Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-67363

Balbooa.comBalbooa Forms Extensio...7.7HIGH
Pre-auth Payment Amount Manipulation in Balbooa Forms by Joomla Ext...

The Balbooa Forms extension for Joomla is susceptible to a significant vulnerability where the stripeCharges and payAuthorize endpoints accept payment amounts from user-controlled parameters. This flaw allows unattended attackers to manipulate payment amounts, potentially allowing them to purchas...

PoC for CVE-2026-48611

PHPbbPHPbb9.8CRITICAL
Improper Authentication in OAuth Implementation Affects phpBB Software

The OAuth implementation in phpBB has a critical flaw where improper authentication checks can lead to account hijacking. This vulnerability is particularly concerning as it may allow unauthorized users to gain access to accounts even if OAuth is not configured or enabled. Default installations a...

Discovered 2 hours ago

PoC for CVE-2026-76581

WordPressWPmu Dev Dashboard9.8CRITICAL
Authentication Bypass Vulnerability in WPMU DEV Dashboard for WordP...

The WPMU DEV Dashboard plugin for WordPress is prone to an authentication bypass vulnerability due to inconsistent handling of HMAC message construction between the `wdpsso_step1` and `wdpsso_step2` AJAX actions. The first step improperly exposes a concatenation of sensitive tokens, while the sec...

PoC for CVE-2018-7600

DrupalDrupal Before 7.58, 8....🟣 EPSS 100%9.8CRITICAL
Remote Code Execution Vulnerability in Drupal by Acquia

Multiple versions of Drupal, including those prior to 7.58 and various 8.x releases, are susceptible to a vulnerability that permits remote attackers to execute arbitrary code. This exploit takes advantage of configuration flaws in several subsystems, particularly those using default or common mo...

PoC for CVE-2014-6271

GnuBash🟣 EPSS 100%9.8CRITICAL
Code Injection Vulnerability in GNU Bash by The GNU Project

GNU Bash versions up to 4.3 are vulnerable to a code injection flaw due to the mishandling of trailing strings after function definitions in environment variables. This vulnerability enables remote attackers to execute arbitrary code by crafting specific environment variables under various condit...

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 100%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

Discovered 4 hours ago

PoC for CVE-2026-18741

FroidenWorksuite Saas4.6MEDIUM
Stored Cross-Site Scripting in Worksuite SaaS Asset Management Module

The Worksuite SaaS platform, in versions prior to 6.0.14, is affected by a stored cross-site scripting vulnerability within its Asset Management module. This allows authenticated administrators to submit malicious JavaScript payloads in the Location and Description fields when adding new assets. ...

PoC for CVE-2026-82587

Open5GSOpen5gs5.3MEDIUM
Memory Corruption Vulnerability in Open5GS AMF Component

A vulnerability has been identified in Open5GS versions up to 2.7.7, specifically within the AMF component. The issue arises from the amf_namf_comm_decode_ue_mm_context_list function, where improper handling of the ueContext.mmContextList[*].allowedNssai parameter may lead to memory corruption, a...

Discovered 6 hours ago

PoC for CVE-2026-82556

ForgejoForgejo5.3MEDIUM
Server-Side Request Forgery Vulnerability in Forgejo Repository Mig...

A vulnerability exists in the Repository Migration Handler of Forgejo, specifically in the function net.LookupIP located in the file services/migrations/allowlist/is_migrate_allowed.go. This issue can be exploited remotely, allowing attackers to perform server-side request forgery. The public dis...

PoC for CVE-2026-82555

TotolinkN600r6.3MEDIUM
Authentication Vulnerability in TOTOLINK N600R Router

A significant vulnerability exists within the TOTOLINK N600R Router, specifically in the loginAuth function of the Authentication Handler component. This flaw arises from the use of insufficiently random values, making the system susceptible to remote exploitation. Attackers could leverage this v...

PoC for CVE-2026-82554

SourcecodesterQueue Management System5.3MEDIUM
Cross-Site Scripting Flaw in SourceCodester Queue Management System

A security flaw exists in the SourceCodester Queue Management System 1.0, specifically within the /api/add_customer.php file. This vulnerability allows attackers to manipulate the 'Name' argument, facilitating cross-site scripting (XSS) attacks. The flaw can be exploited remotely, putting users a...

PoC for CVE-2026-82553

SambitrajStudent Management System5.3MEDIUM
Authorization Bypass in sambitraj Student Management System

A vulnerability exists in the sambitraj Student Management System's Student Dashboard component, specifically within the function mysqli_query in the file student_dashboard.php. This flaw arises due to improper handling of the roll_no argument, enabling unauthorized access to sensitive informatio...

Discovered 7 hours ago

PoC for CVE-2026-82552

LinuxMagma5.3MEDIUM
Denial of Service Vulnerability in Linux Foundation Magma 1.9.0

A vulnerability exists in Linux Foundation Magma 1.9.0 within the gNB Termination Handler's ngap_amf.c file. This flaw enables an attacker to initiate a denial-of-service attack remotely, potentially leading to service disruption. The specific functionalities that could be manipulated remain undi...

PoC for CVE-2026-82551

LinuxMagma6.9MEDIUM
State Issue in Linux Foundation Magma's NGSetup Handler Component

A vulnerability exists in version 1.9.0 of Linux Foundation Magma, specifically within the NGSetup Handler component located in the ngap_amf_handlers.c file. This flaw can be exploited remotely, allowing attackers to execute manipulations that lead to significant state issues. Given that exploit ...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 8 hours ago

PoC for CVE-2026-82550

LinuxMagma6.9MEDIUM
Improper Input Validation in Linux Foundation Magma Affecting Remot...

A security vulnerability exists in the Magma component's NGSetupRequest Handler, specifically related to improper input validation when handling the argument NG-IoT-DefaultPagingDRX. This flaw could allow for remote exploitation, potentially facilitating unauthorized access or control over affect...

PoC for CVE-2026-82549

LinuxMagma6.9MEDIUM
Security Vulnerability in Linux Foundation Magma - Integrity Check ...

A security vulnerability has been identified in the Linux Foundation Magma's SecurityModeComplete handler, specifically affecting version 1.9.0. This flaw allows for improper validation of integrity check values, which could be exploited remotely. The existence of publicly available exploits incr...

PoC for CVE-2026-82548

LinuxMagma6.9MEDIUM
Information Disclosure Vulnerability in Linux Foundation Magma

An information disclosure vulnerability has been identified in Linux Foundation Magma version 1.9.0, specifically affecting the InitialUEMessage Handler component. This vulnerability allows attackers to exploit an unknown function within the application, resulting in the potential exposure of sen...

Discovered 9 hours ago

PoC for CVE-2026-82547

LinuxMagma6.9MEDIUM
Improper Authentication in Linux Foundation Magma 1.9.0

A vulnerability exists in Linux Foundation Magma version 1.9.0, specifically within the Registration Complete Message Handler implemented in the file tasks/amf/amf_fsm.cpp. This flaw can allow unauthorized remote attackers to manipulate the system's authentication processes. It is crucial for use...

PoC for CVE-2026-82545

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A SQL injection vulnerability has been identified in itsourcecode's Sales and Inventory System version 1.0. This flaw resides in the argument handling of the /pages/sup_searchfrm.php file, where improper validation allows remote attackers to manipulate the ID parameter. Such exploitation can lead...

PoC for CVE-2026-82222

WordPressGiveWP10CRITICAL
Deserialization Vulnerability in GiveWP by StellarWP

A deserialization vulnerability exists in the GiveWP plugin, allowing unsanitized user input to manipulate object states and trigger remote code execution. This issue can lead to unauthorized actions being performed on the server, potentially impacting sensitive data and system integrity. The aff...

Discovered 11 hours ago

PoC for CVE-2026-82543

VastsaFilecodebox6.9MEDIUM
Race Condition Vulnerability in vastsa FileCodeBox Affected by Pick...

A race condition vulnerability has been identified in vastsa FileCodeBox, specifically affecting the update_file_usage function within the Pickup Limit Handler component. This flaw allows an attacker to manipulate the system remotely, potentially leading to unauthorized access or alterations of f...

PoC for CVE-2026-82542

TendaHg1010CRITICAL
Buffer Overflow Vulnerability in Tenda HG10 Boa Web Server

A vulnerability has been identified in the Tenda HG10, specifically within the Boa Web Server's formIPv6Routing function. This issue arises due to improper handling of the argument destNet, leading to a buffer overflow condition. This flaw allows attackers to execute remote exploits, potentially ...

PoC for CVE-2026-82541

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A significant security flaw has been identified in the itsourcecode Sales and Inventory System, specifically within the file /pages/sup_edit.php. This vulnerability allows attackers to manipulate the argument ID, leading to SQL injection attacks. The nature of this flaw enables remote exploitatio...

Discovered 12 hours ago

PoC for CVE-2026-82540

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A SQL injection vulnerability has been discovered in the itsourcecode Sales and Inventory System 1.0. This vulnerability affects a specific function in the /pages/cust_searchfrm.php file. By manipulating the argument ID, attackers can execute unauthorized SQL commands, leading to potential data b...

Discovered 13 hours ago

PoC for CVE-2026-82222

WordPressGiveWP10CRITICAL
Deserialization Vulnerability in GiveWP by StellarWP

A deserialization vulnerability exists in the GiveWP plugin, allowing unsanitized user input to manipulate object states and trigger remote code execution. This issue can lead to unauthorized actions being performed on the server, potentially impacting sensitive data and system integrity. The aff...

PoC for CVE-2026-82539

TotolinkA720r9.4CRITICAL
MAC Filtering Vulnerability in TOTOLINK A720R Product

A vulnerability exists in the TOTOLINK A720R router due to improper handling of the 'desc' argument in the MAC Filtering functionality within the cstecgi.cgi file. This flaw can be exploited remotely, allowing attackers to manipulate memory and potentially execute malicious code. The vulnerabilit...

PoC for CVE-2026-82488

Beetel450tc35.1MEDIUM
Cross Site Scripting Vulnerability in Beetel 450TC3 User Management...

A cross site scripting vulnerability has been identified in the Beetel 450TC3 router, specifically within the User Management component. By manipulating the Username argument, an attacker can execute arbitrary scripts in the context of the user's session. This vulnerability can be exploited remot...

Discovered 14 hours ago

PoC for CVE-2026-82487

Beetel450tc35.3MEDIUM
Weak Password Recovery Vulnerability in Beetel 450TC3 Router by Beetel

A security flaw has been identified in the Beetel 450TC3 router's password recovery mechanism that allows remote attackers to manipulate the system, potentially leading to weak password retrieval. This vulnerability could be exploited by unauthorized users who aim to gain access through insecure ...

PoC for CVE-2026-82485

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A security vulnerability in the itsourcecode Sales and Inventory System 1.0 has been identified in the pro_edit.php file. This vulnerability allows an attacker to manipulate the ID parameter, leading to potential SQL injection attacks. Such vulnerabilities may enable unauthorized access to sensit...

Discovered 15 hours ago

PoC for CVE-2026-82484

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A vulnerability exists in the itsourcecode Sales and Inventory System 1.0, where the /pages/emp_searchfrm.php file is susceptible to SQL injection via an improper handling of the ID argument. This flaw allows an attacker to execute arbitrary SQL commands, potentially exposing sensitive database i...

PoC for CVE-2026-45071

SymfonySymfony8.7HIGH
XML Entity Expansion Vulnerability in Symfony PHP Framework

The Symfony PHP framework has a vulnerability in its Crawler component due to improper handling of XML content. Specifically, prior to versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the method Crawler::addXmlContent() enabled DOMDocument::$validateOnParse, allowing for external entity resolution. T...

PoC for CVE-2026-82483

Coppermine-galleryCoppermine Photo Gallery5.1MEDIUM
Cross Site Scripting Vulnerability in Coppermine Photo Gallery by C...

A vulnerability in Coppermine Photo Gallery affects versions up to 1.6.28, specifically impacting the db_input.php file within the Hidden Album Update Endpoint. This vulnerability enables attackers to execute cross site scripting attacks remotely, potentially compromising user data and site integ...

Discovered 17 hours ago

PoC for CVE-2026-82482

Coppermine-galleryCoppermine Photo Gallery5.1MEDIUM
Cross Site Scripting Vulnerability in Coppermine Photo Gallery by C...

A security vulnerability has been identified in Coppermine Photo Gallery, affecting versions up to 1.6.28. This vulnerability resides in the 'edit_profile' endpoint, specifically in the 'profile.php' file, where improper handling of the 'Biography' argument allows for Cross Site Scripting (XSS) a...

PoC for CVE-2026-81766

WordPressReally Simple Security
Arbitrary Code Execution in Really Simple Security Plugin for WordP...

The Really Simple Security WordPress plugin, prior to version 9.8.0, allows administrators of subsites within a multisite network to execute arbitrary code. This is due to the absence of checks ensuring that the user is permitted to install the plugin, which compromises the security of the direct...

PoC for CVE-2026-81660

WordPressGroundhogg — Crm, News...
Stored Cross-Site Scripting Vulnerability in Groundhogg CRM Plugin

The Groundhogg CRM, Newsletters, and Marketing Automation WordPress plugin prior to version 4.5.13 fails to properly validate and escape values received from optional web form fields. This flaw enables unauthenticated attackers to execute Stored Cross-Site Scripting (XSS) attacks, potentially com...

PoC for CVE-2026-76585

WordPressCustomer Reviews For W...
Stored Cross-Site Scripting Vulnerability in WooCommerce Customer R...

The Customer Reviews for WooCommerce plugin prior to version 5.118.0 has a vulnerability that fails to properly sanitize and escape customer review content submitted through its endpoints. This oversight enables unauthenticated users to potentially launch Stored Cross-Site Scripting (XSS) attacks...

PoC for CVE-2026-19722

WordPressWPvivid — Backup, Migr...
Arbitrary File Write Vulnerability in WPvivid Backup Plugin

The WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.133 is susceptible to an arbitrary file write vulnerability. This issue arises as the plugin fails to properly validate the destination paths for files extracted from backup packages during restoration. As a result,...

PoC for CVE-2026-78364

WordPressMw WP Form
Stored Cross-Site Scripting Vulnerability in MW WP Form Plugin by W...

The MW WP Form plugin for WordPress prior to version 5.1.6 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient sanitization and escaping of its form settings. This loophole allows users with Editor permissions to potentially execute malicious scripts in the con...

PoC for CVE-2026-14307

WordPressGeotargetingWP
Cross-Site Scripting Vulnerability in GeotargetingWP Plugin by Word...

The GeotargetingWP plugin for WordPress versions prior to 3.5.6.2 is susceptible to cross-site scripting attacks due to inadequate sanitization and escaping of certain parameters in AJAX responses served with an HTML content type. This vulnerability enables unauthenticated attackers to inject mal...

PoC for CVE-2026-14835

WordPressSogo Add Script To Ind...
Script Injection Vulnerability in SOGO Add Script Plugin for WordPress

The SOGO Add Script to Individual Pages Header Footer plugin for WordPress allows users with contributor-level access and above to insert unverified JavaScript code into the post metadata. This occurs because the plugin does not adequately sanitize or escape custom header/footer script values. As...

Discovered 1 day ago

PoC for CVE-2026-82424

PHPgurukulStudent Information Sy...5.3MEDIUM
SQL Injection Vulnerability in PHPGurukul Student Information System

A security flaw has been discovered in the PHPGurukul Student Information System version 1.0, specifically in the /student_edit1.php file. This vulnerability arises due to improper handling of the ID argument, allowing attackers to execute SQL injection attacks remotely. The exploit has been publ...

PoC for CVE-2026-23989

Opencloud-euReva8.2HIGH
Authorization Bypass in OpenCloud's Reva Platform

The Reva interoperability platform from OpenCloud contains a vulnerability in the GRPC authorization middleware that allows malicious users to bypass scope verification associated with public links. This flaw can be exploited through the archiver service to create archives (zip or tar files) cont...

PoC for CVE-2026-82422

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A security flaw has been identified in the itSourceCode Sales and Inventory System 1.0, specifically within an unknown function in the file /pages/emp_del.php. This vulnerability is exploited by manipulating the argument ID, which can lead to SQL injection attacks. As the exploit code is publicly...

PoC for CVE-2026-82421

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A vulnerability has been identified in the itsourcecode Sales and Inventory System 1.0 concerning improper handling of the argument ID in the file /pages/emp_edit.php. This flaw allows an attacker to manipulate SQL queries, potentially leading to unauthorized access and data manipulation. The exp...

PoC for CVE-2022-38694

Unisoc (shanghai)...Sc9863a//t310/t610/t618/7.8HIGH
Uncontrolled Write Vulnerability in UNISOC BootRom Product

The vulnerability occurring in UNISOC's BootRom allows a possible unchecked write address, enabling local escalation of privilege without requiring additional execution privileges. This flaw poses a significant security risk, as it can be exploited by malicious actors to gain unauthorized access ...

PoC for CVE-2026-82473

KubeedgeKubeedge8.8HIGH
Authentication Bypass in KubeEdge CloudCore Affects Node Task Repor...

The KubeEdge CloudCore component, up to version 1.23.1, is vulnerable to an authentication bypass that allows attackers to submit node task status reports without any authentication. This flaw is exploitable via the HTTPS service on port 10002, enabling unauthorized users to manipulate the percei...

PoC for CVE-2026-4001

WordPressWooCommerce Custom Pro...9.8CRITICAL
Remote Code Execution Vulnerability in Woocommerce Custom Product A...

The Woocommerce Custom Product Addons Pro plugin for WordPress has a vulnerability that allows Remote Code Execution due to insufficient sanitization of user inputs. Specifically, in the process_custom_formula() function, user-defined custom pricing formulas are not properly validated before bein...

Discovered 2 days ago

PoC for CVE-2026-82286

BuilderioGpt-crawler8.8HIGH
Arbitrary File Write Vulnerability in gpt-crawler by BuilderIO

The gpt-crawler, up to version 1.5.1, contains a significant flaw in its handling of the outputFileName parameter in the POST /crawl endpoint. This vulnerability permits unauthenticated users to write arbitrary files to any location within the filesystem. By providing carefully crafted input that...

PoC for CVE-2026-81346

WordPressFrontend Admin By Dyna...4.3MEDIUM
Unauthorized Deletion Vulnerability in Frontend Admin Plugin by Dyn...

The Frontend Admin plugin developed by DynamiApps suffers from an improper authorization vulnerability due to the absence of a capability check on certain AJAX actions. This flaw permits any authenticated user, including subscribers, to delete arbitrary membership plans. As a result, this vulnera...