Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 1 hour ago

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 94%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

Discovered 2 hours ago

PoC for CVE-2026-10777

Ealpha072Student-management-system6.9MEDIUM
ealpha072 Student-Management-System Administrative Backend config.p...

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php of the component Administrative Backend. Such manipulation leads to improper authentication. The ...

PoC for CVE-2026-10775

Sgl-projectSglang2LOW
sgl-project SGLang Cache data_hash denial of service

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service. The attack is restricted to local execution. A high degree of complexity is needed for the attack...

Discovered 3 hours ago

PoC for CVE-2026-10771

CrmebCrmeb Java6.9MEDIUM
crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestT...

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server-side request for...

Discovered 4 hours ago

PoC for CVE-2026-42945

F5Nginx Plus9.2CRITICAL
Heap Buffer Overflow in NGINX Plus and NGINX Open Source Affecting ...

A vulnerability exists in the ngx_http_rewrite_module of NGINX Plus and NGINX Open Source, triggered when a rewrite directive is followed by an if or set directive that includes a Perl-Compatible Regular Expression (PCRE) capture and a replacement string with a question mark. Attackers can exploi...

Discovered 5 hours ago

PoC for CVE-2026-10766

Mlrun2LOW
mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataf...

A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_dataframe_hash of the file mlrun/utils/helpers.py of the component DataFrame Hash Handler. The manipulation leads to use of weak hash. The attack can only be performed from a local en...

Discovered 8 hours ago

PoC for CVE-2026-0257

Palo Alto NetworksCloud Ngfw🟣 EPSS 36%7.8HIGH
Authentication Bypass in Palo Alto Networks PAN-OS Software

The authentication bypass vulnerability in Palo Alto Networks' PAN-OS software presents a significant security risk by allowing unauthorized access to the GlobalProtect portal and gateway. This flaw enables attackers to circumvent authentication mechanisms, potentially gaining unauthorized VPN co...

Discovered 10 hours ago

PoC for CVE-2026-49943

NicBird6.3MEDIUM
Stack-based Buffer Overflow in BIRD Internet Routing Daemon by CZ.NIC

The BIRD Internet Routing Daemon experiences a stack-based buffer overflow due to improper handling of BGP AS_PATH segments. Specifically, in the as_path_match() function, the daemon allocates a fixed-size stack array, while allowing for the expansion of AS_PATH segments without a corresponding c...

Discovered 13 hours ago

PoC for CVE-2026-41089

MicrosoftWindows Server 20129.8CRITICAL
Stack-based Buffer Overflow in Windows Netlogon Affects Microsoft P...

A stack-based buffer overflow vulnerability in Windows Netlogon permits an unauthorized attacker to execute arbitrary code over a network. This flaw may allow attackers to compromise systems by sending specially crafted requests to the affected service, leading to potential system control and dat...

PoC for CVE-2026-27145

Go Standard LibraryCrypto/x509
Inefficient Hostname Verification in Go's x509 Package Affecting Mu...

A vulnerability in Go's x509 package leads to inefficient hostname verification due to multiple iterations over DNS Subject Alternative Name (SAN) entries. The method (*x509.Certificate).VerifyHostname invokes matchHostnames in a loop, causing significant performance degradation when dealing with...

Discovered 14 hours ago

PoC for CVE-2026-10722

CiliumEbpf4.8MEDIUM
Integer Overflow Vulnerability in Cilium eBPF by Cilium

A vulnerability in Cilium's eBPF component allows local attackers to exploit an integer overflow in the loadRawSpec function, located in the btf.go file. This manipulation can compromise the integrity of the LoadCollectionSpec/LoadCollectionSpecFromReader functionality. It is important for users ...

Discovered 15 hours ago

PoC for CVE-2025-48595

GoogleAndroid8.4HIGH
Integer Overflow Vulnerability in Android Components from Google

The integer overflow vulnerability in multiple Android components allows for unintended code execution, potentially leading to local privilege escalation. This flaw does not require additional execution privileges or user interaction, making it a significant concern for system security. Organizat...

Discovered 23 hours ago

PoC for CVE-2026-23744

McpjamInspector🟣 EPSS 30%9.8CRITICAL
Remote Code Execution Vulnerability in MCPJam Inspector by MCP

MCPJam Inspector, designed for local-first development on MCP servers, has a vulnerability allowing remote code execution (RCE) due to improper binding settings. In versions 1.4.2 and earlier, the platform listens on 0.0.0.0 by default, enabling attackers to exploit this configuration through cra...

Discovered 1 day ago

PoC for CVE-2014-6271

GnuBash🟣 EPSS 94%9.8CRITICAL
Code Injection Vulnerability in GNU Bash by The GNU Project

GNU Bash versions up to 4.3 are vulnerable to a code injection flaw due to the mishandling of trailing strings after function definitions in environment variables. This vulnerability enables remote attackers to execute arbitrary code by crafting specific environment variables under various condit...

PoC for CVE-2026-10704

SourcecodesterPizzafy E-commerce System6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pizzafy E-Commerce Sy...

A SQL injection vulnerability exists in the Login function of the /admin/admin_class_novo.php file within the Administrative Control Panel of SourceCodester's Pizzafy E-Commerce System version 1.0. This vulnerability allows malicious actors to manipulate the Username argument, providing an avenue...

PoC for CVE-2026-10703

EipstackgroupOpener5.3MEDIUM
Use After Free Vulnerability in EIPStackGroup OpENer Software

A security vulnerability has been reported in the EIPStackGroup's OpENer software, specifically within the CreateMessageRouterRequestStructure function in the cipmessagerouter.c file. This issue leads to a use after free condition, allowing for potential remote exploitation. The vulnerability has...

PoC for CVE-2026-10694

SourcecodesterOnline Food Ordering S...6.9MEDIUM
SourceCodester Online Food Ordering System index.php include file i...

A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.

PoC for CVE-2026-10692

Johnhuang316Code-index-mcp5.3MEDIUM
Denial of Service in johnhuang316 code-index-mcp Affected Product

A vulnerability has been discovered in the johnhuang316 code-index-mcp component that affects the function responsible for safe regex pattern verification. This weakness can be exploited through the remote manipulation of the regex argument, resulting in inefficient regular expression complexity....

PoC for CVE-2026-10691

Wonderwhy-erDesktopcommandermcp5.3MEDIUM
Denial of Service Vulnerability in wonderwhy-er DesktopCommanderMCP

A security flaw exists in wonderwhy-er DesktopCommanderMCP affecting versions up to 0.2.38, particularly in the src/search-manager.ts file during a 'start_search' operation. The vulnerability arises from inefficient regular expression complexity when manipulating the argument SearchResult[]. This...

PoC for CVE-2026-10690

Wonderwhy-erDesktopcommandermcp5.3MEDIUM
Server-Side Request Forgery Vulnerability in wonderwhy-er DesktopCo...

A server-side request forgery (SSRF) vulnerability exists in wonderwhy-er DesktopCommanderMCP version 0.2.37. This weakness is caused by improper handling of the URL argument in the readFileFromUrl function, located in the filesystem.ts component. An attacker can exploit this flaw to send unautho...

PoC for CVE-2023-21839

OracleWeblogic Server🟣 EPSS 94%7.5HIGH
Unauthenticated Vulnerability in Oracle WebLogic Server by Oracle

A critical vulnerability found in Oracle WebLogic Server allows unauthenticated attackers with network access through T3 and IIOP to exploit the system. Successful exploitation gives attackers unauthorized access to sensitive data, potentially leading to complete control over all data accessible ...

PoC for CVE-2026-10688

AhujasidBlender-mcp5.1MEDIUM
Code Injection Vulnerability in ahujasid Blender-MCP

A security flaw exists in the ahujasid Blender-MCP within the function 'execute_blender_code' located in /src/blender_mcp/server.py. This vulnerability permits attackers to perform code injection by manipulating the 'code' argument. Given that the vulnerability is remotely exploitable, it poses a...

PoC for CVE-2026-10662

AhujasidBlender-mcp5.3MEDIUM
Server-Side Request Forgery Vulnerability in AhujaSid Blender-mcp

A vulnerability has been identified in AhujaSid's Blender-mcp that affects its ZIP File Handler component. The issue resides in the 'requests.get' function within the 'src/blender_mcp/server.py' file, allowing for unique manipulation of the 'zip_file_url' argument. This exploitation can potential...

PoC for CVE-2026-10661

AhujasidBlender-mcp5.3MEDIUM
Injection Vulnerability in AhujaSid Blender-MCP Software

An injection vulnerability has been identified in AhujaSid's Blender-MCP where the 'Open' function within src/blender_mcp/server.py is improperly handling the argument 'input_image_url'. This flaw allows remote attackers to inject malicious data, potentially leading to unauthorized access or exec...

PoC for CVE-2026-10650

WarmcatLibwebsockets6.9MEDIUM
Resource Consumption Vulnerability in warmcat libwebsockets SSH Pro...

A flaw exists in the warmcat libwebsockets product that affects the SSH Protocol Handler's function lws_ssh_parse_plaintext. An attacker can exploit this vulnerability by manipulating the msg_len argument, leading to potential resource consumption issues. This vulnerability can be exploited remot...

PoC for CVE-2026-10650

WarmcatLibwebsockets6.9MEDIUM
Resource Consumption Vulnerability in warmcat libwebsockets SSH Pro...

A flaw exists in the warmcat libwebsockets product that affects the SSH Protocol Handler's function lws_ssh_parse_plaintext. An attacker can exploit this vulnerability by manipulating the msg_len argument, leading to potential resource consumption issues. This vulnerability can be exploited remot...

PoC for CVE-2026-10620

Code-projectsStudent Admission System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Student Admission Syst...

An SQL injection vulnerability has been identified in the Code-Projects Student Admission System 1.0, specifically within the unknown function in the /index.php file. This flaw allows attackers to manipulate the argument 'eid/did', potentially compromising the database. The exploitation can be ex...

PoC for CVE-2026-27212

Nolimits4webSwiper9.4CRITICAL
Prototype Pollution Vulnerability in Swiper Product by Nolimits4web

The Swiper framework, widely used for mobile touch slider functionality, contains a prototype pollution issue affecting versions 6.5.1 to 12.1.1. The vulnerability exists due to improper handling of user input in shared/utils.mjs, specifically at line 94 where the indexOf() function fails to adeq...

PoC for CVE-2026-10619

Sayan365Student-management-system6.9MEDIUM
Improper Authentication Vulnerability in Sayan365 Student Managemen...

A vulnerability has been identified in the Sayan365 Student Management System that facilitates improper authentication across multiple endpoints. The flaw allows remote attackers to bypass authentication mechanisms, potentially leading to unauthorized access. Although the project has been notifie...

PoC for CVE-2026-8206

WordPressKirki – Freeform Page ...9.8CRITICAL
Privilege Escalation in Kirki Freeform Page Builder for WordPress

The Kirki Freeform Page Builder plugin for WordPress is susceptible to privilege escalation due to a flaw in its password reset functionality. Versions 6.0.0 to 6.0.6 permit attackers to utilize an arbitrary email address when submitting password reset requests, potentially allowing unauthorized ...

PoC for CVE-2026-10617

NextlevelbuilderGoclaw6.9MEDIUM
Security Flaw in GoClaw Affects Webhook Authentication Functionality

A vulnerability has been identified in the GoClaw product by nextlevelbuilder, specifically in the resolveAuth function of the Webhook Verification Handler component. This flaw can result in unauthenticated access, allowing a remote attacker to exploit the issue. The vulnerability was publicly di...

PoC for CVE-2026-10616

NextlevelbuilderGoclaw5.3MEDIUM
Authorization Vulnerability in GoClaw by nextlevelbuilder

A vulnerability in GoClaw by nextlevelbuilder, specifically within the Team Task Completion Handler, allows attackers to exploit the TeamTasksTool.executeComplete function. This weakness facilitates remote attacks due to a lack of required authorization checks during the execution of team task co...

PoC for CVE-2026-23744

McpjamInspector🟣 EPSS 30%9.8CRITICAL
Remote Code Execution Vulnerability in MCPJam Inspector by MCP

MCPJam Inspector, designed for local-first development on MCP servers, has a vulnerability allowing remote code execution (RCE) due to improper binding settings. In versions 1.4.2 and earlier, the platform listens on 0.0.0.0 by default, enabling attackers to exploit this configuration through cra...

Discovered 2 days ago

PoC for CVE-2026-31525

LinuxLinux7.8HIGH
Signed Integer Vulnerability in Linux Kernel Affecting Division and...

In the Linux kernel, a flaw in the BPF interpreter's handling of signed 32-bit division and modulo operations can lead to undefined behavior. Specifically, the kernel's abs() macro fails when applied to the minimum value of a signed 32-bit integer, resulting in incorrect calculations and potentia...

PoC for CVE-2025-70849

PodinfoPodinfo6.1MEDIUM
Arbitrary File Upload in Podinfo Versions Affected by Security Over...

Podinfo versions up to 6.9.0 are susceptible to an arbitrary file upload vulnerability due to improper validation in the /store endpoint. This allows attackers to upload malicious files through crafted POST requests. The lack of a restrictive Content-Security-Policy (CSP) and inadequate Content-T...

PoC for CVE-2026-8293

WordPressReally Simple Security7.5HIGH
Bypassing Two-Factor Authentication in Really Simple Security Plugi...

The Really Simple Security plugin for WordPress, prior to version 9.5.10.1, inadequately implements the second-factor authentication challenge in its REST endpoints. This flaw allows attackers who have compromised a user's password to bypass the email OTP requirement, enabling them to gain unauth...

PoC for CVE-2026-10583

NextlevelbuilderGoclaw5.1MEDIUM
Server-Side Request Forgery Vulnerability in Nextlevelbuilder GoClaw

A security flaw has been identified in the GoClaw product by nextlevelbuilder, specifically within the TTS Configuration Endpoint (file internal/http/tts_config.go). This vulnerability enables attackers to conduct server-side request forgery (SSRF) attacks, potentially allowing them to send unaut...

PoC for CVE-2026-10568

ItsourcecodeFees Management System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Fees Management System

A vulnerability has been identified in itsourcecode Fees Management System version 1.0, specifically within the /manage_payment.php file. The vulnerability stems from an insufficient validation of user inputs, which allows for SQL injection attacks through the manipulation of the 'ID' parameter. ...

PoC for CVE-2026-10567

1panel-devCordyscrm5.1MEDIUM
Cross-Site Scripting Vulnerability in CordysCRM by 1Panel-dev

A security vulnerability has been identified in CordysCRM up to version 1.4.1, specifically in the Save function of the ModuleFormService.java file. This vulnerability allows attackers to manipulate the Description argument, leading to potential cross-site scripting (XSS) attacks that can be exec...

PoC for CVE-2026-10566

FoundationagentsMetagpt4.8MEDIUM
Deserialization Vulnerability in FoundationAgents MetaGPT

A deserialization vulnerability has been identified in FoundationAgents MetaGPT versions up to 0.8.2. This flaw resides within the Message.check_instruct_content function located in the metagpt/schema.py file. By manipulating the argument mapping, an attacker can exploit the vulnerability, enabli...

PoC for CVE-2026-10565

Open5GSOpen5gs2.3LOW
Race Condition in Open5GS NGAP Handover Component

A security vulnerability has been identified in Open5GS, specifically within the NGAP Handover component, affecting versions up to 2.7.6. The flaw resides in the gmm_state_security_mode function of the source file src/amf/gmm-sm.c. Successful exploitation of this issue can trigger a race conditio...

PoC for CVE-2026-10559

SourcecodesterPizzafy Ecommerce System5.3MEDIUM
File Inclusion Vulnerability in SourceCodester Pizzafy Ecommerce Sy...

A security flaw has been identified in the SourceCodester Pizzafy Ecommerce System version 1.0. This vulnerability exists in the /index.php file, where an unknown function can be manipulated through the 'page' argument. This manipulation allows for remote file inclusion, potentially leading to un...

PoC for CVE-2026-10558

SourcecodesterPizzafy Ecommerce System5.3MEDIUM
Remote File Inclusion Vulnerability in SourceCodester Pizzafy Ecomm...

A vulnerability exists in the SourceCodester Pizzafy Ecommerce System 1.0 that allows unauthorized file inclusion through a compromised call to the /admin/index.php file. This vulnerability can be exploited remotely, enabling attackers to manipulate the 'page' argument, potentially leading to exp...

PoC for CVE-2026-10550

ElunezEladmin5.3MEDIUM
Command Injection Vulnerability in elunez eladmin Application Deplo...

A command injection vulnerability exists in the elunez eladmin application due to improper handling of the uploadPath argument in the Application Deployment Module. This weakness can allow remote attackers to execute arbitrary commands on the server through crafted requests. Public exploits for t...

PoC for CVE-2026-10548

NousresearchHermes-agent4.8MEDIUM
Improper Authentication in NousResearch Hermes-Agent Affects Creden...

A security vulnerability has been discovered in NousResearch's hermes-agent, specifically affecting the Credential Pool Synchronization component. This flaw arises from the function _sync_anthropic_entry_from_credentials_file within the agent/credential_pool.py file, which allows for improper aut...

PoC for CVE-2026-10529

WestboyCicadascms4.8MEDIUM
Cross Site Scripting Vulnerability in CicadasCMS Task Scheduling Ma...

A vulnerability has been discovered in the Task Scheduling Management Module of westboy's CicadasCMS, specifically within the ScheduleJobController.java file. This weakness allows malicious actors to execute remote cross site scripting (XSS) attacks, potentially leading to unauthorized access or ...

PoC for CVE-2026-10528

OrthancDicom Server4.8MEDIUM
Stack-based Buffer Overflow Vulnerability in Orthanc DICOM Server b...

A security flaw has been identified in the Orthanc DICOM Server, specifically within the DcmItem::read function in the DCMTK Parser component. This vulnerability allows for a stack-based buffer overflow when manipulated, posing a risk during local attacks. The public release of an exploit intensi...

PoC for CVE-2026-10514

1panel-devCordyscrm4.8MEDIUM
Cross Site Scripting Vulnerability in 1Panel-dev CordysCRM by 1Panel

A security vulnerability exists in 1Panel-dev CordysCRM affecting versions up to 1.6.2, specifically within the RequestParamTrimConfig.java file. This flaw allows attackers to manipulate an unspecified function, resulting in cross-site scripting (XSS) vulnerabilities. Successfully exploiting this...

PoC for CVE-2026-10302

ItsourcecodeFees Management System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Fees Management System 1.0

A vulnerability exists in the itsourcecode Fees Management System 1.0 that allows for SQL injection through the manipulate of the ID argument in the /manage_fee.php file. This security flaw can be exploited remotely, permitting unauthorized access to the database and potentially leading to data e...

PoC for CVE-2026-10301

ItsourcecodeFees Management System5.3MEDIUM
Cross Site Scripting Vulnerability in itsourcecode Fees Management ...

A vulnerability has been identified in the itsourcecode Fees Management System 1.0, specifically within the index.php file. This vulnerability arises due to improper handling of the 'page' argument, allowing attackers to execute cross-site scripting (XSS) attacks. The manipulation can be performe...