CVE-2026-82000 to CVE-2026-82999
129 CVEs with public proof-of-concept exploits.
- CVE-2026-820171 PoCIGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area
- CVE-2026-820781 PoCKEVPaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
- CVE-2026-820901 PoCPocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application…
- CVE-2026-821111 PoCiswalle getnote-mcp upload_image index.ts fs.readFileSync path traversal
- CVE-2026-821821 PoCWPvivid Backup & Migration < 0.9.133 - Admin+ SQLi via Upload Cleaner Isolation
- CVE-2026-821831 PoCOAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Steam OpenID Assertion
- CVE-2026-822212 PoCsWordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-822223 PoCsWordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
- CVE-2026-822861 PoCgpt-crawler Arbitrary File Write via outputFileName Parameter
- CVE-2026-823294 PoCsKEVPotential authentication bypass leading to administrative access in Artifactory
- CVE-2026-823921 PoCpnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
- CVE-2026-823931 PoCpnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
- CVE-2026-824171 PoCqs.stringify throws TypeError on objects with a non-callable constructor.isBuffer property
- CVE-2026-824211 PoCitsourcecode Sales and Inventory System emp_edit.php sql injection
- CVE-2026-824221 PoCitsourcecode Sales and Inventory System emp_del.php sql injection
- CVE-2026-824241 PoCPHPGurukul Student Information System student_edit1.php sql injection
- CVE-2026-824731 PoCKubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task Endpoints
- CVE-2026-824821 PoCcoppermine-gallery Coppermine Photo Gallery edit_profile Endpoint profile.php cross site scripting
- CVE-2026-824831 PoCcoppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scripting
- CVE-2026-824841 PoCitsourcecode Sales and Inventory System emp_searchfrm.php sql injection
- CVE-2026-824851 PoCitsourcecode Sales and Inventory System pro_edit.php sql injection
- CVE-2026-824871 PoCBeetel 450TC3 password recovery
- CVE-2026-824881 PoCBeetel 450TC3 User Management cross site scripting
- CVE-2026-825241 PoCUnoPim File Upload RCE via TinyMCE Image Upload Endpoint
- CVE-2026-825391 PoCTOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption
- CVE-2026-825401 PoCitsourcecode Sales and Inventory System cust_searchfrm.php sql injection
- CVE-2026-825411 PoCitsourcecode Sales and Inventory System sup_edit.php sql injection
- CVE-2026-825421 PoCTenda HG10 Boa Web Server formIPv6Routing buffer overflow
- CVE-2026-825431 PoCvastsa FileCodeBox Pickup Limit views.py update_file_usage race condition
- CVE-2026-825451 PoCitsourcecode Sales and Inventory System sup_searchfrm.php sql injection
- CVE-2026-825471 PoCLinux Foundation Magma Registration Complete Message amf_fsm.cpp improper authentication
- CVE-2026-825481 PoCLinux Foundation Magma InitialUEMessage information disclosure
- CVE-2026-825491 PoCLinux Foundation Magma SecurityModeComplete integrity check
- CVE-2026-825501 PoCLinux Foundation Magma NGSetupRequest input validation
- CVE-2026-825511 PoCLinux Foundation Magma NGSetup ngap_amf_handlers.c state issue
- CVE-2026-825521 PoCLinux Foundation Magma gNB Termination ngap_amf.c denial of service
- CVE-2026-825531 PoCsambitraj Student Management System Student Dashboard student_dashboard.php mysqli_query improper authorization
- CVE-2026-825551 PoCTOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
- CVE-2026-825561 PoCForgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side request forgery
- CVE-2026-825871 PoCOpen5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruption
- CVE-2026-825891 PoCOpen5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_transfer denial of service
- CVE-2026-825922 PoCsD-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow
- CVE-2026-825931 PoCD-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow
- CVE-2026-825941 PoCLogNet grpc-spring-boot-starter Annotation Processing improper authorization
- CVE-2026-825951 PoCD-Link DIR-825M System Command Execution formSysCmd sub_456CF4 command injection
- CVE-2026-825961 PoCLatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corruption
- CVE-2026-825971 PoCTOTOLINK NR1800X cstecgi.cgi setUssd command injection
- CVE-2026-825981 PoCSeaCMS Template search.php parseIf code injection
- CVE-2026-825991 PoCSeaCMS Avatar Upload member.php unlink path traversal
- CVE-2026-826001 PoCSeaCMS zyapi.php sql injection
- CVE-2026-826011 PoCSeaCMS err.php cross site scripting
- CVE-2026-826021 PoCSeaCMS ass.php authorization
- CVE-2026-826031 PoCSeaCMS Comment Cache member.php del_pl path traversal
- CVE-2026-826071 PoCCozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wppb_ajax_simple_avatar unrestricted upload
- CVE-2026-826081 PoCKamailio AVP cxdx_avp.c get_4bytes out-of-bounds
- CVE-2026-826091 PoCitsourcecode Sales and Inventory System inv_edit.php sql injection
- CVE-2026-826101 PoCitsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injection
- CVE-2026-826111 PoCitsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection
- CVE-2026-826121 PoCitsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection
- CVE-2026-826131 PoCitsourcecode Online Medicine Delivery System Product Search index.php loadResultList sql injection
- CVE-2026-826141 PoCitsourcecode Online Medicine Delivery System Product Category Filter index.php loadResultList sql injection
- CVE-2026-826151 PoCitsourcecode Online Medicine Delivery System Password Recovery passwordrecover.php find_phone sql injection
- CVE-2026-826161 PoCTOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow
- CVE-2026-826191 PoCSysterel S2OPC subscription_mgr.c use after free
- CVE-2026-826201 PoCSoarkey StudentManagement/学生信息管理系统 CourseDao.java CourseDao.course_ranking sql injection
- CVE-2026-826211 PoCSoarkey StudentManagement/学生信息管理系统 Administrative Servlet AdminDao.java AdminDao.doGet authorization
- CVE-2026-826221 PoCcode-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting
- CVE-2026-826231 PoCopen62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after free
- CVE-2026-826241 PoCcode-projects Simple Inventory System Database Backup File inventorymanagement.sql information disclosure
- CVE-2026-826251 PoCcode-projects Simple Inventory System User Registration register.php cross site scripting
- CVE-2026-826291 PoCjeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload
- CVE-2026-826301 PoCPowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery
- CVE-2026-826311 PoCvalkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free
- CVE-2026-826591 PoCnodemailer before 9.0.1 File Read and SSRF via raw option
- CVE-2026-826641 PoCyaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting
- CVE-2026-826651 PoCyaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversal
- CVE-2026-826661 PoCyaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection
- CVE-2026-826671 PoCyaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forgery
- CVE-2026-826681 PoCklaussilveira GitList Git Command Line CommandLine.php getDefaultBranch os command injection
- CVE-2026-826691 PoCklaussilveira GitList XML Parsing CommandLine.php SimpleXMLElement denial of service
- CVE-2026-826771 PoCvalkey-io valkey Module Timer module.c moduleTimerHandler double free
- CVE-2026-826781 PoCdiem-project diem Administrative Console actions.class.php executeCommand os command injection
- CVE-2026-826791 PoCdiem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload
- CVE-2026-826801 PoCD-Link DSM-G600 Multipart load_file.cgi out-of-bounds write
- CVE-2026-826881 PoCD-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection
- CVE-2026-826891 PoCD-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection
- CVE-2026-826901 PoCD-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection
- CVE-2026-826911 PoCD-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection
- CVE-2026-826921 PoCD-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection
- CVE-2026-826931 PoCTenda AC1206 Web UI telnet TendaTelnet missing authentication
- CVE-2026-826941 PoCTenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication
- CVE-2026-826951 PoCTenda AC18 Telnet telnet missing authentication
- CVE-2026-826961 PoCitsourcecode Sales and Inventory System inv_searchfrm.php sql injection
- CVE-2026-826971 PoCsambitraj Student-Management-System session_start cookie httponly flag
- CVE-2026-826981 PoCsambitraj Student-Management-System aca.sql default password
- CVE-2026-826991 PoCsambitraj Student Management System Password aca.sql cleartext storage
- CVE-2026-827001 PoCcode-projects Online Shopping System Newsletter Subscription offersmail.php cross site scripting
- CVE-2026-827011 PoCcode-projects Online Shopping System Search Functionality action.php sql injection
- CVE-2026-827021 PoCEdimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection
- CVE-2026-827031 PoCEdimax BR-6214K asp_setPing Endpoint ping.asp system os command injection
- CVE-2026-828011 PoCNASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery
- CVE-2026-828021 PoCNASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery
- CVE-2026-828031 PoCarmink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null pointer dereference
- CVE-2026-828051 PoCTypora Mermaid Rendering cross site scripting
- CVE-2026-828071 PoCieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management
- CVE-2026-828081 PoCInbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials
- CVE-2026-828091 PoCvidIQ Vision for YouTube Extension postMessage window.addEventListener information disclosure
- CVE-2026-828101 PoCextension.vn 2FA Authenticator Extension Background Service Worker chrome.runtime.onMessageExternal.addListener information disclosure
- CVE-2026-828111 PoCToggl OÜ Toggl Track Extension postMessage origin validation
- CVE-2026-828131 PoCBEN Group TubeBuddy for YouTube Extension tubebuddymaster1.js TBGlobal.GetToken data authenticity
- CVE-2026-828151 PoCMegaEase EaseProbe Middleware server.go realIP access control
- CVE-2026-828161 PoCdibo-software diboot AI Session Endpoint ai-session authorization
- CVE-2026-828171 PoCdibo-software diboot Tenant Administrator Management API admin access control
- CVE-2026-828181 PoCdibo-software diboot Tenant Resource Assignment resource access control
- CVE-2026-828201 PoCFLVMeta AMF String Processing amf.c amf_string_new heap-based overflow
- CVE-2026-828211 PoCFLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference
- CVE-2026-828331 PoCDoccano Open Source Annotation Tools for Machine Learning Practitioners Project Example Detail Endpoint examples ExampleDetail access…
- CVE-2026-828341 PoCDoccano Open Source Annotation Tools for Machine Learning Practitioners Bulk-Delete Endpoint category-types LabelList access control
- CVE-2026-828351 PoCcaoqianming django-vue-admin file access control
- CVE-2026-828761 PoCPhison PS3111-S11 Controller Firmware Signature Verification Bypass
- CVE-2026-828841 PoCAll in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block
- CVE-2026-829051 PoCsdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery
- CVE-2026-829061 PoCsdcb chats Signed File Download Endpoint FileController.cs DownloadPublic missing authentication
- CVE-2026-829081 PoCMSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow
- CVE-2026-829091 PoCQuantumNous new-api Revoked API Token token session expiration
- CVE-2026-829141 PoCkishan0725 Hospital-Management-System search.php sql injection
- CVE-2026-829211 PoCShopEx ECShop pack.php check_img_type unrestricted upload
- CVE-2026-829221 PoCShopEx ECShop flow.php flow_update_cart sql injection
- CVE-2026-829711 PoCQVidium Opera11 CGI Script net_tr.cgi command injection