CVE-2026-58000 to CVE-2026-58999
80 CVEs with public proof-of-concept exploits.
- CVE-2026-580251 PoCRemote Code Execution via Unsafe Deserialization in LogItem Import
- CVE-2026-580482 PoCsImproper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
- CVE-2026-580491 PoCFFmpeg - Out-of-Bounds Write in RASC Decoder decode_dlta()
- CVE-2026-580501 PoClibssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
- CVE-2026-580511 PoClibssh2 - Free of Uninitialized Pointer in publickey List Cleanup
- CVE-2026-580521 PoC7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
- CVE-2026-580531 PoCGitea act_runner - Container Hardening Bypass via Workflow Container Options
- CVE-2026-580551 PoCnghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
- CVE-2026-580561 PoCRustDesk - FileTransfer Session Authorization Scope Bypass
- CVE-2026-580573 PoCsFlowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
- CVE-2026-580582 PoCsNmap - Integer Underflow in IPv6 Extension Header Parsing
- CVE-2026-581162 PoCsLLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
- CVE-2026-581261 PoCPACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service
- CVE-2026-581271 PoCPACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service
- CVE-2026-581387 PoCsOrkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
- CVE-2026-581431 PoCCotonti Siena 0.9.26 CSRF via admin.php Config Update Endpoint
- CVE-2026-581441 PoCCotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter
- CVE-2026-581651 PoCOpenZiti - Privilege Escalation to Admin via Unauthorized Enrollment Creation
- CVE-2026-581661 PoCOpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete
- CVE-2026-581721 PoCOcelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests
- CVE-2026-581761 PoCRuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints
- CVE-2026-581911 PoCAppium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
- CVE-2026-582631 PoCJodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
- CVE-2026-582891 PoCMicrosoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-583711 PoCSeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP callback Parameter
- CVE-2026-583721 PoCSeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
- CVE-2026-583751 PoCJimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export
- CVE-2026-583761 PoCDolibarr - SQL Injection via sqlfilters Parameter in Multiple REST API List Endpoints
- CVE-2026-583771 PoCJeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys
- CVE-2026-584171 PoCREST API exposes organization membership of private organizations to public
- CVE-2026-584191 PoCNotification API leaks private issue metadata after access revocation
- CVE-2026-584201 PoCLocal File Inclusion via file:// URI in Migration Restore
- CVE-2026-584211 PoCUnauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
- CVE-2026-584231 PoCLFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
- CVE-2026-584241 PoCPermanent Fork PR Workflow Approval Gate Bypass
- CVE-2026-584261 PoCGitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
- CVE-2026-584281 PoCRelease attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- CVE-2026-584291 PoCPublic-Only Personal access tokens scope bypass in Organization and Permission Endpoints
- CVE-2026-584321 PoCMissing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and…
- CVE-2026-584341 PoCPrivate Repository Metadata Remains Accessible After Access Revocation
- CVE-2026-584351 PoCGitea LFS Deploy-Key Privilege Escalation
- CVE-2026-584361 PoCParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
- CVE-2026-584381 PoCCross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
- CVE-2026-584401 PoCWebhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content…
- CVE-2026-584411 PoCSSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
- CVE-2026-584421 PoCRepository migration SSRF via multi-answer DNS allow-list bypass
- CVE-2026-584441 PoCPersonal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
- CVE-2026-584451 PoCCross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
- CVE-2026-584461 PoCPresenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotected MCP Endpoint
- CVE-2026-584471 PoCInvidious - Cross-User Playlist Video Deletion via Missing Ownership Check
- CVE-2026-584481 PoCyudao-cloud < 2026.06 - BPM Module Broken Access Control via process-instance API
- CVE-2026-584501 PoCInvoice Ninja 5.13.26 - Open Redirect in Client Portal Login via intended Parameter
- CVE-2026-584511 PoCHorde IMP < 7.0.1 Path Traversal via Compose.php img src
- CVE-2026-584521 PoCJAIOTlink C492A-W6 4.8.30.57701411 OS Command Injection via SetMAC Endpoint
- CVE-2026-584531 PoCJAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc
- CVE-2026-584541 PoCJAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint
- CVE-2026-584552 PoCsDockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
- CVE-2026-584572 PoCsShenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
- CVE-2026-584601 PoCreact-native-receive-sharing-intent Path Traversal via _display_name
- CVE-2026-584671 PoCCockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php
- CVE-2026-584681 PoCNocoBase 2.1.20 Server-Side Request Forgery via serverRequest wrapper
- CVE-2026-584731 PoCCognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings
- CVE-2026-584751 PoCSustainable Irrigation Platform 5.2.16 Stored XSS via Program Name
- CVE-2026-584761 PoCSustainable Irrigation Platform 5.2.16 CSRF via Administrative GET Requests
- CVE-2026-584771 PoCSustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters
- CVE-2026-584781 PoCSustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL
- CVE-2026-584791 PoCSustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection
- CVE-2026-584802 PoCsBlocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
- CVE-2026-585071 PoCPrivate Repository Existence Disclosure via go-get Meta Endpoint
- CVE-2026-585101 PoCGHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2026-585781 PoCLobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub Skill Import
- CVE-2026-585791 PoCRAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name
- CVE-2026-585831 PoCFluxInk Color Management Driver local privilege escalation
- CVE-2026-585921 PoCLadybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM Integration
- CVE-2026-585931 PoCNodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User
- CVE-2026-586351 PoCWindows Narrator Braille Elevation of Privilege Vulnerability
- CVE-2026-586441 PoCKEVMicrosoft SharePoint Remote Code Execution Vulnerability
- CVE-2026-586581 PoCGPUStack Unauthenticated Information Disclosure via Worker Endpoints
- CVE-2026-586591 PoCPyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter
- CVE-2026-586601 PoCKanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop