Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 5 hours ago

PoC for CVE-2026-11318

Zuler TechnologyDeskin8.5HIGH
Privilege Escalation in Deskin Service on macOS by Unauthenticated ...

Deskin versions up to 3.3.4.3 have a significant vulnerability in the com.deskin.service.installer XPC service. This flaw allows local unprivileged attackers to connect to the root-owned service without authentication, enabling them to execute arbitrary installer packages as the root user. By exp...

Discovered 6 hours ago

PoC for CVE-2026-107707

IntegoIntego Antivirus8.5HIGH
Local Privilege Escalation Vulnerability in Intego Antivirus for Wi...

Intego Antivirus for Windows versions through 3.0.0.1 contains a vulnerability in its optimization module that permits local unprivileged users to delete arbitrary folders as the SYSTEM account. Exploitation occurs when an attacker alters the directory of a scanned duplicate file, leveraging a ju...

Discovered 8 hours ago

PoC for CVE-2026-5430

Wso2Wso2 Universal Gateway10CRITICAL
JWT Authentication Vulnerability in WSO2 Products

The vulnerability in WSO2 products relates to the JWT authentication mechanism, which improperly validates tokens signed with algorithms not explicitly configured or supported. This flaw enables an attacker to create a JSON Web Token (JWT) using an unsupported signing algorithm. If an attacker su...

PoC for CVE-2025-9974

NokiaNokia Ont8HIGH
Input Handling Flaw in ONT/Beacon Device from Nokia

The ONT/Beacon device by Nokia features a critical input handling flaw in its unified WEBUI application. This vulnerability allows low-privileged authenticated users to exploit insufficient validation of user-supplied data, enabling them to execute arbitrary commands on the device's operating sys...

PoC for CVE-2026-18963

Red HatRed Hat Build Of Keycl...9.1CRITICAL
Authorization Flaw in Keycloak Services by Red Hat

A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...

PoC for CVE-2026-31857

CraftcmsCms8.1HIGH
Remote Code Execution in Craft CMS from Craft

Craft CMS has a remote code execution vulnerability due to improper handling of user-controlled input in the conditions system prior to version 5.9.9 and 4.17.4. The affected method, BaseElementSelectConditionRule::getElementIds(), makes use of the unprotected renderObjectTemplate() function, all...

Discovered 9 hours ago

PoC for CVE-2026-107696

FfmpegFfmpeg7.1HIGH
Infinite Loop Vulnerability in FFmpeg's RTSP Redirect Handling

FFmpeg versions up to 9.0.2 have a vulnerability in the RTSP redirect handling within the ff_rtsp_connect() function in libavformat/rtsp.c. The flaw allows attackers with control over the RTSP server to send continuous 302 redirects to the same or a different server. This leads to an infinite loo...

PoC for CVE-2026-107695

FfmpegFfmpeg7.1HIGH
Infinite Loop Vulnerability in FFmpeg HLS Demuxer

FFmpeg versions prior to 8.1.3 contain a vulnerability in the HLS demuxer that can be exploited by remote attackers to create a denial of service condition. This occurs when the parse_playlist() function improperly handles Master Playlist tags embedded in Media Playlists. Attackers may deceive us...

Discovered 11 hours ago

PoC for CVE-2026-9209

MjobMjobtime9.3CRITICAL
Unauthenticated SQL Execution in mJobTime Admin Panel

The mJobTime application, specifically build 15.7.3.32, features an unauthenticated SQL execution vulnerability found in the Login.aspx admin panel. This flaw allows attackers to exploit the runQueryButton postback and exportSqlQuery_Server PageMethod, executing arbitrary SQL commands against the...

PoC for CVE-2026-21589

AtlassianBamboo Data Center9.3CRITICAL
Arbitrary File Access Vulnerability in Atlassian Products

This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerat...

Discovered 12 hours ago

PoC for CVE-2026-105192

LmcacheLmcache9.8CRITICAL
Unauthorized Code Execution in LMCache Distributed Mode by LMCache

The LMCache distributed mode introduces a vulnerability where an unauthenticated ZeroMQ ROUTER allows worker processes to register and share key-value cache blocks. This may lead to code execution as the user running the LMCache process, potentially with elevated privileges if running as root. It...

PoC for CVE-2026-107640

IntegricsEnswitch9.3CRITICAL
Authentication Bypass in Integrics Enswitch API

Integrics Enswitch versions 3.13 through 4.4 are affected by an authentication bypass vulnerability that enables unauthenticated attackers to change account passwords. This issue arises from a flaw in the /api/json/user/password/update/ endpoint, allowing attackers to circumvent authentication by...

Discovered 16 hours ago

PoC for CVE-2026-93509

WordPressWallet System For WooC...6.5MEDIUM
Improper Input Validation in Wallet System for WooCommerce Plugin

The Wallet System for WooCommerce plugin suffers from an improper input validation flaw that allows authenticated attackers with Subscriber-level access to manipulate wallet transfer amounts. An attacker can exploit this vulnerability by minting wallet funds, as the system fails to ensure that tr...

PoC for CVE-2026-104671

WordPressTutorstarter5.3MEDIUM
User Registration Bypass in TutorStarter WordPress Theme by TutorStar

The TutorStarter WordPress theme prior to version 4.0.4 contains a vulnerability where one of its AJAX registration handlers fails to respect the site's user registration setting. This weakness enables unauthenticated visitors to create user accounts on the WordPress site even when user registrat...

PoC for CVE-2026-105190

WordPressEasy Digital Downloads5.3MEDIUM
User Account Creation Vulnerability in Easy Digital Downloads WordP...

The Easy Digital Downloads plugin for WordPress prior to version 3.7.1 contains a security flaw that permits unauthenticated users to create accounts without properly checking the user registration settings of the site. This issue enables unauthorized account creation and grants the created accou...

PoC for CVE-2026-103517

WordPressAirwallex Online Payme...5.3MEDIUM
Vulnerability in Airwallex Online Payments Gateway Plugin for WordP...

The Airwallex Online Payments Gateway plugin for WordPress lacks proper verification of incoming payment notifications when a webhook secret is not configured. This issue enables attackers to forge notifications, potentially leading to unauthorized marking of orders as paid. Website owners using ...

Discovered 17 hours ago

PoC for CVE-2026-105110

IskratelInnbox9.3CRITICAL
OS Command Injection Vulnerability in Iskratel Innbox GPON ONT Devices

An OS Command Injection vulnerability exists in the login.xgi CGI endpoint of Iskratel Innbox GPON ONT devices, allowing unauthorized remote attackers to execute arbitrary commands with root privileges using specific parameters. This security flaw poses a significant risk as it can lead to unauth...

Discovered 20 hours ago

PoC for CVE-2026-94258

WordPressSms Alert2.7LOW
Information Disclosure Vulnerability in SMS Alert WordPress Plugin

The SMS Alert plugin for WordPress has a significant information disclosure flaw found in versions prior to 4.0.1. This vulnerability enables an unauthorized administrator within a multisite network to access and reveal the billing phone numbers of users across different sites. The issue arises f...

PoC for CVE-2026-94275

WordPressTrack Orders For WooCo...5.3MEDIUM
Authorization Bypass in Track Orders Plugin Exposes Customer Inform...

The Track Orders for WooCommerce plugin prior to version 1.2.7 contains a security flaw that allows unauthorized access to sensitive customer information. This vulnerability permits unauthenticated attackers to view critical personal details of users simply by providing their email addresses. As ...

PoC for CVE-2026-94246

WordPressWallet System For WooC...6.3MEDIUM
Authorization Flaw in Wallet System for WooCommerce by WordPress

The Wallet System for WooCommerce plugin for WordPress prior to version 2.8.0 contains an authorization flaw that allows authenticated users, such as subscribers, to make unauthorized withdrawal requests. This issue arises because the plugin fails to confirm that the specified wallet account for ...

PoC for CVE-2026-94245

WordPressWallet System For WooC...6.5MEDIUM
Improper Wallet Transfer Authorization in WooCommerce Plugin by Wor...

The Wallet System for WooCommerce plugin for WordPress prior to version 2.8.0 contains a security flaw that permits authenticated users to execute wallet transfers without the necessary permissions. Specifically, this vulnerability allows any authenticated individual, including those with minimal...

PoC for CVE-2026-86827

WordPressBackWPup5.3MEDIUM
Unauthenticated Backup Trigger Vulnerability in BackWPup WordPress ...

The BackWPup plugin for WordPress, prior to version 5.7.7, is susceptible to a vulnerability that permits unauthenticated attackers to trigger backup jobs on the system. By exploiting this flaw, attackers can initiate any scheduled backup task regardless of its original trigger conditions or timi...

PoC for CVE-2026-94244

WordPressWallet System For WooC...4.3MEDIUM
Vulnerability in Wallet System for WooCommerce Plugin Exposes User ...

The Wallet System for WooCommerce plugin for WordPress versions prior to 2.8.0 lacks proper capability checks, allowing any authenticated user to access sensitive wallet transaction reports. This oversight can lead to unauthorized disclosure of sensitive user data, including customer names, email...

PoC for CVE-2026-86828

WordPressBackWPup6.6MEDIUM
File Extraction Vulnerability in BackWPup Plugin by WordPress

The BackWPup plugin for WordPress prior to version 5.7.7 has a security flaw that fails to adequately restrict the destination path for files extracted during backup restores. This issue arises when the fallback archive library is utilized, allowing high-privileged users to manipulate the backup ...

PoC for CVE-2026-105197

WordPressAppointment Booking Pl...2.7LOW
Authorization Flaw in Appointment Booking Plugin for WordPress

The Appointment Booking Plugin for WordPress versions earlier than 5.6.5 contains an authorization flaw that permits an authenticated user with a staff role to delete any order, customer, or transaction record. This happens even if the records belong to different staff members or exceed their des...

PoC for CVE-2026-86826

WordPressBackWPup5.9MEDIUM
File Download Exposure in BackWPup Plugin for WordPress

The BackWPup plugin for WordPress, prior to version 5.7.7, suffers from improper access control, allowing unauthorized users to access the plugin's working directory. This flaw enables unauthenticated attackers to download backup archives containing sensitive information like database dumps, site...

PoC for CVE-2026-105196

WordPressAppointment Booking Pl...3.3LOW
AI Abilities API Flaw in Appointment Booking Plugin for WordPress

The Appointment Booking Plugin for WordPress, prior to version 5.6.9, contains an authorization vulnerability associated with the AI Abilities API. This flaw permits authenticated users with the LatePoint Agent role to bypass restrictions, allowing them to access, read, and even modify other agen...

PoC for CVE-2026-105198

WordPressAppointment Booking Pl...5.3MEDIUM
Unauthorized Access Vulnerability in Appointment Booking Plugin for...

The Appointment Booking Plugin for WordPress prior to version 5.7.3 contains an improper authentication vulnerability. This flaw allows unauthenticated users to access sensitive customer information such as names, contact details, and order confirmation codes by manipulating the order-item identi...

PoC for CVE-2026-105260

WordPressDatabase Addon For WPf...4.3MEDIUM
CSRF Vulnerability in Database Addon for WPForms by WordPress

A security flaw has been identified in the Database Addon for WPForms plugin. The vulnerability arises from the lack of proper CSRF nonce verification and insufficient capability checks. As a result, attackers can potentially exploit this weakness to delete arbitrary stored form entries. This is ...

PoC for CVE-2026-105195

WordPressBooking Calendar2.7LOW
Insufficient Access Control in Booking Calendar Plugin by WordPress

The Booking Calendar plugin for WordPress, prior to version 11.8.3, features inadequate restrictions allowing users with Editor roles and higher to access and disclose values of arbitrary WordPress options. This vulnerability can potentially expose sensitive configuration details of the WordPress...

PoC for CVE-2026-105194

WordPressEasy Digital Downloads4.3MEDIUM
Access Control Issues in Easy Digital Downloads Plugin for WordPress

The Easy Digital Downloads plugin for WordPress prior to version 3.7.1 is vulnerable due to inadequate restrictions on order data visibility. This flaw allows users with only subscriber-level access to view details of other customers' recent orders, including signed download links that provide un...

PoC for CVE-2026-105193

WordPressBooking Calendar4.8MEDIUM
Predictable Hash Vulnerability in Booking Calendar Plugin for WordP...

The Booking Calendar plugin for WordPress prior to version 11.8 is susceptible to a vulnerability that compromises the integrity of access hashes. This flaw arises from the generation of hashes that lack sufficient entropy, as they are based on low-entropy time-seeded values. An unauthenticated a...

PoC for CVE-2026-104645

WordPressImage Photo Gallery Fi...2.7LOW
Authorization Bypass in Image Photo Gallery Plugin by WordPress

The Image Photo Gallery Final Tiles Grid plugin prior to version 3.6.14 is susceptible to an authorization bypass vulnerability. This security flaw arises from improper verification of user permissions in multiple gallery and image management operations. The plugin erroneously checks ownership ag...

PoC for CVE-2026-103646

WordPressUltimate Multisite9.8CRITICAL
Authentication Bypass in Ultimate Multisite Plugin for WordPress by...

The Ultimate Multisite Plugin for WordPress, prior to version 2.17.0, contains a significant vulnerability that allows unauthenticated attackers to log into existing user accounts, including those of Network Super Admins. This exploit occurs when a checkout form is utilized without a password fie...

PoC for CVE-2026-103692

WordPressFrontend Dashboard9.8CRITICAL
Unauthorized Access Vulnerability in Frontend Dashboard Plugin for ...

The Frontend Dashboard WordPress plugin prior to version 3.0.5 lacks proper authorization checks, allowing unauthenticated users to invoke arbitrary PHP functions or class methods. This vulnerability poses a significant risk as it enables attackers to perform actions that could lead to the takeov...

PoC for CVE-2026-104646

WordPressImage Photo Gallery Fi...6.8MEDIUM
JavaScript Injection Vulnerability in Image Photo Gallery Final Til...

The Image Photo Gallery Final Tiles Grid plugin for WordPress prior to version 3.6.14 is susceptible to a JavaScript injection flaw. This vulnerability arises from inadequate sanitization of gallery configuration values that can be manipulated via the gallery shortcode. Users with contributor-lev...

PoC for CVE-2026-103309

WordPressGptranslate7.5HIGH
Stored Cross-Site Scripting Vulnerability in GPTranslate WordPress ...

The GPTranslate plugin for WordPress, prior to version 2.34.14, is susceptible to stored cross-site scripting attacks. This vulnerability arises from the plugin's failure to adequately restrict who can save translations. Furthermore, it does not correctly escape translations when rendering them o...

Discovered 21 hours ago

PoC for CVE-2026-97332

WordPressUser Private Files5.3MEDIUM
Insufficient File Protection in User Private Files Plugin for WordP...

The User Private Files plugin for WordPress, prior to version 2.2.0, suffers from an access control issue on multisite installations. The plugin fails to enforce access restrictions on private files, as the essential rewrite rule for routing file requests and conducting access checks is not execu...

PoC for CVE-2026-107450

StumpappStump5.4MEDIUM
Access Control Vulnerability in Stump API Affects Smart List Manage...

In Stump API versions up to 0.1.10, a flaw exists in the GraphQL mutations for updating and deleting smart lists. These mutations rely solely on the shared AccessSmartList permission, neglecting to verify the creator's identity of the smart list. This oversight allows any authenticated user with ...

Discovered 22 hours ago

PoC for CVE-2026-107449

LinuxserverHeimdall3.4LOW
SSRF Vulnerability in Heimdall by LinuxServer

The Heimdall application from LinuxServer is vulnerable to Server-Side Request Forgery (SSRF) due to its insufficient protection mechanisms. While the SafeUrlFetcher is intended to mitigate SSRF risks, it is only applied to the ItemController. Other endpoints, like POST /test_config and GET /get_...

Discovered 23 hours ago

PoC for CVE-2026-102253

EsnetIperf38.7HIGH
Denial of Service Vulnerability in iperf3 Affects ESnet

iperf3, in versions earlier than 3.22, is susceptible to a denial of service vulnerability that allows remote, unauthenticated attackers to disrupt server functionality. By sending a specifically crafted control-channel parameter message followed by a single 16-byte UDP datagram, attackers can fo...

Discovered 1 day ago

PoC for CVE-2026-96451

WordPressUltimate Member8.8HIGH
Authorization Bypass Vulnerability in Ultimate Member Plugin by Ult...

A vulnerability exists in the Ultimate Member plugin which allows attackers to bypass authorization controls via user-controlled keys. This flaw can lead to privilege escalation, enabling unauthorized access to user accounts and sensitive information. The affected versions range from n/a to 2.13....

PoC for CVE-2026-63030

WordPressWordPress🟣 EPSS 11%9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2024-7971

GoogleChrome🟣 EPSS 21%9.6CRITICAL
Heap Corruption Vulnerability in Chrome Prior to 128.0.6613.84

A type confusion vulnerability resides in the V8 engine of Google Chrome, making it possible for remote attackers to execute a malicious payload that could lead to heap corruption. By exploiting this vulnerability, an attacker can craft a specific HTML page that, when interacted with by a user, m...

PoC for CVE-2019-2215

GoogleAndroid🟣 EPSS 72%7.8HIGH
Use-After-Free Vulnerability in Android Binder Leading to Elevation...

A use-after-free vulnerability exists in the Android Binder service, which could allow attackers to elevate privileges from an application to the Linux Kernel. Exploitation of this vulnerability does not require any interaction from the user; however, it necessitates either the installation of a ...

PoC for CVE-2026-43284

LinuxLinux8.8HIGH
Vulnerability in Linux Kernel Affects Shared skb Fragments

A vulnerability exists in the Linux kernel that concerns the handling of shared skb fragments during the decryption process in ESP-in-UDP packets. When pages are attached from a pipe directly to an skb using MSG_SPLICE_PAGES, the kernel marked these SKBs with SKBFL_SHARED_FRAG, which plays a cruc...

PoC for CVE-2026-13043

WatchguardEndpoint Security9.3CRITICAL
Missing Authentication Vulnerability in WatchGuard Endpoint Securit...

A missing authentication flaw in the Kernel Memory Access Driver (PSKMAD) employed by WatchGuard endpoint security products enables local, authenticated attackers to circumvent the driver's access-control mechanisms. This can lead to the execution of unauthorized privileged commands, ultimately a...

PoC for CVE-2026-93355

BerriaiLitellm7.6HIGH
Weak Authentication Vulnerability in LiteLLM by OXsecurity

LiteLLM is impacted by a vulnerability that permits attackers to utilize a valid JSON Web Token (JWT) from a designated identity provider to impersonate any existing user. The flaw arises from an email-based fallback lookup process in the authentication flow which bypasses verification of the ema...

PoC for CVE-2026-107166

Open5GSOpen5gs6.9MEDIUM
GTP-U Receive Path Vulnerability in Open5GS by Open5GS

A vulnerability has been reported in Open5GS versions up to 2.7.7 in the GTP-U Receive Path function ogs_pfcp_xact_local_create, which allows remote attackers to manipulate resource allocations. This issue can potentially be exploited without authentication, making it critical to address. Users a...

PoC for CVE-2026-107273

GophishGophish5.3MEDIUM
Server-Side Request Forgery in Gophish by Gophish Team

Gophish versions 0.11.0 to 0.12.1 are prone to a server-side request forgery vulnerability that can be exploited by authenticated low-privileged users. Through the endpoint POST /api/import/site, attackers are able to submit internal URLs that are not blocked by the default dialer deny list. This...