CVE-2026-5000 to CVE-2026-5999
382 CVEs with public proof-of-concept exploits.
- CVE-2026-50001 PoCPromtEngineer localGPT API Endpoint server.py LocalGPTHandler missing authentication
- CVE-2026-50011 PoCPromtEngineer localGPT server.py do_POST unrestricted upload
- CVE-2026-50021 PoCPromtEngineer localGPT LLM Prompt server.py _route_using_overviews injection
- CVE-2026-50031 PoCPromtEngineer localGPT Web api_server.py handle_index information disclosure
- CVE-2026-50041 PoCWavlink WL-WN579X3-C UPNP firewall.cgi sub_4019FC stack-based overflow
- CVE-2026-50061 PoCVault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
- CVE-2026-50071 PoCkazuph mcp-docs-rag add_git_repository/add_text_file index.ts cloneRepository os command injection
- CVE-2026-50111 PoCelecV2 elecV2P JSON webhook runJSFile code injection
- CVE-2026-50121 PoCelecV2 elecV2P rpc pm2run os command injection
- CVE-2026-50131 PoCelecV2 elecV2P :key path.join path traversal
- CVE-2026-50141 PoCelecV2 elecV2P Wildcard log path.join path traversal
- CVE-2026-50151 PoCelecV2 elecV2P Endpoint logs cross site scripting
- CVE-2026-50161 PoCelecV2 elecV2P URL mock eAxios server-side request forgery
- CVE-2026-50171 PoCcode-projects Simple Food Order System Parameter all-tickets.php sql injection
- CVE-2026-50181 PoCcode-projects Simple Food Order System Parameter register-router.php sql injection
- CVE-2026-50191 PoCcode-projects Simple Food Order System Parameter all-orders.php sql injection
- CVE-2026-50201 PoCTotolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection
- CVE-2026-50211 PoCTenda F453 httpd PPTPUserSetting fromPPTPUserSetting stack-based overflow
- CVE-2026-50231 PoCDeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injection
- CVE-2026-50241 PoCD-Link DIR-513 formSetEmail stack-based overflow
- CVE-2026-50279 PoCsLangflow - Path Traversal Arbitrary File Write via upload_user_file
- CVE-2026-50291 PoCRCE in Code Runner MCP Server
- CVE-2026-50301 PoCTotolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection
- CVE-2026-50311 PoCBichitroGan ISP Billing Software Endpoint users-view resource injection
- CVE-2026-50321 PoCW3 Total Cache <= 2.9.3 - Unauthenticated Security Token Exposure via User-Agent Header
- CVE-2026-50331 PoCcode-projects Accounting System Parameter view_costumer.php sql injection
- CVE-2026-50341 PoCcode-projects Accounting System Parameter edit_costumer.php sql injection
- CVE-2026-50351 PoCcode-projects Accounting System Parameter view_work.php sql injection
- CVE-2026-50361 PoCTenda 4G06 Endpoint DhcpListClient fromDhcpListClient stack-based overflow
- CVE-2026-50371 PoCmxml mxmlIndexNew mxml-index.c index_sort stack-based overflow
- CVE-2026-50411 PoCcode-projects Chamber of Commerce Membership Management System pageMail.php fwrite command injection
- CVE-2026-50421 PoCBelkin F9K1122 Parameter formCrossBandSwitch stack-based overflow
- CVE-2026-50431 PoCBelkin F9K1122 Parameter formSetPassword stack-based overflow
- CVE-2026-50441 PoCBelkin F9K1122 Setting formSetSystemSettings stack-based overflow
- CVE-2026-50451 PoCTenda FH1201 Parameter WrlclientSet stack-based overflow
- CVE-2026-50461 PoCTenda FH1201 Parameter WrlExtraSet formWrlExtraSet stack-based overflow
- CVE-2026-50501 PoCPayment Gateway for Redsys & WooCommerce Lite <= 7.0.0 - Improper Verification of Cryptographic Signature to Unauthenticated Payment…
- CVE-2026-50591 PoCaws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability
- CVE-2026-50611 PoCConsul-template vulnerable to sandbox path bypass in file helper via a symlink attack
- CVE-2026-50731 PoCARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter
- CVE-2026-50762 PoCsARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
- CVE-2026-51011 PoCTotolink A3300R Parameter cstecgi.cgi setLanCfg command injection
- CVE-2026-51021 PoCTotolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection
- CVE-2026-51031 PoCTotolink A3300R cstecgi.cgi setUPnPCfg command injection
- CVE-2026-51041 PoCTotolink A3300R cstecgi.cgi setStaticRoute command injection
- CVE-2026-51051 PoCTotolink A3300R Parameter cstecgi.cgi setVpnPassCfg command injection
- CVE-2026-51061 PoCcode-projects Exam Form Submission update_fst.php cross site scripting
- CVE-2026-51184 PoCsDivi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
- CVE-2026-51251 PoCraine consult-llm-mcp server.ts child_process.execSync os command injection
- CVE-2026-51261 PoCSourceCodester RSS Feed Parser file_get_contents server-side request forgery
- CVE-2026-51472 PoCsYunaiV yudao-cloud get-by-website sql injection
- CVE-2026-51481 PoCYunaiV yudao-cloud page sql injection
- CVE-2026-51501 PoCcode-projects Accounting System Parameter viewin_costumer.php sql injection
- CVE-2026-51521 PoCTenda CH22 createFileName formCreateFileName stack-based overflow
- CVE-2026-51531 PoCTenda CH22 WriteFacMac FormWriteFacMac command injection
- CVE-2026-51541 PoCTenda CH22 Parameter setcfm fromSetCfm stack-based overflow
- CVE-2026-51551 PoCTenda CH22 Parameter AdvSetWan fromAdvSetWan stack-based overflow
- CVE-2026-51561 PoCTenda CH22 Parameter QuickIndex formQuickIndex stack-based overflow
- CVE-2026-51571 PoCcode-projects Online Food Ordering System Order order.php cross site scripting
- CVE-2026-51731 PoCExposed Dangerous Method or Function in GitLab
- CVE-2026-51761 PoCTotolink A3300R cstecgi.cgi setSyslogCfg command injection
- CVE-2026-51771 PoCTotolink A3300R cstecgi.cgi setWiFiBasicCfg command injection
- CVE-2026-51781 PoCTotolink A3300R cstecgi.cgi setIptvCfg command injection
- CVE-2026-51791 PoCSourceCodester Simple Doctors Appointment System login.php sql injection
- CVE-2026-51801 PoCSourceCodester Simple Doctors Appointment System ajax.php sql injection
- CVE-2026-51811 PoCSourceCodester Simple Doctors Appointment System ajax.php unrestricted upload
- CVE-2026-51821 PoCSourceCodester Teacher Record System Parameter sql injection
- CVE-2026-51831 PoCTRENDnet TEW-713RE addRouting sub_421494 command injection
- CVE-2026-51841 PoCTRENDnet TEW-713RE setSysAdm command injection
- CVE-2026-51961 PoCcode-projects Student Membership System delete_member.php sql injection
- CVE-2026-51971 PoCcode-projects Student Membership System delete_user.php sql injection
- CVE-2026-51981 PoCcode-projects Student Membership System Admin Login index.php sql injection
- CVE-2026-52011 PoCGdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image
- CVE-2026-52032 PoCsCMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder path traversal
- CVE-2026-52041 PoCTenda CH22 Parameter webtypelibrary formWebTypeLibrary stack-based overflow
- CVE-2026-52061 PoCcode-projects Simple Gym Management System Payment sql injection
- CVE-2026-52091 PoCSourceCodester Leave Application System User Management cross site scripting
- CVE-2026-52101 PoCSourceCodester Leave Application System file inclusion
- CVE-2026-52111 PoCD-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Del stack-based overflow
- CVE-2026-52121 PoCD-Link DNS-1550-04 webdav_mgr.cgi Webdav_Upload_File stack-based overflow
- CVE-2026-52131 PoCD-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflow
- CVE-2026-52141 PoCD-Link DNS-1550-04 account_mgr.cgi cgi_addgroup_get_group_quota_minsize stack-based overflow
- CVE-2026-52151 PoCD-Link DNS-1550-04 network_mgr.cgi cgi_get_ipv6 access control
- CVE-2026-52291 PoCReceive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth…
- CVE-2026-52351 PoCAxiomatic Bento4 MP4 File Ap4Dac4Atom.cpp ReadCache heap-based overflow
- CVE-2026-52361 PoCAxiomatic Bento4 DSI v1 Ap4Dac4Atom.cpp SkipBits heap-based overflow
- CVE-2026-52371 PoCitsourcecode Payroll Management System Parameter manage_user.php sql injection
- CVE-2026-52381 PoCitsourcecode Payroll Management System Parameter view_employee.php sql injection
- CVE-2026-52401 PoCcode-projects BloodBank Managing System admin_state.php cross site scripting
- CVE-2026-52481 PoCgougucms User Registration Login.php reg_submit dynamically-determined object attributes
- CVE-2026-52491 PoCgougucms Record Endpoint record.html cross site scripting
- CVE-2026-52511 PoCz-9527 admin User Update Endpoint user.js dynamically-determined object attributes
- CVE-2026-52522 PoCsz-9527 admin Message Create Endpoint message.js cross site scripting
- CVE-2026-52531 PoCbufanyun HotGo editNotice Endpoint MessageList.vue cross site scripting
- CVE-2026-52541 PoCwelovemedia FFmate Webhook AppJsonTreeView.vue cross site scripting
- CVE-2026-52551 PoCcode-projects Simple Laundry System Parameter delstaffinfo.php cross site scripting
- CVE-2026-52561 PoCcode-projects Simple Laundry System Parameter modify.php sql injection
- CVE-2026-52571 PoCcode-projects Simple Laundry System Parameter delstaffinfo.php sql injection
- CVE-2026-52581 PoCSanster IOPaint File Manager file_manager.py _get_file path traversal
- CVE-2026-52591 PoCAutohomeCorp frostmourne Alarm Preview AlarmController.java server-side request forgery
- CVE-2026-52611 PoCShandong Hoteam InforCenter PLM BaseHandler.ashx uploadFileToIIS unrestricted upload
- CVE-2026-52621 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-52812 PoCsKEVUse after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to…
- CVE-2026-52961 PoCMissing Authorization in GitLab
- CVE-2026-53051 PoCEmail Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Stored XSS
- CVE-2026-53061 PoCCheck & Log Email < 2.0.13 - Unauthenticated Stored XSS
- CVE-2026-53091 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-53101 PoCEnter Software Iperius Backup IperiusAccounts.ini hard-coded key
- CVE-2026-53111 PoCD-Link DNS-1550-04 file_center.cgi Webdav_Access_List access control
- CVE-2026-53121 PoCD-Link DNS-1550-04 dsk_mgr.cgi Get_current_raidtype access control
- CVE-2026-53141 PoCNothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-bounds
- CVE-2026-53151 PoCNothings stb TTF File stb_truetype.h stbtt__buf_get8 out-of-bounds
- CVE-2026-53161 PoCNothings stb stb_vorbis.c setup_free allocation of resources
- CVE-2026-53171 PoCNothings stb stb_vorbis.c start_decoder out-of-bounds write
- CVE-2026-53181 PoCLibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write
- CVE-2026-53191 PoCitsourcecode Payroll Management System navbar.php cross site scripting
- CVE-2026-53201 PoCvanna-ai vanna Chat API Endpoint v2 missing authentication
- CVE-2026-53211 PoCvanna-ai vanna FastAPI/Flask Server cross-domain policy
- CVE-2026-53221 PoCAlejandroArciniegas mcp-data-vis MCP server.js request sql injection
- CVE-2026-53231 PoCpriyankark a11y-mcp index.js A11yServer server-side request forgery
- CVE-2026-53251 PoCSourceCodester Simple Customer Relationship Management System Create Ticket create-ticket.php cross site scripting
- CVE-2026-53261 PoCSourceCodester Leave Application System User Information index.php authorization
- CVE-2026-53271 PoCefforthye fast-filesystem-mcp index.ts handleGetDiskUsage command injection
- CVE-2026-53281 PoCshsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection
- CVE-2026-53301 PoCSourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control
- CVE-2026-53311 PoCOpenCart Extension Installer installer.php path traversal
- CVE-2026-53321 PoCXiaopi Panel WAF Firewall demo.php cross site scripting
- CVE-2026-53331 PoCDefaultFuction Content-Management-System tools.php command injection
- CVE-2026-53341 PoCitsourcecode Online Enrollment System Parameter index.php sql injection
- CVE-2026-53351 PoCMagic Export & Import < 1.2.0 - Unauthenticated PII Disclosure
- CVE-2026-53361 PoCDataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure
- CVE-2026-53371 PoCFrontend File Manager Plugin <= 23.6 - Subscriber+ Arbitrary Download Access via IDOR
- CVE-2026-53381 PoCTenda G103 Setting system.lua action_set_system_settings command injection
- CVE-2026-53391 PoCTenda G103 Setting gpon.lua action_set_net_settings command injection
- CVE-2026-53421 PoCLibRaw TIFF/NEF decoders_libraw.cpp nikon_load_padded_packed_raw out-of-bounds
- CVE-2026-53441 PoCTextpattern XML-RPC TXP_RPCServer.php mt_uploadImage path traversal
- CVE-2026-53461 PoChuimeicloud hm_editor image-to-base64 Endpoint mcp-server.js client.get server-side request forgery
- CVE-2026-53491 PoCTrendnet TEW-657BRM setup.cgi add_apcdb stack-based overflow
- CVE-2026-53501 PoCTrendnet TEW-657BRM setup.cgi update_pcdb stack-based overflow
- CVE-2026-53511 PoCTrendnet TEW-657BRM setup.cgi add_wps_client os command injection
- CVE-2026-53521 PoCTrendnet TEW-657BRM setup.cgi edit os command injection
- CVE-2026-53531 PoCTrendnet TEW-657BRM setup.cgi ping_test os command injection
- CVE-2026-53541 PoCTrendnet TEW-657BRM setup.cgi vpn_connect os command injection
- CVE-2026-53551 PoCTrendnet TEW-657BRM setup.cgi vpn_drop os command injection
- CVE-2026-53601 PoCFree5GC aper type confusion
- CVE-2026-53641 PoCDrag and Drop File Upload for Contact Form 7 <= 1.1.3 - Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass
- CVE-2026-53661 PoCGit Argument Injection in prefecthq/prefect
- CVE-2026-53681 PoCprojectworlds Car Rental Project Parameter login.php sql injection
- CVE-2026-53701 PoCkrayin laravel-crm Activities Module/Notes inbox.spec.ts composeMail cross site scripting
- CVE-2026-53771 PoCIncorrect Authorization in GitLab
- CVE-2026-53941 PoCPimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling
- CVE-2026-54111 PoCWP Captcha PRO <= 5.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2026-54131 PoCNewgen OmniDocs GetWebApiConfiguration information disclosure
- CVE-2026-54141 PoCNewgen OmniDocs WebApiRequestRedirection resource injection
- CVE-2026-54151 PoCWP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link
- CVE-2026-54171 PoCDataease SQLbot Elasticsearch es_engine.py get_es_data_by_http server-side request forgery
- CVE-2026-54181 PoCappsmithorg appsmith Dashboard WebClientUtils.java computeDisallowedHosts server-side request forgery
- CVE-2026-54201 PoCShinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key
- CVE-2026-54261 PoCKnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey value
- CVE-2026-54521 PoCUCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key
- CVE-2026-54531 PoCRico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key
- CVE-2026-54541 PoCGRID Organiser App co.gridapp.organiser app.json hard-coded key
- CVE-2026-54551 PoCDialogue App ca.diagram.dialogue config.json hard-coded key
- CVE-2026-54561 PoCAlign Technology My Invisalign App com.aligntech.myinvisalign.emea BuildConfig.java hard-coded key
- CVE-2026-54571 PoCPropertyGuru AgentNet Singapore App com.allproperty.android.agentnet BuildConfig.java hard-coded key
- CVE-2026-54581 PoCNoelse Individuals & Pro App com.afone.noelse BuildConfig.java hard-coded key
- CVE-2026-54621 PoCWahoo Fitness SYSTM App com.WahooFitness.SYSTM BuildConfig.java hard-coded key
- CVE-2026-54651 PoCAmelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter
- CVE-2026-54701 PoCmixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent server-side request forgery
- CVE-2026-54711 PoCInvestory Toy Planet Trouble App app.investory.toyfactory google-services-desktop.json hard-coded key
- CVE-2026-54721 PoCProjectsAndPrograms School Management System Profile Picture settings.php unrestricted upload
- CVE-2026-54841 PoCBookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control
- CVE-2026-55132 PoCsOnline Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via…
- CVE-2026-55241 PoCDivi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
- CVE-2026-55281 PoCMoussaabBadla code-screenshot-mcp HTTP os command injection
- CVE-2026-55291 PoCDromara lamp-cloud DefUserController pageUser improper authorization
- CVE-2026-55301 PoCOllama Model Pull API download.go server-side request forgery
- CVE-2026-55311 PoCSourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in file
- CVE-2026-55321 PoCScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_execute os command injection
- CVE-2026-55331 PoCbadlogic pi-mono SVG Artifact SvgArtifact.ts cross site scripting
- CVE-2026-55341 PoCitsourcecode Online Enrollment System Parameter index.php sql injection
- CVE-2026-55351 PoCFedML-AI FedML MQTT Message FileUtils.java path traversal
- CVE-2026-55371 PoChalex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection
- CVE-2026-55391 PoCcode-projects Simple Laundry System Parameter modifymember.php cross site scripting
- CVE-2026-55401 PoCcode-projects Simple Laundry System Parameter modifymember.php sql injection
- CVE-2026-55411 PoCcode-projects Simple Laundry System Parameter modmemberinfo.php cross site scripting
- CVE-2026-55421 PoCcode-projects Simple Laundry System Parameter modstaffinfo.php cross site scripting
- CVE-2026-55431 PoCPHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection
- CVE-2026-55441 PoCUTT HiPER 1250GW formRemoteControl stack-based overflow
- CVE-2026-55461 PoCCampcodes Complete Online Learning Management System Crud_model.php add_lesson unrestricted upload
- CVE-2026-55491 PoCTenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key
- CVE-2026-55511 PoCitsourcecode Free Hotel Reservation System Parameter login.php sql injection
- CVE-2026-55521 PoCPHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection
- CVE-2026-55531 PoCitsourcecode Online Cellphone System Parameter available.php sql injection
- CVE-2026-55541 PoCcode-projects Concert Ticket Reservation System Parameter process_search.php sql injection
- CVE-2026-55552 PoCscode-projects Concert Ticket Reservation System Parameter login.php sql injection
- CVE-2026-55562 PoCsbadlogic pi-mono loader.ts discoverAndLoadExtensions code injection
- CVE-2026-55571 PoCbadlogic pi-mono pi-mom Slack Bot slack.ts authentication bypass
- CVE-2026-55581 PoCPHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection
- CVE-2026-55591 PoCAntaresMugisho PyBlade AST Validation sandbox.py _is_safe_ast special elements used in a template engine
- CVE-2026-55601 PoCPHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injection
- CVE-2026-55611 PoCCampcodes Complete POS Management and Inventory System Environment Variable SettingsController.php injection
- CVE-2026-55622 PoCsprovectus kafka-ui Endpoint testexecutions validateAccess code injection
- CVE-2026-55631 PoCAutohomeCorp frostmourne Alarm Preview previewData httpTest sql injection
- CVE-2026-55641 PoCcode-projects Simple Laundry System Parameter searchguest.php sql injection
- CVE-2026-55651 PoCcode-projects Simple Laundry System Parameter delmemberinfo.php sql injection
- CVE-2026-55661 PoCUTT HiPER 1250GW formNatStaticMap strcpy buffer overflow
- CVE-2026-55671 PoCTenda M3 Destination setAdvPolicyData buffer overflow
- CVE-2026-55681 PoCAkaunting Invoice/Billing cross site scripting
- CVE-2026-55691 PoCTechnostrobe HI-LED-WR120-G2 Endpoint access control
- CVE-2026-55701 PoCTechnostrobe HI-LED-WR120-G2 LoginCB index_config improper authentication
- CVE-2026-55711 PoCTechnostrobe HI-LED-WR120-G2 Configuration Data fs information disclosure
- CVE-2026-55721 PoCTechnostrobe HI-LED-WR120-G2 cross-site request forgery
- CVE-2026-55731 PoCTechnostrobe HI-LED-WR120-G2 fs unrestricted upload
- CVE-2026-55741 PoCTechnostrobe HI-LED-WR120-G2 FsBrowseClean deletefile authorization
- CVE-2026-55751 PoCSourceCodester/jkev Record Management System Login index.php sql injection
- CVE-2026-55761 PoCSourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload
- CVE-2026-55771 PoCSong-Li cross_browser details Endpoint uniquemachine_app.py sql injection
- CVE-2026-55781 PoCCodeAstro Online Classroom Parameter addassessment.php sql injection
- CVE-2026-55791 PoCCodeAstro Online Classroom Parameter updatedetailsfromfaculty.php sql injection
- CVE-2026-55801 PoCCodeAstro Online Classroom Parameter addvideos.php sql injection
- CVE-2026-55831 PoCPHPGurukul Online Shopping Portal Project Parameter my-profile.php sql injection
- CVE-2026-55841 PoCFosowl agenticSeek query Endpoint PyInterpreter.py PyInterpreter.execute code injection
- CVE-2026-55851 PoCTencent AI-Infra-Guard Task Detail Endpoint task_manager.go information disclosure
- CVE-2026-55861 PoCzhongyu09 openchatbi Multi-stage Text2SQL Workflow sql injection
- CVE-2026-55871 PoCwbbeyourself MAC-SQL Refiner Agent agents.py _execute_sql sql injection
- CVE-2026-55941 PoCpremAI-io premsql followup.py eval code injection
- CVE-2026-55951 PoCgriptape-ai griptape FileManagerTool save_memory_artifacts_to_disk path traversal
- CVE-2026-55961 PoCgriptape-ai griptape SqlTool tool.py sql injection
- CVE-2026-55971 PoCgriptape-ai griptape ComputerTool tool.py path traversal
- CVE-2026-56011 PoCAcrel Electrical Prepaid Cloud Platform Backup File bin.rar information disclosure
- CVE-2026-56021 PoCNor2-io heim-mcp new_heim_application tools.ts registerTools os command injection
- CVE-2026-56031 PoCelgentos magento2-dev-mcp index.ts executeMagerun2Command os command injection
- CVE-2026-56041 PoCTenda CH22 Parameter CertLocalPrecreate formCertLocalPrecreate stack-based overflow
- CVE-2026-56051 PoCTenda CH22 WrlExtraSet formWrlExtraSet stack-based overflow
- CVE-2026-56071 PoCimprvhub mcp-browser-agent URL Parameter handlers.ts CallToolRequestSchema server-side request forgery
- CVE-2026-56081 PoCBelkin F9K1122 formWlanSetup stack-based overflow
- CVE-2026-56091 PoCTenda i12 Parameter wifiSSIDset formwrlSSIDset stack-based overflow
- CVE-2026-56101 PoCBelkin F9K1015 formWISP5G stack-based overflow
- CVE-2026-56111 PoCBelkin F9K1015 formCrossBandSwitch stack-based overflow
- CVE-2026-56121 PoCBelkin F9K1015 formWlEncrypt stack-based overflow
- CVE-2026-56131 PoCBelkin F9K1015 formReboot stack-based overflow
- CVE-2026-56141 PoCBelkin F9K1015 formSetPassword stack-based overflow
- CVE-2026-56153 PoCsgivanz Vvvebjs File Upload Endpoint upload.php cross site scripting
- CVE-2026-56181 PoCkalcaddle kodbox shareMake/shareCheck server-side request forgery
- CVE-2026-56191 PoCBraffolk mcp-summarization-functions summarize_command mcp-server.ts os command injection
- CVE-2026-56201 PoCitsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection
- CVE-2026-56211 PoCChrisChinchilla Vale-MCP HTTP index.ts os command injection
- CVE-2026-56251 PoCassafelovic gpt-researcher WebSocket researcher.py cross site scripting
- CVE-2026-56281 PoCBelkin F9K1015 Setting formSetSystemSettings stack-based overflow
- CVE-2026-56291 PoCBelkin F9K1015 formSetFirewall stack-based overflow
- CVE-2026-56301 PoCassafelovic gpt-researcher Report API app.py cross site scripting
- CVE-2026-56311 PoCassafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection
- CVE-2026-56321 PoCassafelovic gpt-researcher HTTP REST API Endpoint missing authentication
- CVE-2026-56331 PoCassafelovic gpt-researcher ws Endpoint server-side request forgery
- CVE-2026-56341 PoCprojectworlds Car Rental Project Parameter book_car.php sql injection
- CVE-2026-56351 PoCPHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection
- CVE-2026-56361 PoCPHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection
- CVE-2026-56371 PoCprojectworlds Car Rental System Parameter message_admin.php sql injection
- CVE-2026-56381 PoCHerikLyma CPPWebFramework path traversal
- CVE-2026-56391 PoCPHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection
- CVE-2026-56401 PoCPHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection
- CVE-2026-56411 PoCPHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injection
- CVE-2026-56421 PoCCyber-III Student-Management-System HTTP POST Request update.php improper authorization
- CVE-2026-56431 PoCCyber-III Student-Management-System Admin Add Endpoint notice.php cross site scripting
- CVE-2026-56441 PoCCyber-III Student-Management-System batch-notice.php cross site scripting
- CVE-2026-56451 PoCprojectworlds Car Rental System Parameter pay.php sql injection
- CVE-2026-56461 PoCcode-projects Easy Blog Site login.php sql injection
- CVE-2026-56471 PoCcode-projects Online Shoe Store Add Product admin_feature.php cross site scripting
- CVE-2026-56481 PoCcode-projects Simple Laundry System Parameter userfinishregister.php sql injection
- CVE-2026-56491 PoCcode-projects Online Application System for Admission Endpoint admsnform.php sql injection
- CVE-2026-56501 PoCcode-projects Online Application System for Admission oas.sql sensitive information
- CVE-2026-56591 PoCpytries datrie trie File datrie.pyx Trie.__setstate__ deserialization
- CVE-2026-56601 PoCitsourcecode Construction Management System Parameter borrowed_equip.php sql injection
- CVE-2026-56611 PoCFree5GC NGSetupRequest denial of service
- CVE-2026-56651 PoCcode-projects Online FIR System Login checklogin.php sql injection
- CVE-2026-56661 PoCcode-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
- CVE-2026-56681 PoCCyber-III Student-Management-System add%20notice.php cross site scripting
- CVE-2026-56691 PoCCyber-III Student-Management-System Parameter login.php sql injection
- CVE-2026-56701 PoCCyber-III Student-Management-System upload.php move_uploaded_file unrestricted upload
- CVE-2026-56711 PoCCyber-III Student-Management-System Class Schedule Deletion Endpoint delete_batch.php cross site scripting
- CVE-2026-56721 PoCcode-projects Simple IT Discussion Forum Parameter edit-category.php sql injection
- CVE-2026-56751 PoCitsourcecode Construction Management System Parameter borrowed_tool.php sql injection
- CVE-2026-56761 PoCTotolink A8000R cstecgi.cgi setLanguageCfg missing authentication
- CVE-2026-56771 PoCTotolink A7100RU cstecgi.cgi CsteSystem os command injection
- CVE-2026-56781 PoCTotolink A7100RU cstecgi.cgi setScheduleCfg os command injection
- CVE-2026-56791 PoCTotolink A3300R cstecgi.cgi vsetTr069Cfg os command injection
- CVE-2026-56811 PoCitsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection
- CVE-2026-56822 PoCsMeesho Online Shopping App com.meesho.supply endpoint risky encryption
- CVE-2026-56831 PoCTenda CX12L P2pListFilter fromP2pListFilter stack-based overflow
- CVE-2026-56841 PoCTenda CX12L webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow
- CVE-2026-56851 PoCTenda CX12L addressNat fromAddressNat stack-based overflow
- CVE-2026-56861 PoCTenda CX12L RouteStatic fromRouteStatic stack-based overflow
- CVE-2026-56871 PoCTenda CX12L NatStaticSetting fromNatStaticSetting stack-based overflow
- CVE-2026-56881 PoCTotolink A7100RU cstecgi.cgi setDdnsCfg os command injection
- CVE-2026-56891 PoCTotolink A7100RU cstecgi.cgi setNtpCfg os command injection
- CVE-2026-56901 PoCTotolink A7100RU cstecgi.cgi setRemoteCfg os command injection
- CVE-2026-56911 PoCTotolink A7100RU cstecgi.cgi setFirewallType os command injection
- CVE-2026-56921 PoCTotolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection
- CVE-2026-57051 PoCcode-projects Online Hotel Booking Booking Endpoint booknow.php cross site scripting
- CVE-2026-57184 PoCsDrag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist…
- CVE-2026-57191 PoCitsourcecode Construction Management System borrowedtool.php sql injection
- CVE-2026-57241 PoCMissing Authentication on Streaming gRPC Replication Endpoint
- CVE-2026-57411 PoCsuvarchal docker-mcp-server HTTP index.ts pull_image os command injection
- CVE-2026-57601 PoCCVE-2026-5760
- CVE-2026-57761 PoCEmail Encoder < 2.4.7 - Unauthenticated Stored XSS
- CVE-2026-57961 PoCIncorrect Authorization in GitLab
- CVE-2026-58021 PoCidachev mcp-javadc HTTP os command injection
- CVE-2026-58031 PoCbigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery
- CVE-2026-58051 PoCcode-projects Easy Blog Site contact_us.php sql injection
- CVE-2026-58061 PoCcode-projects Easy Blog Site update.php cross site scripting
- CVE-2026-58101 PoCSourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting
- CVE-2026-58111 PoCSourceCodester Online Food Ordering System POST Parameter Actions.php save_product logic error
- CVE-2026-58121 PoCSourceCodester Pharmacy Product Management System POST Parameter add-sales.php logic error
- CVE-2026-58131 PoCPHPGurukul Online Course Registration check_availability.php sql injection
- CVE-2026-58141 PoCPHPGurukul Online Course Registration check_availability.php sql injection
- CVE-2026-58151 PoCD-Link DIR-645 hedwig.cgi hedwigcgi_main stack-based overflow
- CVE-2026-58161 PoCImproper Resolution of Path Equivalence in GitLab
- CVE-2026-58172 PoCsDocker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
- CVE-2026-58231 PoCitsourcecode Construction Management System borrowed_tool_report.php sql injection
- CVE-2026-58241 PoCcode-projects Simple Laundry System userchecklogin.php sql injection
- CVE-2026-58251 PoCcode-projects Simple Laundry System delmemberinfo.php cross site scripting
- CVE-2026-58261 PoCcode-projects Simple IT Discussion Forum edit-category.php cross site scripting
- CVE-2026-58271 PoCcode-projects Simple IT Discussion Forum question-function.php sql injection
- CVE-2026-58281 PoCcode-projects Simple IT Discussion Forum addcomment.php sql injection
- CVE-2026-58291 PoCcode-projects Simple IT Discussion Forum content.php sql injection
- CVE-2026-58301 PoCTenda AC15 SysToolChangePwd websGetVar stack-based overflow
- CVE-2026-58321 PoCatototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery
- CVE-2026-58331 PoCawwaiid mcp-server-taskwarrior index.ts server.setRequestHandler command injection
- CVE-2026-58341 PoCcode-projects Online Shoe Store admin_running.php cross site scripting
- CVE-2026-58351 PoCcode-projects Online Shoe Store admin_football.php cross site scripting
- CVE-2026-58361 PoCcode-projects Online Shoe Store admin_product.php cross site scripting
- CVE-2026-58371 PoCPHPGurukul News Portal Project news-details.php sql injection
- CVE-2026-58381 PoCPHPGurukul News Portal Project add-subadmins.php sql injection
- CVE-2026-58391 PoCPHPGurukul News Portal Project add-subcategory.php sql injection
- CVE-2026-58401 PoCPHPGurukul News Portal Project check_availability.php sql injection
- CVE-2026-58411 PoCTenda i3 HTTP R7WebsSecurityHandler path traversal
- CVE-2026-58421 PoCdecolua 9router Administrative API Endpoint api authorization
- CVE-2026-58431 PoCDocker Model Runner container-to-host code execution via MLX-LM model_file importlib loading
- CVE-2026-58441 PoCD-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection
- CVE-2026-58471 PoCcode-projects Movie Ticketing System SQL Database Backup File moviedb.sql information disclosure
- CVE-2026-58481 PoCjeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection
- CVE-2026-58491 PoCTenda i12 HTTP path traversal
- CVE-2026-58501 PoCTotolink A7100RU CGI cstecgi.cgi setVpnPassCfg os command injection
- CVE-2026-58511 PoCTotolink A7100RU CGI cstecgi.cgi setUPnPCfg os command injection
- CVE-2026-58521 PoCTotolink A7100RU CGI cstecgi.cgi setIptvCfg os command injection
- CVE-2026-58531 PoCTotolink A7100RU CGI cstecgi.cgi setIpv6LanCfg os command injection
- CVE-2026-58541 PoCTotolink A7100RU CGI cstecgi.cgi setWiFiEasyCfg os command injection
- CVE-2026-58652 PoCsType Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
- CVE-2026-59521 PoCIncorrect Authorization in GitLab
- CVE-2026-59601 PoCcode-projects Patient Record Management System SQL Database Backup File hcpms.sql information disclosure
- CVE-2026-59611 PoCcode-projects Simple IT Discussion Forum topic-details.php sql injection
- CVE-2026-59621 PoCTenda CH22 httpd R7WebsSecurityHandlerfunction path traversal
- CVE-2026-59701 PoCFoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection
- CVE-2026-59711 PoCFoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injection
- CVE-2026-59721 PoCFoundationAgents MetaGPT terminal.py Terminal.run_command os command injection
- CVE-2026-59731 PoCFoundationAgents MetaGPT common.py get_mime_type os command injection
- CVE-2026-59751 PoCTotolink A7100RU CGI cstecgi.cgi setDmzCfg os command injection
- CVE-2026-59761 PoCTotolink A7100RU CGI cstecgi.cgi setStorageCfg os command injection
- CVE-2026-59771 PoCTotolink A7100RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
- CVE-2026-59781 PoCTotolink A7100RU CGI cstecgi.cgi setWiFiAclRules os command injection
- CVE-2026-59791 PoCD-Link DIR-605L POST Request formVirtualServ buffer overflow
- CVE-2026-59801 PoCD-Link DIR-605L POST Request formSetMACFilter buffer overflow
- CVE-2026-59811 PoCD-Link DIR-605L POST Request formAdvFirewall buffer overflow
- CVE-2026-59821 PoCD-Link DIR-605L POST Request formAdvNetwork buffer overflow
- CVE-2026-59831 PoCD-Link DIR-605L POST Request formSetDDNS buffer overflow
- CVE-2026-59841 PoCD-Link DIR-605L POST Request formSetLog buffer overflow
- CVE-2026-59851 PoCcode-projects Simple IT Discussion Forum crud.php sql injection
- CVE-2026-59861 PoCZod jsVideoUrlParser util.js getTime redos
- CVE-2026-59871 PoCSanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine
- CVE-2026-59881 PoCTenda F451 AdvSetWrlsafeset formWrlsafeset stack-based overflow
- CVE-2026-59891 PoCTenda F451 RouteStatic fromRouteStatic stack-based overflow
- CVE-2026-59901 PoCTenda F451 SafeEmailFilter fromSafeEmailFilter stack-based overflow
- CVE-2026-59911 PoCTenda F451 WrlExtraSet formWrlExtraSet stack-based overflow
- CVE-2026-59921 PoCTenda F451 P2pListFilter fromP2pListFilter stack-based overflow
- CVE-2026-59931 PoCTotolink A7100RU CGI cstecgi.cgi setWiFiGuestCfg os command injection
- CVE-2026-59941 PoCTotolink A7100RU CGI cstecgi.cgi setTelnetCfg os command injection
- CVE-2026-59951 PoCTotolink A7100RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection
- CVE-2026-59961 PoCTotolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow os command injection
- CVE-2026-59971 PoCTotolink A7100RU CGI cstecgi.cgi setLoginPasswordCfg os command injection
- CVE-2026-59981 PoCzhayujie chatgpt-on-wechat CowAgent API Memory Content Endpoint service.py dispatch path traversal
- CVE-2026-59991 PoCJeecgBoot SysAnnouncementController improper authorization