Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 7 hours ago
PoC for CVE-2022-41404
A vulnerability exists in the fetch() method of the BasicProfile class within the ini4j library that can be exploited by attackers to trigger a Denial of Service (DoS) condition. This can occur through various unspecified vectors, ultimately incapacitating the application that relies on this libr...
Discovered 9 hours ago
PoC for CVE-2026-91855
A security flaw in Open5GS affects the PFCP Message Handler component, specifically within the handler.c file. This vulnerability allows attackers to trigger a denial of service condition through remote manipulation. As the exploit has been made public, it poses a significant risk to systems runn...
PoC for CVE-2024-58385
Yonyou U8 CRM is susceptible to an unauthenticated SQL injection vulnerability located in the fillbacksettingedit.php configuration endpoint. By manipulating the DontCheckLogin=1 parameter, attackers can bypass authentication. This flaw allows the id parameter to be used in SQL queries without ad...
PoC for CVE-2023-54398
Yonyou U8 Cloud features an unauthenticated vulnerability within the nc.impl.pub.filesystem.FileManageServlet component, allowing remote attackers to execute arbitrary operating system commands. This security flaw is rooted in the doAction method, where raw HTTP request data is processed directly...
PoC for CVE-2026-91854
A cross-site scripting vulnerability exists in the Code-Projects Record Management System 1.0 due to improper handling of user-supplied input in the file main/reg.php. An attacker may exploit this vulnerability by manipulating the 'desc' argument, leading to the execution of arbitrary JavaScript ...
PoC for CVE-2026-91853
A security flaw has been identified in the TOTOLINK X5000R router that allows remote attackers to execute arbitrary operating system commands. This vulnerability arises from insufficient input validation in the exportOvpn function within the Export Ovpn Handler component. By manipulating the 'fil...
Discovered 10 hours ago
PoC for CVE-2026-91849
A security flaw has been identified in WuzhiCMS versions up to 4.1.0, specifically in the Avatar Upload function member::setAvatar located in /index.php. This flaw enables attackers to manipulate the argument 'File', resulting in unrestricted upload capabilities. The vulnerability allows remote e...
PoC for CVE-2026-91848
A security flaw in WuzhiCMS versions up to 4.1.0 allows for SQL injection through the function article::getDataOfJson. The vulnerability arises from improper handling of the title/master_table argument in the file /index.php?m=content&f=article&v=getDataOfJson. This vulnerability poses a signific...
PoC for CVE-2026-76461
A vulnerability in the email parsing functionality of Cisco Secure Email Gateway can be exploited by unauthenticated remote attackers. The issue stems from inadequate validation within the email parsing logic, allowing attackers to send specially crafted emails containing harmful SQL statements. ...
PoC for CVE-2026-91842
A vulnerability exists in the OpenBankProject OBP-API, specifically within the KryoHandler component, where improper handling of deserialization processes allows for potential remote exploitation. This issue is particularly concerning due to the function KryoInjection.invert located in the Redis....
Discovered 11 hours ago
PoC for CVE-2026-91836
A vulnerability has been identified in OpenClaw's ClawScan software, specifically in the Static Scanner component. The flaw is located in the internal/runner/static_scanner.go file and arises from inadequate comparison logic, which leads to missing elements in the execution. This issue can be exp...
PoC for CVE-2026-91835
A vulnerability in the File Classifier of OpenClaw ClawScan (versions up to 0.1.6) has been identified, specifically within the IsBinaryFile function located in internal/runner/static_scanner.go. This defect can lead to interpretation conflicts, requiring attackers to have local access to exploit...
Discovered 14 hours ago
PoC for CVE-2026-91998
Casdoor version 4.4.0 contains a critical authorization bypass vulnerability in the /api/mcp endpoint. This flaw potentially allows attackers with knowledge of any application's clientId and clientSecret to gain unrestricted administrative access across all organizations within the platform. By e...
PoC for CVE-2026-91997
A vulnerability in the Evolution API (up to version 2.3.7) allows attackers to bypass the metricsIPWhitelist middleware due to an incorrect array comparison that consistently evaluates to false. This flaw enables unauthenticated users to access the /metrics endpoint, exposing critical information...
PoC for CVE-2026-91995
An authentication bypass vulnerability exists in Pig software prior to version 4.1.0, specifically within the /register/password endpoint. This issue arises because the system improperly handles password verification, allowing attackers to submit any value as the current password. Consequently, r...
PoC for CVE-2026-91996
The lamp-cloud product up to version 5.10.0 has a significant security flaw that permits unauthenticated attackers to gain access to sensitive information. This vulnerability arises from a misconfigured path pattern that allows access to the server's JVM system property map via the endpoint /defG...
PoC for CVE-2026-91994
Semaphore UI versions up to and including 2.19.12 possess a significant authorization bypass issue within the GetMustCanMiddleware. This vulnerability allows attackers with guest or task_runner roles to bypass necessary permission checks for GET and HEAD requests. As a result, these unauthorized ...
PoC for CVE-2026-91993
Jpom prior to version 2.11.12 allows authenticated users to bypass workspace isolation restrictions. The vulnerability occurs due to improper validation of workspace ownership when accessing the /build/branch-list endpoint. This flaw allows users to submit repository identifiers from other worksp...
Discovered 16 hours ago
PoC for CVE-2026-91782
A vulnerability exists in the GNU Binutils 2.47 specifically within the Dynamic Relocation Allocation component found in the elf_x86_allocate_dynrelocs function. This issue leads to a null pointer dereference, which can be exploited locally. The exploit is publicly known, and it is crucial to upg...
Discovered 17 hours ago
PoC for CVE-2014-0160
The vulnerability in the TLS and DTLS implementations of OpenSSL versions prior to 1.0.1g allows remote attackers to exploit crafted Heartbeat Extension packets. This exploitation results in a buffer over-read, potentially revealing sensitive information from the memory of the affected process. A...
PoC for CVE-2026-91781
A security vulnerability has been identified in GNU Binutils version 2.47, specifically within the elf_x86_64_common_section_index function of the ELF Section Handler. This flaw allows for a null pointer dereference, requiring local exploitation. The issue has been publicly disclosed, raising con...
PoC for CVE-2026-91780
A critical weakness has been identified in GNU Binutils 2.47, specifically within the elf_link_add_object_symbols function in bfd/elflink.c. This vulnerability can lead to null pointer dereference, posing risks for local exploitation. Despite early notification to the project team via a bug repor...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-91779
A security flaw has been identified in GNU Binutils 2.47, specifically in the function responsible for handling EH Frames. This vulnerability allows local attackers to exploit a null pointer dereference, potentially leading to application crashes or unexpected behaviors. The issue originated from...
Discovered 18 hours ago
PoC for CVE-2026-91091
A vulnerability affecting GPAC prior to version abi-16.23 has been identified in the Node Insertion component, specifically within the gf_node_list_insert_child function in the base_scenegraph.c file. This vulnerability can lead to memory corruption, allowing remote exploitation of the affected s...
PoC for CVE-2026-91090
A vulnerability has been identified in GPAC versions up to f1219cde, specifically in the gf_node_activate_ex function located in scenegraph/base_scenegraph.c. This flaw allows for a stack-based buffer overflow, which can be exploited by attackers on the local host. Given the public disclosure of ...
PoC for CVE-2026-91089
A use after free vulnerability has been identified in GPAC, specifically within the function gf_node_get_name_and_id located in the file scenegraph/base_scenegraph.c. This flaw allows remote attackers to exploit the software by manipulating memory usage, potentially leading to unauthorized access...
Discovered 19 hours ago
PoC for CVE-2026-91087
A vulnerability has been identified in GPAC's Compositor component, specifically within the gf_mo_get_od_id function located in media_object.c. This flaw allows for a use after free condition, which can be exploited remotely. Attackers can leverage this vulnerability to manipulate memory usage, p...
PoC for CVE-2026-91086
A security vulnerability has been identified in the MPEG Video Reframer function, specifically in the mpgviddmx_process of the filters/reframe_mpgvid.c file of GPAC up to version f1219cde. This vulnerability allows for heap-based buffer overflow, making it possible for attackers to execute remote...
PoC for CVE-2026-91005
A security flaw has been identified in the SourceCodester Online Faculty Clearance System 1.0, specifically within the Profile Picture Upload component located in the edit_picture.php file. This vulnerability arises from the misconfiguration of the move_uploaded_file function, enabling remote att...
PoC for CVE-2026-91004
A vulnerability exists in the SourceCodester Online Faculty Clearance System 1.0 that allows an attacker to execute a SQL injection via an unknown function in the file /delete_faculty1.php. By manipulating the argument ID, remote attackers can exploit this flaw to extract sensitive data or manipu...
PoC for CVE-2026-16592
The WP Directory Kit plugin for WordPress, up to version 1.5.7, exhibits an authorization flaw that allows users with low-level roles, such as Contributor, to access and disclose non-public content. This includes sensitive information like password-protected listings and hidden fields that should...
PoC for CVE-2026-16593
The WP Directory Kit plugin for WordPress, prior to version 1.5.7, is susceptible to SQL injection due to improper sanitization and escaping of certain widget settings. This flaw allows authenticated users with page builder access (Editor or higher) to manipulate SQL statements, potentially leadi...
PoC for CVE-2026-18232
The WP Directory Kit plugin for WordPress, version 1.5.7, is vulnerable due to inadequate security checks on its public AJAX actions. This flaw permits unauthenticated users to access and retrieve draft and unapproved listings that belong to other users, creating potential privacy and data exposu...
Discovered 20 hours ago
PoC for CVE-2026-91003
A security issue has been identified in the D-Link DI-8300 16.07, specifically within the CGI Service. The vulnerability resides in the function 'rzgl_asp' found in the '/rzgl.asp' file. An improper manipulation of the 'redirct_url' argument can trigger a stack-based buffer overflow. This flaw op...
PoC for CVE-2026-91002
A vulnerability has been detected in Stamparm Maltrail prior to version 3.1, specifically in the Blacklist Endpoint's _blacklist function located in core/httpd.py. This security flaw permits unauthorized users to manipulate the endpoint, leading to missed authentication checks. An attacker could ...
PoC for CVE-2026-91001
A security vulnerability has been identified in the D-Link DI-8400 router, specifically within the DDNS Configuration component. This vulnerability arises from a stack-based buffer overflow due to improper handling of the ddns_asp function located in the file /ddns.asp. A remote attacker can expl...
PoC for CVE-2026-90881
A vulnerability exists in the D-Link DIR-882 router affecting versions up to 20260814, specifically within the CGI Binary component in the 'dllog.cgi' file. This flaw allows for unauthorized information disclosure, making it possible for attackers to manipulate the system remotely. The exploit de...
Discovered 21 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-90880
A security flaw has been identified in the D-Link DSL-3782 router that permits remote command injection through the Diagnostics component. This vulnerability stems from improper handling of the Addr argument in the Diagnostics.asp script, allowing unauthorized execution of commands. Attackers can...
PoC for CVE-2026-90879
A SQL injection vulnerability has been discovered in zyx0814 FilePress, specifically within the Publish Module's search functionality. The flaw arises from improper handling of arguments in the search.php file, potentially allowing attackers to manipulate input parameters, resulting in unauthoriz...
PoC for CVE-2026-90878
A resource consumption vulnerability exists in vLLM by vllm-project, specifically affecting the Jinja Template Rendering component within the chat/completions endpoint. Attackers can exploit this vulnerability remotely by manipulating the chat_template argument, leading to significant resource de...
PoC for CVE-2026-90877
A security issue has been identified in the SourceCodester Online Faculty Clearance System version 1.0, where improper handling of the 'haydi' parameter in the /update_requirement_status.php file allows for SQL injection. This vulnerability can be exploited remotely, potentially compromising data...
Discovered 22 hours ago
PoC for CVE-2026-90876
A security vulnerability has been identified in SourceCodester's Online Faculty Clearance System version 1.0 that exposes the /delete_requirement.php file. This vulnerability arises from improper handling of user input, allowing attackers to manipulate the 'ID' argument. As a result, an SQL injec...
PoC for CVE-2026-90858
A vulnerability has been identified in the online clinic management system developed by Subhajitkhan, specifically in the 'session_start' function located in adminappview.php. This flaw arises from an improper handling of the 'adminmail' argument, which can allow attackers to bypass authenticatio...
PoC for CVE-2026-90857
A vulnerability exists in the SourceCodester College Notes Gallery Management System version 1.0 within an unspecified function of the /dashboard/userprofile.php file, part of the Profile Upload component. The vulnerability allows for an unrestricted file upload if an attacker manipulates the ima...
PoC for CVE-2026-90856
A security vulnerability has been identified in the College Notes Gallery Management System, specifically in the signup.php file within the Registration Flow component. This vulnerability allows for improper privilege management due to manipulation of the 'role' argument. Attackers can exploit th...
Discovered 23 hours ago
PoC for CVE-2026-90852
A vulnerability in Luben zstd-jni affects the ZstdCompressCtx.loadDict function within the Dictionary Sharing component, leading to potential use after free scenarios. The vulnerability can be exploited by an attacker remotely, allowing them to manipulate memory usage adversely. Immediate upgrade...
PoC for CVE-2026-90851
A security flaw has been identified in the PHPGurukul Hostel Management System 3.0, specifically within the /admin/includes/checklogin.php file. This issue arises from improper handling of the argument ID, which leads to inadequate access controls. As a result, an attacker may exploit this vulner...
Discovered 1 day ago
PoC for CVE-2026-90850
A cross site scripting vulnerability has been identified in PHPGurukul Hostel Management System version 3.0, specifically in the manage-students.php file. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser. The attack can be i...