CVE-2026-57000 to CVE-2026-57999
20 CVEs with public proof-of-concept exploits.
- CVE-2026-572191 PoCRabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
- CVE-2026-572391 PoCFoxit PDF Editor/Reader Local Privilege Escalation
- CVE-2026-575173 PoCsControl Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
- CVE-2026-575181 PoCPagekit CMS 1.0.18 Privilege Escalation via UserApiController
- CVE-2026-575201 PoCBitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint
- CVE-2026-575211 PoCBitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController
- CVE-2026-575221 PoCBitwarden Server < 2026.5.0 JSON Injection via Webhook Templates
- CVE-2026-575841 PoCPhalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS
- CVE-2026-575882 PoCsSQL Injection in Nessus via Malicious Scan Result File Import
- CVE-2026-578212 PoCsApache Fineract: Office list: SQL Injection via Subquery in orderBy
- CVE-2026-578276 PoCsJoomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
- CVE-2026-578291 PoCJoomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7
- CVE-2026-578301 PoCJoomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7
- CVE-2026-578501 PoCRustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
- CVE-2026-578511 PoCMSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
- CVE-2026-578581 PoCCal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID
- CVE-2026-578631 PoCCrater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint
- CVE-2026-578861 PoCCross-repository issue/comment attachment re-linking can expose private attachment content
- CVE-2026-579511 PoCMythic < 3.4.0.60 - Broken Permission Filter in payload_build_step Table
- CVE-2026-579521 PoCMythic < 3.4.0.60 - Unauthorized C2 Profile Configuration Access via Unverified Payload UUID