CVE-2026-78000 to CVE-2026-78999
65 CVEs with public proof-of-concept exploits.
- CVE-2026-780491 PoCSysterel S2OPC AddNodes Service sopc_node_mgt_helper_internal.c out-of-bounds
- CVE-2026-780501 PoCComfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow
- CVE-2026-780511 PoCalexta69 MeTube Cookie File cookies.txt file access
- CVE-2026-780541 PoCSourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting
- CVE-2026-780551 PoCSourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting
- CVE-2026-780561 PoCsambitraj Student-Management-System Dashboard sql injection
- CVE-2026-780571 PoCsambitraj Student-Management-System Management Mutation sql injection
- CVE-2026-780591 PoCSourceCodester Stock Management System printOrder.php cross site scripting
- CVE-2026-780601 PoCSourceCodester Stock Management System getOrderReport.php cross site scripting
- CVE-2026-780631 PoCTenda CH22 editFileName formeditFileName command injection
- CVE-2026-780701 PoCJoomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2
- CVE-2026-780711 PoCJoomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2
- CVE-2026-781121 PoCitsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection
- CVE-2026-781151 PoCSourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php improper authorization
- CVE-2026-781222 PoCsdocker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
- CVE-2026-781251 PoCLearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure
- CVE-2026-781371 PoCStoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart
- CVE-2026-781381 PoCFinale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html
- CVE-2026-781391 PoCNotifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR
- CVE-2026-781401 PoCDromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine
- CVE-2026-781411 PoCTenda CH22 exeCommand formexeCommand command injection
- CVE-2026-781421 PoCcode-projects Barangay Resident Profiling Management System Restore/Delete archived_records.php authorization
- CVE-2026-781431 PoCcode-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection
- CVE-2026-781441 PoCcode-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization
- CVE-2026-781451 PoCCTFd __init__.py _is_safe_url redirect
- CVE-2026-781461 PoCNoptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page
- CVE-2026-781511 PoCFormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission Response
- CVE-2026-781531 PoCRestrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization
- CVE-2026-781611 PoCwarmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds write
- CVE-2026-781661 PoCprovectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection
- CVE-2026-781671 PoCEFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication
- CVE-2026-781681 PoCEFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication
- CVE-2026-781691 PoCUTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow
- CVE-2026-781701 PoCUTT HiPER 1200GW formConfigFastDirectionW strcpy buffer overflow
- CVE-2026-781711 PoCitsourcecode Sales and Inventory System processlogin.php sql injection
- CVE-2026-781771 PoCTanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injection
- CVE-2026-781811 PoCractivejs ractive Keypath Ractive#set prototype pollution
- CVE-2026-781821 PoCShenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System plansImmediate PlanController.getImmediatePlans sql injection
- CVE-2026-781851 PoCitsourcecode Sales and Inventory System cust_edit.php sql injection
- CVE-2026-781861 PoCOpen5GS HSS hss-cx-path.c assertion
- CVE-2026-781871 PoCPiwigo Public Authentication cross site scripting
- CVE-2026-781971 PoCSourceCodester Simple Online Food Ordering System ajax.php save_user sql injection
- CVE-2026-781981 PoCSourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection
- CVE-2026-781991 PoCSourceCodester Simple Online Food Ordering System view_prod.php sql injection
- CVE-2026-782001 PoCitsourcecode Library Management System editbooks.php sql injection
- CVE-2026-782011 PoCitsourcecode Payroll System admin_class.php login sql injection
- CVE-2026-782021 PoCitsourcecode Payroll System admin_class.php save_settings unrestricted upload
- CVE-2026-782441 PoCitsourcecode Real Estate Management System search.php sql injection
- CVE-2026-782451 PoCitsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted upload
- CVE-2026-782461 PoCitsourcecode Online Clinic Management System Admin Login login.php sql injection
- CVE-2026-782471 PoCSourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection
- CVE-2026-782481 PoCSourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection
- CVE-2026-782501 PoCbytebot-ai bytebot Agent Execution Workflow infinite loop
- CVE-2026-783291 PoCApache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the…
- CVE-2026-783331 PoC12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode Event Log
- CVE-2026-783641 PoCMW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List
- CVE-2026-784301 PoCsworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injection
- CVE-2026-784341 PoCFaveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_reply missing authentication
- CVE-2026-784351 PoCFaveo Helpdesk Logo SettingsController.php unlink path traversal
- CVE-2026-786381 PoCpeerigon unzip-crx/unzip-crx-3 Archive Extraction index.js unzip path traversal
- CVE-2026-786541 PoCcleverbrush framework/deep deepExtend.ts deepExtend prototype pollution
- CVE-2026-786561 PoCitsourcecode Sales and Inventory System cust_del.php sql injection
- CVE-2026-789031 PoCIncomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer…
- CVE-2026-789041 PoCType confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside…
- CVE-2026-789051 PoCType confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside…