Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-49975

ApacheApache Http Server7.5HIGH
Memory Allocation Vulnerability in Apache HTTP Server by Apache

A memory allocation issue exists in Apache HTTP Server's mod_http module, which can lead to denial of service when an attacker sends crafted HTTP requests with excessive size values. This vulnerability affects a wide range of Apache HTTP Server versions, making it critical for users to implement ...

Discovered 9 hours ago

PoC for CVE-2023-23969

DjangoprojectDjango7.5HIGH
Denial-of-Service Vulnerability in Django Web Framework

Certain versions of the Django web framework, specifically 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, exhibit a vulnerability due to the caching of parsed Accept-Language headers. This caching mechanism is intended to enhance performance by avoiding repetitive parsing. However, wh...

PoC for CVE-2026-9061

WordPressStore Locator WordPress
Stored Cross-Site Scripting Vulnerability in Store Locator Plugin b...

The Store Locator plugin for WordPress prior to version 1.6.9 fails to adequately sanitize and escape the metadata for store logos before saving and displaying it. This gap allows users with administrative privileges to execute Stored Cross-Site Scripting (XSS) attacks, even in scenarios where th...

PoC for CVE-2026-9062

WordPressStore Locator WordPress
Path Traversal Vulnerability in Store Locator Plugin by WordPress

The Store Locator plugin for WordPress prior to version 1.6.9 is susceptible to a path traversal vulnerability. This issue arises from improper validation of parameters used in file paths, permitting high-privilege users, such as administrators, to access sensitive files on the server. Malicious ...

Discovered 11 hours ago

PoC for CVE-2026-20230

CiscoCisco Unified Communic...8.6HIGH
Server-Side Request Forgery Vulnerability in Cisco Unified Communic...

A security flaw in Cisco Unified Communications Manager and its Session Management Edition allows unauthenticated remote attackers to exploit server-side request forgery (SSRF). By sending a specially crafted HTTP request, attackers may manipulate the affected device, leading to unauthorized file...

Discovered 12 hours ago

PoC for CVE-2026-45585

MicrosoftWindows 11 Version 24h26.8MEDIUM
Security Feature Bypass in Windows by Microsoft

A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...

Discovered 16 hours ago

PoC for CVE-2026-53435

JenkinsJenkins8.8HIGH
Jenkins

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to ...

PoC for CVE-2026-24136

SaleorSaleor8.7HIGH
Insecure Direct Object Reference in Saleor E-Commerce Platform

The Saleor e-commerce platform exhibits an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated users to retrieve sensitive information in plain text. Specifically, orders created prior to Saleor version 3.2.0 can have personally identifiable information (PII) exfiltrat...

Discovered 18 hours ago

PoC for CVE-2026-12131

CodeastroHuman Resource Managem...5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Human Resource Management ...

A vulnerability has been detected in the CodeAstro Human Resource Management System version 1.0 that allows an SQL injection attack in the Invoice function of the Payroll.php controller. Manipulation of the ID argument permits attackers to execute arbitrary SQL commands. This flaw presents a sign...

Discovered 19 hours ago

PoC for CVE-2026-12130

CodeastroHuman Resource Managem...5.1MEDIUM
Cross-Site Scripting Vulnerability in CodeAstro HR Management Syste...

A security flaw has been identified in the CodeAstro Human Resource Management System 1.0 that allows for cross-site scripting (XSS) attacks through the manipulation of the 'protitle' argument in the Projects Management Page. This vulnerability can be exploited remotely, potentially compromising ...

PoC for CVE-2026-12129

CodeastroHuman Resource Managem...5.1MEDIUM
Cross Site Scripting Vulnerability in CodeAstro Human Resource Mana...

A cross site scripting vulnerability exists in CodeAstro's Human Resource Management System version 1.0, specifically within the Dashboard Interface component in the file /dashboard/add_tod. The issue arises due to inadequate input validation of the todo_data argument. This flaw permits remote at...

Discovered 21 hours ago

PoC for CVE-2026-0273

Palo Alto NetworksCloud Ngfw5.7MEDIUM
PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI...

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI. The security risk pose...

Discovered 22 hours ago

PoC for CVE-2026-8809

WordPressAdvanced Custom Fields...9.8CRITICAL
Privilege Escalation Vulnerability in Advanced Custom Fields: Exten...

The Advanced Custom Fields: Extended plugin for WordPress is susceptible to a privilege escalation vulnerability due to a validation bypass in the after_validate_save_post() function. This function improperly trusts the attacker-controlled _acf_post_id POST parameter, which allows unauthorized us...

PoC for CVE-2026-48558

SimplehelpSimplehelp9.5CRITICAL
Authentication Bypass Vulnerability in SimpleHelp by SimpleHelp

Versions 5.5.15 and earlier of SimpleHelp, along with pre-release 6.0 versions, are susceptible to an authentication bypass vulnerability in the OIDC authentication process. When configured to use OIDC authentication, the system fails to validate the cryptographic signatures of identity tokens du...

Discovered 1 day ago

PoC for CVE-2026-12066

Pbootcms6.9MEDIUM
PbootCMS Password MemberController.php retrieve password recovery

A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in weak password recov...

PoC for CVE-2026-12065

GrowwStock, Mutual Fund, Go...1LOW
Groww Stock, Mutual Fund, Gold App WebView URL improper authorizati...

A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url scheme. It is possible to launch the attack on the physical...

PoC for CVE-2026-35273

OraclePeoplesoft Enterprise ...9.8CRITICAL
Unauthenticated Remote Access Vulnerability in PeopleSoft Enterpris...

A vulnerability exists in Oracle's PeopleSoft Enterprise PeopleTools that potentially allows an unauthenticated attacker to gain unauthorized access via HTTP, compromising the integrity and confidentiality of the system. If exploited, this could enable a malicious actor to take full control over ...

PoC for CVE-2026-9271

Keepinmind Dashboard N...5.9MEDIUM
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS

Vulnerability Title

PoC for CVE-2026-9269

WordPressSecure Copy Content Pr...3.5LOW
Secure Copy Content Protection and Content Locking < 5.1.5 - Admin+...

The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for e...

Discovered 2 days ago

PoC for CVE-2026-48907

Joomlacontentedit...Joomla Content Editor ...10CRITICAL
Joomla Extension - joomlacontenteditor.net - Remote Code Execution ...

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

PoC for CVE-2026-10795

WordPressUpdraftplus: WP Backup...8.1HIGH
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticat...

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message form...

PoC for CVE-2026-45447

OpenSSLOpenSSL8.8HIGH
Heap Use-After-Free in the PKCS7_verify() Function

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signe...

PoC for CVE-2019-9053

CmsmadesimpleCms Made Simple🟣 EPSS 93%8.1HIGH
SQL Injection Vulnerability in CMS Made Simple by CMS Made Simple, ...

A vulnerability exists in CMS Made Simple version 2.2.8, where the News module can be exploited through a specially crafted URL, allowing an unauthenticated attacker to perform blind time-based SQL injection utilizing the m1_idlist parameter. This can potentially expose sensitive information and ...

PoC for CVE-2026-50507

MicrosoftWindows 10 Version 16076.8MEDIUM
Windows BitLocker Security Feature Bypass Vulnerability

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

PoC for CVE-2017-9841

PHPunit ProjectPHPunit🟣 EPSS 94%9.8CRITICAL
Remote Code Execution in PHPUnit by Sebastian Bergmann

A vulnerability in PHPUnit's eval-stdin.php script prior to versions 4.8.28 and 5.6.3 permits remote attackers to execute arbitrary PHP code. This occurs through crafted HTTP POST requests containing PHP code snippets that initiate execution, particularly when /vendor folders are publicly accessi...

PoC for CVE-2025-43529

AppleSafari8.8HIGH
Use-After-Free Vulnerability in Apple iOS and macOS Products

A significant use-after-free vulnerability has been identified in Apple’s iOS and macOS products, impacting versions prior to the latest updates. This flaw arises due to improper memory management, allowing maliciously crafted web content to trigger arbitrary code execution. Apple has acknowledge...

PoC for CVE-2026-10520

IvantiSentry🟣 EPSS 48%10CRITICAL
OS Command Injection Vulnerability in Ivanti Sentry

An OS Command Injection vulnerability exists in Ivanti Sentry versions before R10.5.2, R10.6.2, and R10.7.1, allowing an unauthenticated remote attacker to execute arbitrary commands with root privileges. This high-risk vulnerability could potentially compromise the integrity and security of the ...

PoC for CVE-2026-42945

F5Nginx Plus9.2CRITICAL
Heap Buffer Overflow in NGINX Plus and NGINX Open Source Affecting ...

A vulnerability exists in the ngx_http_rewrite_module of NGINX Plus and NGINX Open Source, triggered when a rewrite directive is followed by an if or set directive that includes a Perl-Compatible Regular Expression (PCRE) capture and a replacement string with a question mark. Attackers can exploi...

Discovered 3 days ago

PoC for CVE-2026-49975

ApacheApache Http Server7.5HIGH
Memory Allocation Vulnerability in Apache HTTP Server by Apache

A memory allocation issue exists in Apache HTTP Server's mod_http module, which can lead to denial of service when an attacker sends crafted HTTP requests with excessive size values. This vulnerability affects a wide range of Apache HTTP Server versions, making it critical for users to implement ...

PoC for CVE-2026-7473

Arista NetworksEos🟣 EPSS 27%6.9MEDIUM
Tunnel Decapsulation Vulnerability in Arista EOS Networking Equipment

A vulnerability exists in Arista EOS that affects devices with tunnel decapsulation configurations, such as VXLAN and GRE. The issue arises when the switch fails to verify the tunnel protocol type during the decapsulation process, allowing it to incorrectly process and forward unexpected tunneled...

PoC for CVE-2026-20245

CiscoCisco Catalyst Sd-wan ...7.8HIGH
Command Injection Vulnerability in Cisco Catalyst SD-WAN Products

A vulnerability present in the CLI of multiple Cisco Catalyst SD-WAN products allows an authenticated local attacker with netadmin privileges to execute arbitrary commands as the root user. This flaw arises from inadequate validation of user-supplied input, enabling an attacker to upload a specia...

PoC for CVE-2026-11645

GoogleChrome8.8HIGH
Out of Bounds Read and Write in Google Chrome by Google

An out of bounds read and write vulnerability exists in the V8 engine of Google Chrome prior to version 149.0.7827.103, allowing remote attackers to execute arbitrary code within a sandbox environment by utilizing a specially crafted HTML page. This vulnerability poses a significant risk, as it c...

PoC for CVE-2026-0776

DiscordClient7.3HIGH
Local Privilege Escalation Vulnerability in Discord Client

The Discord Client contains a local privilege escalation vulnerability that enables local attackers to gain elevated privileges by exploiting the discord_rpc module. By triggering this vulnerability, an attacker with access to execute low-privileged code can manipulate the application's file load...

PoC for CVE-2026-49975

ApacheApache Http Server7.5HIGH
Memory Allocation Vulnerability in Apache HTTP Server by Apache

A memory allocation issue exists in Apache HTTP Server's mod_http module, which can lead to denial of service when an attacker sends crafted HTTP requests with excessive size values. This vulnerability affects a wide range of Apache HTTP Server versions, making it critical for users to implement ...

PoC for CVE-2018-7600

DrupalDrupal Before 7.58, 8....🟣 EPSS 94%9.8CRITICAL
Remote Code Execution Vulnerability in Drupal by Acquia

Multiple versions of Drupal, including those prior to 7.58 and various 8.x releases, are susceptible to a vulnerability that permits remote attackers to execute arbitrary code. This exploit takes advantage of configuration flaws in several subsystems, particularly those using default or common mo...

PoC for CVE-2023-36808

Glpi-projectGlpi🟣 EPSS 16%8.6HIGH
GLPI vulnerable to SQL injection through Computer Virtual Machine i...

GLPI, a widely used asset and IT management software, is susceptible to SQL injection due to vulnerabilities in its Computer Virtual Machine form and inventory request feature. This flaw allows attackers to manipulate database queries, potentially compromising sensitive data. Users are encouraged...

PoC for CVE-2026-0542

ServicenowServicenow Ai Platform9.2CRITICAL
Remote Code Execution Vulnerability in ServiceNow AI Platform

A potential vulnerability exists in the ServiceNow AI Platform, which may allow an unauthenticated user to execute arbitrary code in the ServiceNow Sandbox under specific conditions. ServiceNow has released security updates to address this issue for both hosted and self-hosted customers. Users ar...

PoC for CVE-2026-48962

PMQsIo::compress7.3HIGH
Arbitrary Code Execution in IO::Compress for Perl

The IO::Compress module for Perl is vulnerable to arbitrary code execution due to its handling of user-supplied output glob strings. When the _parseOutputGlob() method wraps these strings in double quotes, it can inadvertently allow an attacker to inject Perl code. The vulnerability resides in th...

PoC for CVE-2026-28318

SolarwindsServ-u7.5HIGH
Denial of Service Vulnerability in SolarWinds Serv-U

SolarWinds Serv-U is vulnerable to a denial of service attack in which specially crafted POST requests can crash the Serv-U service without requiring authentication. This vulnerability arises from the handling of the Content-Encoding: deflate header, which can lead to service disruption. Users ar...

PoC for CVE-2025-29927

VercelNext.js🟣 EPSS 92%9.1CRITICAL
Authorization Bypass in Next.js Framework by Vercel

A security flaw exists in the Next.js framework that allows an attacker to bypass authorization checks if such checks are implemented in middleware. This vulnerability arises in versions prior to 14.2.25 and 15.2.3. To mitigate risk, it is recommended to restrict incoming requests that include th...

PoC for CVE-2026-49975

ApacheApache Http Server7.5HIGH
Memory Allocation Vulnerability in Apache HTTP Server by Apache

A memory allocation issue exists in Apache HTTP Server's mod_http module, which can lead to denial of service when an attacker sends crafted HTTP requests with excessive size values. This vulnerability affects a wide range of Apache HTTP Server versions, making it critical for users to implement ...

PoC for CVE-2024-20154

MediaTekMt2735, Mt6767, Mt6768...🟣 EPSS 33%8.8HIGH
Out of Bounds Write Vulnerability in MediaTek Modem

A vulnerability has been identified in MediaTek Modem due to a missing bounds check, resulting in a possible out of bounds write. This flaw allows for remote code execution if an unwitting user connects to a malicious base station operated by an attacker. No local execution privileges or user int...

PoC for CVE-2025-71330

Image-sizeImage-size8.7HIGH
image-size 2.0.2 Denial of Service via Malformed ICNS Image Parsing

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to ...

PoC for CVE-2026-25089

FortinetFortisandbox9.1CRITICAL
Fortinet - Fortisandbox

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 m...

PoC for CVE-2026-44963

VeeamBackup And Replication9.4CRITICAL
Veeam - Backup And Replication

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

PoC for CVE-2026-45247

MirasvitFull Page Cache Warmer...9.3CRITICAL
PHP Object Injection Vulnerability in Mirasvit Full Page Cache Warm...

The Mirasvit Full Page Cache Warmer, specifically for Magento 2, is susceptible to a PHP object injection flaw that permits unauthenticated attackers to execute arbitrary code. This vulnerability arises from an unrestricted invocation of PHP's native unserialize() function when handling malformed...

PoC for CVE-2026-9067

WordPressSchema & Structured Da...9.1CRITICAL
Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbi...

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any fil...

PoC for CVE-2026-9060

WordPressStore Locator WordPress3.5LOW
Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style

The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks ...

PoC for CVE-2026-8071

WordPressAnti-spam By Cleantalk...8.8HIGH
Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthen...

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (incl...

PoC for CVE-2026-3326

WordPressXstore8.6HIGH
XStore < 9.7.3 - Unauthenticated SQLi

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection