CVE-2026-9000 to CVE-2026-9999
253 CVEs with public proof-of-concept exploits.
- CVE-2026-90181 PoCEasy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter
- CVE-2026-90551 PoCBooking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via…
- CVE-2026-90601 PoCAgile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style
- CVE-2026-90611 PoCAgile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name
- CVE-2026-90621 PoCAgile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
- CVE-2026-90661 PoCWP Compress < 7.10.04 - Reflected XSS via test_zone
- CVE-2026-90672 PoCsSchema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload
- CVE-2026-908212 PoCsKEVDrupal core - Highly critical - SQL injection - SA-CORE-2026-004
- CVE-2026-90861 PoCKeycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass
- CVE-2026-90902 PoCsCVE-2026-9090
- CVE-2026-91331 PoCArbitrary file read in rabbitmq-aws plugin
- CVE-2026-91471 PoCuproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
- CVE-2026-91581 PoCIn Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a…
- CVE-2026-919812 PoCsKEVUnauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
- CVE-2026-92541 PoCCommand Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
- CVE-2026-92564 PoCsNGINX ngx_http_rewrite_module vulnerability
- CVE-2026-92691 PoCSecure Copy Content Protection and Content Locking < 5.1.5 - Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter
- CVE-2026-92713 PoCsKeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
- CVE-2026-92771 PoCshell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
- CVE-2026-92781 PoCForm Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure
- CVE-2026-92821 PoCW3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
- CVE-2026-92902 PoCsWP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
- CVE-2026-92941 PoCEdimax BR-6428NS POST Request formWanTcpipSetup buffer overflow
- CVE-2026-92951 PoCEdimax BR-6428NS POST Request formWirelessTbl buffer overflow
- CVE-2026-92961 PoCEdimax BR-6428NS POST Request formWlanM system command injection
- CVE-2026-92971 PoCEdimax BR-6428NS POST Request formWlbasic command injection
- CVE-2026-92981 PoComec-project amf PathSwitchRequest memory corruption
- CVE-2026-92991 PoComec-project amf handler.go PDUSessionResourceModifyIndication memory corruption
- CVE-2026-93001 PoComec-project amf NGSetupRequest memory corruption
- CVE-2026-93011 PoComec-project amf NGReset Message memory corruption
- CVE-2026-93021 PoC546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection
- CVE-2026-93031 PoCcalcom cal.diy cross-site request forgery
- CVE-2026-93041 PoCcalcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery
- CVE-2026-93051 PoCQuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection
- CVE-2026-93061 PoCQuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization
- CVE-2026-93421 PoCSourceCodester Hospitals Patient Records Management System view_history.php sql injection
- CVE-2026-93431 PoCEdimax EW-7438RPn webs formWpsStart os command injection
- CVE-2026-93441 PoCEdimax EW-7438RPn webs formWpsStart stack-based overflow
- CVE-2026-93451 PoCEdimax EW-7438RPn webs formWizSurvey buffer overflow
- CVE-2026-93461 PoCEdimax EW-7438RPn webs formWirelessTbl buffer overflow
- CVE-2026-93471 PoCEdimax EW-7438RPn webs formWizSurvey os command injection
- CVE-2026-93481 PoCEdimax EW-7438RPn webs mp stack-based overflow
- CVE-2026-93491 PoCcalcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx getServerSideProps information disclosure
- CVE-2026-93501 PoCNousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization
- CVE-2026-93511 PoCNousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversal
- CVE-2026-93521 PoCNousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosure
- CVE-2026-93531 PoCNousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py injection
- CVE-2026-93541 PoCNousResearch hermes-agent Slack Agent/Mattermost Agent escape output
- CVE-2026-93551 PoCSourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injection
- CVE-2026-93561 PoCSourceCodester Hospitals Patient Records Management System manage_history.php sql injection
- CVE-2026-93581 PoCpostcss-selector-parser AST Serialization container.js toString recursion
- CVE-2026-93591 PoCEdimax EW-7438RPn POST Request formHwSet command injection
- CVE-2026-93601 PoCEdimax EW-7438RPn POST Request formwlencrypt24g buffer overflow
- CVE-2026-93611 PoCEdimax EW-7438RPn POST Request formAccep formAccept command injection
- CVE-2026-93621 PoCEdimax EW-7438RPn Setting formConnectionSetting command injection
- CVE-2026-93631 PoCEdimax EW-7438RPn POST Request formEZCHNwlanSetu formEZCHNwlanSetup command injection
- CVE-2026-93641 PoCprojectworlds Online Art Gallery Shop adminHome.php sql injection
- CVE-2026-93651 PoCEttercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow
- CVE-2026-93661 PoCNousResearch hermes-agent prompt_builder.py _scan_context_content injection
- CVE-2026-93671 PoCNousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injection
- CVE-2026-93681 PoCNousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandbox
- CVE-2026-93691 PoCNousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison
- CVE-2026-93701 PoCulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
- CVE-2026-93711 PoCItzCrazyKns Vane API route.ts missing authentication
- CVE-2026-93721 PoCItzCrazyKns Vane Model Provider API route.ts server-side request forgery
- CVE-2026-93761 PoCJPress UCenter Article Submission Endpoint doWriteSave improper authorization
- CVE-2026-93771 PoCSourceCodester SUP Online Shopping productedit.php cross site scripting
- CVE-2026-93781 PoCEdimax BR-6675nD POST Request formHwSet command injection
- CVE-2026-93791 PoCEdimax BR-6675nD POST Request formWpsStart command injection
- CVE-2026-93801 PoCEdimax BR-6675nD POST Request formL2TPSetup buffer overflow
- CVE-2026-93811 PoCEdimax BR-6675nD POST Request formPPPoESetup buffer overflow
- CVE-2026-93821 PoCEdimax BR-6675nD POST Request formPPTPSetup buffer overflow
- CVE-2026-93831 PoCitsourcecode Electronic Judging System login.php sql injection
- CVE-2026-93841 PoCTotolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection
- CVE-2026-93851 PoCTotolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection
- CVE-2026-93861 PoCTotolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection
- CVE-2026-93871 PoCTotolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection
- CVE-2026-93881 PoCTotolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection
- CVE-2026-93891 PoCTenda F456 L7Im frmL7ImForm buffer overflow
- CVE-2026-93931 PoCH3C Magic B0 aspForm Edit_BasicSSID_5G buffer overflow
- CVE-2026-93991 PoCEdimax BR-6675nD POST Request formsetPPPoE buffer overflow
- CVE-2026-94001 PoCEdimax BR-6675nD POST Request formUSBStorage command injection
- CVE-2026-94011 PoCEdimax BR-6675nD POST Request formWanTcpipSetup buffer overflow
- CVE-2026-94021 PoCEdimax BR-6675nD POST Request formWlanMP command injection
- CVE-2026-94031 PoCEdimax BR-6675nD POST Request formWlSiteSurvey buffer overflow
- CVE-2026-94041 PoCTotolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection
- CVE-2026-94051 PoCTotolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection
- CVE-2026-94061 PoCTotolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection
- CVE-2026-94071 PoCTotolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection
- CVE-2026-94081 PoCTotolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection
- CVE-2026-94091 PoCSushmi-pal Invoice-System User Management user improper authorization
- CVE-2026-94101 PoCSushmi-pal Invoice-System Profile Workflow profile improper authorization
- CVE-2026-94111 PoCSourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection
- CVE-2026-94121 PoCSourceCodester Indian Invoicing System Backend Endpoint access control
- CVE-2026-94131 PoCSourceCodester Indian Invoicing System category.php cross site scripting
- CVE-2026-94141 PoCSourceCodester Indian Invoicing System Invoice Template Render Database-Backed add_order.php cross site scripting
- CVE-2026-94151 PoCcode-projects Employee Management System eloginwel.php cross site scripting
- CVE-2026-94161 PoCcode-projects Employee Management System myprofile.php cross site scripting
- CVE-2026-94171 PoCcode-projects Employee Management System myprofileup.php cross site scripting
- CVE-2026-94181 PoCcode-projects Employee Management System changepassemp.php cross site scripting
- CVE-2026-94191 PoCcode-projects Employee Management System empproject.php cross site scripting
- CVE-2026-94231 PoCEdimax BR-6675nD POST Request mp command injection
- CVE-2026-94241 PoCEdimax EW-7438RPn Content-Type formWlanMP os command injection
- CVE-2026-94251 PoCEdimax EW-7438RPn formWlanMP stack-based overflow
- CVE-2026-94261 PoCEdimax EW-7438RPn formHwSet stack-based overflow
- CVE-2026-94271 PoCEdimax EW-7438RPn webs formWlSiteSurvey stack-based overflow
- CVE-2026-94281 PoCTenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow
- CVE-2026-94291 PoCTenda F1202 WrlExtraSet formWrlExtraSet stack-based overflow
- CVE-2026-94301 PoCTenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow
- CVE-2026-94311 PoCTenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow
- CVE-2026-94321 PoCTotolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection
- CVE-2026-94331 PoCTotolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection
- CVE-2026-94341 PoCTotolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection
- CVE-2026-94351 PoCTotolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection
- CVE-2026-94361 PoCTotolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection
- CVE-2026-94371 PoCDTStack Taier REST API Runtime.exec os command injection
- CVE-2026-94381 PoCyashpokharna2555 StudentManagementSystem courseDel.php resource injection
- CVE-2026-94391 PoCEdimax BR-6675nD stainfo command injection
- CVE-2026-94401 PoCEdimax BR-6478AC POST Request formAccept command injection
- CVE-2026-94411 PoCEdimax BR-6478AC POST Request formiNICbasic command injection
- CVE-2026-94421 PoCEdimax BR-6478AC POST Request formiNICSiteSurvey buffer overflow
- CVE-2026-94431 PoCEdimax BR-6478AC POST Request formL2TPSetup buffer overflow
- CVE-2026-94441 PoCSourceCodester Simple POS and Inventory System GET Parameter deleteproduct.php delete sql injection
- CVE-2026-94451 PoCSourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted upload
- CVE-2026-94461 PoCSourceCodester Simple POS and Inventory System edit_customer.php sql injection
- CVE-2026-94471 PoCSourceCodester Simple POS and Inventory System search.php sql injection
- CVE-2026-94481 PoCcode-projects Employee Management System applyleave.php cross site scripting
- CVE-2026-94491 PoCcode-projects Employee Management System changepassemp.php sql injection
- CVE-2026-94501 PoCcode-projects Employee Management System psubmit.php sql injection
- CVE-2026-94511 PoCcode-projects Employee Management System applyleaveprocess.php sql injection
- CVE-2026-94521 PoCFoundDream miniclawd exec.ts ExecTool.execute os command injection
- CVE-2026-94531 PoCFoundDream miniclawd SkillsLoader skills-loader.ts which command injection
- CVE-2026-94541 PoCTotolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection
- CVE-2026-94551 PoCTotolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection
- CVE-2026-94561 PoCTotolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection
- CVE-2026-94571 PoCTotolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection
- CVE-2026-94581 PoCTotolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection
- CVE-2026-94591 PoCEdimax EW-7438RPn formConnectionSetting stack-based overflow
- CVE-2026-94601 PoCEdimax EW-7438RPn formAccept stack-based overflow
- CVE-2026-94611 PoCEdimax EW-7438RPn formRadius stack-based overflow
- CVE-2026-94621 PoCEdimax EW-7438RPn formWpsProxyEnable stack-based overflow
- CVE-2026-94631 PoCEdimax EW-7438RPn formLicence stack-based overflow
- CVE-2026-94641 PoCYunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-side request forgery
- CVE-2026-94651 PoCTiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection
- CVE-2026-94661 PoCTiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password recovery
- CVE-2026-94671 PoCdebugmcp mcp-debugger server.ts handleGetSourceContext path traversal
- CVE-2026-94681 PoCdazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal
- CVE-2026-94691 PoCyashpokharna2555 StudentManagementSystem success.php sql injection
- CVE-2026-94701 PoCyashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injection
- CVE-2026-94711 PoCyashpokharna2555 StudentManagementSystem student.php cross site scripting
- CVE-2026-94721 PoCdazeb markdown-downloader index.ts create_subdirectory path traversal
- CVE-2026-94731 PoCc-rick jimeng-mcp api.ts generateVideo path traversal
- CVE-2026-94741 PoCyashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection
- CVE-2026-94751 PoCTotolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection
- CVE-2026-94761 PoCTotolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection
- CVE-2026-94771 PoCTotolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection
- CVE-2026-94781 PoCTotolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection
- CVE-2026-94791 PoCEdimax EW-7438RPn formLogout stack-based overflow
- CVE-2026-94801 PoCEdimax EW-7438RPn formrefresh stack-based overflow
- CVE-2026-94811 PoCEdimax EW-7438RPn formStats stack-based overflow
- CVE-2026-94821 PoCEdimax EW-7438RPn formSDHCP stack-based overflow
- CVE-2026-94901 PoCAcer Care Center creates a Named Pipe with a weak Security Descriptor
- CVE-2026-94981 PoCDromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine
- CVE-2026-95001 PoCGNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow
- CVE-2026-95011 PoCGNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion
- CVE-2026-95021 PoCGNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflow
- CVE-2026-95031 PoCGNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference
- CVE-2026-95041 PoCGNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
- CVE-2026-95061 PoCPath Traversal Vulnerability in Bagisto
- CVE-2026-95111 PoCTotolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection
- CVE-2026-95121 PoCTotolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection
- CVE-2026-95131 PoCTotolink CA750-PoE Setting cstecgi.cgi NTPSyncWithHost os command injection
- CVE-2026-95141 PoCTotolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
- CVE-2026-95151 PoCTotolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection
- CVE-2026-95171 PoChemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control
- CVE-2026-95181 PoChemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent cross site scripting
- CVE-2026-95191 PoCstonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site scripting
- CVE-2026-95201 PoCblitz-js blitz Sign-in LoginForm.tsx cross site scripting
- CVE-2026-95211 PoCfraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input
- CVE-2026-95231 PoCAcrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform getCalcmeterDetailDayListTree sql injection
- CVE-2026-95251 PoCitsourcecode Electronic Judging System edit_judge.php sql injection
- CVE-2026-95261 PoCitsourcecode Electronic Judging System edit_team.php sql injection
- CVE-2026-95271 PoCitsourcecode Electronic Judging System judges.php cross site scripting
- CVE-2026-95281 PoCitsourcecode Electronic Judging System delete_judge.php sql injection
- CVE-2026-95291 PoCGNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference
- CVE-2026-95301 PoCGNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds
- CVE-2026-95311 PoCTotolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection
- CVE-2026-95321 PoCTotolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection
- CVE-2026-95331 PoCTotolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection
- CVE-2026-95341 PoCTotolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection
- CVE-2026-95401 PoCvllm-project vllm OpenAI-compatible Serving Path denial of service
- CVE-2026-95411 PoCSquirrel Cnut File sqobject.cpp ReadObject heap-based overflow
- CVE-2026-95421 PoCCodeAstro Leave Management System add_staff.php sql injection
- CVE-2026-95431 PoCTotolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
- CVE-2026-95441 PoCShenzhen Sixun Software Sixun Shanghui Group Business Management System PayConfig sql injection
- CVE-2026-95501 PoCAcrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform upfile path traversal
- CVE-2026-95511 PoCDas Parking Management System 停车场管理系统 API Endpoint ExportParkingRecords xp_cmdshell sql injection
- CVE-2026-95521 PoCDas Parking Management System 停车场管理系统 Search API Endpoint sql injection
- CVE-2026-95581 PoCA Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates…
- CVE-2026-95601 PoCPrivilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands…
- CVE-2026-95621 PoCsambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
- CVE-2026-95641 PoCSourceCodester/oretnom23 Hospitals Patient Records Management System view_patient cross site scripting
- CVE-2026-95651 PoChaojing8312 WorkClaw Blacklist bash.rs is_dangerous os command injection
- CVE-2026-95661 PoCteableio teable Sign-up LoginPage.tsx cross site scripting
- CVE-2026-95671 PoCGPAC MP4Box isom_intern.c MergeFragment null pointer dereference
- CVE-2026-95701 PoCTaskbuilder < 5.0.8 - Reflected XSS via Shortcode
- CVE-2026-95721 PoCGPAC MP4Box media.c Media_GetSample memory leak
- CVE-2026-95731 PoCitsourcecode Student Transcript Processing System index.php sql injection
- CVE-2026-95741 PoCitsourcecode Student Transcript Processing System trans.php sql injection
- CVE-2026-95751 PoCitsourcecode Student Transcript Processing System index.php sql injection
- CVE-2026-95761 PoCFluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export
- CVE-2026-95771 PoCPost Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
- CVE-2026-95791 PoCJeecgBoot SysUser userEdit user.getUsername access control
- CVE-2026-95801 PoCJeecgBoot selectDepart LoginController.selectDepart access control
- CVE-2026-95811 PoCJeecgBoot add access control
- CVE-2026-95821 PoCSourceCodester CET Automated Grading System with AI Predictive Analytics cross-site request forgery
- CVE-2026-95831 PoCSourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposure
- CVE-2026-95841 PoCcode-projects Project Management System Login chk.php sql injection
- CVE-2026-95861 PoCKEVUnauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
- CVE-2026-96031 PoCSourceCodester eDoc Doctor Appointment System delete-session.php authorization
- CVE-2026-96041 PoCJeecgBoot AiragModelController access control
- CVE-2026-96051 PoCGNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow
- CVE-2026-96061 PoCitsourcecode Courier Management System manage_user.php sql injection
- CVE-2026-96071 PoCitsourcecode Courier Management System parcel_list.php sql injection
- CVE-2026-96081 PoCQianFox FoxCMS Administrator Backend edit cross site scripting
- CVE-2026-96091 PoCQianFox FoxCMS Admin.php edit password recovery
- CVE-2026-96271 PoCUTT HiPER 1200GW Web Management setSysAdm strcpy buffer overflow
- CVE-2026-96281 PoCUTT HiPER 1200GW Web Management formPptpClientConfig stack-based overflow
- CVE-2026-96311 PoCUTT HiPER 1250GW Web Management formConfigFastDirectionW strcpy stack-based overflow
- CVE-2026-96321 PoCUTT HiPER 1250GW Web Management formGroupConfig strcpy stack-based overflow
- CVE-2026-96761 PoCf4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification
- CVE-2026-96771 PoCShariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting
- CVE-2026-96911 PoCWordPress Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.1.1 - PHP Object Injection…
- CVE-2026-96941 PoCImproper Neutralization of Substitution Characters in GitLab
- CVE-2026-97021 PoCInPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking
- CVE-2026-97091 PoCThemeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Meta Disclosure
- CVE-2026-97101 PoCThemeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Password Hash Disclosure
- CVE-2026-97691 PoCjusthtml before 1.10.0 Denial of Service via deeply nested HTML
- CVE-2026-97891 PoCNitroSense V3: Security Vulnerability Information
- CVE-2026-98061 PoCStored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert Names
- CVE-2026-98071 PoCIncorrect Authorization in GitLab
- CVE-2026-98091 PoCA stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers…
- CVE-2026-98101 PoCAI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuth
- CVE-2026-98111 PoCA stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for…
- CVE-2026-98151 PoCMagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE
- CVE-2026-98221 PoCWP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX Handlers
- CVE-2026-98303 PoCsBookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
- CVE-2026-98332 PoCsTag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
- CVE-2026-98481 PoCWP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter
- CVE-2026-99731 PoCOut of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox…
- CVE-2026-99971 PoCUse after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to…
- CVE-2026-99981 PoCInteger overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to…
- CVE-2026-99992 PoCsInappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code…