Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 1 hour ago

PoC for CVE-2024-50603

AviatrixController10CRITICAL
Remote Code Execution Vulnerability in Aviatrix Controller by Aviatrix

A vulnerability in Aviatrix Controller allows unauthenticated attackers to exploit improper handling of OS command elements. This security flaw enables the execution of arbitrary code through the manipulation of API requests by injecting shell metacharacters into the parameters 'cloud_type' and '...

Discovered 7 hours ago

PoC for CVE-2025-0398

Longpi1Warehouse5.1MEDIUM
Cross Site Scripting Vulnerability in Longpi1 Warehouse Backend Com...

A Cross Site Scripting vulnerability has been discovered in the Longpi1 Warehouse version 1.0. This issue arises from a flaw in the backend component, specifically in the file located at /resources/..;/inport/updateInport. The vulnerability allows remote attackers to manipulate the 'remark' param...

Discovered 9 hours ago

PoC for CVE-2025-0397

ReckcnSppanadmin5.3MEDIUM
Cross Site Scripting in reckcn SPPanAdmin by reckcn

A vulnerability has been identified in the reckcn SPPanAdmin application that allows for cross site scripting (XSS) attacks. The flaw exists in an unknown function of the administration module located at '/admin/role/edit'. Attackers can manipulate the name parameter, which can potentially lead t...

Discovered 18 hours ago

PoC for CVE-2024-12856

Four-faithF3x247.2HIGH
OS Command Injection Vulnerability in Four-Faith Routers

An operating system command injection vulnerability exists in specific models of Four-Faith routers, enabling authenticated and remote attackers to execute arbitrary OS commands through an HTTP request when modifying the system time. The vulnerability is compounded by the inclusion of default cre...

Discovered 20 hours ago

PoC for CVE-2019-17240

BluditBludit3.7LOW
Bludit

bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.

Discovered 1 day ago

PoC for CVE-2025-0282

IvantiConnect Secure9CRITICAL
Stack-Based Buffer Overflow in Ivanti Connect Secure and Policy Secure

A stack-based buffer overflow vulnerability exists in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways, prior to designated versions. This flaw allows a remote unauthenticated attacker to execute arbitrary code on the affected systems, posing significant risks to s...

PoC for CVE-2025-0392

Guangzhou Huayi I...Jeewms5.3MEDIUM
SQL Injection Vulnerability in Jeewms by Guangzhou Huayi Intelligen...

A SQL injection vulnerability exists in the Jeewms product from Guangzhou Huayi Intelligent Technology, specifically in the datagridGraph function within the graphReportController.do file. This vulnerability allows an attacker to manipulate the store_code argument, permitting unauthorized remote ...

Discovered 2 days ago

PoC for CVE-2025-0391

Guangzhou Huayi I...Jeewms5.3MEDIUM
SQL Injection Vulnerability in Jeewms by Guangzhou Huayi Intelligen...

A SQL injection vulnerability has been identified in Jeewms developed by Guangzhou Huayi Intelligent Technology, affecting versions up to 20241229. The issue is located in the saveOrUpdate function within the CgFormBuildController.java file. This vulnerability allows attackers to manipulate SQL q...

PoC for CVE-2025-0390

Guangzhou Huayi I...Jeewms6.9MEDIUM
Path Traversal Vulnerability in Jeewms by Guangzhou Huayi Intellige...

A path traversal vulnerability in Jeewms by Guangzhou Huayi Intelligent Technology allows an attacker to manipulate file paths within the application. This vulnerability affects the /wmOmNoticeHController.do file and can be exploited remotely. Attackers may exploit this flaw to access unauthorize...

PoC for CVE-2024-12587

WordPressContact Form Master
Reflected Cross-Site Scripting in Contact Form Master Plugin for Wo...

The Contact Form Master plugin for WordPress, up to version 1.0.7, is susceptible to a reflected cross-site scripting (XSS) vulnerability. This flaw arises due to the plugin's failure to properly sanitize and escape user-input parameters before rendering them on the web page. As a result, an atta...

PoC for CVE-2024-53677

ApacheApache Struts
Flawed File Upload Logic in Apache Struts Exposes Vulnerability

A security flaw in the file upload mechanism of Apache Struts could allow an attacker to exploit file upload parameters. This vulnerability enables path traversal, leading to the possibility of uploading a malicious file that can facilitate remote code execution. To mitigate risks, users should u...

PoC for CVE-2024-3400

Palo Alto NetworksPan-os🟣 EPSS 96%10CRITICAL
Palo Alto Networks PAN-OS Command Injection Vulnerability

A vulnerability exists in the GlobalProtect feature of Palo Alto Networks PAN-OS software, allowing for arbitrary file creation. This issue can be exploited by an unauthenticated attacker to execute code with root privileges on the affected firewall systems. Specific configurations and versions a...

Discovered 3 days ago

PoC for CVE-2024-8743

BitpressadminBit File Manager – 100...6.8MEDIUM
Limited JavaScript File Upload Vulnerability in Bit File Manager

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for auth...

PoC for CVE-2025-0349

TendaAc68.7HIGH
Stack-based Buffer Overflow in Tenda AC6 by Tenda

A vulnerability exists in Tenda AC6 15.03.05.16 that allows for a stack-based buffer overflow through the GetParentControlInfo function located in /goform/GetParentControlInfo. Manipulating the 'src' argument could enable remote attackers to exploit the vulnerability, potentially affecting additi...

PoC for CVE-2025-0348

CampcodesDeped Equipment Invent...5.3MEDIUM
Cross-Site Scripting Vulnerability in CampCodes DepEd Equipment Inv...

A cross-site scripting vulnerability has been identified in CampCodes DepEd Equipment Inventory System version 1.0. The flaw is located in the /data/add_employee.php file, where user input is not adequately sanitized. This oversight allows attackers to inject malicious scripts, potentially compro...

PoC for CVE-2025-0347

Code-projectsAdmission Management S...6.9MEDIUM
SQL Injection Vulnerability in Admission Management System by Code-...

A significant SQL injection vulnerability has been identified in the Admission Management System version 1.0 by Code-Projects. This flaw resides in the index.php file, specifically within the login component, where improper handling of the user identifier (u_id) parameter can allow attackers to e...

Discovered 4 days ago

PoC for CVE-2025-0346

Code-projectsContent Management System5.1MEDIUM
Unrestricted Upload Vulnerability in Code-Projects CMS Publish News...

A vulnerability exists in the code-projects Content Management System 1.0, specifically within the Publish News Page component located at /admin/publishnews.php. This issue allows for unrestricted file uploads through manipulation of the 'image' argument, enabling attackers to upload arbitrary fi...

PoC for CVE-2025-0345

LeiyuxiCy-fast5.3MEDIUM
SQL Injection Vulnerability in Leiyuxi Cy-Fast 1.0

A SQL injection vulnerability exists in the listData function of the Leiyuxi Cy-Fast 1.0 product. This security flaw occurs due to improper handling of input arguments, specifically in the argument order within the /sys/menu/listData file. This weakness allows an attacker to manipulate the SQL qu...

PoC for CVE-2025-0344

LeiyuxiCy-fast5.3MEDIUM
SQL Injection Vulnerability in leiyuxi cy-fast 1.0

A vulnerability exists in leiyuxi cy-fast version 1.0 within the listData function located in /commpara/listData. By manipulating the order of function arguments, attackers can exploit this vulnerability to perform SQL injection attacks remotely. This issue exposes sensitive information and may c...

PoC for CVE-2025-0342

CampcodesComputer Laboratory Ma...5.3MEDIUM
Cross-Site Scripting Vulnerability in CampCodes Computer Laboratory...

A cross-site scripting vulnerability exists in the CampCodes Computer Laboratory Management System version 1.0, primarily affecting the file located at /class/edit/edit. This security flaw can be exploited by manipulating the 's_lname' argument, potentially allowing remote attackers to execute ar...

PoC for CVE-2025-0341

CampcodesComputer Laboratory Ma...5.3MEDIUM
Unrestricted File Upload in CampCodes Computer Laboratory Managemen...

A vulnerability has been identified in CampCodes Computer Laboratory Management System 1.0, specifically in the functionality of the file /class/edit/edit. This weakness allows an attacker to manipulate the argument e_photo, leading to unrestricted file uploads. Such attacks can be executed remot...

PoC for CVE-2025-0336

CodezipsProject Management System5.3MEDIUM
SQL Injection Vulnerability in Codezips Project Management System b...

The Codezips Project Management System 1.0 contains a vulnerability in the /pages/forms/teacher.php file that allows remote SQL injection through manipulation of the argument name. This flaw enables attackers to execute arbitrary SQL queries on the database, potentially leading to unauthorized ac...

PoC for CVE-2024-6324

GitlabGitlab4.3MEDIUM
Denial of Service Vulnerability in GitLab CE/EE by GitLab

A Denial of Service vulnerability was identified in GitLab CE/EE that could allow attackers to create cyclic references between epics, leading to resource exhaustion and potential service disruption. This issue affects all versions from 15.7 to 17.5.5, 17.6 from its release to 17.6.3, and 17.7 up...

PoC for CVE-2025-0335

Code-projectsOnline Bike Rental System5.3MEDIUM
Unrestricted Upload Vulnerability in Online Bike Rental System by C...

A vulnerability exists in the Online Bike Rental System 1.0 developed by Code-Projects, centered around the Change Image Handler component. This flaw allows attackers to upload files without proper restrictions, which may lead to unauthorized access and exploitation. The potential for remote atta...

PoC for CVE-2024-12736

WordPressBu Section Editing
Reflected Cross-Site Scripting Vulnerability in BU Section Editing ...

The BU Section Editing WordPress plugin fails to properly sanitize and escape user-supplied input, leading to a reflected cross-site scripting vulnerability. This flaw poses a significant risk for high privilege users such as administrators, as it can allow attackers to inject malicious scripts t...

PoC for CVE-2024-12731

WordPressAklamator Infeed
Reflected Cross-Site Scripting Vulnerability in Aklamator INfeed Pl...

The Aklamator INfeed WordPress plugin, up to version 2.0.0, has a security flaw where it fails to properly sanitize and escape a certain parameter before displaying it on the web page. This vulnerability can expose high-privilege users, such as administrators, to reflected cross-site scripting at...

PoC for CVE-2024-12717

AklamatorAklamator Infeed
Stored Cross-Site Scripting Vulnerability in Aklamator INfeed Plugi...

The Aklamator INfeed WordPress plugin, up to version 2.0.0, is susceptible to Stored Cross-Site Scripting due to improper sanitization and escaping of its settings. This vulnerability permits high privilege users, such as administrators, to conduct attacks that could lead to malicious scripts bei...

PoC for CVE-2025-0334

LeiyuxiCy-fast5.3MEDIUM
SQL Injection Vulnerability in Leiyuxi Cy-Fast Web Application

A vulnerability exists in Leiyuxi Cy-Fast version 1.0, specifically in the listData function located in the /sys/user/listData file. This vulnerability arises due to inadequate validation of input parameters, allowing attackers to manipulate the order of arguments. As a result, it opens the door ...

PoC for CVE-2024-12715

WordPressAsgard Security Scanner
Reflected Cross-Site Scripting in Asgard Security Scanner WordPress...

The Asgard Security Scanner plugin for WordPress, specifically versions up to 0.7, contains a security flaw that arises from inadequate sanitization and escaping of user-supplied input. This oversight can lead to reflected cross-site scripting (XSS) attacks, potentially targeting high-privilege u...

PoC for CVE-2024-12714

WordPressBacklink Monitoring Ma...
Reflected Cross-Site Scripting Vulnerability in Backlink Monitoring...

The Backlink Monitoring Manager plugin for WordPress, up to version 0.1.3, is vulnerable to reflected cross-site scripting. This occurs due to insufficient sanitization and escaping of parameters before rendering them on the page. Attackers may exploit this weakness to inject malicious scripts, p...

PoC for CVE-2024-10815

WordPressPostlists
Reflected Cross-Site Scripting Vulnerability in PostLists Plugin fo...

The PostLists WordPress plugin, up to version 2.0.2, is vulnerable to a reflected cross-site scripting (XSS) issue due to improper handling of the $_SERVER['REQUEST_URI'] parameter. This flaw allows malicious actors to inject harmful scripts into the web page, potentially compromising user data i...

PoC for CVE-2025-0333

LeiyuxiCy-fast5.3MEDIUM
SQL Injection Vulnerability in leiyuxi cy-fast Product

A vulnerability exists in the leiyuxi cy-fast application, specifically within the listData function located in the file /sys/role/listData. This issue arises from poorly validated input that allows attackers to manipulate the order of function arguments, resulting in SQL injection attacks. Such ...

PoC for CVE-2025-0331

YunzMallYunzmall6.9MEDIUM
Arbitrary Password Reset Vulnerability in YunzMall HTTP POST Request

A vulnerability has been identified in YunzMall versions up to 2.4.2, specifically within the changePwd function of the ResetpwdController.php file. This weakness allows for remote manipulation of the password recovery process, potentially enabling unauthorized access to user accounts through wea...

PoC for CVE-2025-0328

KaiyuantongEct Platform6.9MEDIUM
Command Injection Vulnerability in KaiYuanTong ECT Platform Affects...

A command injection vulnerability exists within the KaiYuanTong ECT Platform, particularly in the /public/server/runCode.php file used for handling HTTP POST requests. An attacker can manipulate the 'code' argument, potentially allowing unauthorized commands to be executed on the server. This iss...

PoC for CVE-2024-13213

SingmrHouserent5.3MEDIUM
Cross-Site Scripting Vulnerability in SingMR HouseRent Web Application

A cross-site scripting vulnerability has been identified in the SingMR HouseRent application version 1.0. This weakness exists in the code handling requests to the endpoint /toAdminUpdateHousePage?hID=30, allowing an attacker to inject malicious scripts. The attack can be executed remotely, posin...

PoC for CVE-2024-13212

SingmrHouserent5.3MEDIUM
Unrestricted File Upload Vulnerability in SingMR HouseRent 1.0

A serious vulnerability exists in SingMR HouseRent 1.0, allowing attackers to exploit the singleUpload/upload function found in AddHouseController.java. This flaw enables the manipulation of the file argument, leading to unrestricted file uploads. Given that this vulnerability can be exploited re...

PoC for CVE-2024-13211

SingmrHouserent5.3MEDIUM
Improper Access Control in SingMR HouseRent 1.0

A significant vulnerability has been identified in SingMR HouseRent version 1.0, specifically within the file AdminController.java. This flaw results in improper access controls, allowing unauthorized users to manipulate functionalities that should be restricted. The vulnerability can be exploite...

PoC for CVE-2024-13210

DonglightBookstore电商书城系统说明5.1MEDIUM
Unrestricted File Upload in Donglight Bookstore System 1.0

A vulnerability has been identified in Donglight Bookstore System 1.0, specifically in the uploadPicture function of the AdminBookController located in src/main/java/org/zdd/bookstore/web/controller/admin. An attacker can exploit this flaw to perform unrestricted file uploads, which may lead to f...

PoC for CVE-2024-13209

RedaxoCms5.1MEDIUM
Cross Site Scripting Vulnerability in Redaxo CMS Structure Manageme...

An exploitable cross site scripting vulnerability exists in the Structure Management Page of Redaxo CMS version 5.18.1. This vulnerability is triggered by manipulating the 'Article Name' parameter within the index.php file, allowing attackers to inject malicious scripts. The attack can be execute...

PoC for CVE-2024-13206

ReveAntivirus8.5HIGH
Incorrect Default Permissions in REVE Antivirus for Linux

A vulnerability has been identified in REVE Antivirus version 1.0.0.0 on Linux, resulting in incorrect default permissions for a component within the file /usr/local/reveantivirus/tmp/reveinstall. This security flaw allows local attackers to exploit these permissions, leading to potential unautho...

PoC for CVE-2024-13205

KurniaramadhanE-commerce-PHP5.1MEDIUM
SQL Injection Vulnerability in E-Commerce-PHP by kurniaramadhan

A SQL injection vulnerability exists in the E-Commerce-PHP 1.0 web application, specifically within the Create Product Page at /admin/create_product.php. This vulnerability allows an attacker to manipulate the 'Name' argument, potentially leading to unauthorized access or manipulation of the data...

PoC for CVE-2024-13204

KurniaramadhanE-commerce-PHP5.3MEDIUM
SQL Injection Vulnerability in E-Commerce-PHP by Kurniaramadhan

A remote SQL injection vulnerability exists in E-Commerce-PHP 1.0, specifically within the /blog-details.php file. This flaw arises from improper handling of the blog_id parameter, allowing attackers to manipulate database queries. As a result, unauthorized access to sensitive data could occur. T...

PoC for CVE-2024-13202

Wander-chuSpringboot-blog5.1MEDIUM
Cross-Site Scripting Flaw in wander-chu SpringBoot-Blog by wander-chu

A cross-site scripting vulnerability was identified in the Blog Article Handler of wander-chu SpringBoot-Blog 1.0. The issue arises from improper handling of user-supplied content within the modifiyArticle function in the PageController.java file. This flaw can be exploited remotely, allowing att...

PoC for CVE-2024-13201

Wander-chuSpringboot-blog5.1MEDIUM
Unrestricted File Upload Vulnerability in wander-chu SpringBoot-Blo...

A vulnerability exists in the Admin Attachment Handler of wander-chu's SpringBoot-Blog 1.0, specifically in the file upload function located in the AttachtController.java file. This flaw allows attackers to manipulate the file upload argument, resulting in unrestricted file uploads. This can lead...

PoC for CVE-2024-13200

Wander-chuSpringboot-blog6.9MEDIUM
Improper Access Control in wander-chu SpringBoot-Blog Affects Remot...

A vulnerability exists in the wander-chu SpringBoot-Blog application version 1.0, located in the preHandle function of the BaseInterceptor.java file. This flaw results in improper access controls that can be exploited to perform unauthorized actions remotely. The potential for exploitation has be...

PoC for CVE-2024-13199

LanghsuMblog Blog System5.3MEDIUM
Cross-Site Scripting Vulnerability in langhsu Mblog Blog System

A cross-site scripting vulnerability has been identified in the langhsu Mblog Blog System version 3.5.0, specifically within the Search Bar component. This flaw arises from improper handling of the 'kw' parameter in the '/search' file, allowing remote attackers to execute arbitrary JavaScript in ...

PoC for CVE-2024-13198

LanghsuMblog Blog System6.3MEDIUM
Observable Response Discrepancy in langhsu Mblog Blog System by lan...

A vulnerability has been identified within the langhsu Mblog Blog System version 3.5.0, specifically impacting the login functionality. This vulnerability allows attackers to exploit an observable response discrepancy, providing them the potential to execute remote attacks. The complexity of the ...

PoC for CVE-2024-50603

AviatrixController10CRITICAL
Remote Code Execution Vulnerability in Aviatrix Controller by Aviatrix

A vulnerability in Aviatrix Controller allows unauthenticated attackers to exploit improper handling of OS command elements. This security flaw enables the execution of arbitrary code through the manipulation of API requests by injecting shell metacharacters into the parameters 'cloud_type' and '...

PoC for CVE-2024-11613

NickbossWordPress File Upload9.8CRITICAL
Remote Code Execution and File Manipulation in WordPress File Uploa...

The WordPress File Upload plugin suffers from a significant security vulnerability that allows unauthenticated attackers to exploit the 'wfu_file_downloader.php' file. This is attributed to insufficient sanitization of the 'source' parameter, enabling attackers to dictate a directory path. Conseq...

PoC for CVE-2015-9251

JqueryJquery6.1MEDIUM
Jquery

jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.