CVE-2026-74000 to CVE-2026-74999
18 CVEs with public proof-of-concept exploits.
- CVE-2026-742321 PoCZbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-742331 PoCZbtlink MQWrt infosrvd Command Injection
- CVE-2026-742511 PoCJoomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
- CVE-2026-742521 PoCJoomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
- CVE-2026-748421 PoCKira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image server-side request forgery
- CVE-2026-748431 PoCWavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow
- CVE-2026-748511 PoCPods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback
- CVE-2026-749271 PoCMultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint
- CVE-2026-749281 PoCWP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello Import Routes
- CVE-2026-749291 PoCWP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOR
- CVE-2026-749301 PoCWP Project Manager 2.2.0 - 4.0.6 - Subscriber+ User Activity Feed Disclosure via IDOR
- CVE-2026-749321 PoCWP Fastest Cache 0.9.0.3 - 1.5.0 - Unauthenticated Stored XSS via Host Header Cache Poisoning
- CVE-2026-749361 PoCUse-after-free in the JavaScript: WebAssembly component
- CVE-2026-749391 PoCPrivilege escalation in the DOM: Navigation component
- CVE-2026-749431 PoCUse-after-free in the Graphics: ImageLib component
- CVE-2026-749451 PoCInformation disclosure in the Graphics: Text component
- CVE-2026-749701 PoCSite isolation issue in the Graphics component
- CVE-2026-749921 PoCKirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload