83.10 Privilege Escalation via User Update
- CVE-2026-471031 PoCPython StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
- CVE-2026-471141 PoCIINA < 1.4.3 Command Execution via iina://open URL Scheme
- CVE-2026-471171 PoCOpenMed < 1.5.2 Remote Code Execution via PII Model Loading
- CVE-2026-471201 PoCNezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)
- CVE-2026-471211 PoCSparkle: Binary delta apply intermediate-symlink traversal in malicious .delta
- CVE-2026-471241 PoCNezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members
- CVE-2026-471281 PoCnono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
- CVE-2026-471371 PoCvm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE
- CVE-2026-471391 PoCvm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_server
- CVE-2026-471401 PoCvm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
- CVE-2026-471411 PoCvm2: NodeVM observability builtins leak host process and HTTP request data
- CVE-2026-472001 PoCNuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
- CVE-2026-472091 PoCvm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
- CVE-2026-472101 PoCvm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
- CVE-2026-472131 PoCBoxLite: Timeout Bypass Vulnerability
- CVE-2026-472261 PoCAdmidio: Authorization bypass in file_delete enables cross-folder file removal by authenticated users without delete privileges
- CVE-2026-472271 PoCAdmidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in…
- CVE-2026-472281 PoCAdmidio's CSRF in registration `send_login` mode resets arbitrary user passwords
- CVE-2026-472291 PoCAdmidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation
- CVE-2026-472301 PoCAdmidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders
- CVE-2026-472311 PoCAdmidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders
- CVE-2026-472321 PoCAdmidio PKCS#12 private key export action lacks CSRF protection
- CVE-2026-472331 PoCAdmidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incomplete fix of #2024
- CVE-2026-472341 PoCAdmidio writes session IDs and auto-login cookie values to application logs
- CVE-2026-472431 PoCKata guest escape: runtime-rs guest-root to host-root escape via virtiofs
- CVE-2026-472491 PoCKlever-Go KVM: Hash-array amplification in P2P resolver request handling
- CVE-2026-472501 PoCmcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration
- CVE-2026-472671 PoCGogs: SSRF in webhook deliveries
- CVE-2026-472911 PoCHTTP.sys Remote Code Execution Vulnerability
- CVE-2026-473011 PoCConfiguration Manager Elevation of Privilege Vulnerability
- CVE-2026-473231 PoCApache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
- CVE-2026-473911 PoCPraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
- CVE-2026-473941 PoCPraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
- CVE-2026-473961 PoCPraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
- CVE-2026-473971 PoCPraisonAI has an Arbitrary File Write in Python API
- CVE-2026-473991 PoCPraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
- CVE-2026-474071 PoCPraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
- CVE-2026-474081 PoCpraisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
- CVE-2026-474101 PoCpraisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is…
- CVE-2026-474111 PoCpraisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
- CVE-2026-474141 PoCpraisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label…
- CVE-2026-474151 PoCpraisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
- CVE-2026-474161 PoCpraisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}
- CVE-2026-474171 PoCpraisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
- CVE-2026-474181 PoCpraisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
- CVE-2026-474191 PoCpraisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
- CVE-2026-474231 PoCDOMPurify XSS via `selectedcontent` re-clone
- CVE-2026-474281 PoCVitest browser mode serves unsanitized otelCarrier query parameter as inline script
- CVE-2026-474291 PoCVitest: Arbitrary file can be read and executed when Vitest UI server is listening
- CVE-2026-476301 PoCNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful…
- CVE-2026-476684 PoCsDbGate: Unauthenticated Remote Code Execution via JSON Script Runner
- CVE-2026-476691 PoCDbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE
- CVE-2026-476703 PoCsDbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
- CVE-2026-476711 PoCNhost CLI local configserver allows cross-origin unauthenticated read/write access to local development configuration and secrets
- CVE-2026-476831 PoCvm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
- CVE-2026-476861 PoCvm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE
- CVE-2026-476931 PoCPoweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
- CVE-2026-476941 PoCWWBN AVideo: Stored XSS via unescaped Gallery category description
- CVE-2026-476951 PoCCC-Tweaked has an SSRF Protection Bypass with NAT64
- CVE-2026-476961 PoCWWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint
- CVE-2026-477061 PoCStrawberry GraphQL has a Circular Fragment Reference DOS
- CVE-2026-477071 PoCStrawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
- CVE-2026-477081 PoCMCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper
- CVE-2026-477172 PoCsFUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
- CVE-2026-477181 PoCFUXA provides guest and invalid-token access to protected read APIs in secure mode
- CVE-2026-477221 PoCnebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
- CVE-2026-477251 PoCnebula-mesh: Web UI lacks CSRF tokens on /ui/* mutating endpoints
- CVE-2026-477261 PoCnebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
- CVE-2026-477291 PoCSquid: Memory disclosure in FTP gateway
- CVE-2026-477531 PoCIncus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)
- CVE-2026-477611 PoCTinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
- CVE-2026-477631 PoCpdm: Project-Local State and Config Writes Follow Symlinks
- CVE-2026-477771 PoCMastodon has a consent-check bypass in its remote Collections
- CVE-2026-477811 PoCpdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing
- CVE-2026-478511 PoCUnbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
- CVE-2026-478581 PoClive information startup mode is vulnerable for remote code execution
- CVE-2026-478831 PoCSpring Framework Open Redirect in UrlHandlerFilter