Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:has-public-poc — CVE vulnerabilities tagged 96

96 CVE security advisories tagged "state:has-public-poc" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:has-public-poc" signifies that a specific Common Vulnerabilities and Exposures identifier has been confirmed to have a publicly available proof-of-concept exploit. This designation is critical because it transitions a theoretical flaw into an immediate, actionable threat, allowing attackers to validate the vulnerability’s existence and impact without needing to reverse-engineer the underlying code. Consequently, the risk profile escalates significantly, as the barrier to entry for exploitation drops dramatically, enabling both malicious actors and security researchers to demonstrate the breach. Typical scenarios involve critical remote code execution or privilege escalation flaws where developers can no longer claim ignorance of the exploitability. For organizations, this tag serves as a high-priority alert, necessitating immediate patching or mitigation strategies to prevent active exploitation in the wild, thereby reducing the window of opportunity for adversaries to compromise systems before official fixes are deployed.

CVE ID Title CVSS Severity Published
CVE-2026-8128 SourceCodester SUP Online Shopping viewmsg.php sql injection — SUP Online Shopping CWE-89 7.3 High 2026-05-08
CVE-2026-8116 huangjunsen0406 xiaozhi-mcphub dxtController.ts path traversal — xiaozhi-mcphub CWE-22 6.3 Medium 2026-05-07
CVE-2026-8088 OSGeo gdal GDapi.c GDfieldinfo out-of-bounds — gdal CWE-125 3.3 Low 2026-05-07
CVE-2026-7700 langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection — langflow CWE-94 6.3 Medium 2026-05-03
CVE-2026-7691 Wavlink WL-WN570HA1 adm.cgi set_sys_cmd command injection — WL-WN570HA1 CWE-77 6.3 Medium 2026-05-03
CVE-2026-7679 YunaiV yudao-cloud OAuth2TokenServiceImpl.java getAccessToken improper authentication — yudao-cloud CWE-287 7.3 High 2026-05-03
CVE-2026-7645 ruvnet sublinear-time-solver MCP server.js export_state path traversal — sublinear-time-solver CWE-22 6.5 Medium 2026-05-02
CVE-2026-7602 JeecgBoot FillRuleUtil edit improper authorization — JeecgBoot CWE-285 6.3 Medium 2026-05-02
CVE-2026-7553 code-projects Gym Management System edit_exercises.php sql injection — Gym Management System CWE-89 4.7 Medium 2026-05-01
CVE-2026-7502 LinkStackOrg LinkStack Management Endpoint UserController.php saveLink authorization — LinkStack CWE-639 5.4 Medium 2026-04-30
CVE-2026-7388 EyouCMS Template File FilemanagerLogic.php editFile code injection — EyouCMS CWE-94 4.7 Medium 2026-04-29
CVE-2026-7234 BrowserOperator browser-operator-core server.js startsWith path traversal — browser-operator-core CWE-22 7.3 High 2026-04-28
CVE-2026-7227 SourceCodester Pizzafy Ecommerce System ajax.php login sql injection — Pizzafy Ecommerce System CWE-89 7.3 High 2026-04-28
CVE-2026-7093 code-projects Invoice System in Laravel Invoice Endpoint invoice improper authorization — Invoice System in Laravel CWE-285 6.3 Medium 2026-04-27
CVE-2026-7081 Tenda F456 httpd GstDhcpSetSer fromGstDhcpSetSer buffer overflow — F456 CWE-120 8.8 High 2026-04-27
CVE-2026-7063 code-projects Employee Management System Endpoint eprocess.php sql injection — Employee Management System CWE-89 7.3 High 2026-04-26
CVE-2026-7038 tufantunc ssh-mcp Command Line index.ts insufficiently protected credentials — ssh-mcp CWE-522 3.3 Low 2026-04-26
CVE-2026-5557 badlogic pi-mono pi-mom Slack Bot slack.ts authentication bypass — pi-mono CWE-288 6.3 Medium 2026-04-05
CVE-2026-5484 BookStackApp BookStack Chapter Export ExportFormatter.php chapterToMarkdown access control — BookStack CWE-284 5.3 Medium 2026-04-03
CVE-2026-5320 vanna-ai vanna Chat API Endpoint v2 missing authentication — vanna CWE-306 7.3 High 2026-04-02
CVE-2026-5125 raine consult-llm-mcp server.ts child_process.execSync os command injection — consult-llm-mcp CWE-78 5.3 Medium 2026-03-30
CVE-2026-4963 huggingface smolagents Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_with code injection — smolagents CWE-94 6.3 Medium 2026-03-27
CVE-2026-4467 Comfast CF-AC100 mbox-config command injection — CF-AC100 CWE-77 4.7 Medium 2026-03-20
CVE-2026-4015 GPAC TeXML File load_text.c txtin_process_texml stack-based overflow — GPAC CWE-121 5.3 Medium 2026-03-12
CVE-2026-1589 itsourcecode School Management System index.php sql injection — School Management System CWE-89 7.3 High 2026-01-29
CVE-2026-1119 itsourcecode Society Management System delete_activity.php sql injection — Society Management System CWE-89 7.3 High 2026-01-18
CVE-2025-14096 Credential Disclosure vulnerability in Radiometer Products — ABL90 FLEX and ABL90 FLEX PLUS Analyzers CWE-798 8.4 High 2025-12-17
CVE-2025-13236 itsourcecode Inventory Management System index.php sql injection — Inventory Management System CWE-89 6.3 Medium 2025-11-16
CVE-2025-12745 QuickJS quickjs.c js_array_buffer_slice buffer over-read — QuickJS CWE-126 5.3 Medium 2025-11-05
CVE-2025-11317 Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 findSingConfigPage.do findRolePage sql injection — Data Leakage Prevention System 天锐数据泄露防护系统 CWE-89 7.3 High 2025-10-06

Vulnerabilities classified as state:has-public-poc represent 96 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.