Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 3 hours ago
PoC for CVE-2026-105315
A security issue has been identified in django-haystack versions up to 3.3.0, specifically in the _to_python function found in the haystack/backends/elasticsearch_backend.py file. The vulnerability arises from improper handling of the 'result_class' argument, potentially allowing for the executio...
PoC for CVE-2011-2523
A serious backdoor vulnerability was discovered in vsftpd 2.3.4, affecting downloads made between June 30 and July 3, 2011. This vulnerability allows an attacker to exploit the software and open a remote shell on port 6200/tcp, granting unauthorized access to the system. It poses significant risk...
Discovered 4 hours ago
PoC for CVE-2026-86881
A vulnerability affecting various Apple products has been identified, relating to a flaw in certificate validation procedures. This issue, linked to compromised intermediate certificate authorities, allows attackers to potentially issue certificates with arbitrary extended key usages, undermining...
Discovered 5 hours ago
PoC for CVE-2026-105291
A security flaw has been detected in the feelcrm-os 1.0.0 product from FeelEC, specifically within the GroupController::index function in 'App/Feelcrm/Index/Controller/GroupController.class.php'. This issue arises from improper handling of the 'keyword' argument, allowing for remote cross site sc...
PoC for CVE-2026-105290
A vulnerability in Feelec-Yishu's FeelCRM version 1.0.0 arises from a flaw in the getCurlData endpoint found in the GoogleController.class.php file. This issue permits an attacker to manipulate the URL argument, potentially leading to unauthorized server-side request forgery (SSRF). Due to the na...
PoC for CVE-2026-105289
A vulnerability in the FeelCRM OS version 1.0.0 was identified that enables Cross-Site Scripting (XSS) through the customer_form[remark] parameter. This issue resides within the htmlspecialchars_decode function located in the App/Feelcrm/Common/Model/CrmDefineFormModel.class.php file of the Creat...
Discovered 6 hours ago
PoC for CVE-2026-105288
A security flaw exists in the feelec-yishu feelcrm-os 1.0.0 version, specifically within the IndexController::index function located in the App/ThinkPHP/Common/functions.php file. This vulnerability allows attackers to manipulate the redirect_url argument, potentially leading to cross site script...
PoC for CVE-2026-105287
A vulnerability has been identified in the Feelcrm-os version 1.0.0, specifically within the getMemberByGroups endpoint located in AjaxRequestController.class.php. The flaw arises from improper handling of input parameters, which allows for SQL injection attacks that can be executed remotely. The...
PoC for CVE-2026-40281
The Gotenberg PDF API, a Docker-based tool for PDF file processing, has a significant vulnerability affecting versions 8.30.1 and earlier. It allows unauthenticated attackers to exploit the metadata write endpoint, which inadequately sanitizes metadata values. By including a newline character in ...
PoC for CVE-2026-105286
A vulnerability has been identified in the Totolink A3002MU product, specifically in the File Upload Handler's function sub_44B250. This issue allows for path traversal due to improper handling of the 'filename' argument, enabling attackers to remotely manipulate file uploads. The flaw is now pub...
PoC for CVE-2026-105285
A vulnerability has been identified in Totolink A3002MU that allows for remote exploitation through a stack-based buffer overflow in the QoS Rule Handler. The issue arises from improper handling of user input in the /boafrm/formIpQoS function, specifically when manipulating arguments such as addQ...
Discovered 7 hours ago
PoC for CVE-2026-105284
A vulnerability has been discovered in the Totolink A3002MU router related to the Authentication Check component. An issue exists in the function sub_40FCFC within the /bin/boa file that allows unauthorized remote manipulation. This vulnerability could enable attackers to bypass authorization che...
PoC for CVE-2026-105254
An SQL injection vulnerability has been discovered in the itsourcecode Online Admission System version 1.0. This flaw resides in an unspecified function located in the file /admin/schoolyear.php, where manipulation of the 'sy' argument enables unauthorized SQL commands to be executed. The vulnera...
PoC for CVE-2026-105253
A significant vulnerability exists in itsourcecode's Online Admission System Project 1.0, specifically in the /admin/login1.php file. An attacker can exploit improper handling of the User argument to execute SQL injection attacks remotely. This vulnerability allows unauthorized interference with ...
Discovered 8 hours ago
PoC for CVE-2026-105314
The Papermerge version 3.5.3 is susceptible to a remote code execution vulnerability due to improper handling of directory traversal within the /api/documents/upload endpoint. A standard user can exploit this flaw to write malicious Python .pth files to the site-packages directory. When the Pytho...
Discovered 9 hours ago
PoC for CVE-2026-105247
A SQL injection vulnerability exists in the SourceCodester Online Reviewer Management System version 1.0, specifically in the file /reviewer_0/admins/assessments/Subject/btn_functions.php. An attacker can exploit this vulnerability by manipulating the 'Subject' argument, allowing for unauthorized...
PoC for CVE-2026-105246
A vulnerability exists in the SourceCodester Online Reviewer Management System 1.0, specifically in the file /reviewer_0/admins/assessments/Subject/btn_functions.php. Through improper handling of input in the action parameter for 'update', an attacker can manipulate the argument 'Subject' to exec...
PoC for CVE-2026-105245
A vulnerability exists in sgl-project sglang that allows an attacker to exploit the server_info function in the HTTP Endpoint. This issue arises from improper handling of the api_key argument, which can result in sensitive information being transmitted in cleartext. The vulnerability is present i...
PoC for CVE-2026-105238
A vulnerability exists in ChatGPTNextWeb's NextChat application, specifically in the proxyHandler function of the app/api/proxy.ts file. This flaw arises from improper handling of the 'x-base-url' argument, which allows attackers to perform server-side request forgery. This can be exploited remot...
Discovered 10 hours ago
PoC for CVE-2026-13607
The File Uploads Addon for WooCommerce, Version 1.7.6, poses a risk by allowing customer-uploaded files to be stored in a publicly accessible uploads directory. The addon attempts to restrict access to these files; however, this restriction is not effectively enforced. Consequently, an unauthenti...
PoC for CVE-2026-84169
The UPI QR Code Payment Gateway Plugin for WordPress, up to version 1.4.3, is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated attackers to manipulate payment-confirmation requests, enabling them to falsely mark any order as paid without completing the payme...
PoC for CVE-2026-78371
The File Uploads Addon for WooCommerce prior to version 1.7.6 is susceptible to an improper authorization issue. The plugin fails to ensure that the requester of a customer-uploaded file is indeed the customer who uploaded it. This oversight allows unauthenticated attackers to potentially downloa...
PoC for CVE-2026-105237
A vulnerability exists in Linlinjava Litemall that allows for improper management of excessive authentication attempts at the Login Endpoint. This issue resides within the AdminAuthController.java file, potentially enabling remote attackers to cause a denial of service through excessive login att...
PoC for CVE-2026-105233
An identified vulnerability within the Kishor-23 food-waste-management-system's login functionality in login.php allows for session fixation attacks through manipulation of the PHPSESSID parameter. This flaw enables remote attackers to hijack user sessions, posing a significant security risk. The...
PoC for CVE-2026-105232
A vulnerability has been identified in the Kishor-23 Food Waste Management System's registration page, specifically within the deliverysignup.php file. This flaw allows for SQL injection via manipulated username, email, or location parameters, enabling remote attacks. Details have been disseminat...
PoC for CVE-2026-105231
A vulnerability has been identified in the Kishor-23 Food Waste Management System, specifically within the Admin Registration component in the admin/signup.php file. This vulnerability allows for SQL injection through the manipulation of parameters such as email, username, and location. Attackers...
Discovered 11 hours ago
PoC for CVE-2026-105230
A security flaw has been identified in the Kishor-23 Food Waste Management System, specifically in the deliverymyord.php file. The vulnerability arises from the insecure handling of parameters like delivery_person_id and order_id, which allows for SQL injection attacks. This flaw can be exploited...
PoC for CVE-2026-105229
A vulnerability has been discovered in the kishor-23 food-waste-management-system, specifically within the User Registration Endpoint located in the signup.php file. This vulnerability allows attackers to exploit parameters such as email, name, and gender to perform SQL injection attacks remotely...
PoC for CVE-2026-105226
A code injection vulnerability has been identified in the Newsletter Management module of osCommerce versions up to 2.3.4.1. This security flaw resides in the 'include' function within the admin/newsletters.php file. By manipulating the argument module, an attacker can potentially execute remote ...
PoC for CVE-2026-105225
A code injection vulnerability has been identified in the osCommerce osCommerce2 Payment Page feature, specifically in the 'include' function of the 'includes/classes/payment.php' file. This vulnerability arises from improper handling of the MODULE_PAYMENT_INSTALLED argument, allowing attackers t...
Discovered 12 hours ago
PoC for CVE-2026-105188
A vulnerability exists in the Human Resource Management System (HRMS) 1.0 developed by Code-Projects, specifically within the Live Event History component located at /views/admin/liveEventHistory.php. This issue allows for remote exploitation through the manipulation of the 'eventSubject' paramet...
PoC for CVE-2026-105187
A vulnerability exists within the itsourcecode Online Admission System version 1.0 that allows for SQL injection through the manipulation of the 'ID' parameter in the /admin/key.php file. This vulnerability can be exploited by attackers remotely, potentially leading to unauthorized access to sens...
PoC for CVE-2026-105186
A security flaw exists in the itsourcecode Online Admission System 1.0 affecting the function located in /new.php. By manipulating the argument 'schedid', an attacker can execute a SQL injection attack, allowing unauthorized access to the database. This vulnerability can be exploited remotely, po...
PoC for CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform ope...
PoC for CVE-2026-105185
A SQL injection vulnerability exists in the itsourcecode Online Admission System 1.0, specifically affecting the /admin/examinee.php file. Malicious actors can manipulate the 'ID' argument, enabling unauthorized remote access to the database. This flaw may lead to data leakage, corruption, or fur...
Discovered 13 hours ago
PoC for CVE-2026-105184
A security flaw has been identified in the itsourcecode Online Admission System, specifically within the /admin/creteria.php file. This vulnerability arises due to improper handling of user input, allowing remote attackers to manipulate the argument ID. Such exploitation can lead to SQL injection...
PoC for CVE-2026-105183
A SQL injection vulnerability has been found in the itsourcecode Online Admission System 1.0, specifically affecting the /admin/confirm.php file. The vulnerability allows an attacker to manipulate the argument 'schedid', enabling unauthorized SQL commands to be executed remotely. This could poten...
PoC for CVE-2026-105182
A security flaw exists in the SourceCodester Online Reviewer Management System’s admin panel, specifically within the handling of update actions in the file /reviewer_0/admins/assessments/activities/btn_functions.php. The vulnerability allows attackers to manipulate the input parameter 'Title', l...
PoC for CVE-2026-13247
The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase plugin for WordPress contains a vulnerability that allows stored cross-site scripting due to insufficient input sanitization and output escaping in the 'lgx_tooltip_position' parameter. This flaw enables authenticated attackers ...
PoC for CVE-2026-105181
A security flaw has been discovered in the itsourcecode Online Admission System, specifically within the register1.php file. The vulnerability arises from improper processing of the filename parameter, allowing an attacker to execute SQL injection attacks remotely. This vulnerability can be explo...
Discovered 14 hours ago
PoC for CVE-2026-105180
A vulnerability in Jeebase version 0.0.1 affects the updateUser function within the UserService component. This flaw allows unauthorized manipulation of the user/tempUser argument, leading to dynamic determination of object attributes. This exploitation can be executed remotely, posing a signific...
Discovered 15 hours ago
PoC for CVE-2026-105173
A vulnerability exists in version 1.0 of Human Resource Management developed by Code-Projects, specifically in the Event Creation component located at /humanresourcemanagementsystem/src/store/EventStore.php. The flaw allows for exploitation through improper handling of the eventSubject argument, ...
Discovered 16 hours ago
PoC for CVE-2026-105171
A security vulnerability has been identified within the kishor-23 food-waste-management-system that affects the admin/admin.php file associated with the Role Attribute Handler component. This flaw allows an attacker to manipulate the argument Name, potentially bypassing authorization checks. The ...
PoC for CVE-2026-105170
A vulnerability has been discovered within the Kishor-23 food waste management system, specifically affecting the admin/signup.php file. This flaw enables unauthorized access due to a missing authentication mechanism when manipulating the signup argument. Attackers can exploit this weakness remot...
PoC for CVE-2026-103355
A SQL Injection vulnerability has been identified in the Unlimited Elements for Elementor plugin, specifically affecting versions from n/a through 2.0.20. This flaw allows attackers to execute unauthorized SQL commands, potentially leading to data exposure. Proper input validation is critical to ...
PoC for CVE-2026-105169
A security issue has been uncovered in the Kishor-23 Food Waste Management System, specifically in the Take Order Handler's delivery.php file. The vulnerability arises from improper handling of parameters such as order_id and delivery_person_id, leading to potential SQL injection attacks. This fl...
Discovered 17 hours ago
PoC for CVE-2026-105168
A SQL injection vulnerability has been detected in the Order Assignment Block of the kishor-23 food-waste-management-system. The issue arises from the manipulation of the 'order_id' and 'delivery_person_id' parameters in the 'admin.php' file. This flaw enables attackers to exploit the system remo...
PoC for CVE-2026-105167
A security flaw exists in the Kishor-23 Food Waste Management System, specifically in the admin/donate.php file, where an unprotected function allows for SQL injection through manipulation of the 'location' argument. This vulnerability can be exploited remotely, enabling attackers to execute arbi...
PoC for CVE-2026-105166
A SQL injection vulnerability exists in the Food Donation Form within the Kishor-23 Food Waste Management System, specifically in the insert function of the fooddonateform.php file. This flaw arises from improper handling of user inputs, particularly the 'image-choice' argument. Attackers can exp...
Discovered 20 hours ago
PoC for CVE-2026-92084
The Beaver Builder Page Builder plugin for WordPress contains a vulnerability that permits unauthenticated attackers to execute arbitrary shortcodes. This flaw arises from insufficient validation of values prior to processing do_shortcode, notably within pages that leverage the Sidebar module. At...