Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:has-public-poc — CVE vulnerabilities tagged 96

96 CVE security advisories tagged "state:has-public-poc" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:has-public-poc" signifies that a specific Common Vulnerabilities and Exposures identifier has been confirmed to have a publicly available proof-of-concept exploit. This designation is critical because it transitions a theoretical flaw into an immediate, actionable threat, allowing attackers to validate the vulnerability’s existence and impact without needing to reverse-engineer the underlying code. Consequently, the risk profile escalates significantly, as the barrier to entry for exploitation drops dramatically, enabling both malicious actors and security researchers to demonstrate the breach. Typical scenarios involve critical remote code execution or privilege escalation flaws where developers can no longer claim ignorance of the exploitability. For organizations, this tag serves as a high-priority alert, necessitating immediate patching or mitigation strategies to prevent active exploitation in the wild, thereby reducing the window of opportunity for adversaries to compromise systems before official fixes are deployed.

CVE ID Title CVSS Severity Published
CVE-2026-15482 Aster Telecom Azcall HTTP sis.php sql injection — Azcall CWE-89 7.3 High 2026-07-12
CVE-2026-15137 code-projects Interview Management System View.php sql injection — Interview Management System CWE-89 7.3 High 2026-07-09
CVE-2026-14786 radareorg radare2 str.c r_str_word_get0set integer overflow — radare2 CWE-190 3.3 Low 2026-07-06
CVE-2026-14722 tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection — TidGi-Desktop CWE-94 7.3 High 2026-07-05
CVE-2026-14625 NousResearch hermes-agent server.py shell.exec protection mechanism — hermes-agent CWE-693 6.3 Medium 2026-07-04
CVE-2026-13559 code-projects Real State Services single-list_sale.php add sql injection — Real State Services CWE-89 7.3 High 2026-06-29
CVE-2026-13528 YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal — ruoyi-vue-pro CWE-22 7.3 High 2026-06-29
CVE-2026-13496 itsourcecode Hospital Management System ajaxmedicine.php sql injection — Hospital Management System CWE-89 6.3 Medium 2026-06-28
CVE-2026-13482 skypilot-org skypilot User ID server.py username.encode weak hash — skypilot CWE-328 3.7 Low 2026-06-28
CVE-2026-12773 BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication — litellm CWE-287 7.3 High 2026-06-21
CVE-2026-12066 PbootCMS Password MemberController.php retrieve password recovery — PbootCMS CWE-640 7.3 High 2026-06-12
CVE-2026-11584 CodeAstro Student Attendance Management System createClass.php edit sql injection — Student Attendance Management System CWE-89 6.3 Medium 2026-06-08
CVE-2026-11532 imvks786 student_management_system Student Record add.php access control — student_management_system CWE-284 6.3 Medium 2026-06-08
CVE-2026-11484 SourceCodester Class and Exam Timetabling System archive3.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-06-08
CVE-2026-10619 sayan365 student-management-system improper authentication — student-management-system CWE-287 7.3 High 2026-06-02
CVE-2026-10301 itsourcecode Fees Management System index.php cross site scripting — Fees Management System CWE-79 4.3 Medium 2026-06-01
CVE-2026-10286 CodeAstro Payroll System home_employee.php sql injection — Payroll System CWE-89 6.3 Medium 2026-06-01
CVE-2026-10260 CodeAstro Online Job Portal delete-jobs.php sql injection — Online Job Portal CWE-89 7.3 High 2026-06-01
CVE-2026-10187 Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow — N300RH CWE-121 9.8 Critical 2026-05-31
CVE-2026-10185 SourceCodester Hospitals Patient Records Management System Users.php save sql injection — Hospitals Patient Records Management System CWE-89 7.3 High 2026-05-31
CVE-2026-10178 code-projects Online Music Site AdminEditAlbum.php sql injection — Online Music Site CWE-89 7.3 High 2026-05-31
CVE-2026-10176 Aider-AI Aider Code Generation Workflow sql injection — Aider CWE-89 6.3 Medium 2026-05-31
CVE-2026-10110 code-projects Student Details Management System index.php sql injection — Student Details Management System CWE-89 7.3 High 2026-05-30
CVE-2026-9512 Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection — CA750-PoE CWE-78 6.3 Medium 2026-05-25
CVE-2026-9478 Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection — A8000RU CWE-78 9.8 Critical 2026-05-25
CVE-2026-9451 code-projects Employee Management System applyleaveprocess.php sql injection — Employee Management System CWE-89 6.3 Medium 2026-05-25
CVE-2026-9381 Edimax BR-6675nD POST Request formPPPoESetup buffer overflow — BR-6675nD CWE-120 8.8 High 2026-05-24
CVE-2026-9305 QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection — new-api CWE-89 6.3 Medium 2026-05-23
CVE-2026-8765 Kilo-Org kilocode File Diff API Endpoint worktree-diff.ts Bun.file path traversal — kilocode CWE-22 4.3 Medium 2026-05-17
CVE-2026-8752 h2oai h2o-3 Rapids setproperty Primitive AstSetProperty.java exec access control — h2o-3 CWE-284 5.3 Medium 2026-05-17

Vulnerabilities classified as state:has-public-poc represent 96 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.