Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 2 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 4 hours ago
PoC for CVE-2026-86851
The Livees Checkout WordPress plugin (up to version 7.0.2) suffers from a serious security flaw where it fails to validate user permissions, nonce tokens, or order keys on the order confirmation page. This lack of security checks enables unauthenticated attackers to change the status of any order...
PoC for CVE-2026-103329
The Super Payments plugin for WooCommerce does not adequately authenticate payment webhook notifications. This flaw arises because the signing key used for signature validation is empty by default. Consequently, this allows malicious actors to create valid signatures, enabling them to indicate th...
PoC for CVE-2026-87846
The Nova Poshta Shipping plugin for WordPress versions up to 1.19.8 is exposed to serious security risks due to a lack of authorization, nonce, and ownership checks on an AJAX action. This oversight allows unauthenticated users to delete shipment records associated with arbitrary orders. Attacker...
PoC for CVE-2026-89235
The Testimonials by BestWebSoft plugin for WordPress, up to version 1.0.8, has a vulnerability where it fails to properly sanitize and escape a user-supplied parameter in a SQL query. This oversight allows unauthenticated attackers to manipulate the SQL query by appending additional SQL commands,...
PoC for CVE-2026-85348
The GDPR Data Request Form plugin for WordPress, up to version 1.7.1, lacks adequate CSRF protections when updating its settings. This oversight allows attackers to exploit the vulnerability by tricking a site administrator into executing a malicious request. If successful, this could lead to una...
Discovered 7 hours ago
PoC for CVE-2026-84220
The Kirki WordPress plugin prior to version 6.3.2 is vulnerable to a serious issue where it allows shortcodes in comments to be executed. This happens because the plugin renders comments without properly filtering or moderating them. As a result, unauthenticated users can exploit this vulnerabili...
PoC for CVE-2026-84224
The Kirki WordPress plugin prior to version 6.3.2 contains a flaw that fails to properly validate the host of a provided URL before making a fetch request. This oversight allows users with at least editor-level permissions to send requests to internal services that should ideally be unreachable f...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 9 hours ago
PoC for CVE-2026-93548
The FooSales plugin for WordPress, prior to version 1.43.3, contains a serious vulnerability that allows any authenticated user to impersonate other users, including administrators. This flaw arises from the lack of proper verification to establish if a user is authorized to act on behalf of anot...
PoC for CVE-2026-106097
The Code Snippets plugin for WordPress, prior to version 3.10.0, contains a SQL Injection vulnerability due to improper sanitization and escaping of user-supplied parameters in certain snippet-migration import endpoints. This flaw is particularly concerning for environments utilizing WordPress Mu...
PoC for CVE-2025-15700
The AWP Classifieds plugin for WordPress prior to version 4.4.9 has a significant vulnerability in its listing-import feature. It fails to properly validate the type of files that users can extract from uploaded ZIP archives. Consequently, users with management capabilities can upload arbitrary P...
PoC for CVE-2026-87841
The UnitechPay WordPress plugin version 1.0.6.3 suffers from a significant flaw where it fails to authenticate payment notifications. This vulnerability allows attackers to mark orders as paid without any legitimate payment being processed, in addition to the ability to arbitrarily change the sta...
PoC for CVE-2026-106095
The Code Snippets plugin for WordPress, prior to version 3.10.0, contains a vulnerability that allows an administrator of a single subsite within a multisite network to manipulate snippets for the entire network. This occurs because the plugin does not conduct a proper capability check on certain...
PoC for CVE-2026-92990
The SendPress Newsletters plugin for WordPress contains a security flaw where it secures a logging endpoint with a hardcoded token, consistent across all installations. This design flaw allows unauthorized users to access sensitive newsletter sending logs. Consequently, attackers could obtain inf...
PoC for CVE-2026-88931
The Social Web Suite plugin for WordPress prior to version 4.1.12 contains a vulnerability that fails to restrict unverified access to its configuration settings. This oversight allows attackers to exploit an unauthenticated endpoint to manipulate arbitrary plugin options, including critical ones...
PoC for CVE-2026-86850
The SKU Error Fixer for WooCommerce WordPress plugin allows unauthenticated users to execute certain AJAX actions without performing necessary capability or nonce checks. This oversight enables malicious actors to permanently delete product variations deemed obsolete and exposes sensitive details...
PoC for CVE-2026-92989
The SendPress Newsletters plugin for WordPress fails to adequately restrict user capabilities when managing newsletters. Authenticated users with subscriber-level access can exploit this oversight, allowing them to synchronize all site users into a mailing list and manipulate the newsletter sendi...
PoC for CVE-2026-91940
The crawl4ai tool prior to version 0.9.3 has a vulnerability where the PDFContentScrapingStrategy's _filter_untrusted_fields function fails to properly validate untrusted configuration fields. This flaw enables attackers to submit specially crafted configuration bodies, potentially containing mal...
Discovered 12 hours ago
PoC for CVE-2026-92555
The AKINSOFT WOLVOX Control Panel contains a vulnerability that allows sensitive information to be inserted into data sent by the application. This exposure enables unauthorized access to system resources, highlighting the need for users to update to the latest version to mitigate potential risks...
Discovered 15 hours ago
PoC for CVE-2026-21589
This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerat...
Discovered 16 hours ago
PoC for CVE-2021-30535
A double free vulnerability exists in the International Components for Unicode (ICU) library within Google Chrome versions prior to 91.0.4472.77. This flaw allows a remote attacker to potentially exploit heap corruption by crafting a malicious HTML page. Successful exploitation could lead to arbi...
Discovered 18 hours ago
PoC for CVE-2026-11318
Deskin versions up to 3.3.4.3 have a significant vulnerability in the com.deskin.service.installer XPC service. This flaw allows local unprivileged attackers to connect to the root-owned service without authentication, enabling them to execute arbitrary installer packages as the root user. By exp...
Discovered 19 hours ago
PoC for CVE-2026-107707
Intego Antivirus for Windows versions through 3.0.0.1 contains a vulnerability in its optimization module that permits local unprivileged users to delete arbitrary folders as the SYSTEM account. Exploitation occurs when an attacker alters the directory of a scanned duplicate file, leveraging a ju...
Discovered 21 hours ago
PoC for CVE-2026-5430
The vulnerability in WSO2 products relates to the JWT authentication mechanism, which improperly validates tokens signed with algorithms not explicitly configured or supported. This flaw enables an attacker to create a JSON Web Token (JWT) using an unsupported signing algorithm. If an attacker su...
PoC for CVE-2025-9974
The ONT/Beacon device by Nokia features a critical input handling flaw in its unified WEBUI application. This vulnerability allows low-privileged authenticated users to exploit insufficient validation of user-supplied data, enabling them to execute arbitrary commands on the device's operating sys...
PoC for CVE-2026-18963
A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...
PoC for CVE-2026-31857
Craft CMS has a remote code execution vulnerability due to improper handling of user-controlled input in the conditions system prior to version 5.9.9 and 4.17.4. The affected method, BaseElementSelectConditionRule::getElementIds(), makes use of the unprotected renderObjectTemplate() function, all...
Discovered 22 hours ago
PoC for CVE-2026-107696
FFmpeg versions up to 9.0.2 have a vulnerability in the RTSP redirect handling within the ff_rtsp_connect() function in libavformat/rtsp.c. The flaw allows attackers with control over the RTSP server to send continuous 302 redirects to the same or a different server. This leads to an infinite loo...
PoC for CVE-2026-107695
FFmpeg versions prior to 8.1.3 contain a vulnerability in the HLS demuxer that can be exploited by remote attackers to create a denial of service condition. This occurs when the parse_playlist() function improperly handles Master Playlist tags embedded in Media Playlists. Attackers may deceive us...
Discovered 1 day ago
PoC for CVE-2026-9209
The mJobTime application, specifically build 15.7.3.32, features an unauthenticated SQL execution vulnerability found in the Login.aspx admin panel. This flaw allows attackers to exploit the runQueryButton postback and exportSqlQuery_Server PageMethod, executing arbitrary SQL commands against the...
PoC for CVE-2026-21589
This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerat...
PoC for CVE-2026-105192
The LMCache distributed mode introduces a vulnerability where an unauthenticated ZeroMQ ROUTER allows worker processes to register and share key-value cache blocks. This may lead to code execution as the user running the LMCache process, potentially with elevated privileges if running as root. It...
PoC for CVE-2026-107640
Integrics Enswitch versions 3.13 through 4.4 are affected by an authentication bypass vulnerability that enables unauthenticated attackers to change account passwords. This issue arises from a flaw in the /api/json/user/password/update/ endpoint, allowing attackers to circumvent authentication by...
PoC for CVE-2026-93509
The Wallet System for WooCommerce plugin suffers from an improper input validation flaw that allows authenticated attackers with Subscriber-level access to manipulate wallet transfer amounts. An attacker can exploit this vulnerability by minting wallet funds, as the system fails to ensure that tr...
PoC for CVE-2026-105190
The Easy Digital Downloads plugin for WordPress prior to version 3.7.1 contains a security flaw that permits unauthenticated users to create accounts without properly checking the user registration settings of the site. This issue enables unauthorized account creation and grants the created accou...
PoC for CVE-2026-104671
The TutorStarter WordPress theme prior to version 4.0.4 contains a vulnerability where one of its AJAX registration handlers fails to respect the site's user registration setting. This weakness enables unauthenticated visitors to create user accounts on the WordPress site even when user registrat...
PoC for CVE-2026-103517
The Airwallex Online Payments Gateway plugin for WordPress lacks proper verification of incoming payment notifications when a webhook secret is not configured. This issue enables attackers to forge notifications, potentially leading to unauthorized marking of orders as paid. Website owners using ...
PoC for CVE-2026-105110
An OS Command Injection vulnerability exists in the login.xgi CGI endpoint of Iskratel Innbox GPON ONT devices, allowing unauthorized remote attackers to execute arbitrary commands with root privileges using specific parameters. This security flaw poses a significant risk as it can lead to unauth...
PoC for CVE-2026-94258
The SMS Alert plugin for WordPress has a significant information disclosure flaw found in versions prior to 4.0.1. This vulnerability enables an unauthorized administrator within a multisite network to access and reveal the billing phone numbers of users across different sites. The issue arises f...
PoC for CVE-2026-94246
The Wallet System for WooCommerce plugin for WordPress prior to version 2.8.0 contains an authorization flaw that allows authenticated users, such as subscribers, to make unauthorized withdrawal requests. This issue arises because the plugin fails to confirm that the specified wallet account for ...
PoC for CVE-2026-94275
The Track Orders for WooCommerce plugin prior to version 1.2.7 contains a security flaw that allows unauthorized access to sensitive customer information. This vulnerability permits unauthenticated attackers to view critical personal details of users simply by providing their email addresses. As ...
PoC for CVE-2026-86828
The BackWPup plugin for WordPress prior to version 5.7.7 has a security flaw that fails to adequately restrict the destination path for files extracted during backup restores. This issue arises when the fallback archive library is utilized, allowing high-privileged users to manipulate the backup ...
PoC for CVE-2026-94244
The Wallet System for WooCommerce plugin for WordPress versions prior to 2.8.0 lacks proper capability checks, allowing any authenticated user to access sensitive wallet transaction reports. This oversight can lead to unauthorized disclosure of sensitive user data, including customer names, email...
PoC for CVE-2026-94245
The Wallet System for WooCommerce plugin for WordPress prior to version 2.8.0 contains a security flaw that permits authenticated users to execute wallet transfers without the necessary permissions. Specifically, this vulnerability allows any authenticated individual, including those with minimal...
PoC for CVE-2026-86827
The BackWPup plugin for WordPress, prior to version 5.7.7, is susceptible to a vulnerability that permits unauthenticated attackers to trigger backup jobs on the system. By exploiting this flaw, attackers can initiate any scheduled backup task regardless of its original trigger conditions or timi...
PoC for CVE-2026-105197
The Appointment Booking Plugin for WordPress versions earlier than 5.6.5 contains an authorization flaw that permits an authenticated user with a staff role to delete any order, customer, or transaction record. This happens even if the records belong to different staff members or exceed their des...
PoC for CVE-2026-86826
The BackWPup plugin for WordPress, prior to version 5.7.7, suffers from improper access control, allowing unauthorized users to access the plugin's working directory. This flaw enables unauthenticated attackers to download backup archives containing sensitive information like database dumps, site...
PoC for CVE-2026-105260
A security flaw has been identified in the Database Addon for WPForms plugin. The vulnerability arises from the lack of proper CSRF nonce verification and insufficient capability checks. As a result, attackers can potentially exploit this weakness to delete arbitrary stored form entries. This is ...
PoC for CVE-2026-105198
The Appointment Booking Plugin for WordPress prior to version 5.7.3 contains an improper authentication vulnerability. This flaw allows unauthenticated users to access sensitive customer information such as names, contact details, and order confirmation codes by manipulating the order-item identi...