CVE-CVE-2026-38526
Severity
CRITICAL
CVSS Score
9.9
Description
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file....
PoCs for CVE-CVE-2026-38526
htb-labs-nexus
Buffer Overflow
Shell
0
DiegoRivas1
2026-08-27
Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-...
Buffer Overflow
Shell
0
Shirouuu
2026-09-14
CVE-2026-38526
RCE
Python
0
Harry178945
2026-09-28