CVE-2026-48000 to CVE-2026-48999
85 CVEs with public proof-of-concept exploits.
- CVE-2026-480121 PoCShopware SSO referer trust leading to an arbitrary redirect target
- CVE-2026-480172 PoCsDbGate: Remote Code Execution via functionName injection in loadReader endpoint
- CVE-2026-480202 PoCsTraefik StripPrefix Route-Level Auth Bypass via Path Normalization
- CVE-2026-480303 PoCsPheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)
- CVE-2026-480391 PoCMeta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
- CVE-2026-480511 PoCPapra: SSRF via HTTP redirect bypass in webhook delivery
- CVE-2026-480531 PoCKolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset
- CVE-2026-480581 PoCnebula-mesh: Session and OIDC state cookies lack the Secure attribute
- CVE-2026-480602 PoCsLitestar: HTML Injection Through CSRF Token
- CVE-2026-480951 PoCGHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation
- CVE-2026-481071 PoCRussh: Unchecked keyboard-interactive prompt count in client auth path
- CVE-2026-481081 PoCRussh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
- CVE-2026-481101 PoCRussh: SSH message fields were decoded through allocation-first parsers before field-specific bounds
- CVE-2026-481131 PoCChisel: ACL Bypass via Post-Handshake SSH Channel ExtraData Injection
- CVE-2026-481191 PoCNezha Monitoring: Authenticated agents can forge service-monitor results for other users' services
- CVE-2026-481211 PoC@langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDBSaver allows cross-tenant state access
- CVE-2026-481261 PoCAlgernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
- CVE-2026-481281 PoCBudibase: SSRF via User-Controlled queryId in Automation Execute Query Step
- CVE-2026-481471 PoCBudibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
- CVE-2026-481501 PoCBudibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
- CVE-2026-481511 PoCBudibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
- CVE-2026-481521 PoCBudibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
- CVE-2026-481531 PoCBudibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
- CVE-2026-481691 PoCPraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
- CVE-2026-481701 PoCscimPatch vulnerable to prototype pollution via unfiltered keys in patch
- CVE-2026-481723 PoCsKEVLiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.…
- CVE-2026-481881 PoCSQL Injection via MySQL Quote Method
- CVE-2026-482031 PoCApache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header…
- CVE-2026-482041 PoCApache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter,…
- CVE-2026-482051 PoCApache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing…
- CVE-2026-482061 PoCApache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive…
- CVE-2026-482081 PoCDenial-of-Service via SVG Rendering in Ticket
- CVE-2026-482822 PoCsKEVColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
- CVE-2026-483131 PoCColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
- CVE-2026-484911 PoCTraefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
- CVE-2026-485191 PoCLangflow: Unauthenticated RCE in Shareable Playgrounds
- CVE-2026-485221 PoCPyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes
- CVE-2026-485231 PoCPyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
- CVE-2026-485251 PoCPyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
- CVE-2026-485261 PoCPyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
- CVE-2026-485271 PoCHaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint
- CVE-2026-485291 PoCGitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
- CVE-2026-485583 PoCsKEVSimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
- CVE-2026-485591 PoCLightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags
- CVE-2026-485921 PoCMissing authorization check on save-job event handler in oban_web
- CVE-2026-485941 PoCDecompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
- CVE-2026-485971 PoCAtom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
- CVE-2026-485991 PoCAuthorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding
- CVE-2026-486114 PoCsImproper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to…
- CVE-2026-487104 PoCsKEVStarlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
- CVE-2026-487121 PoCprotobufjs: Denial of service through unbounded Any expansion during JSON conversion
- CVE-2026-487321 PoCWarp: Remote SSH cwd can lead to unauthorized remote command execution
- CVE-2026-487491 PoCIncus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
- CVE-2026-487501 PoCIncus has an arbitrary file write on host via `exec-output` symlink in crafted image
- CVE-2026-487521 PoCIncus has arbitrary file read+write on host via templates/ symlink in malicious image
- CVE-2026-487531 PoCIncus has an arbitrary file write via path traversal in S3 multipart upload
- CVE-2026-487541 PoCIncus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool}
- CVE-2026-487551 PoCIncus has an argument injection in backup compression algorithm leading to AFW and ACE
- CVE-2026-487561 PoCIncus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)
- CVE-2026-487691 PoCIncus has an arbitrary file write on its client due to trusted image hash
- CVE-2026-487701 PoCNotepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash
- CVE-2026-487771 PoCFileBrowser Quantum: Path Traversal in public share PATCH allows file ops outside shared directory
- CVE-2026-487784 PoCsNotepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
- CVE-2026-487881 PoCRemark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
- CVE-2026-487901 PoCturso-cli persists Turso platform JWT with world-readable (0o644) file permissions
- CVE-2026-487911 PoCSigstore Java has a vulnerability with bundle verification of integratedTime
- CVE-2026-487961 PoCCefSharp: `FolderSchemeHandlerFactory` path boundary check can expose files outside the configured root folder
- CVE-2026-488002 PoCsNotepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
- CVE-2026-488011 PoClinkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop
- CVE-2026-488131 PoCFlawfinder output manipulation via untrusted filenames and source text
- CVE-2026-488141 PoCNetwork-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)
- CVE-2026-488161 PoCsigstore-js: Insufficient Verification of Data Authenticity
- CVE-2026-488241 PoCMailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and…
- CVE-2026-488491 PoCIn Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to…
- CVE-2026-488531 PoCRemote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc
- CVE-2026-488621 PoCUnbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMISE concurrency
- CVE-2026-488661 PoCWordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerability
- CVE-2026-4890721 PoCsKEVJoomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
- CVE-2026-489088 PoCsKEVJoomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
- CVE-2026-489094 PoCsJoomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
- CVE-2026-489394 PoCsKEVJoomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
- CVE-2026-489621 PoCIO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
- CVE-2026-489881 PoCmarkdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
- CVE-2026-489901 PoCjoserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
- CVE-2026-489951 PoCpnpm: Tarball hash of GitHub git dependencies is not stored in lockfile