CVE-2026-7000 to CVE-2026-7999
426 CVEs with public proof-of-concept exploits.
- CVE-2026-70111 PoCMaxSite CMS Antispam Plugin plugin_antispam cross site scripting
- CVE-2026-70121 PoCMaxSite CMS Redirect Plugin cross site scripting
- CVE-2026-70131 PoCMaxSite CMS mail_send Plugin cross site scripting
- CVE-2026-70141 PoCMaxSite CMS down_count Plugin cross site scripting
- CVE-2026-70151 PoCMaxSite CMS Guestbook Plugin cross site scripting
- CVE-2026-70161 PoCMaxSite CMS ushki Plugin cross site scripting
- CVE-2026-70181 PoCDatavane Datavines JWT Token TokenManager.java hard-coded key
- CVE-2026-70191 PoCTenda F456 P2pListFilter fromP2pListFilter buffer overflow
- CVE-2026-70201 PoCOllama Tensor Model Transfer transfer.go digestToPath path traversal
- CVE-2026-70211 PoCSmythOS sre Connector Service utils.ts information disclosure
- CVE-2026-70221 PoCSmythOS sre HTTP Header AgentRuntime.class.ts AgentRuntime improper authentication
- CVE-2026-70231 PoCByteDance coze-studio databaseTool database_impl.go ExecuteSQL sql injection
- CVE-2026-70241 PoCrawchen sims deleteFileServlet Endpoint DeleteFileServlet.java path traversal
- CVE-2026-70251 PoCTypecho Ping Back Service Endpoint Service.php sendPingHandle server-side request forgery
- CVE-2026-70282 PoCsCodeAstro Online Job Portal All Jobs delete-jobs.php sql injection
- CVE-2026-70291 PoCTenda F456 addressNat fromaddressNat buffer overflow
- CVE-2026-70301 PoCTenda F456 RouteStatic fromRouteStatic buffer overflow
- CVE-2026-70311 PoCTenda F456 SafeMacFilter fromSafeMacFilter buffer overflow
- CVE-2026-70321 PoCTenda F456 SafeEmailFilter buffer overflow
- CVE-2026-70331 PoCTenda F456 SafeClientFilter fromSafeClientFilter buffer overflow
- CVE-2026-70341 PoCTenda FH1202 httpd WrlExtraSet stack-based overflow
- CVE-2026-70351 PoCTenda FH1202 httpd WrlclientSet fromWrlclientSet stack-based overflow
- CVE-2026-70361 PoCTenda i9 HTTP R7WebsSecurityHandlerfunction path traversal
- CVE-2026-70371 PoCTotolink A8000RU CGI cstecgi.cgi setVpnPassCfg os command injection
- CVE-2026-70381 PoCtufantunc ssh-mcp Command Line index.ts insufficiently protected credentials
- CVE-2026-70391 PoCtufantunc ssh-mcp index.ts shell.write command injection
- CVE-2026-70411 PoC666ghj MiroFish Werkzeug Debugger PIN console information disclosure
- CVE-2026-70421 PoC666ghj MiroFish REST API Endpoint __init__.py create_app missing authentication
- CVE-2026-70431 PoCGreenCMS index.php pluginAddLocal unrestricted upload
- CVE-2026-70441 PoCGreenCMS index.php themeadd unrestricted upload
- CVE-2026-70531 PoCTenda F456 httpd L7Prot frmL7ProtForm buffer overflow
- CVE-2026-70541 PoCTenda F456 httpd PPTPDClient fromPptpUserAdd buffer overflow
- CVE-2026-70551 PoCTenda F456 httpd VirtualSer fromVirtualSer buffer overflow
- CVE-2026-70561 PoCTenda F456 httpd SafeUrlFilter fromSafeUrlFilter buffer overflow
- CVE-2026-70571 PoCTenda F456 httpd setcfm buffer overflow
- CVE-2026-70581 PoC666ghj MiroFish Inter-Process Communication simulation_ipc.py SimulationIPCClient.send_command command injection
- CVE-2026-70591 PoC666ghj MiroFish Query Parameter simulation.py get_simulation_posts path traversal
- CVE-2026-70601 PoCliyupi yu-picture MyBatis-Plus PictureServiceImpl.java PageRequest sql injection
- CVE-2026-70611 PoCToowiredd chatgpt-mcp-server MCP/HTTP docker.service.ts os command injection
- CVE-2026-70621 PoCIntina47 context-sync Git Integration git-integration.ts os command injection
- CVE-2026-70631 PoCcode-projects Employee Management System Endpoint eprocess.php sql injection
- CVE-2026-70641 PoCAgentDeskAI browser-tools-mcp browser-connector.ts os command injection
- CVE-2026-70651 PoCBidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-side request forgery
- CVE-2026-70661 PoCchoieastsea simple-openstack-mcp server.py exec_openstack os command injection
- CVE-2026-70671 PoCD-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection
- CVE-2026-70681 PoCD-Link DIR-825 nmbd sserver.c NMBD_process buffer overflow
- CVE-2026-70691 PoCD-Link DIR-825 miniupnpd upnpsoap.c AddPortMapping buffer overflow
- CVE-2026-70702 PoCscode-projects Inventory Management System Login sql injection
- CVE-2026-70712 PoCsCodeAstro Online Job Portal user-cvs file information disclosure
- CVE-2026-70721 PoCCodePanda Source canteen_management_system login.php sql injection
- CVE-2026-70731 PoCitsourcecode Construction Management System execute.php sql injection
- CVE-2026-70741 PoCitsourcecode Construction Management System execute1.php sql injection
- CVE-2026-70751 PoCitsourcecode Construction Management System locations.php sql injection
- CVE-2026-70761 PoCitsourcecode Courier Management System edit_branch.php sql injection
- CVE-2026-70771 PoCitsourcecode Courier Management System edit_parcel.php sql injection
- CVE-2026-70781 PoCTenda F456 httpd SetIpBind fromSetIpBind buffer overflow
- CVE-2026-70791 PoCTenda F456 httpd AdvSetWan fromAdvSetWan buffer overflow
- CVE-2026-70801 PoCTenda F456 httpd PPTPUserSetting fromPPTPUserSetting buffer overflow
- CVE-2026-70811 PoCTenda F456 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow
- CVE-2026-70821 PoCTenda F456 httpd WrlExtraSet formWrlExtraSet buffer overflow
- CVE-2026-70831 PoClikeadmin-likeshop likeadmin_php dataTable Admin API DataTableLists.php queryResult sql injection
- CVE-2026-70841 PoCHBAI-Ltd Toonflow-app getCodeByLink Endpoint getCodeByLink.ts fetch server-side request forgery
- CVE-2026-70851 PoCHBAI-Ltd Toonflow-app downloadApp Endpoint downloadApp.ts z.url path traversal
- CVE-2026-70861 PoCHBAI-Ltd Toonflow-app Storyboard Export replaceUrl.ts updateStoryboardUrl path traversal
- CVE-2026-70871 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-70881 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-70892 PoCscode-projects Home Service System Appointment Booking booking.php cross site scripting
- CVE-2026-70901 PoCcode-projects Chat System send_message.php cross site scripting
- CVE-2026-70911 PoCcode-projects Invoice System in Laravel User Management user improper authorization
- CVE-2026-70921 PoCcode-projects Invoice System in Laravel Profile profile improper authorization
- CVE-2026-70931 PoCcode-projects Invoice System in Laravel Invoice Endpoint invoice improper authorization
- CVE-2026-70941 PoCShadowCloneLabs GlutamateMCPServers puppeteer_navigate index.ts server-side request forgery
- CVE-2026-70951 PoCcode-projects Employee Management System edit.php cross site scripting
- CVE-2026-70961 PoCTenda HG3 formgponConf os command injection
- CVE-2026-70971 PoCTenda F456 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow
- CVE-2026-70981 PoCTenda F456 httpd DhcpListClient fromDhcpListClient buffer overflow
- CVE-2026-70991 PoCTenda F456 httpd QuickIndex formQuickIndex buffer overflow
- CVE-2026-71001 PoCTenda F456 httpd Natlimit fromNatlimitof buffer overflow
- CVE-2026-71011 PoCTenda F456 httpd WrlclientSet fromWrlclientSet buffer overflow
- CVE-2026-71021 PoCTenda F456 httpd WriteFacMac FromWriteFacMac command injection
- CVE-2026-71071 PoCcode-projects Invoice System in Laravel company unrestricted upload
- CVE-2026-71081 PoCcode-projects Invoice System in Laravel cross-site request forgery
- CVE-2026-71091 PoCcode-projects Invoice System in Laravel API Endpoint item improper authorization
- CVE-2026-71101 PoCcode-projects Invoice System in Laravel item cross site scripting
- CVE-2026-71121 PoCNousResearch hermes-agent API_SERVER_KEY api_server.py _check_auth improper authentication
- CVE-2026-71131 PoCNousResearch hermes-agent Webhooks Endpoint webhook.py missing authentication
- CVE-2026-71141 PoCcode-projects Employee Management System edit.php sql injection
- CVE-2026-71151 PoCcode-projects Employee Management System delete.php sql injection
- CVE-2026-71161 PoCcode-projects Employee Management System mark.php cross site scripting
- CVE-2026-71171 PoCcode-projects Employee Management System approve.php sql injection
- CVE-2026-71181 PoCcode-projects Employee Management System cancel.php sql injection
- CVE-2026-71191 PoCTenda HG3 formCountrystr os command injection
- CVE-2026-71211 PoCTotolink A8000RU CGI cstecgi.cgi setWizardCfg os command injection
- CVE-2026-71221 PoCTotolink A8000RU CGI cstecgi.cgi setUPnPCfg os command injection
- CVE-2026-71231 PoCTotolink A8000RU CGI cstecgi.cgi setIptvCfg os command injection
- CVE-2026-71241 PoCTotolink A8000RU CGI cstecgi.cgi setIpv6LanCfg os command injection
- CVE-2026-71251 PoCTotolink A8000RU CGI cstecgi.cgi setWiFiEasyCfg os command injection
- CVE-2026-71261 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-71271 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-71281 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-71291 PoCSourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
- CVE-2026-71301 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-71311 PoCcode-projects Online Lot Reservation System loginuser.php sql injection
- CVE-2026-71321 PoCcode-projects Online Lot Reservation System download.php readfile path traversal
- CVE-2026-71331 PoCcode-projects Online Lot Reservation System activity.php unrestricted upload
- CVE-2026-71341 PoCcode-projects Online Lot Reservation System edithousepic.php unrestricted upload
- CVE-2026-71351 PoCGPAC MP4Box box_code_base.c elng_box_read out-of-bounds
- CVE-2026-71361 PoCTotolink A8000RU CGI cstecgi.cgi setDmzCfg os command injection
- CVE-2026-71371 PoCTotolink A8000RU CGI cstecgi.cgi setStorageCfg os command injection
- CVE-2026-71381 PoCTotolink A8000RU CGI cstecgi.cgi setNtpCfg os command injection
- CVE-2026-71391 PoCTotolink A8000RU CGI cstecgi.cgi setWiFiAclRules os command injection
- CVE-2026-71401 PoCTotolink A8000RU CGI cstecgi.cgi CsteSystem os command injection
- CVE-2026-71411 PoCvLLM KV Block kv_cache_interface.py has_mamba_layers uninitialized resource
- CVE-2026-71421 PoCWooey API Endpoint scripts.py add_or_update_script improper authorization
- CVE-2026-71431 PoC1000 Projects Portfolio Management System MCA block_status.php sql injection
- CVE-2026-71441 PoC1000 Projects Portfolio Management System MCA update_passwd_process.php authorization
- CVE-2026-71461 PoCAlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery
- CVE-2026-71471 PoCJoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery
- CVE-2026-71481 PoCCodeAstro Online Classroom addnewfaculty sql injection
- CVE-2026-71491 PoCdexhunter kaggle-mcp server.py prepare_kaggle_dataset path traversal
- CVE-2026-71501 PoCdh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forgery
- CVE-2026-71511 PoCTenda HG3 formIPv6Routing formUploadConfig stack-based overflow
- CVE-2026-71521 PoCTotolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection
- CVE-2026-71531 PoCTotolink A8000RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection
- CVE-2026-71541 PoCTotolink A8000RU CGI cstecgi.cgi setAdvancedInfoShow os command injection
- CVE-2026-71551 PoCTotolink A8000RU CGI cstecgi.cgi setLoginPasswordCfg os command injection
- CVE-2026-71561 PoCTotolink A8000RU CGI cstecgi.cgi CsteSystem os command injection
- CVE-2026-71571 PoCdisler aider-mcp-server aider_ai_code server.py command injection
- CVE-2026-71581 PoCdmitryglhf mcp-url-downloader server.py _validate_url_safe server-side request forgery
- CVE-2026-71591 PoCdouinc mkdocs-mcp-plugin server.py list_documents path traversal
- CVE-2026-71601 PoCTenda HG3 formTracert command injection
- CVE-2026-71771 PoCChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgery
- CVE-2026-71781 PoCChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery
- CVE-2026-71791 PoCOSPG binwalk WinCE Extraction Plugin winceextract.py read_null_terminated_string path traversal
- CVE-2026-71941 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-71961 PoCCodeAstro Online Classroom guestdetails sql injection
- CVE-2026-71991 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
- CVE-2026-72001 PoCSourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
- CVE-2026-72021 PoCTotolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection
- CVE-2026-72031 PoCTotolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection
- CVE-2026-72041 PoCTotolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection
- CVE-2026-72051 PoCduartium papers-mcp-server main.py search_papers path traversal
- CVE-2026-72061 PoCdubydu sqlite-mcp entry.py extract_to_json sql injection
- CVE-2026-72111 PoCdvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injection
- CVE-2026-72121 PoCedvardlindelof notes-mcp notes_mcp.py path traversal
- CVE-2026-72131 PoCef10007 MLOps_MCP save_file Tool fastmcp_server.py path traversal
- CVE-2026-72141 PoCeghuzefa engineer-your-data server.py file_inf path traversal
- CVE-2026-72151 PoCegtai gmx-vmd-mcp VMD Launch mcp_server.py launch_vmd_gui_tool command injection
- CVE-2026-72161 PoCdonchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversal
- CVE-2026-72171 PoCDeepractice PromptX Document File index.ts read_pdf absolute path traversal
- CVE-2026-72181 PoCTotolink N300RT libapmib.so formWsc is_cmd_string_valid buffer overflow
- CVE-2026-72191 PoCTotolink N300RT formIpQoS buffer overflow
- CVE-2026-72201 PoCjackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection
- CVE-2026-72211 PoCTencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery
- CVE-2026-72222 PoCscode-projects Coaching Management System Complaint Form complaint.php cross site scripting
- CVE-2026-72231 PoCBigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery
- CVE-2026-72241 PoCSourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injection
- CVE-2026-72251 PoCSourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injection
- CVE-2026-72261 PoCSourceCodester Pizzafy Ecommerce System ajax.php login2 sql injection
- CVE-2026-72271 PoCSourceCodester Pizzafy Ecommerce System ajax.php login sql injection
- CVE-2026-72282 PoCsSourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
- CVE-2026-72292 PoCscode-projects Coaching Management System POST reply.php sql injection
- CVE-2026-72331 PoCArtifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
- CVE-2026-72341 PoCBrowserOperator browser-operator-core server.js startsWith path traversal
- CVE-2026-72351 PoCErlichLiu claude-agent-sdk-master route.ts path traversal
- CVE-2026-72371 PoCAgiFlow scaffold-mcp write-to-file Tool index.ts path traversal
- CVE-2026-72381 PoCcode-projects Online Music Site AdminUpdateAlbum.php unrestricted upload
- CVE-2026-72401 PoCTotolink A8000RU CGI cstecgi.cgi setVpnAccountCfg os command injection
- CVE-2026-72411 PoCTotolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
- CVE-2026-72421 PoCTotolink A8000RU CGI cstecgi.cgi setOpenVpnClientCfg os command injection
- CVE-2026-72431 PoCTotolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection
- CVE-2026-72441 PoCTotolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injection
- CVE-2026-72471 PoCD-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow
- CVE-2026-72481 PoCD-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow
- CVE-2026-72501 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-72641 PoCSourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injection
- CVE-2026-72651 PoCSourceCodester Pizzafy Ecommerce System index.php category sql injection
- CVE-2026-72661 PoCSourceCodester Pizzafy Ecommerce System ajax.php save_order sql injection
- CVE-2026-72671 PoCSourceCodester Pizzafy Ecommerce System view_prod.php sql injection
- CVE-2026-72681 PoCSourceCodester Pizzafy Ecommerce System ajax.php save_category sql injection
- CVE-2026-72691 PoCSourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
- CVE-2026-72701 PoCLocal privilege escalation via execve()
- CVE-2026-72711 PoCDV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversal
- CVE-2026-72721 PoCWilliamCloudQi matlab-mcp-server MCP index.ts execute_matlab_code path traversal
- CVE-2026-72811 PoCSourceCodester Pharmacy Sales and Inventory System index.php supplier cross site scripting
- CVE-2026-72821 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php delete_expired sql injection
- CVE-2026-72831 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection
- CVE-2026-72881 PoCD-Link DIR-825M formVpnConfigSetup sub_4151FC buffer overflow
- CVE-2026-72891 PoCD-Link DIR-825M formWanConfigSetup sub_414BA8 buffer overflow
- CVE-2026-72901 PoCJeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
- CVE-2026-72911 PoCo2oa URL Fetching FileAction.java FileAction server-side request forgery
- CVE-2026-72921 PoCo2oa NodeAgent NodeAgent.java syncFile improper authorization
- CVE-2026-72931 PoCSourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
- CVE-2026-72941 PoCSourceCodester Pizzafy Ecommerce System index.php save_settings cross site scripting
- CVE-2026-72951 PoCSourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting
- CVE-2026-72961 PoCSourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting
- CVE-2026-72971 PoCSourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting
- CVE-2026-72991 PoCCVE-2026-7299
- CVE-2026-73031 PoCXuxueli xxl-job Execution Log JobLogController.java logDetailCat resource injection
- CVE-2026-73051 PoCXuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request forgery
- CVE-2026-73061 PoCXuxueli xxl-job OpenAPI Endpoint OpenApiController.java hard-coded key
- CVE-2026-73141 PoCeiceblue spire-doc-mcp-server base.py get_doc_path path traversal
- CVE-2026-73151 PoCeiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal
- CVE-2026-73161 PoCeiliyaabedini aider-mcp code_with_ai aider_mcp.py command injection
- CVE-2026-73171 PoCGrav CMS Cache Value FileCache.php doGet deserialization
- CVE-2026-73181 PoCelie mcp-project research_server.py search_papers path traversal
- CVE-2026-73191 PoCelinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal
- CVE-2026-73771 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-73841 PoCezequiroga mcp-bases research_server.py search_papers path traversal
- CVE-2026-73851 PoCDecent Comments < 3.0.2 - Unauthenticated Email Address Disclosure
- CVE-2026-73861 PoCfatbobman mail-mcp-bridge mail_mcp_server.py path traversal
- CVE-2026-73881 PoCEyouCMS Template File FilemanagerLogic.php editFile code injection
- CVE-2026-73891 PoCEyouCMS common.php GetSortData sql injection
- CVE-2026-73901 PoCSourceCodester Pharmacy Sales and Inventory System index.php customer cross site scripting
- CVE-2026-73911 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection
- CVE-2026-73922 PoCsSourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection
- CVE-2026-73932 PoCsSourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload
- CVE-2026-73942 PoCsSourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection
- CVE-2026-73961 PoCNousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal
- CVE-2026-73971 PoCNousResearch hermes-agent file_tools.py _check_sensitive_path symlink
- CVE-2026-73981 PoCflorensiawidjaja BioinfoMCP Upload Endpoint app.py upload path traversal
- CVE-2026-74001 PoCgeekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversal
- CVE-2026-74012 PoCsSourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting
- CVE-2026-74031 PoCgeldata gel-mcp server.py fetch_rule path traversal
- CVE-2026-74041 PoCgetsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal
- CVE-2026-74071 PoCSourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection
- CVE-2026-74081 PoCSourceCodester Pizzafy Ecommerce System ajax.php save_menu sql injection
- CVE-2026-74091 PoCSourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection
- CVE-2026-74101 PoCSourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection
- CVE-2026-74161 PoCPolarVista xcode-mcp-server MCP index.ts run_tests os command injection
- CVE-2026-74171 PoCAlgovate xhs-mcp MCP mcp.server.ts xhs_publish_content server-side request forgery
- CVE-2026-74181 PoCUTT HiPER 1250GW NTP strcpy buffer overflow
- CVE-2026-74191 PoCUTT HiPER 1250GW formTaskEdit_ap strcpy buffer overflow
- CVE-2026-74201 PoCUTT HiPER 1250GW ConfigAdvideo strcpy buffer overflow
- CVE-2026-74271 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-74431 PoCBurtTheCoder mcp-dnstwist MCP index.ts fuzz_domain os command injection
- CVE-2026-74451 PoCZachHandley ZMCPTools MCP Log Resource ResourceManager.ts path traversal
- CVE-2026-74461 PoCVetCoders mcp-server-semgrep MCP index.ts create_rule os command injection
- CVE-2026-74471 PoCSourceCodester Pet Grooming Management Software update_customer.php sql injection
- CVE-2026-74581 PoCUser Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint
- CVE-2026-74591 PoCSimple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing…
- CVE-2026-74651 PoCSpectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block…
- CVE-2026-74671 PoCRead More & Accordion <= 3.5.7 - Privilege Escalation via importData
- CVE-2026-74681 PoC1024-lab smart-admin Demo Site index.html access control
- CVE-2026-74691 PoCTenda 4G300 DelFil sub_425A28 command injection
- CVE-2026-74701 PoCTenda 4G300 SafeMacFilter sub_427C3C stack-based overflow
- CVE-2026-74731 PoCKEVArista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
- CVE-2026-74741 PoCNomad vulnerable to path traversal in dynamic host volume which may lead to code execution
- CVE-2026-74811 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-74824 PoCsOllama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
- CVE-2026-74871 PoCAccess Control Check Implemented After Asset is Accessed in GitLab
- CVE-2026-74921 PoCMissing Authorization in GitLab
- CVE-2026-75011 PoCLinkStackOrg LinkStack UserController.php editPage cross site scripting
- CVE-2026-75021 PoCLinkStackOrg LinkStack Management Endpoint UserController.php saveLink authorization
- CVE-2026-75031 PoCcode-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflow
- CVE-2026-75051 PoCnextlevelbuilder GoClaw/GoClaw Lite RPC improper authorization
- CVE-2026-75061 PoCSourceCodester Hotel Management System check sql injection
- CVE-2026-75081 PoCBootstrap CMS Page Creation show.blade.php code injection
- CVE-2026-75101 PoCOWAP DefectDojo Benchmark/Engagement/Product/Survey authorization
- CVE-2026-75121 PoCUTT HiPER 1200GW formUser strcpy buffer overflow
- CVE-2026-75131 PoCUTT HiPER 1200GW formRemoteControl strcpy buffer overflow
- CVE-2026-75152 PoCsBetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
- CVE-2026-75181 PoCOpen5GS AMF SBI Endpoint sdmsubscription-notify amf_namf_callback_handle_sdm_data_change_notify denial of service
- CVE-2026-75191 PoCFujian Apex LiveBOS Endpoint UploadImage.do path traversal
- CVE-2026-75351 PoCOpen5GS transfer-update denial of service
- CVE-2026-75361 PoCOpen5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service
- CVE-2026-75371 PoCMDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
- CVE-2026-75381 PoCTotolink A8000RU CGI cstecgi.cgi vulnerability os command injection
- CVE-2026-75451 PoCSourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection
- CVE-2026-75461 PoCTotolink NR1800X lighttpd find_host_ip stack-based overflow
- CVE-2026-75481 PoCTotolink NR1800X cstecgi.cgi sub_41A68C command injection
- CVE-2026-75491 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php delete_customer sql injection
- CVE-2026-75501 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php save_customer sql injection
- CVE-2026-75531 PoCcode-projects Gym Management System edit_exercises.php sql injection
- CVE-2026-75541 PoCD-Link M60 httpd password recovery
- CVE-2026-75551 PoCitsourcecode Electronic Judging System login.php sql injection
- CVE-2026-75672 PoCsTemporary Login <= 1.0.0 - Authentication Bypass to Account Takeover
- CVE-2026-75741 PoCAnthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use
- CVE-2026-75781 PoCMacCMS Pro Plugin Installation add.html install unrestricted upload
- CVE-2026-75791 PoCAstrBotDevs AstrBot Dashboard auth.py hard-coded credentials
- CVE-2026-75811 PoCalexta69 MeTube CORS Policy main.py on_prepare cross-domain policy
- CVE-2026-75821 PoCAcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write
- CVE-2026-75831 PoCOpen5GS BSF context.c bsf_sess_find_by_ipv6prefix denial of service
- CVE-2026-75851 PoCOpen5GS AMF nudm-handler.c amf_nudm_sdm_handle_provisioned denial of service
- CVE-2026-75861 PoCOpen5GS AMF nudm-handler.c ogs_id_get_value denial of service
- CVE-2026-75871 PoCOpen5GS AMF nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of service
- CVE-2026-75881 PoCggerve coding-standards-mcp server.py get_best_practices path traversal
- CVE-2026-75891 PoCghantakiran splunk-mcp-integration CSV Export csv_export.py create_csv_export path traversal
- CVE-2026-75901 PoCeyal-gor p_69_branch_monkey_mcp Preview Endpoint advanced.py os command injection
- CVE-2026-75911 PoCTimBroddin astro-mcp-server MCP Tool Query Construction index.ts sql injection
- CVE-2026-75921 PoCitsourcecode Courier Management System edit_staff.php sql injection
- CVE-2026-75931 PoCSunwood-ai-labs command-executor-mcp-server MCP index.ts execute_command os command injection
- CVE-2026-75941 PoCFlux159 mcp-game-asset-gen MCP index.ts image_to_3d_async path traversal
- CVE-2026-75951 PoCnextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator tailwind_config_gen.py _format_plugins code injection
- CVE-2026-75961 PoCnextlevelbuilder ui-ux-pro-max-skill Slide Generator generate-slide.py data.get cross site scripting
- CVE-2026-75971 PoCmem0ai mem0 faiss.py pickle.dump deserialization
- CVE-2026-75991 PoCDayoooun hwpx-mcp MCP index.ts export_to_html path traversal
- CVE-2026-76001 PoCArtMin96 yii2-mcp-server MCP index.ts yii_execute_command os command injection
- CVE-2026-76021 PoCJeecgBoot FillRuleUtil edit improper authorization
- CVE-2026-76031 PoCJeecgBoot LoadFile Endpoint FileDownloadUtils.jav checkPathTraversalBatch server-side request forgery
- CVE-2026-76041 PoCJeecgBoot OpenApi Service OpenApiController.java OpenApiController.call server-side request forgery
- CVE-2026-76051 PoCJeecgBoot uploadImgByHttpEndpoint CommonController.java HttpFileToMultipartFileUtil.downloadImageData server-side request forgery
- CVE-2026-76081 PoCTRENDnet TEW-821DAP tools_diagnostic os command injection
- CVE-2026-76091 PoCTRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection
- CVE-2026-76121 PoCitsourcecode Courier Management System edit_user.php sql injection
- CVE-2026-76271 PoC8nite metatrader-4-mcp sync_ea_from_file index.ts CallToolRequestSchema path traversal
- CVE-2026-76281 PoCcrazyrabbitLTC mcp-code-review-server RepoMix repomix.ts executeRepomix command injection
- CVE-2026-76291 PoCkleneway awesome-cursor-mpc-server Ccode-Review Tool codeReview.ts runCodeReviewTool command injection
- CVE-2026-76301 PoCinnocommerce InnoShop Installation Endpoint InstallServiceProvider.php boot improper authentication
- CVE-2026-76311 PoCcode-projects Online Hospital Management System Registration improper authorization
- CVE-2026-76321 PoCcode-projects Online Hospital Management System viewappointment.php sql injection
- CVE-2026-76331 PoCTotolink N300RH cstecgi.cgi setUploadSetting file inclusion
- CVE-2026-76421 PoCpskill9 website-downloader MCP index.ts download_website os command injection
- CVE-2026-76431 PoCChatGPTNextWeb NextChat API Endpoint Next.js cross-domain policy
- CVE-2026-76441 PoCChatGPTNextWeb NextChat actions.ts addMcpServer improper authorization
- CVE-2026-76451 PoCruvnet sublinear-time-solver MCP server.js export_state path traversal
- CVE-2026-76531 PoCr-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injection
- CVE-2026-76541 PoCAdmin Columns <= 7.0.18 - Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value
- CVE-2026-76651 PoCEssential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
- CVE-2026-76681 PoCMikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds
- CVE-2026-76692 PoCssgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer code injection
- CVE-2026-76701 PoCJinher OA UserSel.aspx sql injection
- CVE-2026-76712 PoCsCodeWise Tornet Scooter Mobile App TwoFactor excessive authentication
- CVE-2026-76721 PoCyoulaitech youlai-boot Users Endpoint UserController.java getUserList sql injection
- CVE-2026-76731 PoCcrmeb_java Admin Upload UploadServiceImpl.java unrestricted upload
- CVE-2026-76751 PoCShenzhen Libituo Technology LBT-T300-HW1 apply.cgi start_lan buffer overflow
- CVE-2026-76761 PoCkerwincui FastBee Tool Download Endpoint ToolController.java ToolController.download path traversal
- CVE-2026-76771 PoCkerwincui FastBee System Notice SysNoticeController.java add cross site scripting
- CVE-2026-76781 PoCYunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection
- CVE-2026-76791 PoCYunaiV yudao-cloud OAuth2TokenServiceImpl.java getAccessToken improper authentication
- CVE-2026-76802 PoCsjsbroks COCO Annotator Data Endpoint datasets.py path traversal
- CVE-2026-76811 PoCjsbroks COCO Annotator Dataset API datasets.py authorization
- CVE-2026-76821 PoCEdimax BR-6208AC L2TP Mode setWAN command injection
- CVE-2026-76831 PoCEdimax BR-6428nC Web setWAN command injection
- CVE-2026-76841 PoCEdimax BR-6428nC setWAN buffer overflow
- CVE-2026-76851 PoCEdimax BR-6208AC setWAN buffer overflow
- CVE-2026-76861 PoCeyeo Adblock Plus Legacy Premium Activation premium.preload.js postMessage access control
- CVE-2026-76871 PoClangflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection
- CVE-2026-76891 PoCDolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verification
- CVE-2026-76901 PoCWavlink WL-WN570HA1 adm.cgi set_sys_adm command injection
- CVE-2026-76911 PoCWavlink WL-WN570HA1 adm.cgi set_sys_cmd command injection
- CVE-2026-76921 PoCWavlink WL-WN570HA1 adm.cgi ping_ddns command injection
- CVE-2026-76941 PoCAcrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue sql injection
- CVE-2026-76951 PoCAcrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform elecMaxMinAvgValue sql injection
- CVE-2026-76961 PoCAcrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform uploadH5Files unrestricted upload
- CVE-2026-76971 PoCAMTT Hotel Broadband Operation System cardhand_submit.php sql injection
- CVE-2026-76981 PoCTiandy Easy7 Integrated Management Platform updateDbBackupInfo os command injection
- CVE-2026-76991 PoCDromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injection
- CVE-2026-77001 PoClangflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection
- CVE-2026-77021 PoCtoeverything AFFiNE Public Markdown Preview Endpoint :docId allowDocPreview authorization
- CVE-2026-77031 PoCAV Stumpfl Pixera Two Media Server Websocket API code injection
- CVE-2026-77041 PoCAV Stumpfl Pixera Two Media Server Service Port 1338 path traversal
- CVE-2026-77051 PoCJD Cloud JDCOS Service jdcap set_iptv_info command injection
- CVE-2026-77061 PoCOpen5GS AMF gmm-handler.c gmm_handle_service_request denial of service
- CVE-2026-77071 PoCOpen5GS UDR nudr-handler.c udr_nudr_dr_handle_subscription_context denial of service
- CVE-2026-77081 PoCOpen5GS UDR subscription.c ogs_dbi_subscription_data denial of service
- CVE-2026-77091 PoCjaneczku Calibre-Web Endpoint kobo_auth.py generate_auth_token improper authorization
- CVE-2026-77101 PoCYunaiV yudao-cloud Ruoyi-Vue-Pro JwtAuthenticationTokenFilter.java doFilterInternal improper authentication
- CVE-2026-77111 PoCMindsDB Engine proc_wrapper.py exec unrestricted upload
- CVE-2026-77121 PoCMindsDB Pickle pickle.loads deserialization
- CVE-2026-77131 PoCcrocodilestick Calibre-Web-Automated Kobo auth-token Route kobo_auth.py generate_auth_token improper authorization
- CVE-2026-77141 PoCcrocodilestick Calibre-Web-Automated Admin Endpoint cwa_functions.py missing authentication
- CVE-2026-77151 PoCravenwits mcp-server-arangodb MCP tools.ts arango_backup path traversal
- CVE-2026-77161 PoCcode-projects Gym Management System In PHP/Windows NT index.php sql injection
- CVE-2026-77171 PoCTotolink WA300 POST Request cstecgi.cgi UploadCustomModule buffer overflow
- CVE-2026-77181 PoCTotolink WA300 POST Request cstecgi.cgi setWebWlanIdx command injection
- CVE-2026-77191 PoCTotolink WA300 POST Request cstecgi.cgi loginauth buffer overflow
- CVE-2026-77202 PoCsTotolink WA300 POST Request cstecgi.cgi setLanguageCfg command injection
- CVE-2026-77211 PoCTotolink WA300 cstecgi.cgi NTPSyncWithHost command injection
- CVE-2026-77221 PoCPrefectHQ prefect Health Check API health endswith improper authentication
- CVE-2026-77231 PoCPrefectHQ prefect WebSocket Endpoint in missing authentication
- CVE-2026-77241 PoCPrefectHQ prefect Webhook/Notification validate_restricted_url toctou
- CVE-2026-77251 PoCPrefectHQ prefect GitRepository Pull storage.py argument injection
- CVE-2026-77281 PoCryanjoachim mcp-rtfm MCP update_doc path traversal
- CVE-2026-77291 PoCpixelsock directus-mcp MCP index.ts validateUrl server-side request forgery
- CVE-2026-77301 PoCprivsim mcp-test-runner MCP index.ts child_process.spawn os command injection
- CVE-2026-77311 PoCcode-projects BloodBank Managing System get_state.php sql injection
- CVE-2026-77321 PoCcode-projects BloodBank Managing System request_blood.php unrestricted upload
- CVE-2026-77331 PoCfunadmin Frontend Chunked Upload Endpoint UploadService.php chunkUpload unrestricted upload
- CVE-2026-77381 PoCpuchunjie doc-tools-mcp MCP mcp-server.ts open_document path traversal
- CVE-2026-77391 PoCjustdan96 tsMuxer hevc.cpp setFPS denial of service
- CVE-2026-77401 PoCjustdan96 tsMuxer vvc.cpp setFPS denial of service
- CVE-2026-77411 PoCCodeAstro Online Classroom studentlogin sql injection
- CVE-2026-77421 PoCCodeAstro Online Classroom facultylogin sql injection
- CVE-2026-77431 PoCCodeAstro Online Classroom studentdetails sql injection
- CVE-2026-77441 PoCCodeAstro Online Classroom addnewstudent sql injection
- CVE-2026-77451 PoCCodeAstro Online Classroom facultydetails sql injection
- CVE-2026-77461 PoCSourceCodester Web-based Pharmacy Product Management System edit-admin.php sql injection
- CVE-2026-77471 PoCTotolink N300RH Parameter cstecgi.cgi loginauth buffer overflow
- CVE-2026-77481 PoCTotolink N300RH POST Request cstecgi.cgi setUpgradeFW buffer overflow
- CVE-2026-77491 PoCTotolink N300RH POST Request cstecgi.cgi setWanConfig buffer overflow
- CVE-2026-77501 PoCTotolink N300RH POST Request cstecgi.cgi setMacFilterRules buffer overflow
- CVE-2026-77791 PoCOpen5GS authentication-subscription Endpoint nudr-handler.c udm_nudr_dr_handle_subscription_authentication denial of service
- CVE-2026-77801 PoCOpen5GS smf-registrations Endpoint udm-sm.c udm_state_operational denial of service
- CVE-2026-77811 PoCOpen5GS amf-3gpp-access Endpoint nudm-handler.c udm_nudm_uecm_handle_amf_registration_update denial of service
- CVE-2026-77821 PoCCodeCanyon Perfex CRM Tenant Clients.php project authorization
- CVE-2026-77831 PoCCodeCanyon Perfex CRM Admin Kanban Endpoint AbstractKanban.php applySortQuery sql injection
- CVE-2026-77841 PoCRTGS2017 NagaAgent Skills Endpoint extensions.py path traversal
- CVE-2026-77851 PoCA-G-U-P-T-A wireshark-mcp pyshark_mcp.py quick_capture os command injection
- CVE-2026-77881 PoCAxle-Bucamp MCP-Docusaurus document.py get_content path traversal
- CVE-2026-77911 PoCImproper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows…
- CVE-2026-77981 PoCFluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter
- CVE-2026-78101 PoCUsamaK98 python-notebook-mcp server.py add_cell path traversal
- CVE-2026-78111 PoC54yyyu code-mcp MCP File server.py is_safe_path path traversal
- CVE-2026-78121 PoC54yyyu code-mcp MCP Tool server.py git_operation command injection
- CVE-2026-78221 PoCitsourcecode Courier Management System print_pdets.php sql injection
- CVE-2026-78231 PoCTotolink A8000RU cstecgi.cgi setAppFilterCfg os command injection
- CVE-2026-78321 PoCIObit Advanced SystemCare Service ASC.exe symlink
- CVE-2026-78331 PoCEFM ipTIME C200 ApplyRestore Endpoint iux_set.cgi sub_408F90 command injection
- CVE-2026-78341 PoCEFM ipTIME NAS1dual misc_main.cgi get_csrf_whites stack-based overflow
- CVE-2026-78421 PoCInfility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter
- CVE-2026-78441 PoCchatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file missing authentication
- CVE-2026-78451 PoCchatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hash
- CVE-2026-78461 PoCchatchat-space Langchain-Chatchat OpenAI-Compatible File Upload API openai_routes.py files toctou
- CVE-2026-78471 PoCchatchat-space Langchain-Chatchat Uploaded File openai_routes.py _get_file_id random values
- CVE-2026-78501 PoCWP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute
- CVE-2026-78511 PoCD-Link DI-8100 yyxz.asp sprintf stack-based overflow
- CVE-2026-78531 PoCD-Link DI-8100 HTTP auto_reboot.asp sprintf buffer overflow
- CVE-2026-78541 PoCD-Link DI-8100 POST Parameter url_rule.asp url_rule_asp buffer overflow
- CVE-2026-78551 PoCD-Link DI-8100 HTTP Request tggl.asp tggl_asp buffer overflow
- CVE-2026-78561 PoCD-Link DI-8100 Web Management url_member.asp buffer overflow
- CVE-2026-78571 PoCD-Link DI-8100 CGI user_group.asp sprintf buffer overflow
- CVE-2026-78591 PoCMotors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media
- CVE-2026-78621 PoCEupago Gateway For Woocommerce < 4.7.2 - Unauthenticated Arbitrary Refund Initiation
- CVE-2026-78671 PoCUdisks2: udisks2: local privilege escalation via as-user option spoofing
- CVE-2026-78991 PoCOut of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a…