CVE-2026-71000 to CVE-2026-71999
41 CVEs with public proof-of-concept exploits.
- CVE-2026-712031 PoCchangedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
- CVE-2026-712041 PoCchangedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
- CVE-2026-712051 PoCchangedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force
- CVE-2026-712061 PoCshiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
- CVE-2026-712091 PoCaudiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal
- CVE-2026-712111 PoCmlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
- CVE-2026-713001 PoCApache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
- CVE-2026-713031 PoCLemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP,…
- CVE-2026-713071 PoCLemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the…
- CVE-2026-713081 PoCLemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
- CVE-2026-713091 PoCrclone: Incomplete path validation allows backend root escape in serve restic
- CVE-2026-713171 PoCLemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
- CVE-2026-713221 PoCLemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
- CVE-2026-713251 PoCTraefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
- CVE-2026-713261 PoCTraefik: BasicAuth singleflight key collision allows authenticated identity spoofing
- CVE-2026-713271 PoCTraefik: Gateway API route identity collision allows cross-namespace backend hijacking
- CVE-2026-713621 PoCAdobe Commerce | Incorrect Authorization (CWE-863)
- CVE-2026-714171 PoCLemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
- CVE-2026-714301 PoCnode-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result…
- CVE-2026-714361 PoCMermaid XY Charts are vulnerable to an infinite loop DoS
- CVE-2026-714911 PoCsqlparse: Quadratic O(n²) DoS in group_comments
- CVE-2026-714981 PoCnode-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap…
- CVE-2026-715031 PoCDolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Template
- CVE-2026-715041 PoCDolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset
- CVE-2026-715051 PoCDolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route
- CVE-2026-715061 PoCDolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint
- CVE-2026-715071 PoCDolibarr < 24.0.0 REST API Broken Object-Level Authorization via Bank Account Routes
- CVE-2026-715081 PoCDolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint
- CVE-2026-715091 PoCDolibarr < 24.0.0 Expense Report REST API Improper Authorization via Update Endpoint
- CVE-2026-715101 PoCDolibarr < 24.0.0 Users REST API SQL Injection via filter parameter
- CVE-2026-715111 PoCDolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member Endpoints
- CVE-2026-715541 PoCh2: Duplicate Host header could facilitate request smuggling
- CVE-2026-715571 PoCgo-git: Malicious reference names may modify files outside the reference storage
- CVE-2026-718471 PoCRuby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
- CVE-2026-719591 PoCBitwarden Server < 2026.7.2 Audit Log Injection via POST /collect
- CVE-2026-719601 PoCCudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
- CVE-2026-719621 PoCFlowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
- CVE-2026-719641 PoCCyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload
- CVE-2026-719651 PoCCyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature
- CVE-2026-719661 PoCCyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer
- CVE-2026-719691 PoCOP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations