Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:has-public-poc — CVE vulnerabilities tagged 88

88 CVE security advisories tagged "state:has-public-poc" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:has-public-poc" signifies that a specific Common Vulnerabilities and Exposures identifier has been confirmed to have a publicly available proof-of-concept exploit. This designation is critical because it transitions a theoretical flaw into an immediate, actionable threat, allowing attackers to validate the vulnerability’s existence and impact without needing to reverse-engineer the underlying code. Consequently, the risk profile escalates significantly, as the barrier to entry for exploitation drops dramatically, enabling both malicious actors and security researchers to demonstrate the breach. Typical scenarios involve critical remote code execution or privilege escalation flaws where developers can no longer claim ignorance of the exploitability. For organizations, this tag serves as a high-priority alert, necessitating immediate patching or mitigation strategies to prevent active exploitation in the wild, thereby reducing the window of opportunity for adversaries to compromise systems before official fixes are deployed.

CVE ID Title CVSS Severity Published
CVE-2026-78198 SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection — Simple Online Food Ordering System CWE-89 7.3 High 2026-08-24
CVE-2026-78050 Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow — CF-N1-S CWE-121 9.9 Critical 2026-08-22
CVE-2026-77025 itsourcecode Hospital Management System viewappointmentpending.php sql injection — Hospital Management System CWE-89 6.3 Medium 2026-08-20
CVE-2026-76997 SourceCodester Simple Online Food Ordering System ajax.php save_category sql injection — Simple Online Food Ordering System CWE-89 6.3 Medium 2026-08-20
CVE-2026-76762 code-projects Assessment Management welcome.php sql injection — Assessment Management CWE-89 7.3 High 2026-08-19
CVE-2026-75081 Webkul Bagisto store behavioral workflow — Bagisto CWE-841 4.3 Medium 2026-08-17
CVE-2026-19977 EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication — ipTIME A3004T CWE-287 10.0 Critical 2026-08-17
CVE-2026-19933 DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflow — Customer-Relationship-Management-In-C-Project CWE-121 6.3 Medium 2026-08-16
CVE-2026-19926 Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection — Evergreen CWE-89 7.3 High 2026-08-16
CVE-2026-19791 Tenda G0 httpd web management interface module addStaticRoute stack-based overflow — G0 CWE-121 8.8 High 2026-08-14
CVE-2026-19767 itsourcecode Hospital Management System viewdoctortimings.php sql injection — Hospital Management System CWE-89 6.3 Medium 2026-08-14
CVE-2026-19376 Uasoft Badaso File API api.php class permission — Badaso CWE-275 7.3 High 2026-08-09
CVE-2026-19357 MingSoft MCMS ms-mdiy get information disclosure — MCMS CWE-200 5.3 Medium 2026-08-09
CVE-2026-19006 mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization — openclaw-cn CWE-863 6.3 Medium 2026-08-06
CVE-2026-18897 UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow — HiPER 1250GW CWE-121 8.8 High 2026-08-05
CVE-2026-18773 NousResearch hermes-agent Quick run.py _check_slash_access authorization — hermes-agent CWE-863 6.3 Medium 2026-08-04
CVE-2026-18605 CheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search path — AppCheck Pro CWE-427 7.0 High 2026-08-03
CVE-2026-18592 osCommerce Email Template Configuration EmailController.php EmailController sql injection — osCommerce CWE-89 4.7 Medium 2026-08-03
CVE-2026-17433 nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization — NanoClaw CWE-285 5.3 Medium 2026-07-26
CVE-2026-15620 mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery — clawlet CWE-918 6.3 Medium 2026-07-14
CVE-2026-15545 Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write — Tomato CWE-787 8.8 High 2026-07-13
CVE-2026-15509 Leantime JSON-RPC Endpoint addUser improper authorization — Leantime CWE-285 6.3 Medium 2026-07-12
CVE-2026-15482 Aster Telecom Azcall HTTP sis.php sql injection — Azcall CWE-89 7.3 High 2026-07-12
CVE-2026-15137 code-projects Interview Management System View.php sql injection — Interview Management System CWE-89 7.3 High 2026-07-09
CVE-2026-14786 radareorg radare2 str.c r_str_word_get0set integer overflow — radare2 CWE-190 3.3 Low 2026-07-06
CVE-2026-14722 tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection — TidGi-Desktop CWE-94 7.3 High 2026-07-05
CVE-2026-14625 NousResearch hermes-agent server.py shell.exec protection mechanism — hermes-agent CWE-693 6.3 Medium 2026-07-04
CVE-2026-13559 code-projects Real State Services single-list_sale.php add sql injection — Real State Services CWE-89 7.3 High 2026-06-29
CVE-2026-13528 YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal — ruoyi-vue-pro CWE-22 7.3 High 2026-06-29
CVE-2026-13496 itsourcecode Hospital Management System ajaxmedicine.php sql injection — Hospital Management System CWE-89 6.3 Medium 2026-06-28

Vulnerabilities classified as state:has-public-poc represent 88 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.