CVE-2026-55000 to CVE-2026-55999
145 CVEs with public proof-of-concept exploits.
- CVE-2026-550406 PoCsKEVMicrosoft SharePoint Server Security Feature Bypass Vulnerability
- CVE-2026-550641 PoCVikunja incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
- CVE-2026-550651 PoCVikunja: Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api
- CVE-2026-550671 PoCVikunja: Authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
- CVE-2026-550681 PoCfree5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
- CVE-2026-550861 PoCEtherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
- CVE-2026-550872 PoCsEtherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)
- CVE-2026-551081 PoCKubeVela Terraform remote loader DoS via unbounded file read
- CVE-2026-551621 PoCLemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and OCSP URLs in uploaded certificates
- CVE-2026-551631 PoCLemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite role membership
- CVE-2026-551651 PoCLemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosure
- CVE-2026-551661 PoCLemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR
- CVE-2026-551681 PoCRuntipi: Authenticated arbitrary file write via backup restore symlink planting
- CVE-2026-551801 PoCpnpm: Repository config can expand victim environment secrets into registry requests before scripts run
- CVE-2026-551821 PoCLibreNMS: Remote Code Execution by Signal Alert Transportation Module
- CVE-2026-551951 PoCpy7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
- CVE-2026-5520011 PoCslibssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
- CVE-2026-552081 PoCPimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password…
- CVE-2026-552121 PoCPimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
- CVE-2026-552201 PoCPimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column
- CVE-2026-552292 PoCsGotenberg: SSRF via LibreOffice document processing
- CVE-2026-552451 PoCBifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
- CVE-2026-552551 PoCKEVLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
- CVE-2026-553791 PoCPillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
- CVE-2026-553801 PoCPillow GdImageFile decompression bomb protection bypass
- CVE-2026-553881 PoCpiscina: Prototype Pollution Gadget → RCE via inherited options.filename
- CVE-2026-553891 PoCdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing…
- CVE-2026-553901 PoCArbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
- CVE-2026-554101 PoCNocoBase backup restore schema name allows command injection
- CVE-2026-554151 PoCdatamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
- CVE-2026-554191 PoCReachy Mini: Unrestricted Upload of File with Dangerous Type
- CVE-2026-554261 PoClinuxfabrik-lib: Local privilege escalation using embedded command
- CVE-2026-554411 PoCmise: Arbitrary command execution via task-include files in an untrusted, config-less repository
- CVE-2026-554451 PoCQinglong: Incomplete fix for CVE-2026-3965: Improper Authentication
- CVE-2026-554461 PoCLangflow: Unauthenticated DoS through multipart form boundary file upload
- CVE-2026-554471 PoCLangflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
- CVE-2026-554481 PoCmise: Local credential_command executes untrusted config
- CVE-2026-554503 PoCsLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
- CVE-2026-554601 PoCSnipe-IT: Authorization bypass on bulk editing users
- CVE-2026-554621 PoCSnipe-IT: Authorization bypass on print inventory page
- CVE-2026-554661 PoCSnipe-IT: Stored XSS via inline-served attachment
- CVE-2026-554701 PoCHAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
- CVE-2026-554711 PoCHAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
- CVE-2026-554841 PoCALOS HTTP: Unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing…
- CVE-2026-554851 PoCPiccolo Admin: Privilege escalation - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
- CVE-2026-554871 PoCpnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
- CVE-2026-554881 PoCmotionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
- CVE-2026-554951 PoCCloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
- CVE-2026-554961 PoCCloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate
- CVE-2026-554971 PoCCloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)
- CVE-2026-554991 PoCCloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipients
- CVE-2026-555001 PoC9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover
- CVE-2026-555011 PoC9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
- CVE-2026-555021 PoCCloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials
- CVE-2026-555091 PoCWsgiDAV: Blind SQL injection in the MySQL provider
- CVE-2026-555111 PoCYamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
- CVE-2026-555151 PoCSnipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint
- CVE-2026-555181 PoCAvo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
- CVE-2026-555211 PoCYamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API
- CVE-2026-555221 PoCPraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
- CVE-2026-555251 PoCPraisonAI: SSRF via redirect-following in praisonaiagents web_crawl
- CVE-2026-555261 PoCPraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
- CVE-2026-555271 PoCPraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
- CVE-2026-555281 PoCpraisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862)
- CVE-2026-555291 PoCPraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP server
- CVE-2026-555301 PoCPraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
- CVE-2026-555311 PoCPraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced)
- CVE-2026-555321 PoCPraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP…
- CVE-2026-555331 PoCPraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
- CVE-2026-555341 PoCPraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
- CVE-2026-555351 PoCPraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
- CVE-2026-555361 PoCBrowser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
- CVE-2026-555371 PoCPraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
- CVE-2026-555381 PoCPraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST…
- CVE-2026-555391 PoCPraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft,…
- CVE-2026-555401 PoCPraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
- CVE-2026-555411 PoCPraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
- CVE-2026-555461 PoCQWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
- CVE-2026-555481 PoCYamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
- CVE-2026-555491 PoCYamcs: Reflected XSS in the URL of the Authorize Endpoint
- CVE-2026-555521 PoCYamcs: Unauthenticated Directory Traversal
- CVE-2026-555531 PoCurllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
- CVE-2026-555541 PoCDompdf: Chroot Validation Bypass
- CVE-2026-555591 PoCYamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)
- CVE-2026-555651 PoCYamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
- CVE-2026-555661 PoCYamcs: DOM XSS in Extension Routing
- CVE-2026-555691 PoCaqua: Archive extraction in aqua follows attacker-planted symlinks, allowing writes outside the install directory
- CVE-2026-555751 PoCLiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
- CVE-2026-555781 PoCPheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
- CVE-2026-555792 PoCsPheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
- CVE-2026-555801 PoCmcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
- CVE-2026-555811 PoCmcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
- CVE-2026-555821 PoCmcp-shell: Secure Mode Allowlist Bypass via Git Shell Alias
- CVE-2026-555843 PoCsphpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
- CVE-2026-555851 PoCQWED: Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
- CVE-2026-555881 PoCORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
- CVE-2026-555921 PoCDashy: XSS in workspace url parameter
- CVE-2026-555931 PoCFroxlor: CSRF Vulnerability in Froxlor AJAX Endpoint — Missing Cross-Site Request Forgery Protection
- CVE-2026-555961 PoCPlate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
- CVE-2026-555991 PoCphpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority…
- CVE-2026-556021 PoChttp-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
- CVE-2026-556031 PoChttp-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
- CVE-2026-556041 PoC@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
- CVE-2026-556051 PoC@arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP Endpoint
- CVE-2026-556151 PoCLangroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring…
- CVE-2026-556211 PoCIncus has a project restriction bypass for custom volume copy across projects
- CVE-2026-556221 PoCIncus has a project restriction bypass in instance copy across projects
- CVE-2026-556291 PoCWhistle: Path traversal
- CVE-2026-556341 PoCPimcore: Remote Code Execution via DataObject Class-Definition Field Name
- CVE-2026-556371 PoCgenieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
- CVE-2026-556401 PoCNextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset (…
- CVE-2026-556411 PoC9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
- CVE-2026-556511 PoCEasy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
- CVE-2026-556631 PoCmediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
- CVE-2026-556671 PoCFile Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
- CVE-2026-556681 PoCFile Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
- CVE-2026-556781 PoCArc: Unauthenticated cluster node admission when `cluster.shared_secret` is unset
- CVE-2026-556861 PoCPodman: WORKDIR symlink traversal vulnerability
- CVE-2026-556941 PoCSnipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover
- CVE-2026-556961 PoCPrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required…
- CVE-2026-556971 PoCpnpm: Repository-controlled configDependencies can select a pacquet native install engine
- CVE-2026-556981 PoCpnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
- CVE-2026-556991 PoCpnpm: reserved bin name deletes PNPM_HOME during global remove
- CVE-2026-557031 PoCSnipe-IT: Maintenance Record Disclosure via Missing Authorization on GET
- CVE-2026-557061 PoCsppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.
- CVE-2026-557261 PoCGardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
- CVE-2026-557631 PoCKlever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits
- CVE-2026-557641 PoCKlever-Go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
- CVE-2026-557801 PoCNanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
- CVE-2026-557901 PoCCraft CMS: DOM XSS via GitHub issue title in CraftSupport widget
- CVE-2026-557931 PoCCraft CMS: Stored XSS via Structure entry title in table view
- CVE-2026-558301 PoCRestrictedPython guard hooks can be shadowed via positional-only arguments
- CVE-2026-558311 PoCNetty SPDY SETTINGS frame count materializes unbounded settings map
- CVE-2026-558331 PoCNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
- CVE-2026-558341 PoCPocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
- CVE-2026-558391 PoCKestra: Stored XSS via custom Markdown [[link]] attribute injection
- CVE-2026-558481 PoCmapfish-print: XXE on MapFish Print allows reading arbitrary files of certain types
- CVE-2026-558851 PoCGrav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
- CVE-2026-558901 PoCGrav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()
- CVE-2026-559571 PoCApache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
- CVE-2026-559821 PoCOIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
- CVE-2026-559841 PoCNull Pointer Dereference in AddTime API Causes Authenticated Denial of Service
- CVE-2026-559871 PoCOAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
- CVE-2026-559931 PoCApache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a…
- CVE-2026-559941 PoCApache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a…