CVE-2026-67000 to CVE-2026-67999
73 CVEs with public proof-of-concept exploits.
- CVE-2026-671811 PoCRouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
- CVE-2026-671821 PoCRouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
- CVE-2026-671831 PoCTinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling
- CVE-2026-671841 PoCTinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
- CVE-2026-671851 PoCTinyWeb 0.0.8 Path Traversal via URL Path Component
- CVE-2026-671951 PoCPerspective 5.0.0 RCE via eval() Expression Injection
- CVE-2026-671961 PoCPerspective 5.0.0 XSS via Debug Plugin innerHTML Interpolation
- CVE-2026-671981 PoCPerspective 5.0.0 DoS via VirtualServer Protocol Dispatcher
- CVE-2026-671991 PoCPerspective 5.0.0 DoS via Loop Expression Evaluation
- CVE-2026-672001 PoCPerspective 5.0.0 Path Traversal via cwd_static_file_handler
- CVE-2026-672011 PoCV 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
- CVE-2026-672063 PoCsWolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
- CVE-2026-672071 PoCWolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
- CVE-2026-672081 PoCJuggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
- CVE-2026-672151 PoCcJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
- CVE-2026-672161 PoCcJSON cJSON_Compare Exponential Complexity Denial of Service
- CVE-2026-672171 PoCcJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
- CVE-2026-673091 PoCTraefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass
- CVE-2026-673121 PoCaxios 0.28.0 before 0.33.0 Denial of Service via formToJSON
- CVE-2026-673131 PoCaxios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON
- CVE-2026-673141 PoCaxios before 1.18.0 Prototype Pollution via auth subfields
- CVE-2026-673151 PoCaxios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
- CVE-2026-673161 PoCaxios before 1.18.0 Prototype Pollution via bodyless methods
- CVE-2026-673171 PoCaxios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream
- CVE-2026-673181 PoCaxios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2
- CVE-2026-673191 PoCaxios before 0.33.0 Prototype Pollution via nested option objects
- CVE-2026-673201 PoCaxios before 0.33.0 Prototype Pollution via Node HTTP adapter
- CVE-2026-673401 PoCArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
- CVE-2026-673451 PoCMaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
- CVE-2026-673471 PoCVendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update
- CVE-2026-673481 PoCJulep Insecure Direct Object Reference via GET /executions/{execution_id}
- CVE-2026-673491 PoCOpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
- CVE-2026-673631 PoCJoomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
- CVE-2026-673641 PoCJoomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2
- CVE-2026-674221 PoCpymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
- CVE-2026-674241 PoCFlyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
- CVE-2026-674251 PoCFlyto2 Core: LLM/API keys leak to an attacker-controlled base_url
- CVE-2026-674261 PoCFlyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
- CVE-2026-674271 PoCFlyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
- CVE-2026-674281 PoCFlyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to…
- CVE-2026-674291 PoCFlyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
- CVE-2026-674301 PoCMCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
- CVE-2026-674311 PoCMCP Ruby SDK: Ruby SSE Session Poisoning
- CVE-2026-674321 PoCMCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
- CVE-2026-674381 PoCOliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
- CVE-2026-674451 PoCMailpit: SMTP command parser buffers unbounded command lines before syntax rejection
- CVE-2026-674461 PoCMailpit: Thumbnail generation decodes unbounded image dimensions before scaling
- CVE-2026-674471 PoCMailpit: SMTP DATA line reader buffers over-limit input before size enforcement
- CVE-2026-675501 PoCre2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process…
- CVE-2026-675981 PoCEmlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
- CVE-2026-675992 PoCsClearOS 7.9 OS Command Injection via Log Viewer filter parameter
- CVE-2026-676021 PoCphpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
- CVE-2026-676081 PoCTelenia TVox 26.5.3 OS Command Injection via action_audio.php
- CVE-2026-676091 PoCTelenia TVox 26.5.3 Privilege Escalation via Insecure sudoers Configuration
- CVE-2026-676101 PoCOpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access
- CVE-2026-676111 PoCOpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
- CVE-2026-676121 PoCOpenEMR 8.2.0 Stored XSS via import_template.php Template Management
- CVE-2026-676171 PoCMicroweber CMS 2.0.20 Stored XSS via tag_names Parameter
- CVE-2026-676201 PoCFlowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
- CVE-2026-676211 PoCFlowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
- CVE-2026-676221 PoCFlowise 3.1.4 IDOR in OpenAI Assistants Integration
- CVE-2026-676232 PoCsMistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
- CVE-2026-676872 PoCsInsecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in…
- CVE-2026-676881 PoCICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a…
- CVE-2026-676891 PoCSQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in…
- CVE-2026-678221 PoCTenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function…
- CVE-2026-679171 PoCzuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The…
- CVE-2026-679192 PoCsAn issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and…
- CVE-2026-679202 PoCsAn issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the…
- CVE-2026-679212 PoCsCross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the…
- CVE-2026-679651 PoCAn issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function
- CVE-2026-679661 PoCTenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root…
- CVE-2026-679671 PoCBuffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for…