Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered just now...

PoC for CVE-2026-0300

Palo Alto NetworksCloud Ngfw🟣 EPSS 32%8.7HIGH
Buffer Overflow Vulnerability in Palo Alto Networks User-ID™ Authen...

A buffer overflow vulnerability exists within the User-ID™ Authentication Portal of Palo Alto Networks PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by manipulating specially crafted packets. To miti...

PoC for CVE-2026-67598

EmlogEmlog9.1CRITICAL
TLS Certificate Validation Flaw in Emlog Pro by Emlog

Emlog Pro, as of version 2.6.23, is susceptible to a TLS certificate validation vulnerability that allows attackers in the same network vicinity to intercept HTTPS requests. This exploitation arises from the unconditional disabling of the CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST options ...

Discovered 54 minutes ago

PoC for CVE-2024-2961

The Gnu C LibraryGlibc🟣 EPSS 88%7.3HIGH
Buffer Overflow Vulnerability in GNU C Library's iconv() Function

The iconv() function in the GNU C Library (glibc) has a vulnerability that can cause a buffer overflow when converting strings to the ISO-2022-CN-EXT character set. This flaw occurs due to the function's failure to adequately check the size of the output buffer, allowing it to overflow by up to 4...

Discovered 1 hour ago

PoC for CVE-2026-25243

RedisRedis7.7HIGH
In-memory Data Structure Store Vulnerability in Redis by Redis Labs

Redis, a widely used in-memory data structure store, is impacted by a vulnerability in its RESTORE command. This flaw allows authenticated attackers with permissions to execute the RESTORE command to manipulate serialized payloads, leading to potential memory access issues that can result in remo...

Discovered 2 hours ago

PoC for CVE-2026-15246

WordPressRealhomes Memberships4.3MEDIUM
Vulnerability in RealHomes Memberships Plugin for WordPress Allows ...

The RealHomes Memberships WordPress plugin prior to version 3.1.0 contains a flaw that permits authenticated users, such as Subscribers, to gain access to paid membership packages without completing the required payment. This is due to the absence of checks to verify the payment status, nonce val...

PoC for CVE-2026-70637

Hfiref0xLightftp8.2HIGH
Data Race Vulnerabilities in LightFTP Affected by Concurrency Issues

LightFTP version 2.4 is susceptible to multiple data race vulnerabilities that arise from concurrent execution paths in the control and worker threads. Specifically, when an anonymous attacker issues the LIST command followed by the ABOR command, the control thread may prematurely close data_sock...

Discovered 3 hours ago

PoC for CVE-2026-34990

OpenprintingCups5MEDIUM
Local Privilege Escalation in OpenPrinting CUPS by Unprivileged Users

OpenPrinting's CUPS, an open source printing system for Linux and other Unix-like operating systems, is susceptible to a local privilege escalation vulnerability. An unprivileged user can exploit this flaw to trick the cupsd service into authenticating with an attacker-controlled IPP service on l...

PoC for CVE-2026-34980

OpenprintingCups6.1MEDIUM
Unauthorized Print Job Execution in OpenPrinting CUPS 2.4.16 and Prior

The OpenPrinting CUPS printing system is susceptible to a vulnerability that allows unauthorized clients to send print jobs to a shared PostScript queue without proper authentication. This issue arises in network-exposed instances of cupsd version 2.4.16 and earlier, where an attacker can manipul...

Discovered 4 hours ago

PoC for CVE-2026-19037

WonderTraderWondertrader5.3MEDIUM
Vulnerability in WonderTrader Affects Internal Limit Order Book Cache

A weakness has been discovered in WonderTrader versions up to 0.9.9, specifically in the MatchEngine::update_lob function located in src/WtBtCore/MatchEngine.cpp. This vulnerability impacts the Internal Limit Order Book Cache Handler, potentially allowing attackers to manipulate enforcement of be...

Discovered 5 hours ago

PoC for CVE-2026-19036

ShibbyTomato8.6HIGH
OS Command Injection Vulnerability in Shibby Tomato Router Firmware

A security flaw has been identified in Shibby Tomato 1.28.0000, specifically within the function sub_40F88C located in the file /tmp/ppp/wanoptions. This vulnerability arises from improper handling of the ppp_custom argument, which allows remote attackers to execute arbitrary OS commands. The exp...

PoC for CVE-2026-19035

ShibbyTomato8.6HIGH
OS Command Injection Vulnerability in Shibby Tomato Router Software

A vulnerability in Shibby Tomato 1.28.0000 allows for OS command injection through improper handling of the new_qoslimit_enable argument in the new_qoslimit_start function within the file /etc/qoslimit. This flaw may be exploited remotely, enabling attackers to execute arbitrary commands on the s...

Discovered 6 hours ago

PoC for CVE-2026-19034

ShibbyTomato8.6HIGH
OS Command Injection in Shibby Tomato Router Firmware

A significant vulnerability exists in Shibby Tomato 1.28.0000 within the function new_qoslimit_stop located in /tmp/qoslimittc_stop.sh. This flaw allows attackers to manipulate the wan_iface argument, potentially leading to unauthorized execution of operating system commands. An attacker can laun...

Discovered 8 hours ago

PoC for CVE-2026-18556

N-ableN-central8.2HIGH
Authentication Bypass Vulnerability in N-able N-central

An authentication bypass vulnerability exists in N-able N-central, allowing attackers to exploit an alternate path or channel for unauthorized access. This critical security flaw can compromise the integrity and confidentiality of user data, posing significant risks to organizations utilizing the...

Discovered 9 hours ago

PoC for CVE-2026-19021

SourcecodesterComputer Repair Shop M...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Computer Repair Shop ...

A security vulnerability has been identified in the SourceCodester Computer Repair Shop Management System version 1.0. This issue affects the file /classes/Master.php with the parameter f=delete_product, where an attacker can manipulate the argument ID to perform SQL injection. This vulnerability...

PoC for CVE-2026-19020

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management Sys...

A vulnerability exists in the itsourcecode Hospital Management System 1.0, specifically in the /servicetype.php file. This vulnerability is attributed to a flaw in the argument handling of 'editid', which allows for SQL injection attacks. Attackers can exploit this weakness remotely, potentially ...

PoC for CVE-2026-19019

Poco-aiPoco-agent6.3MEDIUM
Incomplete Cleanup Vulnerability in poco-ai poco-agent Component by...

A significant security flaw has been identified in the poco-ai poco-agent, specifically within the WorkspaceManager._setup_session_persistence function of the Claude File Handler in executor/app/core/workspace.py. This vulnerability leads to incomplete cleanup of session data, potentially allowin...

PoC for CVE-2026-19019

Poco-aiPoco-agent6.3MEDIUM
Incomplete Cleanup Vulnerability in poco-ai poco-agent Component by...

A significant security flaw has been identified in the poco-ai poco-agent, specifically within the WorkspaceManager._setup_session_persistence function of the Claude File Handler in executor/app/core/workspace.py. This vulnerability leads to incomplete cleanup of session data, potentially allowin...

PoC for CVE-2026-19011

TinyAGITinyagi6.9MEDIUM
File Inclusion Vulnerability in TinyAGI by TinyAGI

A vulnerability exists in TinyAGI version 0.0.20 within the function buildSystemPrompt located in the file packages/server/src/routes/agents.ts. This flaw allows for the potential manipulation of files, leading to unauthorized file inclusion. Attackers can exploit this vulnerability remotely, giv...

Discovered 10 hours ago

PoC for CVE-2026-19010

TinyAGITinyagi6.9MEDIUM
Missing Authorization in TinyAGI Message API Endpoint

A vulnerability has been identified in TinyAGI version 0.0.20 within the processMessage function of the Message API Endpoint. This flaw permits unauthorized access, allowing attackers to manipulate the system remotely. Despite an early notification to the developers via an issue report, no respon...

PoC for CVE-2026-19009

TinyAGITinyagi6.9MEDIUM
File Inclusion Vulnerability in TinyAGI Message API Endpoint

A file inclusion vulnerability exists in version 0.0.20 of TinyAGI, specifically in the function collectFiles of the Message API Endpoint. This vulnerability allows for remote manipulation, which could be exploited to access sensitive files on the server. The issue was reported early to the devel...

PoC for CVE-2026-19008

Mf-yangOpenclaw-cn5.3MEDIUM
Link Following Vulnerability in mf-yang Openclaw-CN Tool

A security loophole exists in the mf-yang openclaw-cn tool, specifically within the assertNoSymlinkEscape function of the sandbox-paths.ts file. This flaw permits link following, which can be exploited to manipulate the system remotely. The vulnerability, publicly known, has not yet been addresse...

PoC for CVE-2026-19007

Mf-yangOpenclaw-cn5.3MEDIUM
Improper Privilege Management in Openclaw-CN by mf-yang

A vulnerability has been identified in Openclaw-CN, specifically affecting versions up to 0.2.1. This issue arises within the isApprovedElevatedSender function located in the src/auto-reply/reply/reply-elevated.ts file. This vulnerability can lead to inadequate management of privileges, allowing ...

Discovered 11 hours ago

PoC for CVE-2025-8110

GogsGogs🟣 EPSS 82%8.7HIGH
Improper Symbolic Link Handling in Gogs Product by Gogs Team

The vulnerability in the PutContents API of Gogs arises from improper handling of symbolic links, potentially allowing local execution of arbitrary code. This misconfiguration may expose sensitive data and facilitate unauthorized access to critical systems. Users and administrators are urged to u...

PoC for CVE-2026-13703

WordPressSeo Redirection Plugin
Unauthorized Access in SEO Redirection Plugin for WordPress

The SEO Redirection Plugin for WordPress, prior to version 9.19, contains a flaw that permits logged-in users, regardless of their privileges, to execute specific authenticated AJAX actions without proper capability checks. This vulnerability allows these users to gain access to sensitive configu...

PoC for CVE-2026-14204

WordPressGoogle Authenticator
Cross-Site Request Forgery Vulnerability in Google Authenticator Wo...

The Google Authenticator WordPress plugin prior to version 0.56 is vulnerable to a Cross-Site Request Forgery (CSRF), which can be exploited to compromise two-factor authentication settings. Attackers can send a malicious request to a logged-in user, tricking them into changing their two-factor a...

PoC for CVE-2026-12713

WordPressWPcargo Track & Trace
SQL Injection Vulnerability in WPCargo Track & Trace Plugin for Wor...

The WPCargo Track & Trace WordPress plugin, prior to version 8.0.4, lacks adequate parameter sanitization and escaping practices within its SQL statements. This oversight creates a significant security risk, as it enables unauthenticated users to execute SQL injection attacks. Such vulnerabilitie...

PoC for CVE-2025-15678

WordPressNexter Blocks
Stored Cross-Site Scripting in Nexter Blocks WordPress Plugin by Ne...

The Nexter Blocks WordPress plugin, prior to version 5.0.2, permits users with file upload capabilities to upload SVG files without proper sanitization. This oversight allows these users to execute malicious JavaScript embedded within the SVG files, leading to stored cross-site scripting (XSS) vu...

PoC for CVE-2026-13154

WordPressGutenberg Essential Bl...
Security Flaw in Gutenberg Essential Blocks Plugin Exposing Custom ...

The Gutenberg Essential Blocks plugin for WordPress before version 6.4.0 contains a significant access control vulnerability. It fails to properly verify whether an attacker-supplied post type is publicly viewable prior to executing queries in its public REST routes. This oversight allows unauthe...

PoC for CVE-2026-13153

WordPressGutenberg Essential Bl...
Improper Access Control in Gutenberg Essential Blocks Plugin from W...

The Gutenberg Essential Blocks plugin for WordPress prior to version 6.4.0 has a significant access control vulnerability, which allows unauthenticated users to retrieve sensitive sales metrics. Specifically, the plugin's public REST route permits an over-fetching of non-public WooCommerce inform...

PoC for CVE-2026-11588

WordPressEonsr Aeo Agent6.1MEDIUM
Stored Cross-Site Scripting Vulnerability in EONSR AEO Agent WordPr...

The EONSR AEO Agent plugin for WordPress prior to version 3.7.9 is vulnerable due to inadequate authorization checks on specific REST API routes. This security flaw allows unauthenticated attackers to craft and publish posts with malicious web scripts. These scripts are stored on the server and e...

PoC for CVE-2026-19006

Mf-yangOpenclaw-cn5.3MEDIUM
Incorrect Authorization Vulnerability in Ggateway Exec Approval Flo...

A significant vulnerability has been identified in the Ggateway Exec Approval Flow component of mf-yang's Openclaw-cn version 2026.2.5. This issue resides in the src/agents/bash-tools.exec.ts file, where improper authorization handling can lead to unauthorized access. Attackers may exploit this v...

PoC for CVE-2026-16065

WordPressWelcart E-commerce6.5MEDIUM
SQL Injection Vulnerability in Welcart e-Commerce Plugin for WordPress

The Welcart e-Commerce plugin for WordPress, prior to version 2.11.32, contains a vulnerability where it fails to adequately sanitize data imported from CSV files. This oversight allows users with Editor roles and above to potentially execute SQL injection attacks, manipulating the database and g...

PoC for CVE-2026-16537

WordPressSlick Slider5.4MEDIUM
Stored Cross-Site Scripting Vulnerability in Slick Slider Plugin by...

The Slick Slider plugin for WordPress, before version 0.5.3, contains a vulnerability due to improper sanitization and escaping of a shortcode attribute value. This flaw allows users with Contributor privileges and above to conduct Stored Cross-Site Scripting attacks. When a user views the affect...

PoC for CVE-2026-14829

WordPressCheckimate — WooCommer...8.2HIGH
Access Control Flaw in Checkimate WooCommerce Plugin Allows Unautho...

The Checkimate WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin fails to enforce adequate access controls for its license-management functions. This vulnerability is due to its reliance on a shared secret derived from publicly accessible information, which enables unau...

PoC for CVE-2026-18395

WordPressChild Pages Card5.4MEDIUM
Stored Cross-Site Scripting in Child Pages Card Plugin by WordPress

The Child Pages Card plugin for WordPress prior to version 1.09 is susceptible to stored Cross-Site Scripting (XSS) vulnerabilities. The plugin fails to properly sanitize and escape certain shortcode attributes upon outputting them in web pages. This oversight allows users with contributor privil...

PoC for CVE-2026-16734

WordPressStripe Payment Forms B...7.5HIGH
Unauthenticated Payment Manipulation in WP Full Pay Stripe Plugin

The Stripe Payment Forms plugin by WP Full Pay prior to version 8.5.2 fails to validate ownership of payment intents for certain unauthenticated AJAX actions. This oversight allows malicious users to manipulate payment amounts by utilizing a nonce embedded in public pages. Although an ownership v...

PoC for CVE-2026-16954

WordPressAi Engine6.5MEDIUM
Vulnerability in AI Engine WordPress Plugin Exposes Sensitive Confi...

The AI Engine WordPress plugin prior to version 3.6.4 contains a vulnerability that allows users with the Editor role to access sensitive configuration values, including third-party API keys and authentication tokens. These secrets, typically accessible only by administrators, are exposed in clea...

PoC for CVE-2026-18050

WordPressEvents Manager7.5HIGH
Unauthorized Access Vulnerability in Events Manager Plugin for Word...

The Events Manager plugin for WordPress prior to version 7.4 lacks proper authorization checks on a REST route associated with file uploads. This flaw allows unauthenticated users to access another user's temporary file uploads if they possess knowledge of the temporary identifier, which is high-...

PoC for CVE-2026-16290

WordPressProfilegrid5.3MEDIUM
Authorization Bypass in ProfileGrid WordPress Plugin Affects User P...

The ProfileGrid WordPress plugin versions prior to 6.0.0.0 suffer from a serious vulnerability that allows any unauthenticated visitor to access the member lists of various groups without proper authorization checks. This flaw exposes sensitive information, including member identifiers from priva...

PoC for CVE-2026-16268

WordPressNewsletters8.2HIGH
Security Flaw in Newsletters WordPress Plugin Exposes Sites to Unau...

The Newsletters WordPress plugin prior to version 4.16 is susceptible to a security vulnerability that fails to authenticate or validate bounce-processing requests. This oversight allows unauthenticated attackers to submit malicious user-supplied URLs, leading to arbitrary requests being executed...

PoC for CVE-2026-14240

WordPressTourmaster5.3MEDIUM
Insecure File Exposure in Tourmaster WordPress Plugin

The Tourmaster WordPress plugin prior to version 5.4.9 is susceptible to an insecure file exposure vulnerability. When administrators perform an export for orders or bookings, the exported data is saved in a fixed, predictable file location within a publicly accessible directory. This lack of pro...

PoC for CVE-2026-14547

WordPressEstatik Real Estate Pl...5.3MEDIUM
Mail Relay Vulnerability in Estatik Real Estate Plugin for WordPress

The Estatik Real Estate Plugin for WordPress versions before 4.3.3 is susceptible to an improper input validation vulnerability that bypasses its anti-spam mechanisms. This flaw enables unauthenticated users to exploit the property request form by sending emails to any specified recipient, along ...

PoC for CVE-2026-16054

WordPressDrag And Drop Multiple...
File Deletion Vulnerability in Drag and Drop Multiple File Upload f...

The Drag and Drop Multiple File Upload for WooCommerce plugin prior to version 1.1.8 exhibits a critical security flaw that permits unauthenticated users to exploit a valid nonce, which serves as the sole barrier to executing file deletion operations. This vulnerability allows malicious actors to...

PoC for CVE-2026-14314

WordPressPeprodev WooCommerce R...5.3MEDIUM
Unauthenticated Token Forgery in PeproDev WooCommerce Receipt Uploa...

The PeproDev WooCommerce Receipt Uploader plugin allows attackers to craft unauthorized access tokens that can be used to view image attachments uploaded by other users. This vulnerability occurs because the plugin does not properly validate the relationship between a requested attachment and the...

PoC for CVE-2026-14313

WordPressPeprodev WooCommerce R...5.3MEDIUM
Unauthenticated Write Vulnerability in PeproDev WooCommerce Receipt...

The PeproDev WooCommerce Receipt Uploader plugin for WordPress is impacted by a serious vulnerability that allows unauthenticated users to perform unauthorized write operations. This missing authorization flaw enables potential attackers to exploit the system, posing significant security risks, e...

PoC for CVE-2026-19005

NanocoaiNanoclaw5.3MEDIUM
Improper Privilege Management in nanocoai NanoClaw Child-Agent Crea...

A vulnerability has been identified in the nanocoai NanoClaw product, specifically in the Child-Agent Creation function. The issue is attributed to improper privilege management within the handleCreateAgent method located in the create-agent.ts file. This flaw permits remote attackers to exploit ...

PoC for CVE-2026-71211

MlflowMlflow7.1HIGH
Server-Side Request Forgery in MLflow AI Gateway by Databricks

MLflow's AI Gateway is vulnerable due to an insufficient validation mechanism for the auth_config.api_base value. When creating a gateway secret, the system allows the storage of this value without validating its scheme, host, or IP range. Consequently, the gateway proxy can process HTTP requests...

PoC for CVE-2026-19000

Jeecg TechnologyJeecgboot6.9MEDIUM
Server-Side Request Forgery in JeecgBoot by Jeecg Technology

A server-side request forgery (SSRF) vulnerability has been detected in JeecgBoot versions prior to 3.9.2. This flaw involves an unknown function in the "Anonymous Chat Attachment Parser" component located in the file /airag/chat/send. Attackers can exploit this vulnerability remotely, allowing u...

Discovered 12 hours ago

PoC for CVE-2026-18998

Cosmicstack-labsMercury-agent5.3MEDIUM
Improper Authorization Vulnerability in Cosmicstack-Labs Mercury-Ag...

A vulnerability exists in the Cosmicstack-Labs Mercury-Agent software that allows for improper authorization within the function SubAgent.run found in the delegate_task Tool. This issue affects versions up to 1.1.12 and can be exploited remotely. Details regarding this vulnerability were made pub...

PoC for CVE-2026-18997

Cosmicstack-labsMercury-agent5.3MEDIUM
Authorization Vulnerability in cosmicstack-labs mercury-agent Affec...

A vulnerability exists in the cosmicstack-labs mercury-agent affecting versions up to 1.1.12. The issue arises in the function Agent.handleBgCommand located in the src/core/agent.ts file. This vulnerability enables attackers to exploit incorrect authorization mechanisms remotely, which could lead...