CVE-2026-62000 to CVE-2026-62999
20 CVEs with public proof-of-concept exploits.
- CVE-2026-621831 PoCApache Syncope: User self-service privilege escalation
- CVE-2026-622391 PoCFlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py
- CVE-2026-622401 PoCCrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools
- CVE-2026-622421 PoCSpring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration
- CVE-2026-623231 PoCCloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignored
- CVE-2026-623241 PoCJodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
- CVE-2026-623251 PoCgoshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
- CVE-2026-623821 PoCPasswordPusher before v2.9.6 Authentication Bypass via Null Comparison
- CVE-2026-623881 PoCNLTK before 3.10.0 Insecure Default Configuration in pathsec.py
- CVE-2026-626691 PoCGrav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
- CVE-2026-626731 PoCGrav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
- CVE-2026-626841 PoCFile Browser: Share API exposes the password hash and bypass token
- CVE-2026-626851 PoCFile Browser: Colliding username normalization gives two users the same home directory
- CVE-2026-627352 PoCsWindows HTTP.sys Elevation of Privilege Vulnerability
- CVE-2026-627371 PoCWindows Kernel Elevation of Privilege Vulnerability
- CVE-2026-628431 PoCFile Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
- CVE-2026-629111 PoCMicrosoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2026-629471 PoCOpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
- CVE-2026-629821 PoCGlances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command…
- CVE-2026-629881 PoCFroxlor: Credential and 2FA secret disclosure via Froxlor API endpoints