Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 2 hours ago
PoC for CVE-2026-86808
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been di...
Discovered 3 hours ago
PoC for CVE-2026-86716
A vulnerability has been identified in Cesanta mJS up to version 1.26, specifically within the 'skip_spaces_and_comments' function in src/mjs_tok.c. This issue allows for a heap-based buffer overflow, which can be exploited remotely. The vulnerability has been publicly disclosed, and potential at...
PoC for CVE-2026-86675
A vulnerability exists in the itsourcecode Sales and Inventory System version 1.0, specifically in the /pages/us_edit.php file. This flaw allows for manipulation of the argument 'ID,' leading to potential SQL injection attacks. Attackers can exploit this vulnerability remotely, leveraging publicl...
PoC for CVE-2026-19949
The All-in-One WP Migration and Backup plugin for WordPress contains a SQL injection vulnerability due to inadequate input escaping during the archive restore process. This flaw allows unauthenticated attackers to insert malicious SQL commands into existing queries. As a result, they can potentia...
Discovered 4 hours ago
PoC for CVE-2026-82537
Roo-Code prior to version 3.54.0 contains a vulnerability that enables attackers to bypass the auto-approve mechanism, facilitating unauthorized execution of shell commands. By exploiting a word-boundary mismatch in comment processing between the approval gate's shell parser and bash, attackers c...
PoC for CVE-2026-82536
Roo-Code version 3.54.0 is affected by an auto-approve bypass vulnerability in its shell command parsing logic. This flaw allows malicious actors to exploit the omission of the bash pipe operator in the command parser's token set. By crafting specific command lines that include an allowlisted pre...
PoC for CVE-2026-86674
A session fixation vulnerability exists in the ningzichun Student Management System due to improper handling of session initialization within the login.php file's session_start function. This flaw allows an attacker to hijack active user sessions by manipulating session identifiers. Remote exploi...
PoC for CVE-2026-86673
A vulnerability exists in the ningzichun Student Management System's database connection functionality, specifically in the mysqli_connect function located in config/database.php. This issue allows attackers to exploit hard-coded credentials, potentially enabling unauthorized remote access to the...
PoC for CVE-2026-75650
Adobe Commerce has a vulnerability that allows for improper neutralization of special elements used in a template engine, potentially leading to arbitrary code execution in the context of the current user. An attacker can exploit this issue without requiring any user interaction, posing significa...
PoC for CVE-2026-86672
An information disclosure vulnerability has been detected in the ningzichun Student Management System, particularly within the Backup Handler component. The weakness resides in an unknown function of the example.7z file, allowing unauthorized remote access to sensitive information. As the system ...
PoC for CVE-2026-86670
A significant security vulnerability exists in the aircheng-org iWebShop-5 platform, specifically in the Authentication Storage feature located in the controllers/admin.php file. This flaw allows an attacker to manipulate the argument for passwords, potentially leading to the use of weak password...
Discovered 5 hours ago
PoC for CVE-2026-86669
A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now publi...
PoC for CVE-2026-75650
Adobe Commerce has a vulnerability that allows for improper neutralization of special elements used in a template engine, potentially leading to arbitrary code execution in the context of the current user. An attacker can exploit this issue without requiring any user interaction, posing significa...
PoC for CVE-2026-40369
A vulnerability in the Windows Kernel allows an authorized attacker to exploit an untrusted pointer dereference, potentially enabling them to gain higher privileges on the affected system. This could lead to unauthorized access to sensitive data and administrative functionalities. It's critical f...
PoC for CVE-2026-86668
A security vulnerability has been identified in the iWebShop-5 application provided by aircheng-org, specifically in versions up to 5.15. The vulnerability arises from the improper handling of the 'outerSrc/selectPhoto' argument within the 'uploadFile' function found in 'controllers/pic.php'. Thi...
PoC for CVE-2026-86667
A critical vulnerability has been discovered in aircheng-org's iWebShop-5 versions up to 5.15, specifically within the member_list function found in controllers/member.php. This flaw allows attackers to manipulate the Search argument, leading to SQL injection that can be executed remotely. The vu...
Discovered 6 hours ago
PoC for CVE-2026-56101
OpenBSD prior to a specific commit includes an inverted comparison flaw in the ieee80211_michael_mic_failure() function. This vulnerability allows unauthenticated attackers within RF range to execute a denial of service attack. By sending two specially crafted TKIP frames, spaced appropriately, a...
PoC for CVE-2026-86666
A security flaw is present in the aircheng-org iWebShop-5 versions up to 5.15, particularly affecting the upload_json/uploadFile function in controllers/pic.php. This vulnerability allows for unrestricted file uploads, enabling attackers to upload malicious files remotely. Despite being made awar...
PoC for CVE-2026-83548
A vulnerability exists in the SMA1000 Appliance's Work Place interface that allows for Pre-authentication SSRF attacks. This occurs due to an unintended alternate access path, enabling remote unauthenticated attackers to exploit the system. By leveraging this vulnerability, an attacker may gain u...
PoC for CVE-2026-2931
The Amelia Booking plugin for WordPress is susceptible to Insecure Direct Object References, allowing users to manipulate access to system resources. This flaw exists in versions up to and including 9.1.2, granting authenticated attackers with customer-level access or higher the ability to bypass...
Discovered 7 hours ago
PoC for CVE-2026-75650
Adobe Commerce has a vulnerability that allows for improper neutralization of special elements used in a template engine, potentially leading to arbitrary code execution in the context of the current user. An attacker can exploit this issue without requiring any user interaction, posing significa...
PoC for CVE-2026-86665
A security vulnerability has been identified in iWebShop-5 from aircheng-org, particularly within the Update::index function in the controllers/update.php file. This flaw allows for remote exploitation due to missing authorization checks, potentially enabling unauthorized users to manipulate data...
PoC for CVE-2026-61517
Netis NX10 firmware has a vulnerability that allows authenticated administrators to execute arbitrary shell commands as root. This is achieved through an OS command injection in the ping diagnostic handler, where the IpAddr parameter is improperly validated. The insufficient denylist allows for e...
Discovered 8 hours ago
PoC for CVE-2026-86644
A vulnerability was identified in star7th ShowDoc through version 3.9.1, specifically within the API Page Save Endpoint in the file web_src/public/editor.md/editormd.js. This flaw can be exploited remotely via crafted inputs, leading to potential cross site scripting attacks. To mitigate these ri...
Discovered 10 hours ago
PoC for CVE-2026-10795
The UpdraftPlus: WP Backup & Migration Plugin for WordPress has a vulnerability that allows unauthenticated attackers to bypass authentication mechanisms. This occurs due to inadequate validation of remote communications messages in the UpdraftPlus_Remote_Communications_V2::wp_loaded function. At...
Discovered 16 hours ago
PoC for CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 is vulnerable to exploitation, allowing attackers to perform unauthorized read and write operations on arbitrary files. This is executed through the use of the site cpfr and site cpto commands, enabling remote users to manipulate file contents without permissi...
Discovered 17 hours ago
PoC for CVE-2026-39987
Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...
PoC for CVE-2014-9222
AllegroSoft RomPager versions 4.34 and earlier, employed in various home gateway products, including those from Huawei, have a vulnerability that enables remote attackers to escalate privileges through a specially crafted cookie. This exploitation leverages memory corruption, giving unauthorized ...
Discovered 18 hours ago
PoC for CVE-2026-86519
A security vulnerability has been identified in the Student Crud Operation version 1.0 by Code-Projects, affecting the Backup File Handler component. This vulnerability resides in the /card_activation.sql file, leading to potential information disclosure. Remote attackers can exploit this loophol...
PoC for CVE-2026-86518
A vulnerability has been identified in the Student Crud Operation 1.0, specifically in the /edit.php file. This security flaw allows an attacker to manipulate the ID parameter, enabling SQL injection attacks that can be initiated from a remote location. The risk associated with this vulnerability...
PoC for CVE-2026-86517
A significant SQL injection vulnerability exists in version 1.0 of the itsourcecode Sales and Inventory System. The flaw is located in the mysqli_query function within the /pages/us_searchfrm.php file. An attacker can manipulate the ID argument, facilitating remote SQL injection attacks, which ma...
Discovered 19 hours ago
PoC for CVE-2026-86515
A security vulnerability in vgmstream has been identified, specifically within the add_entry function in the txtp_parser.c file. This weakness allows manipulations of the range_start and range_end parameters, potentially leading to excessive resource consumption. The threat can be executed remote...
PoC for CVE-2026-86514
A vulnerability has been detected in vgmstream, specifically in versions up to r2117, affecting the sscanf function within the txth.c component. This weakness may allow attackers to manipulate data and initiate a stack-based buffer overflow remotely. The potential exploitation of this vulnerabili...
PoC for CVE-2026-86513
A security flaw has been identified in the JSON Pointer parser of jackson-coreutils version 2.0, specifically within the TreePointer.tokensFromInput function. This vulnerability allows for remote execution of attacks that exploit improper resource allocation. The issue was reported to the project...
Discovered 20 hours ago
PoC for CVE-2026-86512
A security vulnerability has been discovered in the java-json-tools json-patch component, specifically in the Copy Move Operations feature. This flaw, found in the methods CopyOperation.apply and MoveOperation.apply, allows for improper access controls, potentially enabling unauthorized actions b...
PoC for CVE-2026-86511
A resource consumption vulnerability has been identified in the Jackson-CoreUtils library version 2.0, found in the BigDecimal.toPlainString function within the JacksonUtils.java file. This vulnerability allows an attacker to manipulate resources, leading to potential denial of service. The explo...
Discovered 21 hours ago
PoC for CVE-2026-86510
A critical vulnerability has been identified in the D-Link DIR-822A A_101 router, specifically within the tunnel_set_params function of the L2TP Control Message Parser. This vulnerability allows for an out-of-bounds write condition that can be exploited remotely. The public disclosure of this exp...
PoC for CVE-2026-86509
A vulnerability exists in the D-Link DIR-895L A1_102b07 router due to a flaw in the sendOffer/sendACK functions within the udhcpcd/serverpacket.c file. This flaw can lead to a stack-based buffer overflow, potentially allowing an attacker to execute arbitrary code. The attack requires access to th...
Discovered 22 hours ago
PoC for CVE-2020-0609
This vulnerability allows an unauthenticated attacker to execute arbitrary code on a target system by sending specially crafted requests to the Windows Remote Desktop Gateway. Successful exploitation could enable the attacker to install programs, view, change or delete data, or create new account...
Discovered 23 hours ago
PoC for CVE-2022-4140
The Welcart e-Commerce plugin for WordPress, prior to version 2.8.5, contains a vulnerability that arises from insufficient validation of user input. This oversight allows an unauthenticated attacker to potentially read arbitrary files on the server. By manipulating the input, the attacker can ga...
Discovered 1 day ago
PoC for CVE-2026-33234
The AutoGPT platform allows users to specify an SMTP server and port, which can lead to potential internal network scanning. This vulnerability arises from the absence of validation checks on user inputs in the SendEmailBlock component. When an authenticated user provides these inputs, AutoGPT by...
PoC for CVE-2026-28576
In the Contacts Provider, a vulnerability exists that allows unauthorized access to the contacts database through an SQL injection attack. Attackers can exploit this flaw without needing any user interaction or elevated privileges, potentially leading to the disclosure of sensitive information st...
PoC for CVE-2025-48384
A vulnerability exists in Git that affects how configuration values are read and written, particularly regarding trailing carriage returns. When a submodule path includes a trailing carriage return, it is altered when read back, which can cause the submodule to be checked out to an incorrect loca...
PoC for CVE-2026-86218
N-central by N-able is susceptible to a critical pre-authentication remote code execution vulnerability, which allows unauthorized parties to execute arbitrary code on vulnerable systems. This issue impacts all versions of N-central prior to 2026.3.1.14, making it essential for users to upgrade t...
PoC for CVE-2026-13181
A vulnerability in Telerik UI for AJAX versions earlier than v2026.2.708 allows an attacker to influence AsyncUploadTypeName processing through forged upload metadata. This manipulation can lead to unsafe type resolution, potentially enabling remote code execution in affected environments. It is ...
PoC for CVE-2026-86321
A vulnerability has been identified in the URL Validation functionality of the java-json-tools jackson-coreutils library, specifically within the 'JsonLoader.fromURL' method. This flaw could allow an attacker to perform server-side request forgery (SSRF), which enables the attacker to exploit the...
PoC for CVE-2026-86319
A vulnerability exists within the json-patch component from java-json-tools, specifically in the JsonPatch.apply function located at src/main/java/com/github/fge/jsonpatch/JsonPatch.java. This vulnerability allows for excessive resource consumption, enabling remote attacks that could lead to Deni...
PoC for CVE-2026-86318
A vulnerability exists in the json-patch component of java-json-tools up to version 1.13, specifically in the JsonMergePatch.fromJson function located in JsonMergePatchDeserializer.java. This flaw can lead to a stack-based buffer overflow, which may be exploited remotely, allowing an attacker to ...
PoC for CVE-2026-86310
A significant SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System 1.0, specifically within an unknown function of the 'cust_edit1.php' file. This flaw allows attackers to manipulate the argument ID, enabling remote exploitation. Such vulnerabilities pose...
PoC for CVE-2026-86309
An SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0 within an unvalidated function in the file /pages/pro_searchfrm.php. This weakness allows attackers to manipulate the ID argument, potentially leading to unauthorized database access and exposure of s...