Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2022-24903

RsyslogRsyslog8.1HIGH
Buffer overflow in TCP syslog server (receiver) components in rsyslog

Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execu...

PoC for CVE-2026-33937

Handlebars-langHandlebars.js9.8CRITICAL
Remote Code Execution Vulnerability in Handlebars by Handlebars.js

In Handlebars versions 4.0.0 through 4.7.8, a vulnerability exists where `Handlebars.compile()` can accept a pre-parsed AST object directly. This leads to the potential injection of arbitrary JavaScript into the generated code because the `value` field of a `NumberLiteral` AST node is emitted dir...

Discovered 57 minutes ago

PoC for CVE-2025-64446

FortinetFortiweb🟣 EPSS 92%9.4CRITICAL
Relative Path Traversal Vulnerability in Fortinet FortiWeb Products

A relative path traversal vulnerability exists in Fortinet FortiWeb products versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.4, 7.4.0 to 7.4.9, 7.2.0 to 7.2.11, and 7.0.0 to 7.0.11. This vulnerability allows an attacker to potentially execute unauthorized administrative commands on the system by sending sp...

Discovered 8 hours ago

PoC for CVE-2022-24355

Tp-linkTl-wr940n8.8HIGH
Arbitrary Code Execution Vulnerability in TP-Link Router

This vulnerability exists in the TP-Link TL-WR940N router, allowing attackers in the network vicinity to execute arbitrary code due to insufficient validation of user-supplied data lengths when parsing file name extensions. This flaw can be exploited without authentication, enabling attackers to ...

Discovered 9 hours ago

PoC for CVE-2026-67207

WolfcmsWolfcms8.7HIGH
Authorization Bypass in Wolf CMS Affected by BackupRestoreController

Wolf CMS versions up to 0.8.3.1 contain an authorization bypass vulnerability in the BackupRestoreController component. This flaw allows authenticated non-administrative users to gain access to sensitive backup functionalities. The issue arises from a PHP operator precedence flaw in the expressio...

PoC for CVE-2026-67206

WolfcmsWolfcms8.7HIGH
Remote Code Execution Flaw in Wolf CMS by Wolf CMS

Wolf CMS versions up to 0.8.3.1 are susceptible to a remote code execution vulnerability due to inadequate file extension validation in the FileManagerController. This flaw enables authenticated attackers with the 'file_manager_mkfile' capability to craft arbitrary PHP files. By exploiting this v...

PoC for CVE-2020-7882

HancomwithAnysign4pc7.5HIGH
anySign directory traversal vulnerability

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

Discovered 11 hours ago

PoC for CVE-2024-28000

WordPressLitespeed Cache🟣 EPSS 68%9.8CRITICAL
Incorrect Privilege Assignment vulnerability in LiteSpeed Cache all...

The CVE-2024-28000 vulnerability is found in the widely-used LiteSpeed Cache Plugin for WordPress websites, allowing unauthenticated users to gain administrator-level access and create new user accounts with the administrator role. This critical privilege escalation vulnerability has a high CVSS ...

Discovered 12 hours ago

PoC for CVE-2026-16723

AlibabaFastjson9CRITICAL
Remote Code Execution Vulnerability in fastjson by Alibaba

A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...

Discovered 14 hours ago

PoC for CVE-2026-67349

OpencostOpencost8.7HIGH
Authentication Bypass in OpenCost Exposing Cloud Provider Credentials

The OpenCost application prior to version 1.121.0 exhibits significant security vulnerabilities that jeopardize sensitive information. It fails to authenticate requests to the GET /helmValues endpoint, which allows unauthorized access to base64-decoded HELM_VALUES, potentially revealing critical ...

PoC for CVE-2026-67348

Julep-aiJulep8.6HIGH
Insecure Direct Object Reference in Julep Affects Tenant Data Privacy

The Julep software is exposed to an insecure direct object reference vulnerability within the get_execution_details endpoint. This flaw permits authenticated users to access execution data of other tenants by manipulating the execution_id parameter. Unauthorized retrieval of sensitive execution r...

PoC for CVE-2026-67347

VendurehqVendure6.1MEDIUM
Cross-Channel Authorization Bypass in Vendure by VendureHQ

Vendure, up to version 3.7.1, is susceptible to a cross-channel authorization bypass in the stock-location.service.ts and asset.service.ts update methods. This vulnerability allows administrators with channel-scoped permissions to manipulate data from other tenants by supplying global IDs of Stoc...

PoC for CVE-2026-67345

DromaraMaxkey8.5HIGH
Insufficient Redirect URI Validation in MaxKey OAuth 2.0 Implementa...

The MaxKey authentication framework up to version 4.1.12 suffers from an insufficient redirect URI validation vulnerability in the DefaultRedirectResolver.hostMatches() method. This flaw allows attackers to hijack OAuth 2.0 authorization codes by manipulating the redirect_uri. If an attacker cont...

Discovered 18 hours ago

PoC for CVE-2026-10702

MozillaFirefox4.3MEDIUM
JIT Miscompilation Vulnerability in Firefox by Mozilla

A JIT (Just-In-Time) miscompilation vulnerability has been identified in the JavaScript Engine of Firefox. This flaw could potentially allow attackers to exploit the JIT component, leading to unexpected behavior or execution of arbitrary code. This issue has been addressed in Firefox version 151....

PoC for CVE-2026-59726

RuvnetRuflo10CRITICAL
Unauthenticated Access in Ruflo Agent Meta-Harness

The Ruflo Agent Meta-Harness prior to version 3.16.3 had a critical security flaw wherein its default Docker deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without any authentication. This oversight potentially allowed an unauthenticated attacker to execute commands, g...

Discovered 22 hours ago

PoC for CVE-2026-66066

RailsRails9.5CRITICAL
Active Storage Vulnerability in Rails Affects Image Upload Security

Active Storage, a framework component of Rails, has a vulnerability that affects versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1. This issue arises from the framework's failure to disable unsafe libvips operations when handling image uploads from untrusted users. An unauthenticated attacker can e...

PoC for CVE-2026-45746

Termix-sshTermix9CRITICAL
Broken Access Control in Termix Web Management Platform

The Termix Web Management Platform includes a vulnerability related to Broken Access Control, specifically in its File Manager feature. This issue stems from inadequate validation of the sessionId parameter, allowing attackers to exploit the backend's trust in a client-controlled identifier. As a...

PoC for CVE-2026-14310

WordPressTutor Lms5.4MEDIUM
Inadequate User Access Control in Tutor LMS WordPress Plugin

The Tutor LMS WordPress plugin prior to version 4.0.0 features a significant flaw in its user access control mechanism. This vulnerability permits authenticated users, regardless of their role, to access Q&A threads not associated with courses they are enrolled in. Moreover, it enables such users...

PoC for CVE-2026-14239

WordPressTourmaster
Stored Cross-Site Scripting in Tourmaster WordPress Plugin

The Tourmaster WordPress plugin prior to version 5.4.8 is vulnerable due to inadequate nonce checks when saving a custom-filter label from user input. This weakness allows unauthenticated attackers to exploit it and potentially inject malicious JavaScript. If a logged-in administrator is tricked ...

PoC for CVE-2026-14305

WordPressWP Delicious5.3MEDIUM
Authorization Bypass in WP Delicious Plugin Affecting WordPress Users

The WP Delicious plugin for WordPress prior to version 1.10.2 is susceptible to an authorization bypass vulnerability. This flaw allows unauthenticated users to exploit AJAX actions without proper authorization. As a result, users can modify certain post metadata, specifically the like counter an...

PoC for CVE-2026-13344

WordPressEssential Addons For E...4.8MEDIUM
Stored Cross-Site Scripting Vulnerability in Essential Addons for E...

The Essential Addons for Elementor WordPress plugin prior to version 6.6.10 is susceptible to Stored Cross-Site Scripting due to inadequate validation of HTML tag names in the Pricing Table widget title. This vulnerability allows users with Contributor-level access and above to inject malicious J...

PoC for CVE-2026-13395

WordPressOnline Scheduling And ...8.6HIGH
SQL Injection Vulnerability in Online Scheduling and Appointment Bo...

The Online Scheduling and Appointment Booking System plugin for WordPress prior to version 27.8 is vulnerable to SQL injection. This flaw arises from the plugin's failure to properly sanitize or cast user-supplied parameters in unauthenticated front-end booking requests. Attackers can exploit thi...

PoC for CVE-2026-13345

WordPressEssential Addons For E...5.3MEDIUM
Improper Access Control in Essential Addons for Elementor by WPDeve...

The Essential Addons for Elementor plugin for WordPress, prior to version 6.6.10, lacks necessary authorization checks in its product-comparison feature. This oversight allows unauthenticated users to access sensitive information, such as the titles, prices, and SKUs of draft, pending, and privat...

PoC for CVE-2026-13178

WordPressEventin7.5HIGH
Unauthorized Order Creation in Eventin WordPress Plugin by Vendor

The Eventin WordPress plugin, prior to version 4.1.16, contains a vulnerability that allows unauthorized order creation. This occurs due to improper authorization checks, enabling attackers to modify order statuses without completing any payment process. As a result, unauthenticated users can cre...

PoC for CVE-2026-13330

WordPressAnimation Addons For E...6.1MEDIUM
Stored Cross-Site Scripting in Animation Addons for Elementor Plugi...

The Animation Addons for Elementor plugin for WordPress allows users with the upload_files capability (Author and above) to upload SVG/SVGZ files without proper sanitization. This oversight enables the potential injection of malicious JavaScript into the application, resulting in stored cross-sit...

PoC for CVE-2026-13143

WordPressWP Travel5.3MEDIUM
Unauthorized Payment Notification Processing in WP Travel Plugin by...

The WP Travel plugin for WordPress, prior to version 11.8.1, contains a vulnerability that allows unauthenticated attackers to manipulate payment statuses. This flaw stems from the plugin's failure to authenticate PayPal Instant Payment Notifications via the necessary post-back handshake. Consequ...

PoC for CVE-2026-13145

WordPressWP Travel4.3MEDIUM
Information Disclosure Vulnerability in WP Travel Plugin by WordPress

The WP Travel plugin for WordPress, prior to version 11.8.1, is susceptible to an information disclosure vulnerability. The flaw occurs because the plugin fails to verify the ownership of booking requests made through the customer account dashboard. Consequently, this allows any authenticated use...

PoC for CVE-2026-11867

WordPressFrontend Admin By Dyna...6.5MEDIUM
Arbitrary Taxonomy Term Management Flaw in Frontend Admin Plugin by...

The Frontend Admin plugin by DynamiApps, prior to version 3.29.7, contains a flaw that allows authenticated users with minimal privileges, like Subscribers, to perform unrestricted operations on taxonomy terms. This vulnerability permits these users to create, modify, and delete arbitrary taxonom...

PoC for CVE-2026-11870

WordPressWP Ghost (hide My WP G...5.4MEDIUM
IP Spoofing Vulnerability in WP Ghost Plugin Affects WordPress Sites

The WP Ghost (Hide My WP Ghost) WordPress plugin prior to version 7.0.05 fails to properly verify that the client IP address originates from a trusted proxy. This oversight allows attackers to manipulate HTTP headers to spoof their IP addresses. As a result, unauthenticated attackers can circumve...

PoC for CVE-2026-11881

WordPressFluent Forms6.1MEDIUM
Stored Cross-Site Scripting Vulnerability in Fluent Forms WordPress...

The Fluent Forms WordPress plugin prior to version 6.2.6 contains a vulnerability that fails to properly sanitize and escape a specific form field configuration setting. When a form is rendered, this oversight enables users with low-level roles, such as Contributor with specific permissions, to p...

PoC for CVE-2026-12500

WordPressWP Travel Engine7.5HIGH
Unauthorized Option Overwrite in WP Travel Engine Plugin for WordPress

The WP Travel Engine plugin for WordPress prior to version 6.8.2 is vulnerable due to insufficient access checks on AJAX actions. This flaw allows unauthenticated users to execute certain actions, specifically overwriting critical site-wide options, as the public nonce required for these actions ...

PoC for CVE-2026-15257

WordPressRegistrationmagic5.3MEDIUM
Unauthorized Access Flaw in RegistrationMagic Plugin for WordPress

The RegistrationMagic WordPress plugin prior to version 6.0.9.4 allows unauthorized users to exploit the absence of proper authorization and nonce checks on front-end editing actions. This vulnerability enables attackers to overwrite the form submissions and associated profile fields of non-admin...

PoC for CVE-2026-15255

WordPressRegistrationmagic5.3MEDIUM
Improper Validation in RegistrationMagic Plugin Exposes User Data

The RegistrationMagic WordPress plugin prior to version 6.0.9.4 contains a security flaw that permits unauthenticated attackers to access sensitive user data. The issue arises from inadequate validation of one-time passwords stored in cookies, which enables unauthorized individuals to retrieve fr...

PoC for CVE-2026-15382

WordPressUltimate Addons For WP...6.5MEDIUM
Unauthenticated Deletion Vulnerability in Ultimate Addons for WPBak...

The Ultimate Addons for WPBakery Page Builder plugin allows for unauthorized deletion of a website's custom-uploaded icon font packs. Prior to version 3.21.4, the plugin fails to implement necessary capability and nonce checks, enabling unauthenticated attackers to issue a single request that can...

PoC for CVE-2026-11782

WordPressPoints And Rewards For...5.9MEDIUM
Authorization Flaw in Points and Rewards for WooCommerce by WordPress

The Points and Rewards for WooCommerce plugin does not implement necessary authorization checks on wallet and points update actions, which are exposed to unauthenticated users. This vulnerability allows attackers to modify or corrupt the wallet balance and loyalty points of any user without verif...

PoC for CVE-2026-15252

WordPressSearch Atlas Seo5.4MEDIUM
Authentication Bypass in Search Atlas SEO Plugin Affects WordPress

The Search Atlas SEO plugin for WordPress prior to version 2.6.12 is susceptible to an authentication bypass flaw due to insufficient validation in an AJAX handler. This vulnerability allows authenticated users, such as Subscribers, to interact with the site's Google Indexing API. Consequently, t...

PoC for CVE-2026-14207

WordPressLifterlms6.1MEDIUM
Cross-Site Scripting Vulnerability in LifterLMS WordPress Plugin

The LifterLMS plugin for WordPress prior to version 10.0.10 is susceptible to a cross-site scripting vulnerability. This flaw arises from the plugin's failure to sanitize event-handler attributes within a course pricing field. As a result, users with editing privileges can inject malicious JavaSc...

PoC for CVE-2026-14231

WordPressLifterlms4.3MEDIUM
Unauthorized Access in LifterLMS WordPress Plugin Allows Exposure o...

The LifterLMS WordPress plugin prior to version 10.0.10 has a vulnerability that fails to adequately verify user capabilities in one of its AJAX handlers. This oversight allows any authenticated user, even those with minimal subscriber-level permissions, to access sensitive titles of internal pos...

PoC for CVE-2026-15250

WordPressAppointment Booking Pl...5.3MEDIUM
Unauthorized Access in Appointment Booking Plugin for WordPress

The Appointment Booking Plugin for WordPress has a significant security flaw that permits unauthenticated users to manipulate certain booking fields through the public booking interface. This vulnerability enables unauthorized individuals to assign privileged values, such as the approval status, ...

PoC for CVE-2026-14318

WordPressGiveWP6.8MEDIUM
Cross-Site Scripting Vulnerability in GiveWP Plugin Affecting WordP...

The GiveWP plugin for WordPress, specifically versions prior to 4.16.3, is vulnerable to a Cross-Site Scripting (XSS) issue. This vulnerability arises from a lack of proper escaping for donation-form template settings before they are displayed in HTML attributes. As a result, users with the 'Give...

PoC for CVE-2026-15240

WordPressCustomer Switching7.5HIGH
User Session Vulnerability in Customer Switching Plugin for WordPress

The Customer Switching plugin for WordPress prior to version 2.1.3 has a security flaw that allows a user with lower privileges to exploit an active session. When an operator switches to another user account, the session is not securely bound, enabling the lower-privileged user to perform actions...

PoC for CVE-2026-15054

WordPressBit Form3.7LOW
Form Submission Bypass in Bit Form Plugin for WordPress

The Bit Form plugin for WordPress has a security flaw that permits unauthenticated users to submit entries through public form submission handlers, even for forms that have been deactivated or unpublished. This oversight allows users to trigger configured workflows, such as email notifications, p...

PoC for CVE-2026-15153

WordPressWP Hotel Booking6.8MEDIUM
SQL Injection Risk in WP Hotel Booking Plugin by WordPress

The WP Hotel Booking plugin for WordPress prior to version 2.3.2 is susceptible to SQL injection due to improper sanitization and escaping of search parameters in administrative listings. Attackers with appropriate booking-management roles could exploit this vulnerability to execute unauthorized ...

PoC for CVE-2026-15235

WordPressMotopress Hotel Booking4.3MEDIUM
Unauthorized Data Exposure in MotoPress Hotel Booking Plugin by Mot...

The MotoPress Hotel Booking WordPress plugin prior to version 6.0.4 lacks sufficient capability checks in its AJAX functionalities. This oversight allows authenticated users with minimal privileges, such as Subscribers, to access sensitive customer information. Specifically, personal data includi...

PoC for CVE-2026-12687

WordPressProfilegrid7.5HIGH
ProfileGrid WordPress Plugin Privilege Escalation Vulnerability

The ProfileGrid WordPress plugin prior to version 5.9.9.8 contains a security flaw that allows anonymous users to bypass registration restrictions. As a result, these users can register into privileged groups without authentication, potentially being assigned roles with elevated permissions, incl...

PoC for CVE-2026-14226

WordPressEasy Appointments4.3MEDIUM
Insufficient Access Control in Easy Appointments WordPress Plugin

The Easy Appointments plugin for WordPress up to version 3.12.26 contains an access control vulnerability that permits users with minimal permissions to access sensitive appointment data through certain REST API endpoints. Specifically, the plugin only checks for a basic user capability that any ...

PoC for CVE-2026-14923

WordPressSync Post With Other Site6.5MEDIUM
Authorization Flaw in Sync Post With Other Site Plugin for WordPress

The Sync Post With Other Site plugin for WordPress prior to version 1.9.3 contains a serious flaw in its authorization mechanism on a REST route that manages post creation and updates. Due to an operator-precedence error, it fails to enforce proper page-editing capabilities, allowing authenticate...

PoC for CVE-2026-14592

WordPressWP Real Ip-based Acces...6.1MEDIUM
Access Control Flaw in WP Real IP-based Access Control Plugin by Wo...

The WP Real IP-based Access Control plugin prior to version 1.3.1 is susceptible to an access control vulnerability, allowing unauthenticated users to insert arbitrary JavaScript into a specific option value. This JavaScript becomes executable when an administrator accesses the plugin's settings ...

PoC for CVE-2026-14602

WordPressRemote Api9CRITICAL
Remote Code Execution Vulnerability in Remote API WordPress Plugin ...

The Remote API WordPress plugin versions up to 0.2 contains a serious security flaw in its handling of user-supplied input. This vulnerability allows unauthenticated attackers to inject malicious PHP objects through deserialization, which could lead to remote code execution if a suitable exploit ...

PoC for CVE-2026-14223

WordPressEasy Appointments4.3MEDIUM
Data Exposure Vulnerability in Easy Appointments Plugin for WordPress

The Easy Appointments WordPress plugin prior to version 3.12.26 contains a significant oversight in its handling of customer data. It fails to properly verify ownership or user capabilities when retrieving stored customer details. This flaw allows users with subscriber-level permissions to access...