CVE-2026-64000 to CVE-2026-64999
19 CVEs with public proof-of-concept exploits.
- CVE-2026-645313 PoCsnet: openvswitch: reject oversized nested action attrs
- CVE-2026-645603 PoCsposix-cpu-timers: Prevent UAF caused by non-leader exec() race
- CVE-2026-645613 PoCsKVM: x86: Check for invalid/obsolete root *after* making MMU pages available
- CVE-2026-645643 PoCssctp: don't free the ASCONF's own transport in DEL-IP processing
- CVE-2026-646008 PoCsxfs: resample the data fork mapping after cycling ILOCK
- CVE-2026-646331 PoCA vulnerability allowing remote unauthenticated code execution on the agent host.
- CVE-2026-6463826 PoCsWordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party…
- CVE-2026-646401 PoCApache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
- CVE-2026-646791 PoCAtlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation
- CVE-2026-647251 PoCAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6…
- CVE-2026-647881 PoCThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing…
- CVE-2026-648211 PoCdjangoSIGE 1.10 CSRF via GET-based Order Cancellation Views
- CVE-2026-648221 PoCdjangoSIGE 1.10 User Enumeration via ForgotPasswordView
- CVE-2026-648241 PoCHome Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
- CVE-2026-648271 PoCTelenia TVox 26.5.3 Authentication Bypass via set_env.php
- CVE-2026-648281 PoCFroiden TableTrack 1.3.10 Stored XSS via Order Notes Field
- CVE-2026-648496 PoCsKEVMLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS…
- CVE-2026-648501 PoCGrav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
- CVE-2026-648631 PoCgoshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite