Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:has-public-poc — CVE vulnerabilities tagged 96

96 CVE security advisories tagged "state:has-public-poc" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:has-public-poc" signifies that a specific Common Vulnerabilities and Exposures identifier has been confirmed to have a publicly available proof-of-concept exploit. This designation is critical because it transitions a theoretical flaw into an immediate, actionable threat, allowing attackers to validate the vulnerability’s existence and impact without needing to reverse-engineer the underlying code. Consequently, the risk profile escalates significantly, as the barrier to entry for exploitation drops dramatically, enabling both malicious actors and security researchers to demonstrate the breach. Typical scenarios involve critical remote code execution or privilege escalation flaws where developers can no longer claim ignorance of the exploitability. For organizations, this tag serves as a high-priority alert, necessitating immediate patching or mitigation strategies to prevent active exploitation in the wild, thereby reducing the window of opportunity for adversaries to compromise systems before official fixes are deployed.

CVE ID Title CVSS Severity Published
CVE-2026-94129 BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where — VALKYRIE AURORA CWE-123 8.8 High 2026-09-21
CVE-2026-93742 Totolink A3002MU formWsc command injection — A3002MU CWE-77 9.9 Critical 2026-09-19
CVE-2026-90811 cosmicstack-labs mercury-agent Shell Permission Manifest permissions.ts PermissionManager.checkShellCommand information disclosure — mercury-agent CWE-200 3.3 Low 2026-09-14
CVE-2026-90789 itsourcecode Leave Management System login.php sql injection — Leave Management System CWE-89 7.3 High 2026-09-14
CVE-2026-90525 itsourcecode Sales and Inventory System cust_pos_trans.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-09-13
CVE-2026-90493 Tonec Internet Download Manager Kernel Driver idmwfp.sys access control — Internet Download Manager CWE-284 8.8 High 2026-09-13
CVE-2026-90487 Xuxueli xxl-job JobGroupController.java privileges management — xxl-job CWE-269 4.3 Medium 2026-09-12
CVE-2026-86515 vgmstream txtp txtp_parser.c add_entry resource consumption — vgmstream CWE-400 4.3 Medium 2026-09-08
CVE-2026-78198 SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection — Simple Online Food Ordering System CWE-89 7.3 High 2026-08-24
CVE-2026-78050 Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow — CF-N1-S CWE-121 9.9 Critical 2026-08-22
CVE-2026-77025 itsourcecode Hospital Management System viewappointmentpending.php sql injection — Hospital Management System CWE-89 6.3 Medium 2026-08-20
CVE-2026-76997 SourceCodester Simple Online Food Ordering System ajax.php save_category sql injection — Simple Online Food Ordering System CWE-89 6.3 Medium 2026-08-20
CVE-2026-76762 code-projects Assessment Management welcome.php sql injection — Assessment Management CWE-89 7.3 High 2026-08-19
CVE-2026-75081 Webkul Bagisto store behavioral workflow — Bagisto CWE-841 4.3 Medium 2026-08-17
CVE-2026-19977 EFM ipTIME A3004T Session Validation httpcon_check_session_url improper authentication — ipTIME A3004T CWE-287 10.0 Critical 2026-08-17
CVE-2026-19933 DefaultFuction Customer-Relationship-Management-In-C-Project Customer Search gets stack-based overflow — Customer-Relationship-Management-In-C-Project CWE-121 6.3 Medium 2026-08-16
CVE-2026-19926 Evergreen open-ils.fielder OpenSRF Service osrf-gateway-v1 sql injection — Evergreen CWE-89 7.3 High 2026-08-16
CVE-2026-19791 Tenda G0 httpd web management interface module addStaticRoute stack-based overflow — G0 CWE-121 8.8 High 2026-08-14
CVE-2026-19767 itsourcecode Hospital Management System viewdoctortimings.php sql injection — Hospital Management System CWE-89 6.3 Medium 2026-08-14
CVE-2026-19376 Uasoft Badaso File API api.php class permission — Badaso CWE-275 7.3 High 2026-08-09
CVE-2026-19357 MingSoft MCMS ms-mdiy get information disclosure — MCMS CWE-200 5.3 Medium 2026-08-09
CVE-2026-19006 mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization — openclaw-cn CWE-863 6.3 Medium 2026-08-06
CVE-2026-18897 UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow — HiPER 1250GW CWE-121 8.8 High 2026-08-05
CVE-2026-18773 NousResearch hermes-agent Quick run.py _check_slash_access authorization — hermes-agent CWE-863 6.3 Medium 2026-08-04
CVE-2026-18605 CheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search path — AppCheck Pro CWE-427 7.0 High 2026-08-03
CVE-2026-18592 osCommerce Email Template Configuration EmailController.php EmailController sql injection — osCommerce CWE-89 4.7 Medium 2026-08-03
CVE-2026-17433 nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization — NanoClaw CWE-285 5.3 Medium 2026-07-26
CVE-2026-15620 mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery — clawlet CWE-918 6.3 Medium 2026-07-14
CVE-2026-15545 Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write — Tomato CWE-787 8.8 High 2026-07-13
CVE-2026-15509 Leantime JSON-RPC Endpoint addUser improper authorization — Leantime CWE-285 6.3 Medium 2026-07-12

Vulnerabilities classified as state:has-public-poc represent 96 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.