CVE-2026-53000 to CVE-2026-53999
52 CVEs with public proof-of-concept exploits.
- CVE-2026-530751 PoCppp: require CAP_NET_ADMIN in target netns for unattached ioctls
- CVE-2026-531638 PoCslocking/rtmutex: Skip remove_waiter() when waiter is not enqueued
- CVE-2026-532641 PoCnet/sched: act_api: use RCU with deferred freeing for action lifecycle
- CVE-2026-533595 PoCsKVM: x86: Fix shadow paging use-after-free due to unexpected role
- CVE-2026-533601 PoCKVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
- CVE-2026-533611 PoCaf_unix: Set gc_in_progress to true in unix_gc().
- CVE-2026-533652 PoCsvsock/virtio: fix zerocopy completion for multi-skb sends
- CVE-2026-534131 PoCZoom Clients - Buffer Over-write
- CVE-2026-534351 PoCIn Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in…
- CVE-2026-534871 PoCKite has an authenticated cluster RBAC bypass in /api/v1/overview
- CVE-2026-535193 PoCsNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
- CVE-2026-535201 PoCNezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
- CVE-2026-535301 PoCratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
- CVE-2026-535311 PoCratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
- CVE-2026-535411 PoCOliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering
- CVE-2026-535501 PoCjs-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases
- CVE-2026-535511 PoCfree5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
- CVE-2026-535521 PoCGoploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
- CVE-2026-535531 PoCGoploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise
- CVE-2026-535711 PoCVite: `server.fs.deny` bypass on Windows alternate paths
- CVE-2026-535721 PoCKEDA: PostgreSQL connection string parameter injection via incomplete whitespace escaping
- CVE-2026-535762 PoCsKestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
- CVE-2026-535871 PoClibgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data
- CVE-2026-535951 PoCFreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
- CVE-2026-536001 PoCasync-tar PAX extension-header desync enables tar entry/content smuggling
- CVE-2026-536061 PoCsanitize-html has an incomplete URI scheme validation that allows javascript: URIs through action, formaction, data, poster, and…
- CVE-2026-536071 PoC@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header
- CVE-2026-536221 PoCTraefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
- CVE-2026-536241 PoCFiber: HSTS header never set in helmet middleware due to incorrect protocol check
- CVE-2026-536321 PoCNTLMv2 hash disclosure via UNC path handling on Windows
- CVE-2026-536331 PoCVitest: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
- CVE-2026-536461 PoCFOSSBilling: Client password reset token reuse allows persistent account takeover
- CVE-2026-536471 PoCFOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint
- CVE-2026-536531 PoCGrav: Unauthenticated denial of service via unbounded image derivative dimensions
- CVE-2026-536551 PoCnode-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file…
- CVE-2026-536941 PoCPotential local privileges escalation through argument injection in the nxchmod.sh script
- CVE-2026-537271 PoCcss_parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
- CVE-2026-537533 PoCsCrawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
- CVE-2026-537551 PoCCrawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
- CVE-2026-537591 PoClinuxfabrik-lib: Insecure creation of SQLite databases
- CVE-2026-537651 PoCchrome-devtools-mcp: daemon.pid write follows symlinks in /tmp fallback runtime directory
- CVE-2026-537661 PoCchrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
- CVE-2026-537872 PoCsAmasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload
- CVE-2026-538041 PoCOTRS Community Edition OS Command Injection via PGP Configuration
- CVE-2026-538051 PoCNVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API
- CVE-2026-538751 PoCpicklescan - Scanning Bypass via Dynamic Eval in scan_pytorch
- CVE-2026-539131 PoCApache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the…
- CVE-2026-539251 PoCGlances: Arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
- CVE-2026-539511 PoCCopier: trust-prefix bypass via path traversal runs tasks unprompted
- CVE-2026-539591 PoC4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user
- CVE-2026-539651 PoCMCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial of service
- CVE-2026-539761 PoCOpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter