CVE-2026-84000 to CVE-2026-84999
29 CVEs with public proof-of-concept exploits.
- CVE-2026-840591 PoCICP DAS UA-2200/UA-5200 CGI ArmAngstromInstructionSet command injection
- CVE-2026-841111 PoCChanjet CRM jxf_dump_table.php sql injection
- CVE-2026-841531 PoCXinhu Rainrock RockOA index.php toaddval sql injection
- CVE-2026-842871 PoCNousResearch hermes-agent Session Chat api_server.py denial of service
- CVE-2026-842881 PoCNousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.prompt denial of service
- CVE-2026-842891 PoCNousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation
- CVE-2026-843611 PoCComposer: Perforce source URL permits P4PORT `rsh:` command execution
- CVE-2026-843711 PoCApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
- CVE-2026-844231 PoCCasdoor upload-resource API resource.go missing authentication
- CVE-2026-844251 PoCzhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service
- CVE-2026-844271 PoCzhayujie CowAgent Bash Tool bash.py denial of service
- CVE-2026-844301 PoCgouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
- CVE-2026-844311 PoCAirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRealPath path traversal
- CVE-2026-844371 PoCOpenCart Autocomplete Workflow address.php cross site scripting
- CVE-2026-844381 PoCOpenCart Autocomplete Workflow edit.php cross site scripting
- CVE-2026-844411 PoCPiwigo Image Derivative i.php path traversal
- CVE-2026-844421 PoCMapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt getDataColumn path traversal
- CVE-2026-846962 PoCsPhison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands
- CVE-2026-848331 PoCntegrals openbrowser Browser Agent Message Construction agent.ts resource consumption
- CVE-2026-848391 PoCtsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authentication
- CVE-2026-848401 PoCtsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missing authentication
- CVE-2026-848411 PoCtsi-coop tsi-dpdp-cms client-side enforcement of server-side security
- CVE-2026-848521 PoCReader Tools PDF Reader App File ActSplashNew.handleDeeplink path traversal
- CVE-2026-848561 PoCrowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of service
- CVE-2026-848571 PoCsigoden aichat API Endpoint serve.rs memory allocation
- CVE-2026-848851 PoCsimular-ai Agent-S CodeAgent code_agent.py denial of service
- CVE-2026-848861 PoCsimular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumption
- CVE-2026-848871 PoCsimular-ai Agent-S Model-generated GUI Action Execution Workflow grounding.py denial of service
- CVE-2026-848881 PoCRightNow-AI OpenFang tool_runner.rs shell_exec memory allocation