CVE-2026-4000 to CVE-2026-4999
344 CVEs with public proof-of-concept exploits.
- CVE-2026-40071 PoCTenda W3 POST Parameter wifiSSIDget stack-based overflow
- CVE-2026-40081 PoCTenda W3 POST Parameter wifiSSIDset stack-based overflow
- CVE-2026-40091 PoCjarikomppa soloud WAV File dr_wav.h drwav_read_pcm_frames_s16__msadpcm out-of-bounds
- CVE-2026-40102 PoCsThakeeNathees pocketlang pkByteBufferAddString memory corruption
- CVE-2026-40121 PoCrxi fe fe.c read_ out-of-bounds
- CVE-2026-40141 PoCitsourcecode Cafe Reservation System Registration signup.php sql injection
- CVE-2026-40151 PoCGPAC TeXML File load_text.c txtin_process_texml stack-based overflow
- CVE-2026-40161 PoCGPAC SVG Parser load_svg.c svgin_process out-of-bounds write
- CVE-2026-40203 PoCsGravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API
- CVE-2026-40401 PoCOpenClaw File Existence tools.exec.safeBins information exposure
- CVE-2026-40411 PoCTenda i12 exeCommand vos_strcpy stack-based overflow
- CVE-2026-40421 PoCTenda i12 WifiMacFilterGet formWifiMacFilterGet stack-based overflow
- CVE-2026-40431 PoCTenda i12 wifiSSIDget formwrlSSIDget stack-based overflow
- CVE-2026-40441 PoCprojectsend Delete import-orphans.php realpath path traversal
- CVE-2026-40451 PoCprojectsend Auth.php response discrepancy
- CVE-2026-40561 PoCUser Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation
- CVE-2026-40602 PoCsGeo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'sort' Parameter
- CVE-2026-40791 PoCSQL Chart Builder < 2.3.8 - Unauthenticated SQL Injection
- CVE-2026-41063 PoCsHT Mega < 3.0.7 – Unauthenticated PII Disclosure
- CVE-2026-41101 PoCUltimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
- CVE-2026-41121 PoCImproper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a…
- CVE-2026-41151 PoCPuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verification
- CVE-2026-41631 PoCWavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection
- CVE-2026-41641 PoCWavlink WL-WN578W2 POST Request wireless.cgi GuestWifi command injection
- CVE-2026-41661 PoCWavlink WL-NU516U1 login.cgi sub_404F68 cross site scripting
- CVE-2026-41671 PoCBelkin F9K1122 formReboot stack-based overflow
- CVE-2026-41681 PoCTecnick TCExam Group tce_edit_group.php cross site scripting
- CVE-2026-41701 PoCTopsec TopACM HTTP Request nmc_sync.php os command injection
- CVE-2026-41711 PoCCodeGenieApp serverless-express API Endpoint TodoList.ts authorization
- CVE-2026-41721 PoCTRENDnet TEW-632BRP HTTP POST Request ping_response.cgi stack-based overflow
- CVE-2026-41731 PoCCodePhiliaX Chat2DB Database Export DMDBManage.java updateProcedure sql injection
- CVE-2026-41741 PoCRadare2 Mach-O File mach0.c walk_exports_trie resource consumption
- CVE-2026-41801 PoCD-Link DIR-816 goahead redirect.asp access control
- CVE-2026-41811 PoCD-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow
- CVE-2026-41821 PoCD-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow
- CVE-2026-41831 PoCD-Link DIR-816 goahead form2WlanBasicSetup.cgi stack-based overflow
- CVE-2026-41841 PoCD-Link DIR-816 goahead form2Wl5BasicSetup.cgi stack-based overflow
- CVE-2026-41851 PoCGPAC MP4Box swf_parse.c swf_def_bits_jpeg stack-based overflow
- CVE-2026-41861 PoCUEditor JSONP Callback controller.php cross site scripting
- CVE-2026-41871 PoCTiandy Easy7 Integrated Management Platform Device Identifier UpdateLocalDevInfo.jsp missing authentication
- CVE-2026-41881 PoCD-Link DIR-619L boa formSchedule stack-based overflow
- CVE-2026-41891 PoCphpipam Section edit-result.php sql injection
- CVE-2026-41901 PoCJawherKl node-api-postgres user.js User.getAll sql injection
- CVE-2026-41911 PoCJawherKl node-api-postgres Profile Picture index.js path.extname unrestricted upload
- CVE-2026-41921 PoCAvinashBole quip-mcp-server index.ts setupToolHandlers command injection
- CVE-2026-41931 PoCD-Link DIR-823G goahead UpdateClientInfo access control
- CVE-2026-41941 PoCD-Link DNS-1550-04 system_mgr.cgi cgi_set_wto access control
- CVE-2026-41951 PoCD-Link DNS-1550-04 wizard_mgr.cgi command injection
- CVE-2026-41961 PoCD-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection
- CVE-2026-41971 PoCD-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection
- CVE-2026-41981 PoChypermodel-labs mcp-server-auto-commit index.ts getGitChanges command injection
- CVE-2026-41991 PoCbazinga012 mcp_code_executor index.ts installDependencies command injection
- CVE-2026-42001 PoCglowxq glowxq-oj ProblemCaseController.java uploadTestcaseZipUrl server-side request forgery
- CVE-2026-42011 PoCglowxq glowxq-oj SysFileController.java upload unrestricted upload
- CVE-2026-42031 PoCD-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection
- CVE-2026-42041 PoCD-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection
- CVE-2026-42051 PoCD-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection
- CVE-2026-42061 PoCD-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection
- CVE-2026-42071 PoCD-Link DNS-1550-04 system_mgr.cgi cgi_ntp_time command injection
- CVE-2026-42091 PoCD-Link DNS-1550-04 account_mgr.cgi cgi_chg_admin_pw command injection
- CVE-2026-42101 PoCD-Link DNS-1550-04 time_machine.cgi cgi_tm_set_share command injection
- CVE-2026-42111 PoCD-Link DNS-1550-04 local_backup_mgr.cgi Local_Backup_Info stack-based overflow
- CVE-2026-42121 PoCD-Link DNS-1550-04 download_mgr.cgi Downloads_Schedule_Info stack-based overflow
- CVE-2026-42131 PoCD-Link DNS-1550-04 gui_mgr.cgi cgi_myfavorite_verify stack-based overflow
- CVE-2026-42141 PoCD-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Setting stack-based overflow
- CVE-2026-42151 PoCFlowCI flow-core-x SMTP Host ConfigServiceImpl.java save server-side request forgery
- CVE-2026-42161 PoCi-SENS SmartLog App air.SmartLog.android hard-coded credentials
- CVE-2026-42171 PoCXREAL Nebula App ai.nreal.nebula.universal CloudStoragePlugin.java credentials storage
- CVE-2026-42181 PoCmyAEDES App aedes.me.beta EngageBayUtils.java information disclosure
- CVE-2026-42191 PoCINDEX Conferences & Exhibitions Organization YWF BPOF APGCS App ae.index.apgcs BuildConfig.java hard-coded credentials
- CVE-2026-42201 PoCTechnologies Integrated Management Platform SetWebpagePic.jsp unrestricted upload
- CVE-2026-42211 PoCTiandy Easy7 Integrated Management Platform Endpoint uploadLedImage unrestricted upload
- CVE-2026-42221 PoCSSCMS download PathUtils.RemoveParentPath path traversal
- CVE-2026-42231 PoCitsourcecode Payroll Management System manage_employee.php sql injection
- CVE-2026-42251 PoCCMS Made Simple User Management listusers.php cross site scripting
- CVE-2026-42261 PoCLB-LINK BL-WR9000 get_virtual_cfg sub_44E8D0 stack-based overflow
- CVE-2026-42271 PoCLB-LINK BL-WR9000 get_hidessid_cfg sub_44D844 buffer overflow
- CVE-2026-42281 PoCLB-LINK BL-WR9000 set_wifi sub_458754 command injection
- CVE-2026-42291 PoCvanna-ai vanna bigquery_vector.py remove_training_data sql injection
- CVE-2026-42301 PoCvanna-ai vanna Endpoint __init__.py update_sql sql injection
- CVE-2026-42311 PoCvanna-ai vanna Endpoint __init__.py run_sql server-side request forgery
- CVE-2026-42321 PoCTiandy Integrated Management Platform getAuthorityByUserId sql injection
- CVE-2026-42331 PoCThingsGateway download path traversal
- CVE-2026-42341 PoCSSCMS DDL SitesAddController.Submit.cs sql injection
- CVE-2026-42351 PoCitsourcecode Online Enrollment System login.php sql injection
- CVE-2026-42361 PoCitsourcecode Online Enrollment System index.php sql injection
- CVE-2026-42371 PoCitsourcecode Free Hotel Reservation System index.php sql injection
- CVE-2026-42381 PoCitsourcecode College Management System courses.php sql injection
- CVE-2026-42391 PoCLagom WHMCS Template Datatables prototype pollution
- CVE-2026-42401 PoCOpen5GS CCA smf_s6b_sta_cb denial of service
- CVE-2026-42411 PoCitsourcecode College Management System time-table.php sql injection
- CVE-2026-42421 PoCBabyChakra Pregnancy & Parenting App app.babychakra.babychakra Configuration.java credentials storage
- CVE-2026-42431 PoCLa Nacion App app.lanacion.activity BuildConfig.java credentials storage
- CVE-2026-42501 PoCAlbert Sağlık Hizmetleri ve Ticaret Albert Health Google Cloud Service Account Key service-account.json credentials storage
- CVE-2026-42511 PoCCityData CityChat ai.citydata.citychat credentials.json credentials storage
- CVE-2026-42521 PoCTenda AC8 IPv6 check_is_ipv6 ip address for authentication
- CVE-2026-42531 PoCTenda AC8 Web UploadCfg route_set_user_policy_rule os command injection
- CVE-2026-42541 PoCTenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow
- CVE-2026-42551 PoCDLL Injection Privilege Escalation
- CVE-2026-42576 PoCsContact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
- CVE-2026-42591 PoCUltimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions
- CVE-2026-42841 PoCtaoofagi easegen-admin PPT File PPTUtil.java downloadFile server-side request forgery
- CVE-2026-42851 PoCtaoofagi easegen-admin Pdf2MdUtil.java recognizeMarkdown path traversal
- CVE-2026-42871 PoCTiandy Easy7 Integrated Management Platform Endpoint queryResources sql injection
- CVE-2026-42881 PoCTiandy Easy7 Integrated Management Platform Endpoint getDevDetailedInfo sql injection
- CVE-2026-42891 PoCTiandy Easy7 Integrated Management Platform getRecByTemplateId sql injection
- CVE-2026-43071 PoCfrdel/agent0ai agent-zero files.py get_abs_path path traversal
- CVE-2026-43081 PoCfrdel/agent0ai agent-zero document_query.py handle_pdf_document server-side request forgery
- CVE-2026-43181 PoCUTT HiPER 810G formApLbConfig strcpy buffer overflow
- CVE-2026-43191 PoCcode-projects Simple Food Order System add-item.php sql injection
- CVE-2026-43321 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-43381 PoCActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure
- CVE-2026-43421 PoCingress-nginx comment-based nginx configuration injection
- CVE-2026-43501 PoCPerfmatters <= 2.5.9.1 - Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter
- CVE-2026-43541 PoCTRENDnet TEW-824DRU Web apply_sec.cgi sub_420A78 cross site scripting
- CVE-2026-43551 PoCPortabilis i-Educar Endpoint educar_servidor_curso_lst.php cross site scripting
- CVE-2026-43561 PoCitsourcecode University Management System add_result.php cross site scripting
- CVE-2026-43571 PoCEmbed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload
- CVE-2026-43701 PoCImproper TLS Client/Server authentication and certificate verification on Database Cluster
- CVE-2026-43751 PoCDoLeads Integrator <= 1.2.2 & wp2epub <= 0.65 - Unauthenticated RCE
- CVE-2026-43901 PoCTeamSpeak 3 Server Connection State Management process_resend_queue use after free
- CVE-2026-43911 PoCTeamSpeak 3 Server ECC Key heap-based overflow
- CVE-2026-43921 PoCTeamSpeak 3 Server clientek Handshake assertion
- CVE-2026-43981 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-44061 PoCGravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter
- CVE-2026-44081 PoCSamba: remote code execution in samr
- CVE-2026-44321 PoCYITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOR
- CVE-2026-44441 PoCStack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit stack corruption…
- CVE-2026-44471 PoCInappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a…
- CVE-2026-44651 PoCD-Link DIR-513 formSysCmd os command injection
- CVE-2026-44661 PoCComfast CF-AC100 mbox-config command injection
- CVE-2026-44671 PoCComfast CF-AC100 mbox-config command injection
- CVE-2026-44681 PoCComfast CF-AC100 mbox-config command injection
- CVE-2026-44691 PoCitsourcecode Online Frozen Foods Ordering System admin_edit_menu_action.php sql injection
- CVE-2026-44701 PoCitsourcecode Online Frozen Foods Ordering System admin_edit_menu.php sql injection
- CVE-2026-44711 PoCitsourcecode Online Frozen Foods Ordering System admin_edit_employee.php sql injection
- CVE-2026-44721 PoCitsourcecode Online Frozen Foods Ordering System admin_edit_supplier.php sql injection
- CVE-2026-44731 PoCitsourcecode Online Doctor Appointment System appointment_action.php sql injection
- CVE-2026-44741 PoCitsourcecode University Management System admin_single_student_update.php cross site scripting
- CVE-2026-44809 PoCsSamba: samba: remote code execution in printing subsystem via unescaped job description
- CVE-2026-44841 PoCMasteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator
- CVE-2026-44851 PoCitsourcecode College Management System search_student.php sql injection
- CVE-2026-44861 PoCD-Link DIR-513 Web Service formEasySetPassword stack-based overflow
- CVE-2026-44871 PoCUTT HiPER 1200GW websHostFilter strcpy buffer overflow
- CVE-2026-44881 PoCUTT HiPER 1250GW setSysAdm strcpy buffer overflow
- CVE-2026-44891 PoCTenda A18 Pro fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow
- CVE-2026-44901 PoCTenda A18 Pro openSchedWifi setSchedWifi stack-based overflow
- CVE-2026-44911 PoCTenda A18 Pro SetIpMacBind fromSetIpMacBind stack-based overflow
- CVE-2026-44921 PoCTenda A18 Pro formSetQosBand set_qosMib_list stack-based overflow
- CVE-2026-44931 PoCTenda A18 Pro MAC Filtering Configuration Endpoint setMacFilterCfg sub_423B50 stack-based overflow
- CVE-2026-44941 PoCatjiu pybbs TopicApiController.java create cross site scripting
- CVE-2026-44951 PoCatjiu pybbs CommentApiController.java create cross site scripting
- CVE-2026-44961 PoCsigmade Git-MCP-Server gitUtils.ts child_process.exec os command injection
- CVE-2026-44971 PoCTotolink WA300 cstecgi.cgi recvUpgradeNewFw os command injection
- CVE-2026-44991 PoCD-Link DIR-820LW SSDP ssdpcgi_main os command injection
- CVE-2026-45001 PoCbagofwords1 bagofwords code_execution.py generate_df injection
- CVE-2026-45041 PoCeosphoros-ai db-gpt Incomplete Fix editor sql injection
- CVE-2026-45051 PoCeosphoros-ai DB-GPT FastAPI Endpoint controller.py module_plugin.refresh_plugins unrestricted upload
- CVE-2026-45061 PoCMindinventory MindSQL mindsql_core.py ask_db code injection
- CVE-2026-45071 PoCMindinventory MindSQL mindsql_core.py ask_db sql injection
- CVE-2026-45081 PoCPbootCMS Member Login MemberController.php checkUsername sql injection
- CVE-2026-45091 PoCPbootCMS File Upload file.php incomplete blacklist
- CVE-2026-45101 PoCPbootCMS Parameter MemberController.php alert_location cross site scripting
- CVE-2026-45111 PoCvanna-ai vanna legacy exec injection
- CVE-2026-45121 PoCWP reCaptcha by WebDesignBy < 2.0 – Admin+ Stored XSS
- CVE-2026-45131 PoCvanna-ai vanna base.py ask sql injection
- CVE-2026-45141 PoCPbootCMS Backend UserController.php access control
- CVE-2026-45151 PoCFoundation Agents MetaGPT operator.py code_generate code injection
- CVE-2026-45161 PoCFoundation Agents MetaGPT DataInterpreter write_analysis_code.py injection
- CVE-2026-45241 PoCAuthentication Bypass Using an Alternate Path or Channel in GitLab
- CVE-2026-45271 PoCCross-Site Request Forgery (CSRF) in GitLab
- CVE-2026-45281 PoCtrueleaf ApiFlow URL Validation http_proxy.service.ts validateUrlSecurity server-side request forgery
- CVE-2026-45291 PoCD-Link DHP-1320 SOAP redirect_count_down_page stack-based overflow
- CVE-2026-45301 PoCapconw Aix-DB terminology_retriever.py sql injection
- CVE-2026-45321 PoCcode-projects Simple Food Ordering System Database Backup food.sql file access
- CVE-2026-45331 PoCcode-projects Simple Food Ordering System all-tickets.php sql injection
- CVE-2026-45341 PoCTenda FH451 WrlExtraSet formWrlExtraSet stack-based overflow
- CVE-2026-45351 PoCTenda FH451 WrlclientSet stack-based overflow
- CVE-2026-45361 PoCAcrel Environmental Monitoring Cloud Platform unrestricted upload
- CVE-2026-45371 PoCCudy TR1200 ipsec.lua action_ipsec_conn command injection
- CVE-2026-45381 PoCPyTorch pt2 Loading deserialization
- CVE-2026-45391 PoCpygments archetype.py AdlLexer redos
- CVE-2026-45401 PoCprojectworlds Online Notes Sharing System Parameters login.php sql injection
- CVE-2026-45411 PoCjanmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification
- CVE-2026-45421 PoCSSCMS layerImage Endpoint LayerImageController.Submit.cs path traversal
- CVE-2026-45431 PoCWavlink WL-WN578W2 POST Request firewall.cgi command injection
- CVE-2026-45441 PoCWavlink WL-WN578W2 POST Request login.cgi cross site scripting
- CVE-2026-45501 PoCcode-projects Simple Gym Management System func.php sql injection
- CVE-2026-45511 PoCTenda F453 Parameters SafeClientFilter fromSafeClientFilter memory corruption
- CVE-2026-45521 PoCTenda F453 Parameters VirtualSer fromVirtualSer memory corruption
- CVE-2026-45531 PoCTenda F453 Parameters Natlimit fromNatlimit stack-based overflow
- CVE-2026-45541 PoCTenda F453 WriteFacMac FormWriteFacMac privilege escalation
- CVE-2026-45551 PoCD-Link DIR-513 boa formEasySetTimezone memory corruption
- CVE-2026-45571 PoCcode-projects Exam Form Submission update_s1.php cross site scripting
- CVE-2026-45581 PoCLinksys MR9600 SmartConnect.lua smartConnectConfigure os command injection
- CVE-2026-45621 PoCMacCMS Timming API Endpoint Timming.php weak authentication
- CVE-2026-45631 PoCMacCMS Member Order Detail User.php order_info authorization
- CVE-2026-45641 PoCyangzongzhuan RuoYi Quartz Job job code injection
- CVE-2026-45651 PoCTenda AC21 SetNetControlList formSetQosBand buffer overflow
- CVE-2026-45661 PoCBelkin F9K1122 formWISP5G stack-based overflow
- CVE-2026-45672 PoCsTenda A15 UploadCfg stack-based overflow
- CVE-2026-45681 PoCSourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql injection
- CVE-2026-45691 PoCSourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection
- CVE-2026-45701 PoCSourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql injection
- CVE-2026-45711 PoCSourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection
- CVE-2026-45721 PoCSourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection
- CVE-2026-45731 PoCSourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injection
- CVE-2026-45741 PoCSourceCodester Simple E-learning System User Profile Update sql injection
- CVE-2026-45751 PoCcode-projects Exam Form Submission update_s2.php cross site scripting
- CVE-2026-45761 PoCcode-projects Exam Form Submission update_s5.php cross site scripting
- CVE-2026-45771 PoCcode-projects Exam Form Submission update_s4.php cross site scripting
- CVE-2026-45781 PoCcode-projects Exam Form Submission update_s3.php cross site scripting
- CVE-2026-45791 PoCcode-projects Simple Laundry System Parameters viewdetail.php sql injection
- CVE-2026-45801 PoCcode-projects Simple Laundry System Parameters checkupdatestatus.php sql injection
- CVE-2026-45811 PoCcode-projects Simple Laundry System Parameters checklogin.php sql injection
- CVE-2026-45821 PoCShenzhen HCC Technology MPOS M6 PLUS Bluetooth missing authentication
- CVE-2026-45831 PoCShenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replay
- CVE-2026-45841 PoCShenzhen HCC Technology MPOS M6 PLUS Cardholder Data cleartext transmission
- CVE-2026-45851 PoCTiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection
- CVE-2026-45861 PoCCodePhiliaX Chat2DB JDBC Driver Upload JdbcDriverController.java upload unrestricted upload
- CVE-2026-45881 PoCkalcaddle kodbox Site-level API key shareOut.class.php shareSafeGroup hard-coded key
- CVE-2026-45891 PoCkalcaddle kodbox fileGet Endpoint editor.class.php PathDriverUrl server-side request forgery
- CVE-2026-45901 PoCkalcaddle kodbox loginSubmit API index.class.php cross-site request forgery
- CVE-2026-45911 PoCkalcaddle kodbox fileThumb Endpoint app.php checkBin os command injection
- CVE-2026-45921 PoCkalcaddle kodbox Password Login index.class.php tfaVerify improper authentication
- CVE-2026-45931 PoCerupts erupt MCP Tool EruptDataQuery.java EruptDataQuery sql injection
- CVE-2026-45941 PoCerupts erupt EruptJpaUtils.java geneEruptHqlOrderBy sql injection
- CVE-2026-45951 PoCcode-projects Exam Form Submission update_s6.php cross site scripting
- CVE-2026-45961 PoCprojectworlds Lawyer Management System lawyers.php cross site scripting
- CVE-2026-45971 PoC648540858 wvp-GB28181-pro Stream Proxy Query StreamProxyProvider.java selectAll sql injection
- CVE-2026-46121 PoCitsourcecode Free Hotel Reservation System Parameter index.php sql injection
- CVE-2026-46131 PoCSourceCodester E-Commerce Site products.php sql injection
- CVE-2026-46141 PoCitsourcecode sanitize or validate this input Parameter subjects.php sql injection
- CVE-2026-46151 PoCSourceCodester Online Catering Reservation search.php sql injection
- CVE-2026-46161 PoCbolo-blog Article Title article cross site scripting
- CVE-2026-46171 PoCSourceCodester Patients Waiting Area Queue Management System Patient Check-In api_patient_checkin.php ValidateToken improper authorization
- CVE-2026-46231 PoCDefaultFuction Jeson-Customer-Relationship-Management-System API Module System.php server-side request forgery
- CVE-2026-46241 PoCSourceCodester Online Library Management System Parameter home.php sql injection
- CVE-2026-46251 PoCSourceCodester Online Admission System programmes.php sql injection
- CVE-2026-46261 PoCprojectworlds Lawyer Management System lawyer_booking.php cross site scripting
- CVE-2026-46314 PoCsCockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
- CVE-2026-46321 PoCitsourcecode Online Enrollment System Parameter index.php sql injection
- CVE-2026-46601 PoCGo-getter may allow to arbitrary filesystem reads through git operations
- CVE-2026-46721 PoCMissing Authorization in GitLab
- CVE-2026-46921 PoCSandbox escape in the Responsive Design Mode component
- CVE-2026-47473 PoCsRemote code execution via RPCSEC_GSS packet validation
- CVE-2026-47771 PoCSourceCodester Sales and Inventory System POST Parameter view_supplier.php sql injection
- CVE-2026-47781 PoCSourceCodester Sales and Inventory System HTTP GET Parameter update_category.php sql injection
- CVE-2026-47791 PoCSourceCodester Sales and Inventory System HTTP GET Parameter update_customer_details.php sql injection
- CVE-2026-47801 PoCSourceCodester Sales and Inventory System HTTP GET Parameter update_out_standing.php sql injection
- CVE-2026-47811 PoCSourceCodester Sales and Inventory System HTTP GET Parameter update_purchase.php sql injection
- CVE-2026-47822 PoCsAvada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter
- CVE-2026-47831 PoCitsourcecode College Management System Parameter add-single-student-results.php sql injection
- CVE-2026-47841 PoCcode-projects Simple Laundry System Parameter checkcheckout.php sql injection
- CVE-2026-47981 PoCAvada Builder <= 3.15.1 - Unauthenticated SQL Injection via 'product_order' Parameter
- CVE-2026-48002 PoCslodash vulnerable to Code Injection via `_.template` imports key names
- CVE-2026-48021 PoCCockpit: cockpit: arbitrary command execution via crafted links in system logs ui
- CVE-2026-48101 PoCRemote Code Execution in Google Agent Development Kit (ADK)
- CVE-2026-48121 PoCAdvanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query…
- CVE-2026-48131 PoCCode injection in the Lutece Core
- CVE-2026-48221 PoCEnter Software Iperius Backup Backup Service temp file
- CVE-2026-48231 PoCEnter Software Iperius Backup NTLM2 information disclosure
- CVE-2026-48241 PoCEnter Software Iperius Backup Backup Job Configuration File privileges management
- CVE-2026-48251 PoCSourceCodester Sales and Inventory System HTTP GET Parameter update_sales.php sql injection
- CVE-2026-48261 PoCSourceCodester Sales and Inventory System HTTP GET Parameter update_stock.php sql injection
- CVE-2026-48301 PoCkalcaddle kodbox Public Share userShare.class.php add privilege escalation
- CVE-2026-48311 PoCkalcaddle kodbox Password-protected Share auth.class.php can improper authentication
- CVE-2026-48331 PoCOrc discount Markdown markdown.c compile recursion
- CVE-2026-48351 PoCcode-projects Accounting System Web Application add_costumer.php cross site scripting
- CVE-2026-48361 PoCcode-projects Accounting System delete.php sql injection
- CVE-2026-48381 PoCSourceCodester Malawi Online Market display.php sql injection
- CVE-2026-48391 PoCSourceCodester Food Ordering System Parameter purchase.php sql injection
- CVE-2026-48401 PoCNetcore Power 15AX Diagnostic Tool netis.cgi setTools os command injection
- CVE-2026-48411 PoCcode-projects Online Food Ordering System Shopping Cart cart.php sql injection
- CVE-2026-48421 PoCitsourcecode Online Enrollment System Parameter index.php sql injection
- CVE-2026-48441 PoCcode-projects Online Food Ordering System Admin Login admin.php sql injection
- CVE-2026-48451 PoCdameng100 muucmf index.html cross site scripting
- CVE-2026-48461 PoCdameng100 muucmf autoReply.html cross site scripting
- CVE-2026-48471 PoCdameng100 muucmf list.html cross site scripting
- CVE-2026-48481 PoCdameng100 muucmf list.html cross site scripting
- CVE-2026-48491 PoCcode-projects Simple Laundry System Parameter modify.php cross site scripting
- CVE-2026-48501 PoCcode-projects Simple Laundry System Parameter checkregisitem.php sql injection
- CVE-2026-48601 PoC648540858 wvp-GB28181-pro API Endpoint RedisTemplateConfig.java GenericFastJsonRedisSerializer deserialization
- CVE-2026-48612 PoCsWavlink WL-NU516U1 nas.cgi ftext stack-based overflow
- CVE-2026-48621 PoCUTT HiPER 1250GW Parameter formConfigDnsFilterGlobal strcpy buffer overflow
- CVE-2026-48681 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-48751 PoCitsourcecode Free Hotel Reservation System index.php unrestricted upload
- CVE-2026-48761 PoCitsourcecode Free Hotel Reservation System index.php sql injection
- CVE-2026-48771 PoCitsourcecode Payroll Management System index.php cross site scripting
- CVE-2026-48791 PoCMissing Authorization in GitLab
- CVE-2026-48821 PoCUser Registration Advanced Fields <= 1.6.20 - Unauthenticated Arbitrary File Upload
- CVE-2026-48852 PoCsPiotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload
- CVE-2026-48921 PoCCVE-2026-4892
- CVE-2026-48931 PoCCVE-2026-4893
- CVE-2026-48981 PoCcode-projects Online Food Ordering System contact.php cross site scripting
- CVE-2026-48991 PoCcode-projects Online Food Ordering System food.php cross site scripting
- CVE-2026-49001 PoCcode-projects Online Food Ordering System localhost.sql privilege escalation
- CVE-2026-49021 PoCTenda AC5 POST Request addressNat fromAddressNat memory corruption
- CVE-2026-49031 PoCTenda AC5 POST Request QuickIndex formQuickIndex memory corruption
- CVE-2026-49041 PoCTenda AC5 POST Request setcfm formSetCfm stack-based overflow
- CVE-2026-49051 PoCTenda AC5 POST Request WifiWpsOOB formWifiWpsOOB stack-based overflow
- CVE-2026-49061 PoCTenda AC5 POST Request WizardHandle decodePwd stack-based overflow
- CVE-2026-49071 PoCPage-Replica Page Replica Endpoint sitemap sitemap.fetch server-side request forgery
- CVE-2026-49081 PoCcode-projects Simple Laundry System Parameter modstaffinfo.php sql injection
- CVE-2026-49091 PoCcode-projects Exam Form Submission update_s7.php cross site scripting
- CVE-2026-49101 PoCShenzhen Ruiming Technology Streamax Crocus Endpoint RemoteFormat.do sql injection
- CVE-2026-49161 PoCMissing Authorization in GitLab
- CVE-2026-49221 PoCCross-Site Request Forgery (CSRF) in GitLab
- CVE-2026-49351 PoCSureTriggers < 1.1.23 – Unauthenticated SQLi
- CVE-2026-49461 PoCNSA Ghidra Auto-Analysis Annotation Command Execution
- CVE-2026-49531 PoCmingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery
- CVE-2026-49541 PoCmingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection
- CVE-2026-49551 PoCShenzhen Ruiming Technology Streamax Crocus OperateStatistic.do sql injection
- CVE-2026-49561 PoCShenzhen Ruiming Technology Streamax Crocus Parameter DevicePrint.do sql injection
- CVE-2026-49571 PoCOpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file
- CVE-2026-49581 PoCOpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization
- CVE-2026-49591 PoCOpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication
- CVE-2026-49601 PoCTenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow
- CVE-2026-49611 PoCTenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow
- CVE-2026-49621 PoCUltraVNC Service version.dll uncontrolled search path
- CVE-2026-49631 PoChuggingface smolagents Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_with code injection
- CVE-2026-49641 PoCletta-ai letta File URL message_helper.py _convert_message_create_to_message server-side request forgery
- CVE-2026-49651 PoCletta-ai letta Incomplete Fix CVE-2025-6101 ast_parsers.py resolve_type eval injection
- CVE-2026-49661 PoCitsourcecode Free Hotel Reservation System index.php sql injection
- CVE-2026-49681 PoCSourceCodester Diary App diary.php cross-site request forgery
- CVE-2026-49691 PoCcode-projects Social Networking Site Alert home.php cross site scripting
- CVE-2026-49701 PoCcode-projects Social Networking Site Endpoint delete_photos.php sql injection
- CVE-2026-49711 PoCSourceCodester Note Taking App cross-site request forgery
- CVE-2026-49721 PoCcode-projects Online Reviewer System btn_functions.php cross site scripting
- CVE-2026-49731 PoCSourceCodester Online Quiz System add-question.php cross site scripting
- CVE-2026-49741 PoCTenda AC7 POST Request SetSysTimeCfg fromSetSysTime memory corruption
- CVE-2026-49751 PoCTenda AC15 POST Request setcfm formSetCfm memory corruption
- CVE-2026-49761 PoCTotolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
- CVE-2026-49861 PoCWPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery
- CVE-2026-49871 PoCSureForms <= 2.5.2 - Unauthenticated Payment Amount Validation Bypass via 'form_id'
- CVE-2026-49881 PoCOpen5GS CCA Message smf_s6b denial of service
- CVE-2026-49921 PoCwandb OpenUI HTMLAnnotator server.py get_share HTML injection
- CVE-2026-49931 PoCwandb OpenUI config.py hard-coded credentials
- CVE-2026-49941 PoCwandb OpenUI APIStatusError server.py generic_exception_handler information exposure
- CVE-2026-49951 PoCwandb OpenUI Window Message Event index.html cross site scripting
- CVE-2026-49961 PoCSinaptik AI PandasAI pandasai-lancedb Extension lancedb.py get_relevant_docs_by_id sql injection
- CVE-2026-49971 PoCSinaptik AI PandasAI sql_sanitizer.py is_sql_query_safe path traversal
- CVE-2026-49981 PoCSinaptik AI PandasAI Chat Message code_executor.py CodeExecutor.execute code injection
- CVE-2026-49991 PoCz-9527 admin isImg Check upload.js uploadFile path traversal