CVE-2026-6000 to CVE-2026-6999
268 CVEs with public proof-of-concept exploits.
- CVE-2026-60001 PoCcode-projects Online Library Management System SQL Database Backup File library.sql information disclosure
- CVE-2026-60031 PoCcode-projects Simple IT Discussion Forum user.php cross site scripting
- CVE-2026-60041 PoCcode-projects Simple IT Discussion Forum delete-category.php sql injection
- CVE-2026-60051 PoCcode-projects Patient Record Management System hematology_print.php sql injection
- CVE-2026-60061 PoCcode-projects Patient Record Management System edit_hpatient.php sql injection
- CVE-2026-60071 PoCitsourcecode Construction Management System del.php sql injection
- CVE-2026-60091 PoCJaspersoft Library Deserialisation Vulnerability
- CVE-2026-60101 PoCCodeAstro Online Classroom takeassessment2.php sql injection
- CVE-2026-60111 PoCOpenClaw assertPublicHostname web-fetch.ts server-side request forgery
- CVE-2026-60121 PoCD-Link DIR-513 POST Request formSetPassword buffer overflow
- CVE-2026-60131 PoCD-Link DIR-513 POST Request formSetRoute buffer overflow
- CVE-2026-60141 PoCD-Link DIR-513 POST Request formAdvanceSetup buffer overflow
- CVE-2026-60151 PoCTenda AC9 POST Request QuickIndex formQuickIndex stack-based overflow
- CVE-2026-60161 PoCTenda AC9 POST Request WizardHandle decodePwd stack-based overflow
- CVE-2026-60241 PoCTenda i6 HTTP R7WebsSecurityHandlerfunction path traversal
- CVE-2026-60251 PoCTotolink A7100RU CGI cstecgi.cgi setSyslogCfg os command injection
- CVE-2026-60261 PoCTotolink A7100RU CGI cstecgi.cgi setPortalConfWeChat os command injection
- CVE-2026-60271 PoCTotolink A7100RU CGI cstecgi.cgi setUrlFilterRules os command injection
- CVE-2026-60281 PoCTotolink A7100RU CGI cstecgi.cgi setPptpServerCfg os command injection
- CVE-2026-60291 PoCTotolink A7100RU CGI cstecgi.cgi setVpnAccountCfg os command injection
- CVE-2026-60301 PoCitsourcecode Construction Management System del1.php sql injection
- CVE-2026-60311 PoCcode-projects Simple IT Discussion Forum add-category-function.php sql injection
- CVE-2026-60321 PoCcode-projects Simple Laundry System checkcheckout.php cross site scripting
- CVE-2026-60331 PoCCodeAstro Online Classroom updatedetailsfromstudent.php sql injection
- CVE-2026-60341 PoCcode-projects Vehicle Showroom Management System ProfitAndLossReport.php cross site scripting
- CVE-2026-60351 PoCcode-projects Vehicle Showroom Management System ServiceAndSalesReport.php cross site scripting
- CVE-2026-60361 PoCcode-projects Vehicle Showroom Management System VehicleDetailsFunction.php sql injection
- CVE-2026-60371 PoCcode-projects Vehicle Showroom Management System AddVehicleFunction.php sql injection
- CVE-2026-60381 PoCcode-projects Vehicle Showroom Management System RegisterCustomerFunction.php sql injection
- CVE-2026-60421 PoCmusl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity
- CVE-2026-60631 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-60731 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-61051 PoCperfree go-fastdfs-web doInstall InstallController.java improper authorization
- CVE-2026-61061 PoC1Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting
- CVE-2026-61081 PoC1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection
- CVE-2026-61091 PoCFoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery
- CVE-2026-61101 PoCFoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
- CVE-2026-61112 PoCsFoundationAgents MetaGPT common.py decode_image server-side request forgery
- CVE-2026-61121 PoCTotolink A7100RU CGI cstecgi.cgi setRadvdCfg os command injection
- CVE-2026-61131 PoCTotolink A7100RU CGI cstecgi.cgi setTtyServiceCfg os command injection
- CVE-2026-61141 PoCTotolink A7100RU CGI cstecgi.cgi setNetworkCfg os command injection
- CVE-2026-61151 PoCTotolink A7100RU CGI cstecgi.cgi setAppCfg os command injection
- CVE-2026-61161 PoCTotolink A7100RU CGI cstecgi.cgi setDiagnosisCfg os command injection
- CVE-2026-61171 PoCAstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox
- CVE-2026-61182 PoCsAstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection
- CVE-2026-61191 PoCAstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery
- CVE-2026-61201 PoCTenda F451 httpd DhcpListClient fromDhcpListClient stack-based overflow
- CVE-2026-61211 PoCTenda F451 httpd WrlclientSet stack-based overflow
- CVE-2026-61221 PoCTenda F451 httpd L7Prot frmL7ProtForm stack-based overflow
- CVE-2026-61231 PoCTenda F451 httpd addressNat fromAddressNat stack-based overflow
- CVE-2026-61241 PoCTenda F451 httpd SafeMacFilter fromSafeMacFilter stack-based overflow
- CVE-2026-61251 PoCDromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection
- CVE-2026-61261 PoCzhayujie chatgpt-on-wechat CowAgent Administrative HTTP Endpoint missing authentication
- CVE-2026-61291 PoCzhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication
- CVE-2026-61301 PoCchatboxai chatbox Model Context Protocol Server Management System ipc-stdio-transport.ts StdioClientTransport os command injection
- CVE-2026-61311 PoCTotolink A7100RU CGI cstecgi.cgi setTracerouteCfg os command injection
- CVE-2026-61321 PoCTotolink A7100RU CGI cstecgi.cgi setLedCfg os command injection
- CVE-2026-61331 PoCTenda F451 SafeUrlFilter fromSafeUrlFilter stack-based overflow
- CVE-2026-61341 PoCTenda F451 qossetting fromqossetting stack-based overflow
- CVE-2026-61351 PoCTenda F451 SetIpBind fromSetIpBind stack-based overflow
- CVE-2026-61361 PoCTenda F451 L7Im frmL7ImForm stack-based overflow
- CVE-2026-61371 PoCTenda F451 AdvSetWan fromAdvSetWan stack-based overflow
- CVE-2026-61381 PoCTotolink A7100RU CGI cstecgi.cgi setAccessDeviceCfg os command injection
- CVE-2026-61391 PoCTotolink A7100RU CGI cstecgi.cgi UploadOpenVpnCert os command injection
- CVE-2026-61401 PoCTotolink A7100RU CGI cstecgi.cgi UploadFirmwareFile os command injection
- CVE-2026-61421 PoCtushar-2223 Hotel Management System roomdelete.php sql injection
- CVE-2026-61431 PoCfarion1231 cc-switch ProxyServer server.rs cross-domain policy
- CVE-2026-61451 PoCUser Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter
- CVE-2026-61481 PoCcode-projects Vehicle Showroom Management System MonthTotalReportUpdateFunction.php sql injection
- CVE-2026-61491 PoCcode-projects Vehicle Showroom Management System BookVehicleFunction.php sql injection
- CVE-2026-61501 PoCcode-projects Simple Laundry System checkupdatestatus.php cross site scripting
- CVE-2026-61511 PoCcode-projects Vehicle Showroom Management System PaymentStatusFunction.php sql injection
- CVE-2026-61521 PoCcode-projects Vehicle Showroom Management System StaffAddingFunction.php sql injection
- CVE-2026-61531 PoCcode-projects Vehicle Showroom Management System StaffDetailsFunction.php sql injection
- CVE-2026-61541 PoCTotolink A7100RU CGI cstecgi.cgi setWizardCfg os command injection
- CVE-2026-61551 PoCTotolink A7100RU CGI cstecgi.cgi setWanCfg os command injection
- CVE-2026-61561 PoCTotolink A7100RU CGI cstecgi.cgi setIpQosRules os command injection
- CVE-2026-61571 PoCTotolink A800R app.so setAppEasyWizardConfig buffer overflow
- CVE-2026-61581 PoCTotolink N300RH upgrade.so setUpgradeUboot os command injection
- CVE-2026-61591 PoCcode-projects Simple ChatBox Endpoint insert.php cross site scripting
- CVE-2026-61601 PoCcode-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disclosure
- CVE-2026-61611 PoCcode-projects Simple ChatBox Endpoint insert.php sql injection
- CVE-2026-61621 PoCPHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scripting
- CVE-2026-61631 PoCcode-projects Lost and Found Thing Management catageory.php sql injection
- CVE-2026-61641 PoCcode-projects Lost and Found Thing Management addcat.php sql injection
- CVE-2026-61651 PoCcode-projects Vehicle Showroom Management System Login_check.php sql injection
- CVE-2026-61661 PoCcode-projects Vehicle Showroom Management System UpdateVehicleFunction.php sql injection
- CVE-2026-61671 PoCcode-projects Faculty Management System subject-print.php sql injection
- CVE-2026-61681 PoCTOTOLINK A7000R cstecgi.cgi setWiFiEasyGuestCfg stack-based overflow
- CVE-2026-61822 PoCscode-projects Simple Content Management System login.php sql injection
- CVE-2026-61832 PoCscode-projects Simple Content Management System index.php sql injection
- CVE-2026-61842 PoCscode-projects Simple Content Management System welcome.php cross site scripting
- CVE-2026-61861 PoCUTT HiPER 1200GW formNatStaticMap strcpy buffer overflow
- CVE-2026-61871 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-61881 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-61891 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-61901 PoCitsourcecode Construction Management System employees.php sql injection
- CVE-2026-61911 PoCitsourcecode Construction Management System equipments.php sql injection
- CVE-2026-61921 PoCuclouvain openjpeg pi.c opj_pi_initialise_encode integer overflow
- CVE-2026-61931 PoCPHPGurukul Daily Expense Tracking System register.php sql injection
- CVE-2026-61941 PoCTotolink A3002MU HTTP Request formWlanSetup sub_410188 stack-based overflow
- CVE-2026-61951 PoCTotolink A7100RU CGI cstecgi.cgi setPasswordCfg os command injection
- CVE-2026-61961 PoCTenda F456 exeCommand fromexeCommand stack-based overflow
- CVE-2026-61971 PoCTenda F456 AdvSetWrlsafeset formWrlsafeset stack-based overflow
- CVE-2026-61981 PoCTenda F456 NatStaticSetting fromNatStaticSetting stack-based overflow
- CVE-2026-61991 PoCTenda F456 qossetting fromqossetting stack-based overflow
- CVE-2026-62001 PoCTenda F456 webtypelibrary formwebtypelibrary stack-based overflow
- CVE-2026-62012 PoCsCodeAstro Online Job Portal Delete Job Posting job-delete.php access control
- CVE-2026-62021 PoCcode-projects Easy Blog Site post.php sql injection
- CVE-2026-62032 PoCsUser Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter
- CVE-2026-62042 PoCsLibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations…
- CVE-2026-62181 PoCaandrew-me ytDownloader Error Details Panel createTextNode cross site scripting
- CVE-2026-62191 PoCaandrew-me ytDownloader Compressor Feature compressor.js child_process.exec command injection
- CVE-2026-62201 PoCHummerRisk Video File Download URL ServerService.java ServerService.addServer server-side request forgery
- CVE-2026-62241 PoCnocobase plugin-workflow-javascript Vm.js createSafeConsole sandbox
- CVE-2026-62271 PoCBackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter
- CVE-2026-62671 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2026-62681 PoCEventPress < 22.2 – Reflected Cross-Site Scripting
- CVE-2026-62691 PoCIncorrect Authorization in GitLab
- CVE-2026-62711 PoCCareer Section <= 1.7 - Unauthenticated Arbitrary File Upload
- CVE-2026-62741 PoCAuthentication Bypass in DTS Electronics' Redline WR3200
- CVE-2026-62771 PoCIncorrect Authorization in GitLab
- CVE-2026-62795 PoCsAvada (Fusion) Builder <= 3.15.2 - Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode…
- CVE-2026-63001 PoCUse after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
- CVE-2026-63073 PoCsType Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox…
- CVE-2026-63301 PoCML-KEM ARM64 NEON ciphertext comparison only compares half of the input
- CVE-2026-63351 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-63361 PoCIncorrect Authorization in GitLab
- CVE-2026-63521 PoCIncorrect Authorization in GitLab
- CVE-2026-63551 PoCCVE-2026-6355
- CVE-2026-63561 PoCCVE-2026-6356
- CVE-2026-63791 PoCWP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter
- CVE-2026-63811 PoCWP Maps < 4.9.3 - Subscriber+ Local File Inclusion
- CVE-2026-63821 PoCMultiple elFinder Plugins - Authenticated OS Command Injection
- CVE-2026-64211 PoCMobatek MobaXterm Home Edition msimg32.dll uncontrolled search path
- CVE-2026-64334 PoCsCustom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCE
- CVE-2026-64401 PoCGoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
- CVE-2026-64831 PoCWavlink WL-WN530H4 internet.cgi snprintf os command injection
- CVE-2026-64861 PoCclassroombookings User Display Name layout.php read cross site scripting
- CVE-2026-64871 PoCQihui jtbc5 CMS Code Endpoint manage.php path traversal
- CVE-2026-64881 PoCQueryMine sms GET Request Parameter editcourse.php sql injection
- CVE-2026-64891 PoCQueryMine sms Background Management addteacher.php unrestricted upload
- CVE-2026-64901 PoCQueryMine sms GET Request Parameter deletecourse.php sql injection
- CVE-2026-64911 PoClibvips nip2 vips7compat.c im_minpos_vec heap-based overflow
- CVE-2026-64921 PoCarnobt78 Hotel Booking Management System Health Check Endpoint detailed information disclosure
- CVE-2026-64931 PoClukevella rallly Reset Password reset-password-form.tsx cross site scripting
- CVE-2026-64951 PoCAjax Load More < 7.8.4 - Reflected XSS
- CVE-2026-64961 PoCprasathmani TinyFileManager POST Parameter filemanager.php path traversal
- CVE-2026-64971 PoCprasathmani TinyFileManager File Upload filemanager.php server-side request forgery
- CVE-2026-65601 PoCH3C Magic B0 aspForm Edit_BasicSSID buffer overflow
- CVE-2026-65611 PoCEyouCMS Index.php edit_adminlogo unrestricted upload
- CVE-2026-65621 PoCdameng100 muucmf index.html getListByPage sql injection
- CVE-2026-65631 PoCH3C Magic B1 aspForm SetAPWifiorLedInfoById buffer overflow
- CVE-2026-65641 PoCEMQ EMQX Enterprise Session Handling improper authorization
- CVE-2026-65681 PoCkodcloud KodExplorer Public Share share.class.php initShareOld path traversal
- CVE-2026-65701 PoCkodcloud KodExplorer systemMember.class.php initInstall authorization
- CVE-2026-65711 PoCkodcloud KodExplorer systemRole.class.php roleGroupAction authorization
- CVE-2026-65721 PoCCollabora KodExplorer fileUpload Endpoint share.class.php improper authorization
- CVE-2026-65731 PoCPHPEMS Instant Exam Creation exams.master.php temppage server-side request forgery
- CVE-2026-65741 PoCosuuu LightPicture API Upload Endpoint lp.sql hard-coded credentials
- CVE-2026-65761 PoCliangliangyy DjangoBlog WeChat Bot commonapi.py CommandHandler command injection
- CVE-2026-65771 PoCliangliangyy DjangoBlog logtracks Endpoint views.py missing authentication
- CVE-2026-65781 PoCliangliangyy DjangoBlog Setting settings.py hard-coded credentials
- CVE-2026-65791 PoCliangliangyy DjangoBlog Clean Endpoint views.py missing authentication
- CVE-2026-65801 PoCliangliangyy DjangoBlog Amap API Call views.py hard-coded key
- CVE-2026-65811 PoCH3C Magic B1 aspForm SetMobileAPInfoById buffer overflow
- CVE-2026-65821 PoCTransformerOptimus SuperAGI Vector Database Management Endpoint vector_dbs.py get_vector_db_details missing authentication
- CVE-2026-65831 PoCTransformerOptimus SuperAGI API Key Management Endpoint api_key.py edit_api_key authorization
- CVE-2026-65841 PoCTransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization
- CVE-2026-65851 PoCTransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorization
- CVE-2026-65861 PoCTransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization
- CVE-2026-65871 PoCvibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery
- CVE-2026-65881 PoCserge-chat serge Model API Endpoint model.py delete_model missing authentication
- CVE-2026-65891 PoCComfyUI server.py create_origin_only_middleware cross-site request forgery
- CVE-2026-65901 PoCComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal
- CVE-2026-65911 PoCComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal
- CVE-2026-65921 PoCComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting
- CVE-2026-65931 PoCComfyUI View Endpoint server.py cross site scripting
- CVE-2026-65941 PoCbrikcss merge prototype pollution
- CVE-2026-65951 PoCProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injection
- CVE-2026-65961 PoClangflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload
- CVE-2026-65971 PoClangflow-ai langflow Flow Using API core.py has_api_terms credentials storage
- CVE-2026-65981 PoClangflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file
- CVE-2026-65991 PoClangflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection
- CVE-2026-66001 PoClangflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting
- CVE-2026-66011 PoCLagom WHMCS Template Datatables resource consumption
- CVE-2026-66021 PoCrickxy Hospital Management System his_admin_account.php unrestricted upload
- CVE-2026-66031 PoCmodelscope agentscope _python.py execute_shell_command code injection
- CVE-2026-66041 PoCmodelscope agentscope Cloud Metadata Endpoint _openai_tools.py openai_audio_to_text server-side request forgery
- CVE-2026-66051 PoCmodelscope agentscope Internal Service _common.py _get_bytes_from_web_url server-side request forgery
- CVE-2026-66061 PoCmodelscope agentscope _agent_base.py _process_audio_block server-side request forgery
- CVE-2026-66071 PoClm-sys fastchat Worker API Endpoint api_generate resource consumption
- CVE-2026-66081 PoClm-sys fastchat Arena Side-by-Side View add_text control flow
- CVE-2026-66091 PoCliangliangyy DjangoBlog views.py form_valid improper authorization
- CVE-2026-66101 PoCliangliangyy DjangoBlog Setting settings.py hard-coded credentials
- CVE-2026-66111 PoCliangliangyy DjangoBlog File Upload Endpoint settings.py hard-coded key
- CVE-2026-66121 PoCTransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution authorization
- CVE-2026-66131 PoCTransformerOptimus SuperAGI agent.py get_schedule_data authorization
- CVE-2026-66141 PoCTransformerOptimus SuperAGI project.py get_projects_organisation authorization
- CVE-2026-66151 PoCTransformerOptimus SuperAGI Multipart Upload resources.py upload path traversal
- CVE-2026-66161 PoCTransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgery
- CVE-2026-66171 PoClanggenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side request forgery
- CVE-2026-66181 PoClanggenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery
- CVE-2026-66191 PoClanggenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
- CVE-2026-66201 PoCSonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal
- CVE-2026-66211 PoC1024bit extend-deep index.js prototype pollution
- CVE-2026-66221 PoCBichitroGan ISP Billing Software Customer edit cross site scripting
- CVE-2026-66231 PoCBichitroGan ISP Billing Software Profile users-view cross site scripting
- CVE-2026-66241 PoCBichitroGan ISP Billing Software Pool List add cross site scripting
- CVE-2026-66251 PoCmoxi624 Mogu Blog v2 Picture Storage Service LocalFileServiceImpl.java LocalFileServiceImpl.uploadPictureByUrl server-side request forgery
- CVE-2026-66261 PoCCockpit-HQ Cockpit Asset Handler/Aggregate data query logic injection
- CVE-2026-66281 PoCphili67 Ecclesia CRM Query Viewer view ValidateInput sql injection
- CVE-2026-66291 PoCMetasoft 美特软件 MetaCRM Interface sql.jsp Statement.executeUpdate sql injection
- CVE-2026-66301 PoCTenda F451 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow
- CVE-2026-66311 PoCTenda F451 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow
- CVE-2026-66321 PoCTenda F451 httpd SafeClientFilter fromSafeClientFilter buffer overflow
- CVE-2026-66331 PoCYifang CMS Extended Management L_rbac_admin.php store cross site scripting
- CVE-2026-66341 PoCusememos UpdateInstanceSetting App.tsx memos_access_token improper authorization
- CVE-2026-66351 PoCrowboatlabs rowboat tools_webhook app.py tool_call improper authentication
- CVE-2026-66361 PoCp2r3 convert API buildCache.js Bun.serve path traversal
- CVE-2026-66431 PoCA stack-based buffer overflow vulnerability in the VPN Clients on the ADM
- CVE-2026-66441 PoCA command injection vulnerability was found in the PPTP VPN Clients on the ADM
- CVE-2026-66481 PoCQibo CMS Internal Message cross site scripting
- CVE-2026-66491 PoCQibo CMS headers server-side request forgery
- CVE-2026-66501 PoCZ-BlogPHP ZBA File app_upload.php UnPack unrestricted upload
- CVE-2026-66511 PoCerponline.xyz ERP Online Inventory Edit Item cross site scripting
- CVE-2026-66521 PoCPagekit CMS StringStorage Template PhpEngine.php evaluate eval injection
- CVE-2026-66541 PoCUse-After-Free and Double-Free in IntoIter::drop when element drop panics
- CVE-2026-66621 PoCericc-ch copilot-api Token Endpoint server.ts cors cross-domain policy
- CVE-2026-66641 PoCPgBouncer integer overflow in PgBouncer network packet parsing
- CVE-2026-66661 PoCPgBouncer crash in kill_pool_logins_server_error
- CVE-2026-67131 PoCIncorrect Authorization in GitLab
- CVE-2026-67411 PoCLatePoint <= 5.4.1 - Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability
- CVE-2026-67431 PoCWebSystems WebTOTUM Calendar cross site scripting
- CVE-2026-67441 PoCBagisto Downloadable Link copy server-side request forgery
- CVE-2026-67451 PoCBagisto Custom Scripts cross site scripting
- CVE-2026-67651 PoCInformation disclosure in the Form Autofill component
- CVE-2026-67701 PoCOther issue in the Storage: IndexedDB component
- CVE-2026-67901 PoCIn Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what…
- CVE-2026-67991 PoCComfast CF-N1-S Endpoint mbox-config command injection
- CVE-2026-68071 PoCNSA GRASSMARLIN Improper Restriction of XML External Entity Reference
- CVE-2026-68152 PoCsCVE-2026-6815
- CVE-2026-68211 PoCMissing Authorization in GitLab
- CVE-2026-68262 PoCsConcrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
- CVE-2026-68491 PoCOS Command Injection in TUBITAK BILGEM's Pardus OS My Computer
- CVE-2026-68541 PoCMy Calendar <= 3.7.8 - Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters
- CVE-2026-68571 PoCCamel-infinispan: camel-infinispan: remote code execution via unsafe deserialization
- CVE-2026-68581 PoCTransbank Webpay < 1.14.0 - Unauthenticated Stored XSS
- CVE-2026-68741 PoCericc-ch copilot-api Header token dns rebinding
- CVE-2026-68753 PoCsSandbox Escape in ServiceNow AI Platform
- CVE-2026-68781 PoCByteDance verl grader.py math_equal sandbox
- CVE-2026-68961 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-69601 PoCBookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field
- CVE-2026-69761 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2026-69771 PoCvanna-ai vanna Legacy Flask API improper authorization
- CVE-2026-69781 PoCJiZhiCMS addcache.html htmlspecialchars_decode sql injection
- CVE-2026-69791 PoCdevlikeapro WAHA API Request media.controller.ts server-side request forgery
- CVE-2026-69801 PoCDivyanshu-hash GitPilot-MCP main.py repo_path command injection
- CVE-2026-69811 PoCIhateCreatingUserNames2 AiraHub2 Endpoint AiraHub.py sync_agents server-side request forgery
- CVE-2026-69831 PoCpagekit download server-side request forgery
- CVE-2026-69841 PoCAstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engine
- CVE-2026-69851 PoCCesanta Mongoose TCP Option net_builtin.c handle_opt infinite loop
- CVE-2026-69861 PoCCesanta Mongoose GCM Authentication Tag tls_aes128.c mg_aes_gcm_decrypt signature verification
- CVE-2026-69881 PoCTenda HG10 Boa Service formRouting formRoute buffer overflow
- CVE-2026-69891 PoCTenda F453 Telnet Service telnet TendaTelnet command injection
- CVE-2026-69901 PoCprojeto-siga novo cross site scripting
- CVE-2026-69922 PoCsLinksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection
- CVE-2026-69931 PoCgo-kratos http.DefaultServeMux Fallback server.go NewServer confused deputy