CVE-2026-63000 to CVE-2026-63999
51 CVEs with public proof-of-concept exploits.
- CVE-2026-630031 PoCdjango CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
- CVE-2026-6303062 PoCsKEVWordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-630391 PoCApache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
- CVE-2026-630721 PoCHeap Buffer Overflow in CMS Key Unwrapping
- CVE-2026-630775 PoCsKEVIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- CVE-2026-630801 PoCAptabase SQL Injection via ClickHouse query backend
- CVE-2026-630811 PoCPerfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field
- CVE-2026-630821 PoCPerfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment
- CVE-2026-630851 PoCAxelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational Record Persistence
- CVE-2026-630861 PoCtext-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions
- CVE-2026-630871 PoCGrafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint
- CVE-2026-630931 PoCCursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace
- CVE-2026-630941 PoCSigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
- CVE-2026-630951 PoCDendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint
- CVE-2026-630961 PoCDendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
- CVE-2026-630971 PoCDendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure
- CVE-2026-630981 PoCTheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
- CVE-2026-630991 PoCTheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints
- CVE-2026-631001 PoCMaybe 0.6.0 Missing Authorization via HostingsController show/update
- CVE-2026-631011 PoCOpen Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export Endpoint
- CVE-2026-631071 PoCLimeSurvey SSRF via REST API Survey Template Host Header
- CVE-2026-631081 PoCRoo Code 3.54.0 Command Injection via Parameter Expansion Parsing
- CVE-2026-631181 PoCMCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
- CVE-2026-631231 PoCTina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
- CVE-2026-631351 PoCYOURLS: Stored XSS in referrer statistics chart via crafted Referer header
- CVE-2026-631881 PoClogto-tunnel serves files outside --experience-path via path traversal
- CVE-2026-632232 PoCsCodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
- CVE-2026-633081 PoCHelm Files.Lines Denial of Service via Empty Chart Files
- CVE-2026-633111 PoCNLTK before 3.10.0 SSRF via DNS Resolution Failure
- CVE-2026-633351 PoCRabbitMQ Java client malformed body frame triggers raw command assembler exception
- CVE-2026-633361 PoCRabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
- CVE-2026-634621 PoCUnleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
- CVE-2026-635201 PoCMicrosoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2026-635631 PoCSharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled…
- CVE-2026-636211 PoCApache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without…
- CVE-2026-636401 PoCMagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
- CVE-2026-636411 PoCMagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
- CVE-2026-636421 PoCMagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
- CVE-2026-636431 PoCMagicMirror: ssrf calendar .js
- CVE-2026-636671 PoCApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
- CVE-2026-637202 PoCsdatamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
- CVE-2026-637301 PoCHyperDX < 2.31.0 SSRF via Webhook Test Endpoint
- CVE-2026-637311 PoCHyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint
- CVE-2026-637641 PoCLMDeploy Server-Side Request Forgery via HTTP Redirect Bypass
- CVE-2026-637651 PoCChatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation
- CVE-2026-637661 PoCGPT-SoVITS 20250606v2pro OS Command Injection via webui.py
- CVE-2026-637671 PoCktransformers Unauthenticated Pickle Deserialization RCE via ZMQ
- CVE-2026-637681 PoCcal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State
- CVE-2026-637691 PoCHuginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
- CVE-2026-637701 PoCGlance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
- CVE-2026-637711 PoCAdminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header