CVE-2026-75000 to CVE-2026-75999
43 CVEs with public proof-of-concept exploits.
- CVE-2026-750111 PoCkylecui NetForensicMCP index.js execAsync command injection
- CVE-2026-750121 PoCTOTOLINK EX1200L Password Configuration cstecgi.cgi setPasswordCfg null pointer dereference
- CVE-2026-750131 PoCTOTOLINK EX1200L cstecgi.cgi setWizardCfg null pointer dereference
- CVE-2026-750141 PoCSourceCodester Pet Grooming Management Software get_barcode_data.php sql injection
- CVE-2026-750771 PoCSourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting
- CVE-2026-750781 PoCSourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting
- CVE-2026-750791 PoCSourceCodester Class and Exam Timetabling System edit_subject2.php sql injection
- CVE-2026-750801 PoCSourceCodester Class and Exam Timetabling System edit_subject1.php sql injection
- CVE-2026-750811 PoCWebkul Bagisto store behavioral workflow
- CVE-2026-750821 PoCWebkul Bagisto Customer-Registration Notification Email register cross site scripting
- CVE-2026-750861 PoCitsourcecode Hospital Management System viewroom.php sql injection
- CVE-2026-750871 PoCitsourcecode Hospital Management System viewdepartment.php sql injection
- CVE-2026-750881 PoCitsourcecode Hospital Management System viewbilling.php sql injection
- CVE-2026-750891 PoCPHPGurukul Complaint Management System check_availability.php sql injection
- CVE-2026-750901 PoCEricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf_to_hf_tokenizer out-of-bounds
- CVE-2026-750931 PoCsonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size
- CVE-2026-750941 PoCCOMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection
- CVE-2026-751301 PoCContext7 2.1.2 Prompt Injection via Custom AI Instructions
- CVE-2026-751341 PoCSEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload
- CVE-2026-754171 PoCA SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within…
- CVE-2026-754181 PoCA path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with…
- CVE-2026-754191 PoCgo-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in…
- CVE-2026-756044 PoCsNext.js: Unauthenticated Remote Code Execution on windows-hosted servers
- CVE-2026-756161 PoCCommand Injection in Router Web Management Interface
- CVE-2026-757731 PoCkarakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
- CVE-2026-757741 PoCkarakeep-app karakeep OAuth Sign-In auth.ts improper authentication
- CVE-2026-757781 PoCcode-projects Task Management System Login Form index.php select_with_multiple_condition sql injection
- CVE-2026-757831 PoCTRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow
- CVE-2026-757841 PoCTRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow
- CVE-2026-757961 PoCAI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP User Tools
- CVE-2026-757971 PoCAI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter
- CVE-2026-757981 PoCAI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor Assistant
- CVE-2026-758601 PoCJSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update
- CVE-2026-758711 PoCServer-Side Request Forgery (SSRF) in GitLab AI Gateway
- CVE-2026-758761 PoCxianrendzw EasyReport Move Operations ModuleController.java sql injection
- CVE-2026-758771 PoCTRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow
- CVE-2026-758981 PoCRAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
- CVE-2026-759761 PoCTRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow
- CVE-2026-759781 PoCxianrendzw EasyReport QueryerFactory DataSourceController.java DataSourceController.add permission
- CVE-2026-759791 PoCxianrendzw EasyReport SQL Preview Endpoint DesignerController.java previewSqlText special elements in template engine
- CVE-2026-759841 PoCTRENDnet TEW-823DRU admin.cgi command injection
- CVE-2026-759851 PoCTRENDnet Router ping.cgi command injection
- CVE-2026-759861 PoCcode-projects Online Job Portal System Password Recovery ForPass.php sql injection