CVE-2026-77000 to CVE-2026-77999
58 CVEs with public proof-of-concept exploits.
- CVE-2026-770001 PoCWP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login Flow
- CVE-2026-770011 PoCSocial Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Unauthenticated Authentication Bypass
- CVE-2026-770021 PoCSmilePass Selfie Login <= 1.0.2 - Unauthenticated Authentication Bypass
- CVE-2026-770031 PoCContent Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_content_mask
- CVE-2026-770041 PoCComfast CF-N1-S mbox-config sprintf command injection
- CVE-2026-770071 PoCHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButton API Secret Disclosure
- CVE-2026-770081 PoCHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Settings Update
- CVE-2026-770091 PoCWatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console
- CVE-2026-770101 PoCHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Join URL Disclosure and Class Access Code Bypass
- CVE-2026-770121 PoCIcollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password
- CVE-2026-770131 PoCIcollect <= 1.0.0 - Unauthenticated User and Term Creation via Unrestricted Method Dispatch
- CVE-2026-770161 PoCWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass Assignment
- CVE-2026-770171 PoCWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Read via Candidate Profile Mass Assignment
- CVE-2026-770181 PoCWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate Profile Mass Assignment
- CVE-2026-770191 PoCCodeAstro Apartment Visitor Management System forgotpw.php sql injection
- CVE-2026-770201 PoCCodeAstro Apartment Visitor Management System password-recovery.php sql injection
- CVE-2026-770221 PoCComfast CF-N1-S SSID Configuration mbox-config sub_44B438 stack-based overflow
- CVE-2026-770251 PoCitsourcecode Hospital Management System viewappointmentpending.php sql injection
- CVE-2026-770311 PoCTenda CH22 formcreateFileName command injection
- CVE-2026-770361 PoCelunez eladmin GenConfigController improper authorization
- CVE-2026-771131 PoCPath Traversal Vulnerability in apport-unpack
- CVE-2026-771151 PoCBrave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters
- CVE-2026-771161 PoCBrave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview
- CVE-2026-771481 PoCComfast CF-N1-S Web Management mbox-config sub_44B50C stack-based overflow
- CVE-2026-773541 PoCkin-openapi: Uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
- CVE-2026-773911 PoCSourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP cross-site request forgery
- CVE-2026-773921 PoCSourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.php saveUser sql injection
- CVE-2026-774151 PoCJSONata: Arbitrary Code Execution via crafted JSONata expressions
- CVE-2026-776471 PoCSPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is…
- CVE-2026-776811 PoCCodeAstro Online Job Portal update-profile.php unrestricted upload
- CVE-2026-776831 PoCComfast CF-N1-S mbox-config system command injection
- CVE-2026-776861 PoCDolibarr Account card.php improper authorization
- CVE-2026-776931 PoCOrder Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajax
- CVE-2026-776941 PoCEventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_token
- CVE-2026-776951 PoCWoo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and Manipulation
- CVE-2026-777011 PoCWCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest Orders
- CVE-2026-777041 PoCAmelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Update and Self-Approval
- CVE-2026-777541 PoCKirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis
- CVE-2026-777571 PoCDirectorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing Submission
- CVE-2026-777581 PoCStripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed…
- CVE-2026-777641 PoCGamiPress < 7.9.9.6 - Subscriber+ Arbitrary User Points and Achievement Award via Watch-Video Listeners
- CVE-2026-777821 PoCRank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txt
- CVE-2026-777831 PoCRank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure
- CVE-2026-777841 PoCRank Math SEO < 1.0.277 - Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as
- CVE-2026-777851 PoCRank Math SEO < 1.0.277 - Author+ Non-Public Post Content Disclosure via Abilities API
- CVE-2026-777861 PoCRank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo Ability
- CVE-2026-777871 PoCRank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk
- CVE-2026-777881 PoCRank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas
- CVE-2026-777891 PoCStripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Modification via IDOR
- CVE-2026-777901 PoCRegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' Parameter
- CVE-2026-777921 PoCRegistrationMagic < 6.0.9.9 - Unauthenticated Stored XSS via Rating Field
- CVE-2026-777931 PoCRegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field
- CVE-2026-777941 PoCRegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity
- CVE-2026-778062 PoCsSPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is…
- CVE-2026-779391 PoCFlextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint
- CVE-2026-779451 PoCTRENDnet TEW-821DAP ssi upload.cgi command injection
- CVE-2026-779461 PoCTRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow
- CVE-2026-779881 PoCTRENDnet TEW-823DRU CLI Configuration Tool nvram_get command injection