CVE-2026-60000 to CVE-2026-60999
8 CVEs with public proof-of-concept exploits.
- CVE-2026-6000411 PoCsKEVGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- CVE-2026-600931 PoCApache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without…
- CVE-2026-601041 PoCBitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
- CVE-2026-601051 PoCMonsta FTP < 2.14.5 SSRF via IPv4-Mapped IPv6 Address Bypass
- CVE-2026-601141 PoCSustainable Irrigation Platform 5.2.16 Path Traversal via JSON Backup Restore
- CVE-2026-601212 PoCsVitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
- CVE-2026-6013746 PoCsKEVWordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
- CVE-2026-602064 PoCsVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected…