Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 2 hours ago
PoC for CVE-2026-78250
A vulnerability exists in Bytebot AI's Bytebot 0.0.1, specifically within the Agent Execution Workflow component. This issue allows an attacker to execute a remote exploit that induces an infinite loop, causing server unresponsiveness. The vulnerability primarily affects versions that are no long...
PoC for CVE-2026-78248
A SQL injection vulnerability exists in the SourceCodester Simple Online Food Ordering System version 1.0 within the file /fos/admin/ajax.php when the 'Name' argument is manipulated. This flaw allows remote attackers to execute arbitrary SQL commands, potentially compromising the integrity and se...
PoC for CVE-2026-78247
A security vulnerability has been identified in the Simple Online Food Ordering System version 1.0 by SourceCodester. This flaw is located in the /fos/admin/ajax.php file, specifically in the confirm_order action. By manipulating the ID parameter, an attacker can execute SQL injection, potentiall...
Discovered 3 hours ago
PoC for CVE-2026-78246
A SQL injection vulnerability has been identified in version 1.0 of the itsourcecode Online Clinic Management System, specifically within the Admin Login feature's login.php file. By manipulating the Username parameter, an attacker could exploit this flaw to execute arbitrary SQL commands remotel...
Discovered 4 hours ago
PoC for CVE-2026-78245
A vulnerability exists in itsourcecode Online Pharmacy System 1.0 due to an improper handling of file uploads in the User Registration component. Specifically, the flaw lies within the 'move_uploaded_file' function in 'all_users/register.php', where manipulation of the 'photo' argument enables un...
PoC for CVE-2026-78244
A SQL injection vulnerability exists in the search.php file of the itsourcecode Real Estate Management System 1.0. This flaw allows attackers to manipulate parameters such as search/delivery_type/search_price/property_type, potentially leading to unauthorized access to the database. The exploit c...
Discovered 9 hours ago
PoC for CVE-2026-78202
A significant vulnerability has been discovered in the itsourcecode Payroll System 1.0, specifically within the save_settings function of the admin_class.php file. This weakness allows attackers to manipulate the 'img' argument, which results in an unrestricted upload capability. The vulnerabilit...
PoC for CVE-2026-78201
A SQL injection vulnerability exists in the login function of the admin_class.php file within itsourcecode Payroll System 1.0, allowing attackers to manipulate the Username argument. This manipulation can be executed remotely, posing significant risks to data integrity and system security. The vu...
PoC for CVE-2026-78200
A significant security flaw exists in the itsourcecode Library Management System version 1.0, specifically within an unidentified function in the editbooks.php file. This issue allows an attacker to manipulate the argument ID for SQL injection attacks, which can be executed remotely. Given the ex...
PoC for CVE-2026-78199
A significant SQL injection vulnerability has been identified in the SourceCodester Simple Online Food Ordering System, specifically affecting the view_prod.php file. This vulnerability occurs due to improper handling of the ID argument, allowing attackers to manipulate SQL queries and potentiall...
Discovered 10 hours ago
PoC for CVE-2026-78198
A security vulnerability has been identified in the Simple Online Food Ordering System developed by SourceCodester, specifically relating to the processing of the file /fos/admin/ajax.php with the action parameter set to add_to_cart. Unsanitized input for the 'pid' argument can lead to SQL inject...
PoC for CVE-2026-78197
A SQL injection vulnerability exists in the SourceCodester Simple Online Food Ordering System found in the /fos/admin/ajax.php file's save_user action. By manipulating the Username parameter, an attacker can execute arbitrary SQL queries on the database. This vulnerability can be exploited remote...
PoC for CVE-2026-78187
A vulnerability has been identified in Piwigo 16.3.0 that affects the Public Authentication Page component, allowing attackers to exploit an unknown function via manipulation of the lang parameter. This can lead to cross site scripting (XSS), where malicious scripts can be executed in the user's ...
Discovered 11 hours ago
PoC for CVE-2026-78186
A vulnerability has been identified in Open5GS within the HSS component, specifically in the src/hss/hss-cx-path.c file. This issue allows for a manipulation of the User-Name argument, leading to a reachable assertion that can be exploited remotely. The vulnerability could allow attackers to exec...
PoC for CVE-2026-78185
An SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0 due to improper handling of input in the /pages/cust_edit.php file. By manipulating the ID argument, an attacker can execute remote commands, potentially leading to unauthorized access to the database...
PoC for CVE-2026-78182
A security flaw has been discovered in the function PlanController.getImmediatePlans of the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System, specifically affecting versions up to 300R004C00B300. This vulnerability allows an attacker to manipulate the order and sort of ar...
PoC for CVE-2026-78181
A vulnerability exists in Ractive.js, affecting version 1.4.4 and earlier, specifically in the Keypath Handler's Ractive#set function. This weakness allows attackers to manipulate object prototype attributes, potentially leading to unauthorized modifications. The vulnerability can be exploited re...
Discovered 12 hours ago
PoC for CVE-2020-5504
In versions prior to 4.9.4 for phpMyAdmin 4 and 5.0.1 for phpMyAdmin 5, an SQL injection vulnerability exists on the user accounts page. This flaw allows an attacker with a valid MySQL account to inject malicious SQL statements by altering their username input when querying the user accounts. Suc...
PoC for CVE-2026-78177
A vulnerability exists in TanStack's devtools-vite, specifically in version 0.7.0, where the 'installPackage' function of the Development Devtools Event Bus component is susceptible to OS command injection. This occurs through improper handling of the 'packageName' argument, allowing an attacker ...
Discovered 13 hours ago
PoC for CVE-2026-78171
A vulnerability exists in the itsourcecode Sales and Inventory System 1.0, specifically within the file /pages/processlogin.php. This security issue allows for SQL injection through manipulation of the 'User' argument, enabling a remote attacker to exploit the system. As the exploit has been publ...
PoC for CVE-2026-78170
A significant vulnerability has been identified in the UTT HiPER 1200GW router, specifically within the strcpy function in the /goform/formConfigFastDirectionW file. The flaw allows an attacker to execute arbitrary manipulation of the 'ssid' argument, potentially leading to a buffer overflow cond...
PoC for CVE-2026-78169
A vulnerability exists in the UTT HiPER 1250GW that affects its HTTP Request Handler, specifically in the function 'strcpy' utilized within the file '/goform/aspRemoteApConfTempSend'. An attacker can exploit a manipulation of the 'Profile' argument leading to a stack-based buffer overflow. This v...
PoC for CVE-2026-78168
A vulnerability in the EFM ipTIME T24000M model compromises the function responsible for checking session URLs, leading to improper authentication. This flaw can be exploited remotely, posing a significant risk as it allows potential attackers to manipulate the authentication process without prop...
Discovered 14 hours ago
PoC for CVE-2026-78167
A significant weakness has been identified in the EFM ipTIME T16000M router due to a flaw in the session validation handler, specifically in the function httpcon_check_session_url. This vulnerability allows attackers to exploit the device remotely, leading to improper authentication and potential...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-15718
A security flaw in Mozilla Firefox allows for potential remote code execution exploits. Although the exploit code for this vulnerability is publicly available, there have been no confirmed instances of its exploitation in the wild. Users are advised to upgrade to Firefox version 152.0.6 or later ...
PoC for CVE-2026-78166
A security flaw exists in the Apache Kafka user interface provided by Provectus, specifically in the executeSmartFilterTest function within the Groovy Code Handler. This vulnerability permits an attacker to inject malicious code remotely, leading to potential unauthorized access and manipulation ...
PoC for CVE-2026-78161
A vulnerability exists in warmcat libwebsockets 4.5.0 within the report_raw_cbor function located in lib/misc/lecp.c, leading to the possibility of an out-of-bounds write. This issue allows for remote exploitation, which could potentially compromise the integrity and security of systems using thi...
PoC for CVE-2026-78161
A vulnerability exists in warmcat libwebsockets 4.5.0 within the report_raw_cbor function located in lib/misc/lecp.c, leading to the possibility of an out-of-bounds write. This issue allows for remote exploitation, which could potentially compromise the integrity and security of systems using thi...
PoC for CVE-2026-10053
GitLab has addressed a critical path traversal vulnerability present in GitLab CE/EE across multiple versions. Under certain conditions, this flaw could enable an authenticated user to execute arbitrary code remotely via the package registry. This vulnerability highlights the importance of timely...
Discovered 15 hours ago
PoC for CVE-2026-66917
The JoomGallery extension for Joomla is susceptible to a stored cross-site scripting (XSS) vulnerability. This flaw allows authenticated users with the appropriate privileges to embed malicious JavaScript into uploaded images. When other users visit the affected page, the injected script executes...
PoC for CVE-2026-66916
An unauthenticated access control bypass vulnerability exists in the JoomGallery extension for Joomla. When a gallery category is secured with a password, the standard HTML view successfully enforces this password requirement. However, the JSON view does not enforce the same checking protocols, a...
Discovered 16 hours ago
PoC for CVE-2026-78145
A security flaw has been identified in CTFd versions up to 3.8.4, specifically within the _is_safe_url function located in CTFd/utils/validators/__init__.py. This vulnerability allows an attacker to manipulate the 'Next' parameter, leading to an open redirect issue. Exploitation can be performed ...
PoC for CVE-2026-78144
An authorization bypass vulnerability exists in the Barangay Resident Profiling Management System 1.0, specifically within the boarders.php file of the Boarder Management Module. This flaw allows attackers to manipulate the argument ID, leading to unauthorized actions. The vulnerability can be ex...
Discovered 17 hours ago
PoC for CVE-2026-78143
A security vulnerability exists within the Barangay Resident Profiling Management System 1.0, specifically in the residents.php file associated with its Resident Search functionality. This flaw enables attackers to manipulate search arguments, leading to potential SQL injection attacks. Such expl...
PoC for CVE-2026-78142
A vulnerability exists in the Barangay Resident Profiling Management System, specifically affecting the Restore/Delete component located in the archived_records.php file. This issue arises due to improper handling of the resident_id parameter, allowing for an authorization bypass. The flaw can be...
PoC for CVE-2026-78141
A command injection vulnerability exists in the Tenda CH22 router version 1.0.0.1 within the formexeCommand function found in the /goform/exeCommand file. This vulnerability allows attackers to manipulate input arguments, specifically 'cmdinput', potentially enabling them to execute arbitrary com...
Discovered 19 hours ago
PoC for CVE-2024-9264
The experimental SQL Expressions feature in Grafana enables users to evaluate `duckdb` queries which can contain user input. However, the queries are inadequately sanitized prior to being processed by `duckdb`, creating a vulnerability that could lead to command injection and local file inclusion...
PoC for CVE-2026-78140
A vulnerability exists in Dromara UJCMS versions up to 10.1.3, specifically in the update function of the WebFileTemplateController.java file. The flaw enables a server-side template injection, allowing attackers to manipulate special elements within the template engine. This vulnerability can be...
Discovered 1 day ago
PoC for CVE-2026-78115
A security issue has been identified in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the User Account Update functionality located in /admin/edit_user_account.php. This vulnerability allows attackers to manipulate the 'id' or 'username' parameters, leading...
PoC for CVE-2026-78112
A vulnerability has been identified in the itsourcecode Hospital Management System Project in PHP version 1.0, specifically within the /viewservicetype.php file. This weakness allows for SQL injection attacks through the manipulation of the 'delid' argument, potentially exposing sensitive data an...
PoC for CVE-2026-77003
The Content Mask plugin for WordPress prior to version 1.8.5.5 contains a vulnerability that fails to validate user permissions when creating post types. This oversight permits users with minimal roles, such as Contributor, to publish posts and pages without possessing the required publish capabi...
PoC for CVE-2026-77116
The Brave Popup Builder plugin suffers from a broken access control vulnerability that affects versions up to 0.8.5. This flaw allows any logged-in user, including those with Subscriber or WooCommerce Customer roles, to access popup content by manipulating the post ID in the URL. Such unauthorize...
PoC for CVE-2026-77115
The Brave Popup Builder plugin allows for the reflection of UTM query parameters into the popup form HTML without proper escaping. This vulnerability can be exploited by attackers to execute malicious scripts in the context of the user's browser, potentially leading to unauthorized actions or dat...
PoC for CVE-2026-13598
The RestrictMate plugin for WordPress prior to version 1.3.0 contains a flaw that fails to properly restrict the user role during the account registration process. This oversight permits unauthenticated attackers to create a new account with administrative privileges, enabling them to gain unauth...
PoC for CVE-2026-14853
The WooCommerce Bookings plugin for WordPress prior to version 3.9.0 contains an improper access control vulnerability. It lacks adequate checks on an AJAX action, enabling users with Subscriber-level roles or higher to create draft bookable products by bypassing the nonce verification process. T...
PoC for CVE-2026-75616
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when handling specific WAN-related configuration operations. An authenticated administrator can exploit this issue due to inadequate input validation, enabling them to execute arbitrary system c...
PoC for CVE-2026-47630
The NVIDIA Triton Inference Server for Linux has a vulnerability that allows an attacker to exploit an absolute path traversal. By successfully executing this exploit, an attacker could potentially execute arbitrary code, compromising the integrity and security of the system. It highlights the im...
PoC for CVE-2026-78063
A command injection vulnerability exists in the Tenda CH22 router, specifically in the formeditFileName function located in the /goform/editFileName file. This flaw allows an attacker to manipulate the editNameMit argument, enabling the execution of arbitrary commands remotely. The exploit has be...
PoC for CVE-2026-78060
A significant cross-site scripting vulnerability has been detected in the SourceCodester Stock Management System, specifically affecting the file /php_action/getOrderReport.php. This flaw allows attackers to manipulate the parameters clientName and clientContact to inject malicious scripts. The v...