CVE-2026-49000 to CVE-2026-49999
80 CVEs with public proof-of-concept exploits.
- CVE-2026-490092 PoCsNorthern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.
- CVE-2026-490421 PoCApache Camel: langchain4j-tools: filter tool argument headers against declared parameters
- CVE-2026-490481 PoCJoomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for Joomla < 6.4.1
- CVE-2026-490492 PoCsJoomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
- CVE-2026-490692 PoCsWordPress WPZOOM Portfolio plugin <= 1.4.21 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-490791 PoCWordPress JetSearch plugin <= 3.5.17 - SQL Injection vulnerability
- CVE-2026-490832 PoCsWordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability
- CVE-2026-490851 PoCWordPress WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.4 - PHP Object Injection…
- CVE-2026-490861 PoCApache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers,…
- CVE-2026-490971 PoCApache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP…
- CVE-2026-490981 PoCApache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that…
- CVE-2026-490991 PoCApache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence…
- CVE-2026-491041 PoCWordPress Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin <= 1.2.1 - PHP Object…
- CVE-2026-491051 PoCWordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.4 - PHP Object Injection vulnerability
- CVE-2026-491141 PoCONNX symlink-following and path-traversal arbitrary file write
- CVE-2026-491271 PoCMusic Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be
- CVE-2026-491281 PoCMusic Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling
- CVE-2026-491291 PoCMusic Player Daemon < 0.24.11 SSRF via CurlInputPlugin
- CVE-2026-491301 PoCMusic Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx
- CVE-2026-491441 PoCBrowserStack Runner 0.9.5 Path Traversal via _default HTTP Handler
- CVE-2026-491601 PoCHTTP.sys Denial of Service Vulnerability
- CVE-2026-491763 PoCsWindows WalletService Elevation of Privilege Vulnerability
- CVE-2026-492291 PoCActual: Disabled OpenID users keep access through existing session tokens
- CVE-2026-492301 PoCApache APISIX: Authentication bypass in jwe-decrypt
- CVE-2026-492571 PoCmcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
- CVE-2026-492601 PoCPhpWeasyPrint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of…
- CVE-2026-492621 PoCAimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy
- CVE-2026-492681 PoCApache Shiro: LDAP DN Injection in DefaultLdapRealm
- CVE-2026-492791 PoCWWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)
- CVE-2026-492911 PoCmcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
- CVE-2026-493361 PoC@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in…
- CVE-2026-493421 PoCYARD static cache reads raw traversal paths before router sanitization
- CVE-2026-493431 PoCKlever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
- CVE-2026-493441 PoCMercator has a Personal Identifiable Information Leak from Query Executor feature
- CVE-2026-493451 PoCMercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)
- CVE-2026-493522 PoCs9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
- CVE-2026-493531 PoC9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
- CVE-2026-493581 PoCPhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
- CVE-2026-493591 PoCPhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
- CVE-2026-493651 PoCApache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack…
- CVE-2026-493961 PoCNezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's agents
- CVE-2026-493971 PoCNezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
- CVE-2026-494021 PoCDeno: Command Injection via spawnSync & spawn on Windows
- CVE-2026-494061 PoCDeno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
- CVE-2026-494111 PoCDeno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
- CVE-2026-494131 PoCFlaw in Linuxulator execution of setugid binaries
- CVE-2026-494171 PoCMultiple vulnerabilities in the sound(4) mmap path
- CVE-2026-494401 PoCDeno: Miller-Rabin Primality Test Allows Zero Rounds
- CVE-2026-494471 PoCCosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
- CVE-2026-494581 PoCDOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
- CVE-2026-494591 PoCDOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
- CVE-2026-494682 PoCsLiteLLM: Authentication Bypass via Host Header Injection
- CVE-2026-494711 PoCSerena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
- CVE-2026-494892 PoCsOpenCATS - SQL Injection in DataGrid sortDirection Parameter
- CVE-2026-494911 PoCPixa Bank 2.0 SQL Injection via agence-ajax.php API
- CVE-2026-494921 PoCMarkdown Preview Enhanced OS Command Injection in External File and Link Opening
- CVE-2026-494942 PoCsXcitium Client Security / Comodo Internet Security Remote Denial of Service
- CVE-2026-497541 PoCHTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
- CVE-2026-497571 PoCOAuth2/OIDC account takeover in AshAuthentication via email-based user matching
- CVE-2026-497721 PoCWordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability
- CVE-2026-497773 PoCsWordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
- CVE-2026-498511 PoCMistune: Potential DoS via quadratic-time parsing in parse_link_text
- CVE-2026-498521 PoCjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
- CVE-2026-498561 PoC@jshookmcp/jshook: ICMP probe and traceroute skip local-network SSRF authorization
- CVE-2026-498571 PoCauth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback
- CVE-2026-498581 PoCAPI Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
- CVE-2026-498641 PoCwetty vulnerable to DOM XSS via file-download filename
- CVE-2026-498661 PoClibp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
- CVE-2026-499431 PoCCZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation…
- CVE-2026-499524 PoCsDiscuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
- CVE-2026-499531 PoCDiscuz! X5.0 CAPTCHA Bypass via Predictable Character Set
- CVE-2026-499541 PoCDiscuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory
- CVE-2026-4997510 PoCsApache HTTP Server: mod_http2 denial of service
- CVE-2026-499821 PoCtmp: Type-confusion bypass of _assertPath in tmp@0.2.6 allows path traversal via non-string prefix/postfix/template
- CVE-2026-499861 PoCCortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
- CVE-2026-499871 PoCRepomix: Command Injection (RCE) via `--remote-branch` Argument Injection
- CVE-2026-499881 PoCRepomix: attach_packed_output can bypass file-read secret scanning for supported local files
- CVE-2026-499891 PoCCrateDB's Blob HTTP handler bypasses authorization
- CVE-2026-499931 PoC@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all…
- CVE-2026-499981 PoCCentrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass