Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 2 hours ago
PoC for CVE-2026-82922
A security vulnerability exists in ShopEx ECShop affecting the flow_update_cart function in the /flow.php file. The flaw allows manipulation of the rec_id argument, leading to SQL injection attacks that can be executed remotely. This vulnerability has been publicly disclosed, posing a risk to unp...
Discovered 3 hours ago
PoC for CVE-2026-82921
A vulnerability exists within ShopEx ECShop versions up to 2.5.1 in the check_img_type functionality located in admin/pack.php. Specifically, this weakness allows an attacker to manipulate the pack_img argument, resulting in unrestricted file uploads. This flaw exposes affected systems to potenti...
PoC for CVE-2026-82914
A security flaw has been identified in version 1.0 of the kishan0725 Hospital Management System, specifically affecting the /search.php file. This vulnerability arises from inadequate input validation in the 'Contact' argument, allowing an attacker to execute SQL injection attacks remotely. The p...
PoC for CVE-2026-82909
The new-api component of QuantumNous contains a vulnerability in its Revoked API Token Handler, allowing attackers to manipulate the system and cause session expiration. This issue arises from an unspecified functionality within the API usage token file, which can be exploited remotely. Affected ...
Discovered 4 hours ago
PoC for CVE-2026-82908
A vulnerability exists in MSI Dragon Center, found in the MmioWritePath function of the NTIOLib_X64.sys library. This issue arises from improper handling of argument counts and element sizes, leading to integer overflow. The exploit requires local access to the affected system, and while the vuln...
PoC for CVE-2026-82906
A significant security flaw has been identified in sdcb chats versions up to 1.12.0. This vulnerability affects the DownloadPublic function within the Signed File Download Endpoint, specifically in the FileController.cs file. The issue arises due to inadequate authentication checks, allowing unau...
PoC for CVE-2026-82905
A vulnerability has been identified in SDCB Chats, specifically in versions up to 1.12.0. The issue resides within the McpController function of the fetch-tools Endpoint, compromising the system's security by allowing unauthorized server-side request forgery. This flaw can be exploited remotely, ...
PoC for CVE-2026-82835
A vulnerability has been discovered in Django-Vue-Admin version 1.0, where an improper access control issue exists in the '/api/file/' endpoint. The flaw allows remote attackers to manipulate the 'file_id' argument, potentially leading to unauthorized access to sensitive files and data. This vuln...
Discovered 5 hours ago
PoC for CVE-2026-82834
A security issue has been identified in the Doccano Open Source Annotation Tools, particularly within the Bulk-Delete Endpoint for the LabelList function. This vulnerability allows for improper access control, potentially enabling remote exploitation. The issue affects versions of Doccano up to a...
PoC for CVE-2026-82833
A vulnerability exists in Doccano Open Source Annotation Tools that affects the Project Example Detail Endpoint in versions up to 1.8.5. This flaw allows unauthorized access due to improper access controls in the ExampleDetail function of the endpoint located at /v1/projects/1/examples/. Given th...
PoC for CVE-2026-82821
A vulnerability exists in FLVMeta, affecting versions up to 1.2.2, specifically within the AMF Object Parsing component. This deficiency enables an attacker to exploit the function amf_object_get located in the src/amf.c file, causing a null pointer dereference. Although the attack can be initiat...
PoC for CVE-2026-82820
A heap-based buffer overflow vulnerability exists in the AMF string processing function `amf_string_new` of FLVMeta up to version 1.2.2. This flaw arises from improper handling of argument length, allowing attackers to potentially exploit the vulnerability remotely. Although the project maintaine...
Discovered 6 hours ago
PoC for CVE-2026-82818
A significant access control vulnerability exists in dibo-software's diboot version 3.8.0, specifically affecting the Tenant Resource Assignment Handler found in the file /api/iam/tenant/resource. The vulnerability arises from improper validation of the tenantId argument, which could allow attack...
PoC for CVE-2026-82817
A vulnerability exists in dibo-software diboot version 3.8.0, related to the Tenant Administrator Management API. Unauthorized manipulation of the 'tenantId' argument leads to improper access controls, potentially enabling remote attackers to exploit the API without proper authorization. Despite ...
PoC for CVE-2026-82816
A vulnerability exists in Dibo-Software's Diboot version 3.8.0 involving the AI Session Endpoint located at /api/ai-session/. This issue allows for an authorization bypass, which can be exploited remotely. The nature of this vulnerability could expose sensitive functionalities of the application ...
PoC for CVE-2026-82815
A vulnerability has been identified in MegaEase EaseProbe up to version 2.3.0 that affects the realIP function in the Middleware component. The flaw involves the improper handling of the X-Forwarded-For/X-Real-IP/True-Client-IP headers, which can lead to unauthorized access. This vulnerability al...
Discovered 7 hours ago
PoC for CVE-2026-82813
A significant vulnerability has been identified in the TubeBuddy for YouTube Extension by BEN Group, affecting versions up to 5.8.4 on Chrome browsers. The flaw resides in the TBGlobal.GetToken function within the tubebuddymaster1.js file, which fails to adequately verify the authenticity of data...
PoC for CVE-2026-82811
A security vulnerability has been identified in the Toggl Track Extension version 4.11.16 that allows remote attackers to exploit an origin validation error through the postMessage handler. This vulnerability could enable an attacker to manipulate messages coming from unauthorized origins. The ve...
PoC for CVE-2026-76569
A reflected XSS vulnerability has been identified in the Phoca Download extension used for Joomla. Malicious actors can exploit this flaw through the search GET parameter, potentially executing arbitrary JavaScript in the context of the user's browser, leading to unauthorized access and data expo...
PoC for CVE-2026-82810
A vulnerability has been discovered in the extension.vn 2FA Authenticator Extension version 1.0.0.2, specifically within the Background Service Worker component. The flaw resides in the function chrome.runtime.onMessageExternal.addListener, which fails to properly manage the sender.id argument. T...
PoC for CVE-2026-82809
An information disclosure vulnerability has been identified in the vidIQ Vision for YouTube Extension (version 3.199.0) for Chrome. The flaw resides in the window.addEventListener method utilized by the postMessage handler, allowing an attacker to manipulate the argument 'vidiqEvent' and extract ...
Discovered 8 hours ago
PoC for CVE-2026-82808
A vulnerability has been detected in the Inbox Foundry ActiveInbox Extension for Chrome, which affects versions up to 7.10.24. It involves the improper handling of Google OAuth Client Secret within the file dist/service-worker.production-esm.js. This flaw allows an attacker to manipulate hard-cod...
PoC for CVE-2026-82807
A local privilege escalation vulnerability exists in the ieungSoft Ultra RAMDisk Pro 1.82. The issue is located in the URDSCSI.sys library within the Kernel Driver component, where inadequate privilege management can be exploited. The attack requires local access to the system, and details of the...
PoC for CVE-2026-82805
A cross-site scripting vulnerability exists in Typora versions up to 1.13.8 and 1.14.6, affecting the Mermaid Rendering Engine. This flaw allows for the manipulation of the classDef/style argument, which can be exploited remotely. The vulnerability has been publicly disclosed, and users are advis...
PoC for CVE-2026-82803
A vulnerability exists in the Armink Struct2json library in version 1.0, specifically in the function S2J_STRUCT_GET_string_ELEMENT located in the header file `s2jdef.h`, which is responsible for JSON deserialization. This flaw arises from the manipulation of the argument `valuestring`, leading t...
Discovered 9 hours ago
PoC for CVE-2026-82802
A vulnerability has been identified in NASA's Earthdata-Search version 1.0.0 related to the OpenSearchGranuleSearchLambda function, located in the handler.js file. This flaw allows an attacker to manipulate the openSearchOsdd argument, potentially leading to a server-side request forgery (SSRF). ...
PoC for CVE-2026-82801
A vulnerability exists in the scaleImage function within the serverless/src/scaleImage/handler.js file of NASA's Earthdata-Search product version 1.0.0. This flaw allows a remote attacker to exploit the scale Endpoint, potentially leading to unauthorized server-side request forgery (SSRF). The ex...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-82703
A security vulnerability has been identified in the Edimax BR-6214K router, specifically affecting the asp_setPing endpoint within the file www/ping.asp. This flaw allows an attacker to manipulate the pingstr argument, enabling remote OS command injection. The exploitation of this vulnerability p...
PoC for CVE-2026-82702
A significant OS command injection vulnerability exists in the Edimax BR-6214K Router, specifically within the www/wlanMP.asp file of the asp_WlanMP Endpoint. By manipulating the eatFunc argument, an attacker can exploit this flaw remotely, potentially allowing unauthorized access to execute syst...
Discovered 10 hours ago
PoC for CVE-2026-82701
A vulnerability exists in the Online Shopping System version 1.0, specifically within the Search Functionality component. An attacker can manipulate the 'keyword' parameter in the /action.php file, leading to a SQL injection exploit. This vulnerability can be triggered remotely, making it crucial...
PoC for CVE-2026-82700
A cross-site scripting vulnerability has been identified in the Online Shopping System 1.0 developed by Code-Projects, specifically within the Newsletter Subscription feature accessed via the /offersmail.php file. An attacker can exploit this vulnerability by manipulating the 'email' argument, po...
PoC for CVE-2026-82699
A vulnerability exists within the sambitraj Student Management System, specifically in the Password Handler component of the aca.sql file. This flaw allows for the manipulation of the Password argument, resulting in the potential cleartext storage of sensitive user information. The vulnerability ...
PoC for CVE-2026-82698
The sambitraj Student-Management-System is affected by a vulnerability that allows attackers to exploit a default password found in the aca.sql file. This security flaw enables unauthorized remote access to the system. As the exploit is now publicly available, it presents a significant risk to us...
Discovered 11 hours ago
PoC for CVE-2026-82697
A vulnerability has been identified in the sambitraj Student-Management-System that affects the session management functionality. Specifically, the 'session_start' function does not enforce the 'HttpOnly' flag on session cookies, exposing users to potential session hijacking. This vulnerability c...
PoC for CVE-2026-82696
A security vulnerability exists within version 1.0 of the itsourcecode Sales and Inventory System, specifically in the /pages/inv_searchfrm.php file. This flaw allows attackers to manipulate input arguments, leading to potential SQL injection attacks. These attacks can be executed remotely, makin...
PoC for CVE-2026-82695
A security flaw has been identified in Tenda AC18 routers where the Telnet handler is susceptible to missing authentication. This vulnerability allows attackers to access critical functions of the router remotely, making it possible to exploit the device without authentication. The exploit has be...
PoC for CVE-2026-82694
A security vulnerability has been detected in the Tenda AC1206 device, specifically within the Web User Interface (UI) where the R7WebsSecurityHandler function lacks proper authentication checks. This flaw enables remote attackers to gain unauthorized access, potentially leading to exploitation o...
Discovered 12 hours ago
PoC for CVE-2026-82693
A significant security vulnerability has been identified in the Tenda AC1206's Web UI, specifically affecting the Telnet function. This flaw allows unauthorized remote access to the system through the /goform/telnet interface due to inadequate authentication measures. As a result, attackers can e...
PoC for CVE-2026-82692
A security vulnerability exists in D-Link's DNS-340L and DNS-345 products, specifically within the /cgi-bin/iscsi_mgr.cgi file. This flaw allows unauthorized manipulation of user inputs such as alias, username, password, and volume_location, enabling remote attackers to execute arbitrary OS comma...
PoC for CVE-2026-82691
A potential OS command injection vulnerability has been identified in the D-Link ShareCenter NAS devices, specifically in the CGI Handler component located at /cgi-bin/usb_device.cgi. Attackers may manipulate the f_ups_ip argument to execute arbitrary commands on the operating system from a remot...
PoC for CVE-2026-82690
A vulnerability has been identified in D-Link DNS-327L and DNS-340L series devices, specifically in the file /cgi-bin/ve_mgr.cgi. The flaw allows for os command injection through manipulation of the argument f_dev, enabling remote attackers to execute arbitrary commands on vulnerable devices. Thi...
Discovered 13 hours ago
PoC for CVE-2026-82689
A vulnerability found in D-Link ShareCenter NAS devices allows for OS command injection through the manipulation of user input in the ISO Image Handler. Affected models include DNS-320L, DNS-327L, DNS-340L, and DNS-345, all of which utilize the file /cgi-bin/isomount_mgr.cgi. Attackers can exploi...
PoC for CVE-2026-82688
A security vulnerability exists in the D-Link DNS-340L and DNS-345 models, located in the Virtual Volume Handler component's virtual_vol.cgi file. This flaw allows for potential OS command injection via manipulation of the arguments f_sharename, f_target, or f_name, enabling remote attackers to e...
PoC for CVE-2026-82876
The Phison PS3111-S11 controller firmware exhibits a critical flaw in its RSA signature verification process. The firmware improperly validates RSA signatures using a public modulus that is hardcoded within the firmware image, instead of employing securely stored immutable references. This design...
PoC for CVE-2026-82680
A security weakness has been detected in the D-Link DSM-G600 version 1.01, specifically affecting the file /load_file.cgi within the Multipart Handler component. This vulnerability allows for an out-of-bounds write condition, which can be exploited remotely by attackers. The public disclosure of ...
PoC for CVE-2026-82679
A security flaw exists in the Diem Widget Editor component, specifically in the dmWidgetContentBaseMediaForm.php file. This vulnerability allows an attacker to manipulate the system and perform unrestricted file uploads, which can be initiated remotely. This poses a significant risk for unauthori...
Discovered 14 hours ago
PoC for CVE-2026-82678
An OS command injection vulnerability has been identified in the Diem Administrative Console, specifically in the executeCommand function located in the actions.class.php file. This flaw allows a remote attacker to manipulate the dm_command argument, potentially leading to unauthorized command ex...
PoC for CVE-2026-82677
A vulnerability has been identified in the Valkey 9.1.0 product from Valkey-io, specifically within the moduleTimerHandler function located in src/module.c. This flaw allows for a double free scenario, which can be exploited remotely, posing a significant risk. An exploit has been publicly disclo...
PoC for CVE-2026-18963
A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...