Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-2576

WordPressBusiness Directory Plu...7.5HIGH
SQL Injection Vulnerability in Business Directory Plugin for WordPress

The Business Directory Plugin for WordPress is prone to a time-based SQL Injection vulnerability through the 'payment' parameter. This flaw arises from inadequate escaping of user-supplied input and insufficient preparation of the SQL query. It permits attackers without authentication to inject a...

Discovered 51 minutes ago

PoC for CVE-2025-34037

LinksysE4200🟣 EPSS 82%10CRITICAL
OS Command Injection Vulnerability in E-Series Linksys Routers

An OS command injection vulnerability is present in various E-Series Linksys routers, specifically through the /tmUnblock.cgi and /hndUnblock.cgi endpoints accessed over HTTP on port 8080. This security flaw arises from the failure to properly sanitize user-supplied input sent to the ttcp_ip para...

Discovered 1 hour ago

PoC for CVE-2025-34282

Thingsboard, Inc.Thingsboard6.9MEDIUM
Server-Side Request Forgery Vulnerability in ThingsBoard Product by...

ThingsBoard versions prior to 4.2.1 are susceptible to a server-side request forgery (SSRF) vulnerability within the Image Upload Gallery feature. This security issue arises when an attacker uploads a malicious SVG file that contains references to remote URLs. If the server processes these SVG fi...

Discovered 2 hours ago

PoC for CVE-2025-4615

Palo Alto NetworksCloud Ngfw7HIGH
Improper Input Neutralization in Palo Alto Networks PAN-OS Manageme...

A vulnerability exists in the management web interface of Palo Alto Networks PAN-OS software that allows an authenticated administrator to bypass crucial system restrictions and execute arbitrary commands. While this issue can lead to unauthorized actions, the security implications are notably re...

Discovered 5 hours ago

PoC for CVE-2026-4910

Shenzhen Ruiming ...Streamax Crocus6.9MEDIUM
SQL Injection Vulnerability in Shenzhen Ruiming Technology Streamax...

A security vulnerability has been identified in the Streamax Crocus product by Shenzhen Ruiming Technology, specifically within the /RemoteFormat.do file of the Endpoint component. This vulnerability arises from improper manipulation of an argument within the function, enabling an attacker to exe...

PoC for CVE-2026-4909

Code-projectsExam Form Submission4.8MEDIUM
Cross Site Scripting Vulnerability in Exam Form Submission by Code-...

A security weakness has been identified in the Exam Form Submission software, specifically within the file /admin/update_s7.php. The vulnerability arises due to improper handling of user inputs, allowing an attacker to manipulate the 'sname' argument. This exploitation can lead to cross site scri...

PoC for CVE-2026-4908

Code-projectsSimple Laundry System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Simple Laundry System ...

A security flaw has been identified in the Simple Laundry System version 1.0, specifically affecting the modstaffinfo.php file in the Parameter Handler component. This vulnerability allows for SQL injection through improper handling of the userid argument, enabling attackers to manipulate databas...

Discovered 6 hours ago

PoC for CVE-2026-4907

Page-replicaPage Replica5.3MEDIUM
Server-Side Request Forgery Vulnerability in Page Replica by Page-R...

A server-side request forgery (SSRF) vulnerability has been discovered in Page Replica, specifically within the sitemap.fetch function of the Endpoint component. This flaw can be exploited by manipulating the argument 'url', allowing attackers to send requests from the server to unintended locati...

Discovered 7 hours ago

PoC for CVE-2026-4906

TendaAc58.7HIGH
Stack-based Buffer Overflow in Tenda AC5 Routers

A stack-based buffer overflow vulnerability exists within the Tenda AC5 router, specifically in the 'decodePwd' function of the '/goform/WizardHandle' component. This security flaw allows attackers to manipulate the 'WANT/WANS' argument via a crafted POST request, potentially enabling remote code...

Discovered 9 hours ago

PoC for CVE-2026-4905

TendaAc58.7HIGH
Buffer Overflow Vulnerability in Tenda AC5 Router

A critical security flaw exists in the Tenda AC5 router due to a stack-based buffer overflow in the 'formWifiWpsOOB' function. This vulnerability is triggered by manipulating specific arguments in the POST Request Handler. If exploited, attackers could execute arbitrary code remotely. As the deta...

PoC for CVE-2026-4904

TendaAc58.7HIGH
Stack-Based Buffer Overflow in Tenda AC5 Router

A vulnerability has been identified in the Tenda AC5 router affecting the function formSetCfm found in the POST Request Handler component. This flaw allows for manipulation of the argument funcpara1, potentially leading to a stack-based buffer overflow. The issue can be exploited remotely, posing...

PoC for CVE-2026-4903

TendaAc58.7HIGH
Buffer Overflow Vulnerability in Tenda AC5 Router

A vulnerability in the Tenda AC5 router, specifically in version 15.03.06.47, allows for a stack-based buffer overflow via the formQuickIndex function of the /goform/QuickIndex component. This issue arises from improper handling of the PPPOEPassword argument in POST requests, which can be exploit...

PoC for CVE-2026-4902

TendaAc58.7HIGH
Stack-Based Buffer Overflow in Tenda AC5 Router

A vulnerability exists in Tenda's AC5 router that allows for a stack-based buffer overflow through improper handling of a POST request in the addressNat component. This flaw occurs when the argument 'page' is manipulated by an attacker, potentially leading to unauthorized remote access and system...

Discovered 10 hours ago

PoC for CVE-2026-4900

Code-projectsOnline Food Ordering S...6.9MEDIUM
Privilege Escalation in code-projects Online Food Ordering System b...

A vulnerability has been detected in the Online Food Ordering System 1.0 developed by code-projects. The issue resides in the file /dbfood/localhost.sql, where improper access controls allow for the potential manipulation of sensitive files and directories. This vulnerability can be exploited rem...

PoC for CVE-2026-4899

Code-projectsOnline Food Ordering S...4.8MEDIUM
Cross-Site Scripting Vulnerability in Online Food Ordering System b...

A security flaw has been identified in the Online Food Ordering System (version 1.0) developed by Code-Projects. This vulnerability involves an improper handling of user-supplied input within the /dbfood/food.php file, specifically targeting the argument 'cuisines'. This oversight allows for cros...

PoC for CVE-2026-24061

GnuInetutils🟣 EPSS 87%9.8CRITICAL
Remote Authentication Bypass in GNU Inetutils Telnetd

The GNU Inetutils telnet daemon (telnetd) is vulnerable to a remote authentication bypass that can occur when an attacker manipulates the USER environment variable by specifying a '-f root' value. This flaw allows unauthorized users to gain access without proper authentication. Affected users sho...

Discovered 11 hours ago

PoC for CVE-2026-4898

Code-projectsOnline Food Ordering S...5.3MEDIUM
Cross-Site Scripting Vulnerability in Online Food Ordering System b...

A vulnerability exists in the Online Food Ordering System 1.0 developed by Code-Projects, specifically within the /dbfood/contact.php file. This weakness allows for the exploitation of user-supplied input in the 'Name' parameter, enabling attackers to execute cross-site scripting (XSS) attacks re...

PoC for CVE-2020-1056

MicrosoftMicrosoft Edge (edgeht...🟣 EPSS 15%8.1HIGH
Elevation of Privilege Vulnerability in Microsoft Edge Browser

An elevation of privilege vulnerability in Microsoft Edge arises from improper enforcement of cross-domain policies. This flaw could allow an attacker to obtain sensitive information from one domain and inject it into another, potentially compromising users' security. If exploited through a malic...

Discovered 12 hours ago

PoC for CVE-2026-24126

WeblateorgWeblate6.6MEDIUM
Input Validation Flaw in Weblate SSH Management Console

Weblate, a web-based localization tool, has a security vulnerability in its SSH management console prior to version 5.16.0. The console does not correctly validate user input when adding SSH host keys, which can lead to an argument injection vulnerability, allowing potentially unauthorized action...

Discovered 14 hours ago

PoC for CVE-2024-36039

PyMySQLPyMySQL6.3MEDIUM
SQL Injection Vulnerability in PyMySQL Affects Data Security

A security vulnerability in PyMySQL versions up to 1.1.0 exposes applications to SQL injection attacks when untrusted JSON input is utilized. This occurs because the keys within the input are not properly escaped by the escape_dict function, potentially allowing malicious users to manipulate SQL ...

Discovered 18 hours ago

PoC for CVE-2019-25650

RiverpastRiver Past Camdo8.6HIGH
Buffer Overflow Vulnerability in River Past CamDo by River Past

River Past CamDo version 3.7.6 is vulnerable to a structured exception handler buffer overflow. This vulnerability allows local attackers to execute arbitrary code by providing a specially crafted string in the Lame_enc.dll name field. By manipulating a 280-byte buffer with a non-sequential excep...

PoC for CVE-2019-25649

RiverpastRiver Past Audio Conve...6.8MEDIUM
Local Buffer Overflow Vulnerability in River Past Audio Converter b...

River Past Audio Converter version 7.7.16 is susceptible to a local buffer overflow vulnerability that can be exploited by attackers. By entering an excessively long string into the 'E-Mail and Activation Code' field, an attacker can trigger a denial of service condition, causing the application ...

PoC for CVE-2019-25648

IvideogoMyvideoconverter Pro6.9MEDIUM
Local Buffer Overflow in MyVideoConverter Pro by iVideoGo

MyVideoConverter Pro version 3.14 suffers from a local buffer overflow vulnerability, which can be exploited by attackers to crash the application. By entering an excessively long string of up to 10,000 bytes into the 'Copy and Paste Registration Code' field, malicious users can trigger a denial ...

PoC for CVE-2018-25218

PassfabRar Password Recovery8.6HIGH
SEH Buffer Overflow Vulnerability in PassFab RAR Password Recovery ...

The vulnerability in PassFab RAR Password Recovery 9.3.2 is due to a structured exception handler (SEH) buffer overflow, which can be exploited by local attackers. By crafting a malicious payload that includes a buffer overflow, NSEH jump, and shellcode, attackers can manipulate the software duri...

PoC for CVE-2018-25219

PassfabExcel Password Recovery8.6HIGH
Buffer Overflow Vulnerability in PassFab Excel Password Recovery by...

The vulnerability in PassFab Excel Password Recovery 8.3.1 is attributed to a structured exception handling (SEH) buffer overflow, which can be exploited by local attackers. By inputting a specially crafted payload into the Licensed E-mail and Registration Code fields during the registration proc...

PoC for CVE-2018-25217

RttsoftwarePDF Explorer8.6HIGH
Structured Exception Handler Overflow Vulnerability in PDF Explorer...

PDF Explorer version 1.5.66.2 is susceptible to an SEH overflow vulnerability that enables local attackers to execute arbitrary code. By exploiting this vulnerability, attackers can manipulate the structured exception handling records, allowing them to overwrite critical data. The attack involves...

PoC for CVE-2018-25216

AnyburnAnyburn6.9MEDIUM
Local Buffer Overflow Vulnerability in AnyBurn by AnyBurn Technologies

AnyBurn version 4.3 is susceptible to a local buffer overflow vulnerability that can be triggered by an attacker providing an excessively long string in the 'Image file name' field. During the 'Copy disk to Image' operation, an attacker can input a 10000-byte payload, leading to a denial of servi...

PoC for CVE-2018-25214

MagnetosoftMegaping6.9MEDIUM
Local Buffer Overflow Vulnerability in MegaPing by MagnetoSoft

MegaPing is susceptible to a local buffer overflow vulnerability that can lead to a denial-of-service condition. When an attacker supplies a payload that exceeds the expected limits in the Destination Address List field during the Finger function, it can lead to a crash of the application. This f...

PoC for CVE-2018-25215

RecoverlostpasswordExcel Password Recover...6.8MEDIUM
Local Buffer Overflow Vulnerability in Excel Password Recovery Prof...

Excel Password Recovery Professional version 8.2.0.0 is susceptible to a local buffer overflow vulnerability that can lead to denial of service. By inputting a maliciously crafted string of 5000 bytes or more into the 'E-Mail and Registrations Code' field, an attacker can trigger a crash of the a...

PoC for CVE-2018-25213

NsauditorNsauditor Local Seh Bu...8.6HIGH
Buffer Overflow Vulnerability in Nsauditor by Netspark

Nsauditor 3.0.28.0 is affected by a buffer overflow vulnerability due to inadequate handling of input in the DNS Lookup tool. This allows local attackers to execute arbitrary code by crafting a malicious payload that overwrites the structured exception handling (SEH) chain. By injecting shellcode...

PoC for CVE-2018-25211

AlloksoftSplitter8.5HIGH
Buffer Overflow Vulnerability in Allok Video Splitter by Allok Soft

Allok Video Splitter version 3.1.1217 has a buffer overflow vulnerability that can be exploited by local attackers. By inputting an oversized string (exceeding 780 bytes) into the License Name field during registration, an attacker can trigger the overflow when they click the Register button. Thi...

PoC for CVE-2018-25212

BoxoftWav To Wma Converter8.6HIGH
Local Buffer Overflow Vulnerability in Boxoft Wav-WMA Converter by ...

Boxoft Wav-WMA Converter version 1.0 is susceptible to a local buffer overflow vulnerability within its structured exception handling routines. This flaw enables attackers to execute arbitrary code on affected Windows systems by crafting malicious WAV files. By supplying a specially formatted WAV...

Discovered 19 hours ago

PoC for CVE-2026-4877

ItsourcecodePayroll Management System5.3MEDIUM
Cross-Site Scripting Vulnerability in itsourcecode Payroll Manageme...

A cross-site scripting (XSS) vulnerability has been identified in the itsourcecode Payroll Management System versions up to 1.0. This security flaw resides in the /index.php file, where improper handling of the 'page' argument allows malicious actors to execute arbitrary scripts in the context of...

PoC for CVE-2026-4876

ItsourcecodeFree Hotel Reservation...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Free Hotel Reservation ...

A vulnerability has been discovered in the itsourcecode Free Hotel Reservation System version 1.0, particularly in the file /admin/mod_amenities/index.php?view=editpic. This issue can be exploited by manipulating the argument ID, leading to SQL injection attacks. The vulnerability allows unauthor...

PoC for CVE-2026-4875

ItsourcecodeFree Hotel Reservation...5.1MEDIUM
Unrestricted File Upload Vulnerability in itsourcecode Free Hotel R...

A vulnerability has been identified in the itsourcecode Free Hotel Reservation System version 1.0 that allows for unrestricted file uploads. This occurs due to improper handling of the file input in the script located at /admin/mod_amenities/index.php?view=add. An attacker can exploit this flaw r...

Discovered 20 hours ago

PoC for CVE-2018-25210

Web-ofisiTicaret V48.8HIGH
SQL Injection Vulnerability in WebOfisi E-Ticaret by WebOfisi

WebOfisi E-Ticaret 4.0 contains a SQL injection flaw in the 'urun' GET parameter, allowing unauthenticated attackers to execute malicious SQL queries. By manipulating the 'urun' parameter, attackers can perform various SQL injection techniques, including boolean-based blind, error-based, time-bas...

PoC for CVE-2018-25209

SourceforgeOpenbiz Cubi Lite8.8HIGH
SQL Injection Vulnerability in OpenBiz Cubi Lite from BigChef

OpenBiz Cubi Lite version 3.0.8 contains a SQL injection flaw in its login form, permitting unauthenticated attackers to manipulate database queries via the username parameter. By sending crafted POST requests to /bin/controller.php with malicious SQL input in the username field, an attacker coul...

PoC for CVE-2018-25208

QdpmQdpm8.8HIGH
SQL Injection Vulnerability in qdPM by qdPM Inc.

qdPM 9.1 contains a vulnerability that enables unauthenticated attackers to exploit the application through SQL injection. By manipulating the filter_by parameters in craftily designed POST requests directed at the timeReport endpoint, attackers can execute arbitrary SQL commands. This exploitati...

PoC for CVE-2018-25207

HscriptsOnline Quiz Maker7.1HIGH
SQL Injection Flaw in Online Quiz Maker by HScripts

Online Quiz Maker 1.0 has been identified to contain SQL injection vulnerabilities specifically in the 'catid' and 'usern' parameters. These vulnerabilities allow authenticated attackers to execute arbitrary SQL commands by submitting specially crafted POST requests to the quiz-system.php or add-...

PoC for CVE-2018-25206

SitemakinKomseo Cart8.8HIGH
SQL Injection Vulnerability in KomSeo Cart by KomSeo

KomSeo Cart version 1.3 is susceptible to an SQL injection vulnerability that can be exploited by attackers. This flaw allows malicious actors to inject SQL commands via the 'my_item_search' parameter in the edit.php file. By sending carefully crafted POST requests, attackers can perform boolean-...

PoC for CVE-2018-25205

MediasoftproAsp.net Jvideo Kit8.8HIGH
SQL Injection Vulnerability in ASP.NET jVideo Kit by MediaSoftPro

The ASP.NET jVideo Kit 1.0 is susceptible to an SQL injection flaw that enables unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'query' parameter in the search functionality. This vulnerability allows attackers to send specially crafted SQL payloads via GET or POST...

PoC for CVE-2018-25203

WecodexOnline Store System Cms8.8HIGH
SQL Injection Vulnerability in Online Store System CMS by WeCodex

The Online Store System CMS version 1.0 includes a vulnerability that permits unauthenticated users to execute SQL injection attacks. By exploiting this flaw, attackers can inject malicious SQL code through the email parameter during client access actions. This is achieved by sending crafted POST...

PoC for CVE-2018-25204

WecodexLibrary Cms8.8HIGH
SQL Injection Vulnerability in Library CMS by WeCodex

Library CMS version 1.0 contains an SQL injection vulnerability that allows attackers to bypass authentication by sending specially crafted SQL queries through the username parameter in POST requests to the admin login endpoint. This flaw can be exploited through boolean-based blind SQL injection...

PoC for CVE-2018-25202

WecodexSat Cfdi8.8HIGH
SQL Injection Vulnerability in SAT CFDI 3.3 by SAT

The SAT CFDI 3.3 product is susceptible to an SQL injection vulnerability that occurs in its signIn endpoint. This vulnerability enables attackers to execute arbitrary SQL code via the 'id' parameter, allowing them to manipulate database queries. Through the exploitation of this vulnerability, at...

PoC for CVE-2018-25201

Wecodex SolutionsSchool Management Syst...7.1HIGH
SQL Injection Vulnerability in School Management System CMS by WeCodex

The School Management System CMS 1.0 is susceptible to an SQL injection vulnerability in its admin login interface. This flaw permits hackers to bypass authentication controls by injecting malicious SQL code through the username input. Using boolean-based blind SQL injection techniques, attackers...

PoC for CVE-2018-25185

WecodexWecodex Restaurant Cms8.8HIGH
SQL Injection Vulnerability in Wecodex Restaurant CMS

Wecodex Restaurant CMS version 1.0 has a vulnerability that allows attackers to exploit SQL injection through the username parameter on the login page. By sending specially crafted POST requests, attackers may execute malicious SQL queries that can manipulate the underlying database. This vulnera...

PoC for CVE-2018-25195

WecodexWecodex Hotel Cms8.8HIGH
SQL Injection Vulnerability in Wecodex Hotel CMS 1.0

Wecodex Hotel CMS 1.0 is susceptible to SQL injection via its admin login functionality, enabling unauthenticated attackers to execute SQL commands through the username parameter in POST requests. This weakness allows attackers to bypass authentication measures, potentially accessing sensitive da...

PoC for CVE-2018-25183

WecodexShipping System Cms8.8HIGH
SQL Injection Vulnerability in Shipping System CMS by Unauthenticat...

Shipping System CMS version 1.0 is susceptible to an SQL injection vulnerability that enables unauthenticated attackers to bypass normal authentication mechanisms. By exploiting the username parameter, attackers can inject carefully crafted SQL statements through boolean-based blind techniques vi...

Discovered 23 hours ago

PoC for CVE-2026-4862

UttHiper 1250gw8.7HIGH
Buffer Overflow Vulnerability in UTT HiPER 1250GW Device

A security vulnerability has been identified in the UTT HiPER 1250GW device, specifically within the function strcpy located in the /goform/formConfigDnsFilterGlobal file of the Parameter Handler component. This flaw allows an attacker to manipulate the GroupName argument, triggering a buffer ove...

PoC for CVE-2026-4861

WavlinkWl-nu516u18.7HIGH
Stack-based Buffer Overflow Vulnerability in Wavlink Product

A vulnerability has been discovered in the Wavlink WL-NU516U1 device, specifically affecting the function ftext located in the /cgi-bin/nas.cgi file. This issue arises due to improper handling of the Content-Length argument, leading to a stack-based buffer overflow. Attackers can exploit this vul...