CVE-2026-79000 to CVE-2026-79999
13 CVEs with public proof-of-concept exploits.
- CVE-2026-794831 PoCFastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An…
- CVE-2026-796151 PoCQuiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR
- CVE-2026-796211 PoCCatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient
- CVE-2026-796221 PoCdekdee adobe-xd-mcp file-access-from-request Endpoint xd-parser.ts path traversal
- CVE-2026-797061 PoCBreeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal
- CVE-2026-797921 PoCzackees transcribe-anything Yt-dlp Download ytldp_download.py ytdlp_download os command injection
- CVE-2026-797931 PoCcode-projects Online Shopping System sumit_form.php cross site scripting
- CVE-2026-798041 PoCSililaWijesinghe Food Ordering System search.php sql injection
- CVE-2026-798451 PoCcode-projects Simple Inventory System edit.php sql injection
- CVE-2026-799111 PoCTOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow
- CVE-2026-799121 PoCTOTOLINK N600R cstecgi.cgi getCurrentTime command injection
- CVE-2026-799951 PoCUser Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via IDOR
- CVE-2026-799961 PoCUser Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Settings