CVE-2026-73000 to CVE-2026-73999
53 CVEs with public proof-of-concept exploits.
- CVE-2026-730301 PoCunearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
- CVE-2026-730331 PoCSucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php
- CVE-2026-730342 PoCsDB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header
- CVE-2026-730371 PoCNext AI Draw.io 0.2.1 - 0.4.16 Reflected XSS via unsanitized mcp query parameter
- CVE-2026-730721 PoCVim: Heap Buffer Overflow when Loading a Spell File
- CVE-2026-730861 PoCnanoid: Integer Overflow or Wraparound
- CVE-2026-732281 PoCDjango REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies…
- CVE-2026-732291 PoCDjango REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
- CVE-2026-732311 PoCFaker: helpers.fake exploitable into arbritary code execution
- CVE-2026-732921 PoCSemaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
- CVE-2026-732961 PoCMicrosoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
- CVE-2026-733001 PoCBudibase: SQL Injection via `multipleStatements: true`
- CVE-2026-733011 PoCBudibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
- CVE-2026-733021 PoCBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
- CVE-2026-733031 PoCBudibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
- CVE-2026-733041 PoCBudibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
- CVE-2026-733051 PoCBudibase: Privilege escalation via public role assignment API missing app-level authorization
- CVE-2026-733071 PoCBudibase: SSRF via bare fetch() in uploadUrl during AI table generation
- CVE-2026-733081 PoCBudibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
- CVE-2026-734061 PoCBudibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
- CVE-2026-734091 PoCBudibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
- CVE-2026-734101 PoCBudibase: SSRF via DNS rebinding in the REST datasource integration
- CVE-2026-734241 PoCAstro: Unauthenticated path override in the @astrojs/vercel ISR function
- CVE-2026-734251 PoC@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
- CVE-2026-734291 PoCRussh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
- CVE-2026-734811 PoCphpList < 3.7.0-RC5 Cross-Site Request Forgery via Bounce Rules
- CVE-2026-734821 PoCphpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php
- CVE-2026-734981 PoCMCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_attachment
- CVE-2026-735021 PoCkin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has…
- CVE-2026-735051 PoCOh My Posh: Arbitrary command execution via template injection in the path segment
- CVE-2026-735061 PoCOh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
- CVE-2026-735091 PoCOpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
- CVE-2026-735141 PoCPostGIS address_standardizer Out-of-Bounds Write via standardize_address()
- CVE-2026-735151 PoCPostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer
- CVE-2026-735191 PoCWolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
- CVE-2026-735611 PoCHub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
- CVE-2026-735641 PoCfrp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
- CVE-2026-735661 PoCnode-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
- CVE-2026-735681 PoCpy-libp2p: yamux connection DoS via oversized data frame
- CVE-2026-735708 PoCsKEVA remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is…
- CVE-2026-736331 PoCApache Struts: Unbounded read of a JSON request body
- CVE-2026-736471 PoCQuasar Framework: Prototype pollution in Quasar extend() utility
- CVE-2026-736501 PoCSVGO: removeScripts plugin leaves some executable scripts intact
- CVE-2026-736511 PoCTypeORM: migration:generate template-literal code injection
- CVE-2026-736541 PoCTrigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
- CVE-2026-736701 PoCCMS Admin SQL Injection via db_data.php table_name Parameter
- CVE-2026-736711 PoCSaurus CMS Unauthenticated Open Redirect via logout url parameter
- CVE-2026-736731 PoCNetis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication
- CVE-2026-736782 PoCsMindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
- CVE-2026-736791 PoCImpressCMS Authenticated RCE via PHP Custom Tag eval()
- CVE-2026-738451 PoCCKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMqaServer`)
- CVE-2026-738471 PoCEmlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
- CVE-2026-739741 PoClinuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)