Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 2 hours ago
PoC for CVE-2026-95270
A vulnerability in dgtlmoon Changedetection.io has been identified, affecting versions up to 0.60.7. This flaw resides in the check_password function within the Hash Comparison component, specifically in the file flask_app.py. An attacker can exploit this vulnerability to create observable timing...
Discovered 6 hours ago
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
Discovered 7 hours ago
PoC for CVE-2026-91827
The Ninja Forms plugin version 3.15.3 for WordPress has a critical security flaw that allows unauthorized attackers to exploit user-submitted form data. When form submissions are exported to CSV by an administrator, the plugin fails to properly sanitize the deserialized data, creating an opportun...
PoC for CVE-2026-92438
The Ninja Forms plugin for WordPress, specifically version 3.15.3, is susceptible to a vulnerability due to its failure to properly escape submitted form field values. This oversight allows unauthenticated users to submit data through publicly accessible forms. When these values are displayed on ...
PoC for CVE-2026-88788
The Text Styler WordPress plugin, up to version 1.1.1, is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user-supplied styling values. This vulnerability enables users with contributor-level access or higher to introduce malicious JavaScript into the output. As...
Discovered 12 hours ago
PoC for CVE-2026-94493
The Gigatech PDV5701 has been identified with a vulnerability in its WebSocket Service, specifically affecting the processing of the /index.html file. This security flaw allows for missing authentication, making it possible for attackers to exploit the system remotely. The potential for exploitat...
Discovered 13 hours ago
PoC for CVE-2026-94492
A security vulnerability has been uncovered within the Yonyou U8cloud 5.x software, specifically in the OpenAPI component located at /u8cloud/openapi/so.saleorder.sendaudit. This vulnerability enables attackers to manipulate the 'operator' argument, leading to potential SQL injection attacks. Suc...
PoC for CVE-2026-43786
A privilege escalation issue has been discovered in Apple's macOS, which may allow an application to obtain unauthorized root privileges. This vulnerability arises from insufficient entitlement checks in the system, leading to potential exploitation that can compromise system integrity. It is cru...
Discovered 15 hours ago
PoC for CVE-2026-94426
A vulnerability exists in the xuxueli XXL-Job software that allows for cross-site scripting (XSS) through a flaw in the `jobgroup/insert` function. This vulnerability can be exploited remotely by manipulating the argument 'Name'. The potential for exploitation is heightened as the flaw has been p...
PoC for CVE-2026-28618
A vulnerability in the Android OS identified as a heap buffer overflow can allow potential attackers to execute remote code without requiring any user interaction. This weakness resides in the 'dec_frm_prepare' function of the 'oapv.c' file, which can be exploited to conduct out-of-bounds writes,...
Discovered 16 hours ago
PoC for CVE-2026-94540
DesktopSMS 1.11.0 by MrPear is susceptible to an unauthorized access vulnerability, enabling local attackers to utilize the application's local service. This flaw allows attackers to send SMS messages and retrieve SMS-derived content without requiring user interaction or pairing confirmation. An ...
PoC for CVE-2026-94536
The Lamp-cloud software, up to version 5.10.0, is susceptible to an information disclosure vulnerability due to inadequate validation of the 'employeeId' parameter in the '/anyone/visible/resource' endpoint. This flaw permits authenticated users to exploit the system, enabling them to read roles ...
PoC for CVE-2026-94535
An authorization bypass vulnerability exists in the deleteMyNotice endpoint of lamp-cloud (versions up to 5.10.0). This flaw allows authenticated users to craft malicious DELETE requests, targeting arbitrary notice IDs, thus enabling them to delete notifications that belong to other users without...
PoC for CVE-2026-94534
Lamp-Cloud versions up to 5.10.0 are susceptible to a serious security issue where user identity is not properly validated during profile updates. This vulnerability allows authenticated attackers to manipulate user profiles by sending requests with targeted user IDs. Attackers can alter critical...
PoC for CVE-2026-94534
Lamp-Cloud versions up to 5.10.0 are susceptible to a serious security issue where user identity is not properly validated during profile updates. This vulnerability allows authenticated attackers to manipulate user profiles by sending requests with targeted user IDs. Attackers can alter critical...
PoC for CVE-2026-94533
The lamp-cloud product, specifically through version 5.10.0, suffers from an authorization bypass vulnerability in the FileAnyoneController. This flaw permits authenticated users to download arbitrary attachments from other users. By manipulating valid attachment identifiers, attackers can exploi...
PoC for CVE-2026-94532
Lamp-Cloud, up to version 5.10.0, has a vulnerability in the getUserInfoById endpoint which allows authenticated users to bypass authorization checks. This flaw enables individuals to access full profiles of any user within the system by manipulating the userId parameter. As a consequence, attack...
PoC for CVE-2026-77078
The multer middleware used for handling multipart/form-data in Node.js applications has a vulnerability that can be exploited to trigger a denial of service (DoS). This occurs when a multipart request containing two specially crafted text field names is sent. The first field attempts to create an...
Discovered 18 hours ago
PoC for CVE-2025-6325
A vulnerability exists in King Addons for Elementor, developed by KingAddons.com, that allows attackers to escalate their privileges. This Incorrect Privilege Assignment flaw enables unauthorized users to gain elevated access to restricted functionalities within the plugin. The issue affects all ...
Discovered 19 hours ago
PoC for CVE-2026-94501
The jshERP software version 3.6 is susceptible to an authorization bypass vulnerability within its userBusiness CRUD endpoints. This flaw enables authenticated users to perform operations on authorization-related rows without proper privilege checks. As a result, attackers can alter user-role map...
PoC for CVE-2026-94497
The jshERP product version 3.6 has a significant vulnerability related to improper validation of object ownership in its API endpoints for information retrieval, updates, and deletions across various resource types. This oversight allows authenticated users to exploit the system by directly submi...
PoC for CVE-2026-94496
The jshERP software version 3.6 contains a vulnerability in its role management endpoints that fails to properly validate caller permissions. This oversight allows authenticated users to manipulate role data and potentially delete roles. Consequently, attackers can exploit the vulnerable /role/up...
PoC for CVE-2026-94495
jshERP versions prior to 3.6 contain a flaw that allows authenticated users to bypass authorization checks within the SystemConfigService.updateSystemConfig function. This vulnerability enables attackers to manipulate tenant-specific system configurations, including critical parameters related to...
PoC for CVE-2026-94494
The jshERP application, up to version 3.6, contains a vulnerability that allows authenticated users to bypass tenant isolation. This flaw enables these users to access sensitive records of other tenants through the GET /tenant/info endpoint. By iterating the primary key, attackers can enumerate v...
PoC for CVE-2026-94414
jshERP prior to version 3.6 contains a vulnerability in the POST /userBusiness/updateBtnStr endpoint. This flaw occurs due to the absence of an authorization check, allowing authenticated users to potentially alter role-specific button-permission configurations. Malicious actors can exploit this ...
PoC for CVE-2026-94413
An issue in jshERP versions up to 3.6 allows authenticated users to access unsalted MD5 password hashes through the /user/info endpoint. This enables attackers to request arbitrary user information by supplying specific user IDs, exposing sensitive password digests. These hashes can be exploited ...
PoC for CVE-2026-94412
The jshERP application through version 3.6 contains a significant vulnerability in its password reset functionality. Specifically, the authorization bypass affects the POST /user/resetPwd endpoint, which allows authenticated users to reset passwords of any other user by simply specifying a target...
PoC for CVE-2026-94411
jshERP version 3.6 is susceptible to a privilege escalation vulnerability found within the updateOneValueByKeyIdAndType endpoint. This flaw allows authenticated users to manipulate their access privileges unlawfully. By submitting a POST request containing their user ID and a list of role IDs des...
Discovered 20 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-94488
A cross-site scripting vulnerability exists in Telegram Desktop prior to version 6.9.4, allowing attackers to exploit the HTML export functionality. The issue is present in the method button.text.toUtf8 within export_output_html.cpp. An attacker must entice a victim to utilize the HTML export fea...
Discovered 23 hours ago
PoC for CVE-2026-94129
A vulnerability exists in the BioStar VALKYRIE AURORA software, specifically in the IOCTL handler within the BS_RVSIO64.sys file. This vulnerability allows for a write-what-where condition via manipulation of the PhysicalAddress argument. As a result, local attackers could exploit this vulnerabil...
Discovered 1 day ago
PoC for CVE-2026-94216
A security weakness has been found in ST Engineering's iDirect Evolution and Velocity WebServer products, where the 'authorize' function in the HTTP Header Handler component allows for manipulation of request arguments. Specifically, altering the 'Success' parameter can lead to an open redirect, ...
PoC for CVE-2026-94214
A security flaw has been identified in ST Engineering iDirect Evolution and Velocity WebServer affecting the Management Service's login component. The vulnerability arises from improper handling of the Host header in the /login.html file, enabling attackers to manipulate URL requests resulting in...
PoC for CVE-2026-94211
A vulnerability has been identified in Hyve5 Leantime up to version 3.9.8, specifically affecting the Project Dashboard component. This flaw allows malicious actors to inject cross-site scripting (XSS) payloads through the '/app/Domain/Dashboard/Templates/show.blade.php' file. The manipulation of...
PoC for CVE-2026-74469
A vulnerability exists in the Linux kernel related to SCTP (Stream Control Transmission Protocol) which allows for a transport count overflow. The function sctp_assoc_add_peer() increments a 16-bit transport_count for each unique peer. When the transport_count exceeds 65,536, it wraps around to z...
PoC for CVE-2026-68121
A vulnerability in the Linux kernel's PPPoE implementation allows for header pointer mismanagement during device header callbacks. When a send action is blocked, it can lead to an invalidated pointer within the socket buffer (skb) head. This issue arises specifically when transitioning from a non...
PoC for CVE-2026-94210
A vulnerability has been identified in the Hyve5 Leantime Kanban Board affecting versions up to 3.9.8. This specific flaw in the function getAllGrouped located in the file app/Domain/Tickets/Services/Tickets.php allows attackers to execute cross-site scripting (XSS) attacks remotely. Successful e...
PoC for CVE-2026-81000
The vulnerability in the Linux kernel's TUN and TAP interfaces arises from incorrect management of packet data when tun_get_user() operates with oversized headroom requests. This flaw can lead to an improper allocation of packet data storage, potentially allowing skb->data to be located outside o...
PoC for CVE-2026-80844
A flaw exists within the Linux kernel's AH6 module related to the validation of routing header segments. The function ipv6_rearrange_rthdr() improperly assumes that the 'segments_left' field of a routing header will not exceed the number of addresses defined in the hdrlen field. However, this hol...
PoC for CVE-2026-8932
A vulnerability in libcurl arises from its connection pooling mechanism, where previously established connections can be reused despite changes to mTLS configuration settings. This flaw occurs because certain TLS parameters associated with client certificates are not adequately checked during the...
PoC for CVE-2026-92400
The WooCommerce PayPal Payment Gateway plugin for WordPress contains a vulnerability where it fails to validate incoming payment notifications properly. Specifically, prior to version 9.2.1, the plugin does not confirm that a payment notification is associated with the store's own merchant accoun...
PoC for CVE-2026-86802
The To Do List Member plugin for WordPress is affected by a vulnerability that lacks adequate authorization and nonce checks in its import routine. This flaw permits unauthenticated users to generate arbitrary published posts and taxonomy terms. Moreover, the plugin does not validate the source o...
PoC for CVE-2026-85113
The GiveWP plugin for WordPress, up to version 4.16.9, is susceptible to a vulnerability that allows unauthenticated users to execute arbitrary shortcodes. This occurs because the plugin fails to adequately remove shortcode delimiters from user-supplied input before rendering it on public pages. ...
PoC for CVE-2026-85010
The RestroPress plugin for WordPress is susceptible to a significant vulnerability that enables unauthenticated users to manipulate the pricing of item add-ons. Specifically, prior to version 3.4.6, the plugin fails to perform adequate validation of the item add-on price supplied by the client wh...
PoC for CVE-2026-94152
A significant security flaw has been identified in Omega Solution's FBP Fulfillment by People 2025, specifically within the User Profile API component. This vulnerability arises from improper handling of the user ID argument, which can facilitate an unauthorized access scenario. Attackers can exp...
PoC for CVE-2026-94151
A vulnerability has been detected in Omega Solution's HRM OS affecting the Role Permission API within the file /role-permission/permission. This weakness arises from a manipulation of the roleId argument, which could allow attackers to bypass authentication measures. The vulnerability can be expl...
PoC for CVE-2026-94150
A security flaw has been identified within the Omega Solution HRM OS, specifically affecting the SVG File Upload component. This vulnerability allows an attacker to manipulate an unknown function in the /media/view/ directory, leading to potential cross site scripting (XSS) attacks. Such attacks ...
PoC for CVE-2026-94149
A vulnerability has been discovered in Omega Solution HRM OS, specifically within the Role Permission Retrieval Endpoint. The issue arises from improper management of resource identifiers due to the manipulation of the argument roleId. This vulnerability allows attackers to potentially exploit th...
PoC for CVE-2026-33439
OpenIdentityPlatform's OpenAM, an access management solution, is susceptible to a pre-authentication Remote Code Execution vulnerability due to unsafe Java deserialization. This issue arises from the handling of the jato.clientSession HTTP parameter, allowing unauthenticated attackers to execute ...
PoC for CVE-2026-94145
A vulnerability has been identified in xuxueli XXL-Job, affecting the Task Management Interface. An improper handling of user input in the JobInfoController.java file enables attackers to execute cross-site scripting (XSS) attacks. The vulnerability allows for remote exploitation by manipulating ...