CVE-2026-8000 to CVE-2026-8999
230 CVEs with public proof-of-concept exploits.
- CVE-2026-80231 PoCPath traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read
- CVE-2026-80281 PoCFlowiseAI Flowise Endpoint account.service.ts verify information disclosure
- CVE-2026-80311 PoCPicoTronica e-Clinic Healthcare System ECHS API Endpoint patient-records missing authentication
- CVE-2026-80321 PoCPicoTronica e-Clinic Healthcare System ECHS echs.js hard-coded credentials
- CVE-2026-80331 PoCPicoTronica e-Clinic Healthcare System ECHS Response Header v2 information disclosure
- CVE-2026-80373 PoCsKEVOS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager &…
- CVE-2026-80542 PoCsUnauthenticated SQL Injection in dotCMS Publish Audit API
- CVE-2026-80711 PoCSpam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass
- CVE-2026-80811 PoCrouter-for-me CLIProxyAPI api_tools.go server-side request forgery
- CVE-2026-80821 PoCBpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection
- CVE-2026-80831 PoCSourceCodester Pharmacy Sales and Inventory System ajax.php save_user sql injection
- CVE-2026-80841 PoCOSGeo gdal HDF-EOS Grid File SWapi.c memmove out-of-bounds
- CVE-2026-80861 PoCOSGeo gdal SWapi.c SWnentries heap-based overflow
- CVE-2026-80871 PoCOSGeo gdal GDapi.c GDnentries heap-based overflow
- CVE-2026-80881 PoCOSGeo gdal GDapi.c GDfieldinfo out-of-bounds
- CVE-2026-80891 PoCweMail < 2.1.3 - Reflected Cross-Site Scripting
- CVE-2026-80971 PoCCodeAstro Online Classroom askquery.php sql injection
- CVE-2026-80981 PoCcode-projects Feedback System checklogin.php sql injection
- CVE-2026-81121 PoC8421bit MiniClaw kernel.ts executeCognitivePulse os command injection
- CVE-2026-81131 PoC8421bit MiniClaw executeSkillScript kernel.ts isPathInside path traversal
- CVE-2026-81141 PoCJeecgBoot JSON Object loadTreeData sql injection
- CVE-2026-81151 PoCgyoridavid short-video-maker REST API rest.ts path traversal
- CVE-2026-81161 PoChuangjunsen0406 xiaozhi-mcphub dxtController.ts path traversal
- CVE-2026-81171 PoCSourceCodester Pizzafy Ecommerce System index.php cross site scripting
- CVE-2026-81191 PoCOpen5GS NSSF nghttp2-server.c ogs_sbi_stream_find_by_id denial of service
- CVE-2026-81201 PoCOpen5GS NSSF nnssf-handler.c denial of service
- CVE-2026-81211 PoCOpen5GS NSSF conv.c ogs_sbi_parse_plmn_list denial of service
- CVE-2026-81221 PoCOpen5GS NSSF message.c ogs_sbi_discovery_option_add_service_names denial of service
- CVE-2026-81231 PoCOpen5GS NSSF message.c ogs_sbi_discovery_option_add_snssais denial of service
- CVE-2026-81241 PoCGPAC box_code_base.c sidx_box_read allocation of resources
- CVE-2026-81251 PoCcode-projects Simple Chat System sendMessage.php sql injection
- CVE-2026-81261 PoCSourceCodester Comment System post_comment.php sql injection
- CVE-2026-81271 PoCeladmin Users API Endpoint UserController.java checkLevel access control
- CVE-2026-81281 PoCSourceCodester SUP Online Shopping viewmsg.php sql injection
- CVE-2026-81291 PoCSourceCodester SUP Online Shopping wishlist.php sql injection
- CVE-2026-81301 PoCSourceCodester SUP Online Shopping message.php sql injection
- CVE-2026-81311 PoCSourceCodester SUP Online Shopping replymsg.php sql injection
- CVE-2026-81321 PoCCodeAstro Leave Management System login.php sql injection
- CVE-2026-81331 PoCzyx0814 FilePress Shares Filelist API admin.php sql injection
- CVE-2026-81361 PoCSourceCodester Pharmacy Sales and Inventory System index.php users cross site scripting
- CVE-2026-81371 PoCTotolink X5000R formDdns sub_458E40 buffer overflow
- CVE-2026-81381 PoCTenda CX12L SetPptpServerCfg” formSetPPTPServer stack-based overflow
- CVE-2026-81511 PoCSimple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF
- CVE-2026-81551 PoCBuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR
- CVE-2026-81571 PoCVitepos < 3.4.2 - Outlet Manager+ Privilege Escalation
- CVE-2026-81611 PoCmultiparty vulnerable to Denial of Service via Prototype Pollution leading to Uncaught Exception
- CVE-2026-81631 PoCInfility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter
- CVE-2026-81721 PoCSimple Basic Contact Form <= 20250114 - Reflected XSS
- CVE-2026-818111 PoCsBurst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
- CVE-2026-81881 PoCWavlink NU516U1 adm.cgi change_wifi_password os command injection
- CVE-2026-81891 PoCWavlink NU516U1 adm.cgi wzdrepeater os command injection
- CVE-2026-81901 PoCWavlink NU516U1 adm.cgi wan os command injection
- CVE-2026-81911 PoCWavlink NU516U1 adm.cgi wifi_region os command injection
- CVE-2026-81921 PoCWavlink NU516U1 adm.cgi wzdap os command injection
- CVE-2026-81931 PoCAkaunting Invoice PDF Rendering dompdf.php server-side request forgery
- CVE-2026-81941 PoCosTicket Dispatcher class.dispatcher.php cross-site request forgery
- CVE-2026-81951 PoCJeecgBoot SVG File CommonController.java cross site scripting
- CVE-2026-81962 PoCsJeecgBoot mLogin Endpoint LoginController.java authorization
- CVE-2026-82064 PoCsKirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
- CVE-2026-82071 PoCGibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing…
- CVE-2026-82081 PoCGibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive…
- CVE-2026-82091 PoCGibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web…
- CVE-2026-82101 PoCaandrew-me tgpt Update helper.go helper.Update command injection
- CVE-2026-82111 PoCcodelibs Fess JSP File AdminDesignAction.java update code injection
- CVE-2026-82121 PoCOSGeo gdal SWapi.c SWSDfldsrch heap-based overflow
- CVE-2026-82131 PoCOSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflow
- CVE-2026-82141 PoCIndustrial Application Software IAS Canias ERP RMI doAction improper authentication
- CVE-2026-82151 PoCIndustrial Application Software IAS Canias ERP RMI iasRequestFileEvent path traversal
- CVE-2026-82171 PoCIndustrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command injection
- CVE-2026-82181 PoCDevs Palace ERP Online purchase_return_save cross site scripting
- CVE-2026-82191 PoCDevs Palace ERP Online supplier-save cross site scripting
- CVE-2026-82201 PoCDevs Palace ERP Online customer-save cross site scripting
- CVE-2026-82211 PoCDevs Palace ERP Online item-save cross site scripting
- CVE-2026-82221 PoCOpen5GS sm-policies Endpoint nbsf-handler.c pcf_nbsf_management_handle_register denial of service
- CVE-2026-82231 PoCOpen5GS sm-policies Endpoint pcf_sess_sbi_discover_and_send denial of service
- CVE-2026-82241 PoCOpen5GS PCF context.c pcf_sess_set_ipv6prefix denial of service
- CVE-2026-82251 PoCOpen5GS delete Endpoint sm-sm.c pcf_npcf_smpolicycontrol_handle_delete denial of service
- CVE-2026-82261 PoCOpen5GS types.c ogs_pcc_rule_install_flow_from_media denial of service
- CVE-2026-82271 PoCWavlink NU516U1 adm.cgi wzdapMesh os command injection
- CVE-2026-82281 PoCWavlink NU516U1 wireless.cgi advance os command injection
- CVE-2026-82291 PoCWavlink NU516U1 wireless.cgi WifiBasic os command injection
- CVE-2026-82301 PoCWavlink NU516U1 login.cgi sys_login1 os command injection
- CVE-2026-82311 PoCCodeAstro Online Catering Ordering System deleteorder.php sql injection
- CVE-2026-82341 PoCEFM ipTIME A8004T WifiBasicSet formWifiBasicSet stack-based overflow
- CVE-2026-82351 PoC8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection
- CVE-2026-82361 PoCConcrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate for endpoint…
- CVE-2026-82372 PoCsConcrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
- CVE-2026-82391 PoCConcrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
- CVE-2026-82411 PoCIndustrial Application Software IAS Canias ERP RMI iasGetServerInfoEvent improper authorization
- CVE-2026-82421 PoCIndustrial Application Software IAS Canias ERP Login RMI doAction response discrepancy
- CVE-2026-82441 PoCIndustrial Application Software IAS Canias ERP Login RMI improper authentication
- CVE-2026-82481 PoCOpen5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
- CVE-2026-82491 PoCOpen5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
- CVE-2026-82501 PoCOpen5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of service
- CVE-2026-82511 PoCOpen5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
- CVE-2026-82521 PoCOpen5GS SMF smf_nsmf_handle_create_data_in_hsmf null pointer dereference
- CVE-2026-82531 PoCDevs Palace ERP Online purchase_save cross site scripting
- CVE-2026-82541 PoCDevs Palace ERP Online sales_save cross site scripting
- CVE-2026-82551 PoCDevs Palace ERP Online add_new_customer cross site scripting
- CVE-2026-82561 PoCDevs Palace ERP Online mr-save cross site scripting
- CVE-2026-82571 PoCWebAssembly Binaryen BrOn wasm-ir-builder.cpp makeBrOn assertion
- CVE-2026-82581 PoCSquirrel sqstdstring.cpp validate_format stack-based overflow
- CVE-2026-82591 PoCTenda AC6 httpd telnet os command injection
- CVE-2026-82601 PoCD-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
- CVE-2026-82611 PoCSquirrel sqobject.cpp Load heap-based overflow
- CVE-2026-82621 PoCDevs Palace ERP Online chart-save cross site scripting
- CVE-2026-82631 PoCTenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection
- CVE-2026-82641 PoCTenda AC6 httpd WifiApScan formWifiApScan os command injection
- CVE-2026-82651 PoCTenda AC6 httpd getLogFile get_log_file os command injection
- CVE-2026-82661 PoCOpen5GS SMF gsm-build.c gsm_build_pdu_session_establishment_accept denial of service
- CVE-2026-82671 PoCOpen5GS SMF smf_nsmf_handle_created_data_in_vsmf denial of service
- CVE-2026-82681 PoCOpen5GS SMF OpenAPI_list_create denial of service
- CVE-2026-82691 PoCOpen5GS SMF smf_nsmf_handle_create_sm_context denial of service
- CVE-2026-82701 PoCOpen5GS SMF ogs_nas_parse_qos_rules denial of service
- CVE-2026-82711 PoCD-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection
- CVE-2026-82721 PoCD-Link DNS-320 webfile_mgr.cgi chown os command injection
- CVE-2026-82741 PoCnpitre cramfs-tools Directory cramfsck.c do_directory path traversal
- CVE-2026-82751 PoCbettercap zerogod IPP Service zerogod_ipp_primitives.go ippReadChunkedBody integer coercion
- CVE-2026-82761 PoCbettercap MySQL Server mysql_server.go integer coercion
- CVE-2026-82801 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2026-82881 PoCOpen5GS SMF gsm-handler.c denial of service
- CVE-2026-82891 PoCOpen5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of service
- CVE-2026-82901 PoCOpen5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of service
- CVE-2026-82911 PoCOpen5GS NRF nnrf-handler.c ogs_nnrf_nfm_handle_nf_profile denial of service
- CVE-2026-82921 PoCOpen5GS NRF conv.c yuarel_parse denial of service
- CVE-2026-82931 PoCReally Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP Skip
- CVE-2026-83051 PoCOpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication
- CVE-2026-83181 PoCVectifyAI PageIndex PDF Table of Contents page_index.py toc_transformer infinite loop
- CVE-2026-83191 PoCaiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memory resource consumption
- CVE-2026-83201 PoCjishenghua jshERP updatePlatformConfigByKey Endpoint UserService.java getUserByWeixinCode server-side request forgery
- CVE-2026-83211 PoCinkeep agents runAuth Middleware runAuth.ts createDevContext authentication bypass
- CVE-2026-83371 PoCConcrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
- CVE-2026-83441 PoCD-Link DIR-816 formDMZ.cgi sub_445E7C command injection
- CVE-2026-83451 PoCD-Link DIR-816 singlePortForward sub_445E7C command injection
- CVE-2026-83461 PoCD-Link DIR-816 portForward command injection
- CVE-2026-83471 PoCConcrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
- CVE-2026-83491 PoComec-project amf NGAP Message memory corruption
- CVE-2026-83781 PoCFrontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scripting via File Rename
- CVE-2026-83791 PoCFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download
- CVE-2026-83802 PoCsFrontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post Deletion
- CVE-2026-83832 PoCsLearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API
- CVE-2026-83852 PoCsWP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback
- CVE-2026-83862 PoCsWP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID
- CVE-2026-83891 PoCJIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-84513 PoCsInsufficient input validation leading to memory overread
- CVE-2026-84522 PoCsKEVMemory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
- CVE-2026-84614 PoCsHeap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
- CVE-2026-84672 PoCsUnauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
- CVE-2026-84721 PoCMissing Authorization in GitLab
- CVE-2026-84812 PoCsRemote Code Execution via Code Validation Endpoint
- CVE-2026-85011 PoCCVE-2026-8501
- CVE-2026-85891 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-86671 PoCIncorrect Authorization in GitLab
- CVE-2026-86791 PoCAudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' Parameter
- CVE-2026-87132 PoCsAvada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
- CVE-2026-87231 PoCqs.stringify crashes on null/undefined entries in comma-format arrays under encodeValuesOnly
- CVE-2026-87241 PoCDataease Data Dashboard SqlparserUtils.java SqlparserUtils.transFilter sql injection
- CVE-2026-87251 PoCCoreWorxLab CAAL test-hass Endpoint webhooks.py server-side request forgery
- CVE-2026-87281 PoCOpen5GS NRF conv.c ogs_sbi_discovery_option_parse_plmn_list denial of service
- CVE-2026-87291 PoCOpen5GS NRF message.c denial of service
- CVE-2026-87301 PoCOpen5GS NRF context.c ogs_sbi_nf_instance_set_id denial of service
- CVE-2026-87311 PoCOpen5GS NRF client.c ogs_sbi_client_add denial of service
- CVE-2026-87326 PoCsWP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
- CVE-2026-87331 PoCInvestintech SlimPDFReader SlimPDFReader.exe sub_3B4610 stack-based overflow
- CVE-2026-87341 PoCOinone Pamirs queryListByWrapper RSQLToSQLNodeConnector.makeVariable sql injection
- CVE-2026-87351 PoCOinone Pamirs appConfigQuery PamirsParserConfig.java JsonUtils.parseMap deserialization
- CVE-2026-87361 PoCOinone Pamirs RestController LocalFileClient.java request.getParameter path traversal
- CVE-2026-87371 PoCSanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing authentication
- CVE-2026-87381 PoCSanluan PublicCMS Trade Payment Flow TradeOrderController.java AccountGatewayComponent.pay logic error
- CVE-2026-87391 PoCSanluan PublicCMS SafeConfigComponent.java getSignKey hard-coded key
- CVE-2026-87401 PoCSanluan PublicCMS templateResult API TemplateResultDirective.java execute special elements used in a template engine
- CVE-2026-87411 PoCEMQX QoS 2 PUBLISH Packet emqx_persistent_session_ds.erl race condition
- CVE-2026-87431 PoCOpen5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorization
- CVE-2026-87441 PoCOpen5GS NRF context.c ogs_sbi_nf_service_add denial of service
- CVE-2026-87451 PoCOpen5GS AUSF nausf-handler.c ogs_timer_add denial of service
- CVE-2026-87461 PoCOpen5GS NRF nghttp2-server.c discover_handler use after free
- CVE-2026-87471 PoCZ-BlogPHP Commend Approval c_system_event.php CheckComment improper authorization
- CVE-2026-87501 PoCh2oai h2o-3 ImportFile API PersistNFS.java importFiles information disclosure
- CVE-2026-87511 PoCh2oai h2o-3 JAR Model.java importBinaryModel deserialization
- CVE-2026-87521 PoCh2oai h2o-3 Rapids setproperty Primitive AstSetProperty.java exec access control
- CVE-2026-87531 PoCkalcaddle Kodbox fileThumb Plugin VideoResize.class.php parseVideoInfo command injection
- CVE-2026-87541 PoCAstrBotDevs AstrBot File Upload chat.py post_file path traversal
- CVE-2026-87551 PoCfishaudio Bert-VITS2 Model hiyoriUI.py _get_all_models path traversal
- CVE-2026-87561 PoCfishaudio Bert-VITS2 Gradio webui_preprocess.py generate_config path traversal
- CVE-2026-87571 PoCadenhq hive Delete Request routes_sessions.py _read_events_tail path traversal
- CVE-2026-87581 PoCMetasoft 美特软件 MetaCRM upload3.jsp unrestricted upload
- CVE-2026-87591 PoCxiandafu beetl SpELFunction SpELFunction.java expression language injection
- CVE-2026-87641 PoCH3C Magic B3 aspForm UpdateWanParams buffer overflow
- CVE-2026-87651 PoCKilo-Org kilocode File Diff API Endpoint worktree-diff.ts Bun.file path traversal
- CVE-2026-87661 PoCKilo-Org kilocode Environment Variable config.ts load information disclosure
- CVE-2026-87671 PoCvercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection
- CVE-2026-87681 PoCvercel ai provider-utils download-blob.ts validateDownloadUrl server-side request forgery
- CVE-2026-87691 PoCvercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumption
- CVE-2026-87701 PoCcontinuedev continue JSON-RPC Server lsTool.ts lsTool path traversal
- CVE-2026-87711 PoClinlinjava litemall Front-end WeChat API WxGoodsController.java list sql injection
- CVE-2026-87721 PoClinlinjava litemall Admin Endpoint sql injection
- CVE-2026-87731 PoClinlinjava litemall Database Setting DbUtil.java load argument injection
- CVE-2026-87741 PoCEdimax BR-6228NC POST Request mp command injection
- CVE-2026-87751 PoCEdimax BR-6428NS POST Request formL2TPSetup buffer overflow
- CVE-2026-87761 PoCEdimax BR-6428NS POST Request formPPTPSetup buffer overflow
- CVE-2026-87771 PoCEdimax BR-6428NS POST Request formStaDrvSetup command injection
- CVE-2026-87791 PoComec-project amf handler.go NGSetupRequest memory corruption
- CVE-2026-87801 PoComec-project amf NGAP Message dispatcher.go memory corruption
- CVE-2026-87811 PoComec-project amf handler.go RANConfiguration null pointer dereference
- CVE-2026-87821 PoComec-project amf NGAP Message handler.go null pointer dereference
- CVE-2026-87831 PoComec-project amf dispatcher.go UERadioCapabilityCheckResponse null pointer dereference
- CVE-2026-87841 PoCnpitre cramfs-tools cramfsck.c change_file_status symlink
- CVE-2026-87851 PoCprojectworlds hospital-management-system-in-php GET Parameter update_info.php getAllPatientDetail sql injection
- CVE-2026-87861 PoCTencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorization
- CVE-2026-87941 PoCPaperCut NG/MF: User enumeration via timing attack
- CVE-2026-88091 PoCAdvanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter
- CVE-2026-88251 PoCElementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API
- CVE-2026-88322 PoCsWPCode <= 2.3.5 - Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost
- CVE-2026-88361 PoClwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow
- CVE-2026-88381 PoCRemote Code Execution via eval() Injection in amazon-redshift-python-driver
- CVE-2026-88391 PoCMapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Reference via REST API Endpoints
- CVE-2026-88571 PoCFull RCE using EasyTimeline Extension
- CVE-2026-88631 PoCCVE-2026-8863
- CVE-2026-88881 PoCCVE-2026-8888
- CVE-2026-89321 PoCincomplete mTLS config matching in conn reuse
- CVE-2026-89351 PoCAdvanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation
- CVE-2026-89811 PoCLazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML
- CVE-2026-89821 PoCHard-coded / Backdoor Accounts
- CVE-2026-89831 PoCBackdoor Authentication Token
- CVE-2026-89841 PoCUnauthenticated RCE
- CVE-2026-89851 PoCUnauthenticated Command Injection
- CVE-2026-89861 PoCCommand Injection via Malicious OCPP Server
- CVE-2026-89871 PoCAuthenticated Heap Overflow
- CVE-2026-89881 PoCAccess to Bootloader
- CVE-2026-89891 PoCOpen Recovery Mode