Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-82222
A deserialization vulnerability exists in the GiveWP plugin, allowing unsanitized user input to manipulate object states and trigger remote code execution. This issue can lead to unauthorized actions being performed on the server, potentially impacting sensitive data and system integrity. The aff...
PoC for CVE-2026-82222
A deserialization vulnerability exists in the GiveWP plugin, allowing unsanitized user input to manipulate object states and trigger remote code execution. This issue can lead to unauthorized actions being performed on the server, potentially impacting sensitive data and system integrity. The aff...
Discovered 2 hours ago
PoC for CVE-2026-82485
A security vulnerability in the itsourcecode Sales and Inventory System 1.0 has been identified in the pro_edit.php file. This vulnerability allows an attacker to manipulate the ID parameter, leading to potential SQL injection attacks. Such vulnerabilities may enable unauthorized access to sensit...
PoC for CVE-2026-82484
A vulnerability exists in the itsourcecode Sales and Inventory System 1.0, where the /pages/emp_searchfrm.php file is susceptible to SQL injection via an improper handling of the ID argument. This flaw allows an attacker to execute arbitrary SQL commands, potentially exposing sensitive database i...
Discovered 3 hours ago
PoC for CVE-2026-45071
The Symfony PHP framework has a vulnerability in its Crawler component due to improper handling of XML content. Specifically, prior to versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the method Crawler::addXmlContent() enabled DOMDocument::$validateOnParse, allowing for external entity resolution. T...
PoC for CVE-2026-82483
A vulnerability in Coppermine Photo Gallery affects versions up to 1.6.28, specifically impacting the db_input.php file within the Hidden Album Update Endpoint. This vulnerability enables attackers to execute cross site scripting attacks remotely, potentially compromising user data and site integ...
Discovered 5 hours ago
PoC for CVE-2026-82482
A security vulnerability has been identified in Coppermine Photo Gallery, affecting versions up to 1.6.28. This vulnerability resides in the 'edit_profile' endpoint, specifically in the 'profile.php' file, where improper handling of the 'Biography' argument allows for Cross Site Scripting (XSS) a...
PoC for CVE-2026-81660
The Groundhogg CRM, Newsletters, and Marketing Automation WordPress plugin prior to version 4.5.13 fails to properly validate and escape values received from optional web form fields. This flaw enables unauthenticated attackers to execute Stored Cross-Site Scripting (XSS) attacks, potentially com...
PoC for CVE-2026-81766
The Really Simple Security WordPress plugin, prior to version 9.8.0, allows administrators of subsites within a multisite network to execute arbitrary code. This is due to the absence of checks ensuring that the user is permitted to install the plugin, which compromises the security of the direct...
PoC for CVE-2026-19722
The WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.133 is susceptible to an arbitrary file write vulnerability. This issue arises as the plugin fails to properly validate the destination paths for files extracted from backup packages during restoration. As a result,...
PoC for CVE-2026-76585
The Customer Reviews for WooCommerce plugin prior to version 5.118.0 has a vulnerability that fails to properly sanitize and escape customer review content submitted through its endpoints. This oversight enables unauthenticated users to potentially launch Stored Cross-Site Scripting (XSS) attacks...
PoC for CVE-2026-78364
The MW WP Form plugin for WordPress prior to version 5.1.6 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient sanitization and escaping of its form settings. This loophole allows users with Editor permissions to potentially execute malicious scripts in the con...
PoC for CVE-2026-14307
The GeotargetingWP plugin for WordPress versions prior to 3.5.6.2 is susceptible to cross-site scripting attacks due to inadequate sanitization and escaping of certain parameters in AJAX responses served with an HTML content type. This vulnerability enables unauthenticated attackers to inject mal...
PoC for CVE-2026-14835
The SOGO Add Script to Individual Pages Header Footer plugin for WordPress allows users with contributor-level access and above to insert unverified JavaScript code into the post metadata. This occurs because the plugin does not adequately sanitize or escape custom header/footer script values. As...
Discovered 12 hours ago
PoC for CVE-2026-82424
A security flaw has been discovered in the PHPGurukul Student Information System version 1.0, specifically in the /student_edit1.php file. This vulnerability arises due to improper handling of the ID argument, allowing attackers to execute SQL injection attacks remotely. The exploit has been publ...
PoC for CVE-2026-23989
The Reva interoperability platform from OpenCloud contains a vulnerability in the GRPC authorization middleware that allows malicious users to bypass scope verification associated with public links. This flaw can be exploited through the archiver service to create archives (zip or tar files) cont...
Discovered 13 hours ago
PoC for CVE-2026-82422
A security flaw has been identified in the itSourceCode Sales and Inventory System 1.0, specifically within an unknown function in the file /pages/emp_del.php. This vulnerability is exploited by manipulating the argument ID, which can lead to SQL injection attacks. As the exploit code is publicly...
Discovered 14 hours ago
PoC for CVE-2026-82421
A vulnerability has been identified in the itsourcecode Sales and Inventory System 1.0 concerning improper handling of the argument ID in the file /pages/emp_edit.php. This flaw allows an attacker to manipulate SQL queries, potentially leading to unauthorized access and data manipulation. The exp...
Discovered 16 hours ago
PoC for CVE-2022-38694
The vulnerability occurring in UNISOC's BootRom allows a possible unchecked write address, enabling local escalation of privilege without requiring additional execution privileges. This flaw poses a significant security risk, as it can be exploited by malicious actors to gain unauthorized access ...
Discovered 18 hours ago
PoC for CVE-2026-82473
The KubeEdge CloudCore component, up to version 1.23.1, is vulnerable to an authentication bypass that allows attackers to submit node task status reports without any authentication. This flaw is exploitable via the HTTPS service on port 10002, enabling unauthorized users to manipulate the percei...
Discovered 22 hours ago
PoC for CVE-2026-4001
The Woocommerce Custom Product Addons Pro plugin for WordPress has a vulnerability that allows Remote Code Execution due to insufficient sanitization of user inputs. Specifically, in the process_custom_formula() function, user-defined custom pricing formulas are not properly validated before bein...
Discovered 1 day ago
PoC for CVE-2026-82286
The gpt-crawler, up to version 1.5.1, contains a significant flaw in its handling of the outputFileName parameter in the POST /crawl endpoint. This vulnerability permits unauthenticated users to write arbitrary files to any location within the filesystem. By providing carefully crafted input that...
PoC for CVE-2026-81346
The Frontend Admin plugin developed by DynamiApps suffers from an improper authorization vulnerability due to the absence of a capability check on certain AJAX actions. This flaw permits any authenticated user, including subscribers, to delete arbitrary membership plans. As a result, this vulnera...
PoC for CVE-2026-80488
The WP Ultimate CSV Importer plugin for WordPress prior to version 9.0 has a vulnerability that arises from improper sanitization and escaping of imported field values. This flaw can be exploited by high-privilege users, such as administrators, allowing them to execute arbitrary SQL commands. Suc...
PoC for CVE-2026-80311
The Stripe Payment Forms plugin by WP Full Pay for WordPress contains a vulnerability that allows an authenticated user to cancel subscriptions that do not belong to them. This oversight occurs due to the lack of proper verification to confirm that a subscription is associated with the requesting...
PoC for CVE-2026-81200
The MasterStudy LMS WordPress Plugin prior to version 3.7.42 contains an access control vulnerability that allows users with the instructor role to access sensitive order information of other users. This includes data such as names, email addresses, phone numbers, and postal addresses by simply e...
PoC for CVE-2026-81342
The MasterStudy LMS WordPress plugin prior to version 3.7.43 contains a vulnerability that fails to properly validate redirect parameters during user registration. This flaw permits unauthenticated users to manipulate the registration process, enabling them to redirect legitimate users to potenti...
PoC for CVE-2026-81026
The MasterStudy LMS WordPress Plugin, prior to version 3.7.40, contains a critical vulnerability where payment notifications are not adequately verified. This flaw allows unauthenticated users to mark full-price orders as completed without proper validation of payment details like amount, receive...
PoC for CVE-2026-77008
The HEL Online Classroom plugin for WordPress, up to version 1.0.3, lacks proper authorization and authentication checks when saving settings. This oversight allows unauthorized individuals to alter the configuration, potentially rerouting online classrooms and compromising the integrity of sessi...
PoC for CVE-2026-77012
The 爱采集数据采集和发布 plugin for WordPress is vulnerable due to its unauthenticated endpoints that use a hardcoded default secret. This flaw permits unauthorized attackers to execute file reading operations, send arbitrary requests, and write content outside designated upload paths, which significantly ...
PoC for CVE-2026-77704
The Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.9 features an authorization vulnerability that allows users to change appointment statuses without proper capability checks. This flaw enables customers to set arbitrary statuses on their bookings, includin...
PoC for CVE-2026-77010
The HEL Online Classroom plugin for WordPress prior to version 1.0.3 lacks proper authorization checks on its REST API routes. This oversight permits unauthenticated users to acquire a signed join link for any classroom, even those secured with an access code. Such vulnerabilities allow unauthori...
PoC for CVE-2026-77786
The Rank Math SEO WordPress plugin, prior to version 1.0.277, contains a flaw in permissions handling. This vulnerability allows users with the Editor role to initiate automated SEO fixes without the necessary privileges, enabling them to alter site-wide core WordPress settings. Such unauthorized...
PoC for CVE-2026-77007
The HEL Online Classroom plugin for WordPress, specifically version 1.0.3, is susceptible to a critical security vulnerability that lacks proper authorization checks on a REST API route. This oversight enables unauthenticated users to access sensitive configuration settings, including a shared se...
PoC for CVE-2026-76586
The Appointment Booking Calendar and Scheduling plugins for WordPress prior to version 1.6.3 exhibit a serious issue where the actual payment amount is not verified against the expected server-side price during the online payment confirmation process. This flaw enables unauthenticated users to se...
PoC for CVE-2026-19430
The Catfolders Document Gallery Pro plugin for WordPress prior to version 2.0.7 exposes REST API routes without proper authorization. This issue allows unauthorized users to generate a forgeable token, enabling them to list and download unpublished folder contents, thereby compromising the privac...
PoC for CVE-2026-18234
The MStore API plugin for WordPress prior to version 4.21.1 contains a significant vulnerability in its payment handling mechanism. It fails to verify the ownership of the orders being processed, allowing any authenticated user, including those with minimal roles such as Subscribers, to manipulat...
PoC for CVE-2026-76546
The User Profile Builder plugin for WordPress, prior to version 4.0.1, contains a vulnerability due to insufficient output escaping of its optional shortcode. This flaw could allow users with contributor privileges to execute Stored Cross-Site Scripting (XSS) attacks. Any user viewing the affecte...
PoC for CVE-2026-76547
The User Profile Builder WordPress plugin prior to version 4.0.1 exhibits a flaw in its deserialization process, failing to properly validate the data when importing configuration files. This vulnerability enables high privilege users, such as administrators, to potentially perform PHP Object Inj...
PoC for CVE-2026-76548
The User Profile Builder plugin for WordPress prior to version 4.0.1 features a misconfiguration in its front-end file upload functionality. This oversight permits unauthenticated users to upload files, a privilege typically restricted to user roles with higher access rights. As a result, these u...
PoC for CVE-2026-17520
The Newsletters plugin for WordPress, prior to version 4.17, is susceptible to a vulnerability that arises from the inadequate randomness in its API key generation process. The API key is derived from a publicly known value, which allows unauthenticated attackers to predict the key. This opens th...
PoC for CVE-2026-18233
The MStore API WordPress plugin prior to version 4.21.1 contains a critical flaw that allows authenticated users, including those with subscriber roles, to manipulate order statuses. Specifically, the plugin does not adequately verify whether the orders accessed through its delivery endpoints bel...
PoC for CVE-2026-17522
The Newsletters WordPress plugin prior to version 4.17 is susceptible to a Cross-Site Request Forgery (CSRF) attack due to the absence of nonce or capability checks when saving settings. This oversight allows logged-in attackers to overwrite arbitrary settings, including sensitive API credentials...
PoC for CVE-2026-16947
The Total Processing plugin for WooCommerce versions up to 7.3 has a significant security flaw that allows attackers to exploit improper path validation. This vulnerability enables unauthenticated users to craft malicious server-side requests, leading to the potential redirection of verification ...
PoC for CVE-2026-16600
The SmartAIPress plugin, utilized in WordPress environments, lacks adequate security checks on certain AJAX actions and fails to validate user-supplied URLs. This oversight permits users with subscriber-level access and above to manipulate the site into fetching arbitrary URLs, both internal and ...
PoC for CVE-2026-16259
The Uix UserCenter plugin for WordPress fails to verify that the account being modified through an unauthenticated profile-update action is associated with the requester. This vulnerability arises from a hardcoded signing key used for token authentication that remains the same across all installa...
PoC for CVE-2026-10522
The MemberHero plugin for WordPress, up to version 6.9, suffers from a serious security issue where it fails to properly restrict the fields that can be provided during the frontend registration process. This oversight allows unauthorized users to create new accounts with arbitrary roles, includi...
PoC for CVE-2026-16061
The Rest Routes plugin for WordPress, specifically versions up to 5.5.5, contains a significant security flaw where user input from a public REST route is not properly sanitized or validated. As a result, this oversight could allow unauthenticated attackers to inject malicious SQL queries, potent...
PoC for CVE-2026-66384
An authenticated user can exploit a specific condition in JFrog Artifactory, allowing them to write data outside the designated Docker cache path when using remote repositories. This could lead to unintended data exposure and potential integrity issues within the environment, necessitating immedi...