CVE-2026-65000 to CVE-2026-65999
48 CVEs with public proof-of-concept exploits.
- CVE-2026-650082 PoCsGrav before 2.0.7 Remote Code Execution via Blueprint dynamicData
- CVE-2026-650101 PoCDatasets Symlink-following Arbitrary File Write via Extractor.extract()
- CVE-2026-650121 PoCInvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder
- CVE-2026-650131 PoCOnlook tRPC Insecure Direct Object Reference via multiple procedures
- CVE-2026-650531 PoCHorde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part Name
- CVE-2026-653211 PoCPyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
- CVE-2026-653432 PoCsA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe…
- CVE-2026-653491 PoCAn out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe…
- CVE-2026-654003 PoCsKEVAn authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9,…
- CVE-2026-654421 PoCWordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability
- CVE-2026-655911 PoCn8n before 1.123.64 Sanitizer Bypass Remote Code Execution
- CVE-2026-656001 PoCTraefik before v2.11.52 Authentication Bypass via ReplacePathRegex
- CVE-2026-656011 PoCTraefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
- CVE-2026-656021 PoCTraefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass
- CVE-2026-656402 PoCsWordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher.…
- CVE-2026-656432 PoCsEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
- CVE-2026-656501 PoCElgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
- CVE-2026-656931 PoCMicroweber CMS 2.0.20 Server-Side Template Injection via Mail Templates
- CVE-2026-656943 PoCsMicroweber CMS 2.0.20 Path Traversal via ServeStaticFileController
- CVE-2026-656951 PoCOffice-Word-MCP-Server 1.1.11 Path Traversal via document tools
- CVE-2026-656961 PoCOverseerr 1.35.0 Authorization Bypass via pushSubscriptions API
- CVE-2026-656971 PoCFathom Lite 1.3.1 Stored XSS via /collect Endpoint
- CVE-2026-656981 PoCVoid 1.3.4 Path Traversal via AI Agent File-Reading Tools
- CVE-2026-656991 PoCAgentGPT 1.0.0 Authorization Bypass via Agent Task Creation
- CVE-2026-657001 PoCh2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API
- CVE-2026-657011 PoCSoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route
- CVE-2026-657021 PoCVanna 2.0.2 Path Traversal via FileSystemConversationStore
- CVE-2026-657071 PoCLikeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint
- CVE-2026-657081 PoCsysPass 3.2.11 Insecure Direct Object Reference via AccountFileController
- CVE-2026-657091 PoCsysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API
- CVE-2026-657101 PoCsysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption
- CVE-2026-657111 PoCsysPass 3.2.11 Authenticated OS Command Injection via Backup Path
- CVE-2026-657613 PoCsJoomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
- CVE-2026-658341 PoCCapsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
- CVE-2026-658351 PoCCapsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation…
- CVE-2026-658831 PoCJoomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0
- CVE-2026-658911 PoCJoomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content…
- CVE-2026-658931 PoCArbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
- CVE-2026-658981 PoCDOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig
- CVE-2026-659001 PoCDOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM
- CVE-2026-659011 PoCDOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName
- CVE-2026-659021 PoCDOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
- CVE-2026-659141 PoCDOMPurify before 3.3.2 Mutation XSS via Re-Contextualization
- CVE-2026-659161 PoCCyberPanel Missing Authorization in cancelBackupCreation Handler
- CVE-2026-659171 PoCCyberPanel IncBackups IDOR via Sequential Backup ID
- CVE-2026-659181 PoCPyTorch torchvision GIF Decoder Out-of-bounds Heap Read
- CVE-2026-659191 PoCMeshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload
- CVE-2026-659201 PoCDiffusers Path Traversal via weight_map Arbitrary File Read