CVE-2026-61000 to CVE-2026-61999
23 CVEs with public proof-of-concept exploits.
- CVE-2026-613431 PoCLibreBooking path traversal
- CVE-2026-614241 PoCJoomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
- CVE-2026-614471 PoCPraisonAI before 1.6.78 Remote Code Execution via CodeAgent
- CVE-2026-614592 PoCsMCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools
- CVE-2026-614601 PoCKrayin CRM Insecure Direct Object Reference via Controllers
- CVE-2026-614611 PoCDify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text
- CVE-2026-614982 PoCsVitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php
- CVE-2026-615116 PoCsvBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
- CVE-2026-615141 PoCPuwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456
- CVE-2026-615151 PoCPuwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
- CVE-2026-615181 PoCISPConfig Authenticated SQL Injection via Remote API primary_id Parameter
- CVE-2026-615231 PoCWebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor
- CVE-2026-615241 PoCWebsiteBaker CMS < 2.13.10 File Upload RCE via Module Installation
- CVE-2026-616091 PoCPterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
- CVE-2026-616321 PoCPyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
- CVE-2026-616631 PoCdjango CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
- CVE-2026-616901 PoCGrav: Decompression Bomb via ZipArchiver - Missing Extraction Limits
- CVE-2026-617361 PoCLightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
- CVE-2026-617401 PoCLightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
- CVE-2026-618081 PoCLightRAG: Missing Authentication for Critical API Functions in Default Configuration
- CVE-2026-618421 PoCGrav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)
- CVE-2026-618761 PoCLuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting
- CVE-2026-619461 PoCWordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability