Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 4 hours ago

PoC for CVE-2026-105145

WeaviateVerba6.9MEDIUM
Information Disclosure in Weaviate Verba by Seeker

A vulnerability exists in Weaviate Verba versions up to 2.1.3, particularly within the get_environment function of the generate_stream Endpoint, located in goldenverba/components/util.py. This flaw enables remote attackers to potentially expose sensitive information, leading to unauthorized acces...

Discovered 6 hours ago

PoC for CVE-2025-60787

MotionEye ProjectMotionEye🟣 EPSS 18%7.2HIGH
OS Command Injection Vulnerability in MotionEye by MotionEye Project

MotionEye versions up to and including 0.43.1b4 are susceptible to OS Command Injection through improperly sanitized configuration parameters like image_file_name. This vulnerability allows remote authenticated users with administrative privileges to inject malicious commands into Motion configur...

PoC for CVE-2026-27944

0xjackyNginx-ui9.8CRITICAL
Authentication Bypass in Nginx UI Affects Nginx Web Server

Nginx UI, a web interface for the Nginx web server, has a critical security flaw where the /api/backup endpoint is accessible without authentication. This vulnerability allows unauthenticated attackers to retrieve a complete system backup that includes sensitive information such as user credentia...

PoC for CVE-2026-105137

LaradockLaradock2.3LOW
Remote Code Download Vulnerability in Laradock Build Process

A vulnerability exists in the Laradock Build Process, specifically related to an unknown function in the workspace/Dockerfile file. This flaw allows an attacker to download code without performing integrity checks. The attack can be executed remotely, posing a significant risk to systems utilizin...

PoC for CVE-2026-103956

AwsLoom10CRITICAL
Authentication Flaw in Loom for AWS Affects AWS Services

An authentication flaw in Loom for AWS versions prior to 1.6.1 exposes the system to unauthorized remote actors. This vulnerability enables such actors to gain super-admin access to the agent control plane, allowing them to register tool servers, access stored integration credentials, and alter I...

Discovered 7 hours ago

PoC for CVE-2026-105135

InternlmMindsearch10CRITICAL
Code Injection Vulnerability in InternLM MindSearch Product by Inte...

A code injection vulnerability exists in InternLM MindSearch version 0.1.0, specifically within the ExecutionAction.run function located in the mindsearch/agent/graph.py file. This vulnerability allows attackers to manipulate input arguments, leading to remote code execution. The potential exploi...

PoC for CVE-2024-51482

ZoneminderZoneminder🟣 EPSS 37%10CRITICAL
ZoneMinder vulnerable to SQL Injection, fix released in 1.37.64

ZoneMinder, a popular open-source closed-circuit television software, has a vulnerability that exposes versions v1.37.* up to and including v1.37.64 to a boolean-based SQL injection attack through the web/ajax/event.php endpoint. This flaw can allow an attacker to manipulate SQL queries, potentia...

PoC for CVE-2026-97332

WordPressUser Private Files
Insufficient File Protection in User Private Files Plugin for WordP...

The User Private Files plugin for WordPress, prior to version 2.2.0, suffers from an access control issue on multisite installations. The plugin fails to enforce access restrictions on private files, as the essential rewrite rule for routing file requests and conducting access checks is not execu...

PoC for CVE-2026-86817

WordPressFive Star Business Pro...
Sensitive Data Exposure in Five Star Business Profile Plugin for Wo...

The Five Star Business Profile and Schema WordPress plugin prior to version 2.4.0 is susceptible to a flaw that improperly controls the callbacks for resolving default values in schema fields. This weakness enables authenticated users with Author-level permissions or higher to insert values that ...

PoC for CVE-2026-104118

WordPressRazorpay For WooCommerce
Unauthorized Access Vulnerability in Razorpay for WooCommerce Plugin

The Razorpay for WooCommerce plugin prior to version 4.8.8 contains a vulnerability that allows unauthenticated users to bypass ownership checks on a REST API route. As a result, attackers can manipulate shipping information for arbitrary orders during the checkout process, posing a significant r...

PoC for CVE-2026-93549

WordPressCocart
Cross-Site Request Forgery Vulnerability in CoCart WordPress Plugin

The CoCart plugin for WordPress prior to version 4.9.7 lacks adequate REST API authentication filtering on its endpoints. This oversight circumvents the built-in nonce protection of WordPress, making the system vulnerable to cross-site request forgery attacks. An attacker can exploit this vulnera...

PoC for CVE-2026-104119

WordPressSimple Shopping Cart
Stored Cross-Site Scripting Vulnerability in Simple Shopping Cart P...

The Simple Shopping Cart plugin for WordPress versions prior to 5.2.6 is affected by a vulnerability that results from improper escaping of settings field values when outputting them on the admin settings page. This flaw enables high-privilege users, such as administrators, to execute Stored Cros...

PoC for CVE-2026-17005

WordPressHorizontal Scrolling A...
Stored Cross-Site Scripting Vulnerability in Horizontal Scrolling A...

The Horizontal Scrolling Announcements Plugin for WordPress, up to version 2.6, is vulnerable to Stored Cross-Site Scripting (XSS). This vulnerability arises from insufficient input sanitization and escaping of announcement settings, which are directly outputted into the front-end context. Conseq...

Discovered 10 hours ago

PoC for CVE-2026-105099

Omega SolutionCoinex Crypto5.1MEDIUM
Cross Site Scripting Vulnerability in Omega Solution CoinEx Crypto

A weakness has been detected in the Omega Solution CoinEx Crypto 2025 platform, specifically within the Ticket Attachment Upload component found in the /user/ticket file. This vulnerability allows for manipulation that can lead to cross site scripting (XSS) attacks, which may be executed remotely...

PoC for CVE-2026-105098

Omega SolutionCoinex Crypto5.3MEDIUM
Information Disclosure in Omega Solution CoinEx Crypto 2025 Support...

A critical vulnerability has been identified in the Support Ticket API of Omega Solution CoinEx Crypto 2025. This security flaw allows attackers to manipulate parameters associated with the ticketing system, resulting in unauthorized access to sensitive information. Given that this attack can be ...

Discovered 11 hours ago

PoC for CVE-2026-105097

Omega SolutionCoinex Crypto5.3MEDIUM
Authorization Bypass in Omega Solution CoinEx Crypto Customer Infor...

A security vulnerability has been found in an unknown function of the Omega Solution CoinEx Crypto 2025's Customer Information API, specifically in the /customer-currency/ path. This vulnerability allows an attacker to manipulate the argument ID, resulting in an authorization bypass. This means t...

Discovered 12 hours ago

PoC for CVE-2025-21065

SamsungRetail Mode6.6MEDIUM
Improper Input Validation in Samsung's Retail Mode

A vulnerability exists in Samsung's Retail Mode prior to version 5.59.11 due to improper input validation. This flaw enables self attackers to execute privileged commands on their own devices, which can lead to unauthorized actions and potential compromise of device integrity. It is essential for...

PoC for CVE-2026-39808

FortinetFortisandbox🟣 EPSS 47%9.1CRITICAL
OS Command Injection Vulnerability in Fortinet FortiSandbox

An OS command injection vulnerability exists in Fortinet FortiSandbox versions 4.4.0 through 4.4.8. This flaw arises from improper neutralization of special elements used in operating system commands. An attacker can exploit this vulnerability to execute unauthorized commands, potentially comprom...

PoC for CVE-2026-105096

Omega SolutionCoinex Crypto5.3MEDIUM
Authorization Bypass Vulnerability in Omega Solution CoinEx Crypto ...

A vulnerability has been identified in the Customer Profile API of Omega Solution CoinEx Crypto 2025, stemming from improper handling of the argument ID. This flaw can enable unauthorized remote users to bypass access controls. While the product’s official website is no longer available, indicati...

Discovered 14 hours ago

PoC for CVE-2008-0600

LinuxLinux Kernel
Local Privilege Escalation in Linux Kernel Versions by Vendor

The vmsplice_to_pipe function in the Linux kernel versions 2.6.17 through 2.6.24.1 contains a flaw where it fails to properly validate certain userspace pointers before dereferencing them. This oversight allows local users to exploit the functionality of the vmsplice system call by supplying craf...

Discovered 15 hours ago

PoC for CVE-2026-19660

WordPressDivi Membership9.8CRITICAL
Authentication Bypass Vulnerability in Divi Membership Plugin for W...

The Divi Membership plugin for WordPress has a critical vulnerability that allows unauthenticated attackers to bypass authentication processes, enabling them to log in as any existing user, including administrators. This issue arises from a flaw in how the `process_paypal_callback` function handl...

Discovered 16 hours ago

PoC for CVE-2026-14461

BitwizardMtr5.1MEDIUM
Out-of-Bound Read Vulnerability in MTR Product by Travis Cross

The mtr tool is affected by an Out-of-Bound read vulnerability in the ipinfo_lookup() function, which can be exploited if an attacker manipulates the TXT response used during AS lookups. By delivering a DNS response larger than 512 bytes and incorporating a crafted compression pointer in the answ...

Discovered 18 hours ago

PoC for CVE-2022-0891

LibtiffLibtiff6.1MEDIUM
Heap Buffer Overflow in libtiff Library Affects Multiple Versions

A vulnerability exists within the libtiff library that may allow attackers to exploit a heap buffer overflow through the 'ExtractImageSection' function in 'tiffcrop.c'. By crafting a malformed TIFF image file, an attacker can trigger unsafe or out-of-bounds memory access, which could lead to vari...

Discovered 22 hours ago

PoC for CVE-2026-92592

CraftcmsCms8.7HIGH
Remote Code Execution Vulnerability in Craft CMS by Craft CMS

Craft CMS versions 4.8.0 to 4.18.5 and 5.0.0 to 5.10.12 contain a vulnerability that allows authenticated users to exploit signed cookies. Attackers can manipulate a license-shun cookie, leveraging an improper HMAC key that isn't bound to its intended purpose. By transferring this signed cookie i...

Discovered 1 day ago

PoC for CVE-2026-104983

Linux MintXreader5.3MEDIUM
Path Traversal Vulnerability in Linux Mint Xreader PDF Handler

A path traversal vulnerability exists in the PDF Attachment Saving Handler of Linux Mint's Xreader up to version 4.6.9. This issue arises from improper handling of file paths in the g_file_get_child function, allowing malicious actors to manipulate attachment arguments and access unintended files...

PoC for CVE-2026-96962

WordPressPie Register3.7LOW
Access Control Vulnerability in Pie Register WordPress Plugin

The Pie Register plugin for WordPress prior to version 3.8.4.14 has a significant access control vulnerability that leaves user data exposed. Specifically, this flaw allows unauthenticated users who possess a valid invitation code to access a report containing the usernames and email addresses of...

PoC for CVE-2026-92923

WordPressUnlimited Elements For...6.3MEDIUM
SQL Injection Vulnerability in Unlimited Elements for Elementor Plu...

The Unlimited Elements for Elementor plugin for WordPress prior to version 2.0.21 contains a vulnerability that allows users with minimal privileges (as low as a subscriber) to execute blind SQL injection attacks. This flaw arises from inadequate sanitization and escaping of parameters used in SQ...

PoC for CVE-2026-91078

WordPressTillkit8.2HIGH
Authentication Bypass in TillKit WordPress Plugin by TillKit

The TillKit WordPress plugin, prior to version 1.0.5, creates a privileged POS account with a hard-coded PIN known publicly. This design flaw permits unauthenticated attackers to exploit the public POS login endpoint, gaining access to a privileged POS session without undergoing necessary identit...

PoC for CVE-2026-92437

WordPressMailchimp For WooCommerce5.3MEDIUM
Improper Authentication Vulnerability in Mailchimp for WooCommerce ...

The Mailchimp for WooCommerce plugin prior to version 6.3 contains a vulnerability that permits unauthenticated attackers to manipulate or remove another user's abandoned cart records. This exploit occurs due to the lack of necessary authentication, nonce verification, or ownership checks when ha...

PoC for CVE-2026-89236

WordPressSaveto Wishlist Lite8.6HIGH
SQL Injection Vulnerability in SaveTo Wishlist Lite Plugin by WordP...

The SaveTo Wishlist Lite plugin for WordPress prior to version 1.1.5 contains a security vulnerability that allows unauthenticated attackers to inject malicious SQL code through unsanitized parameters in the ORDER BY clause. This flaw permits attackers to execute arbitrary SQL queries, leading to...

PoC for CVE-2026-94239

WordPressLoco Translate6.8MEDIUM
Stored Cross-Site Scripting Vulnerability in Loco Translate Plugin ...

The Loco Translate WordPress plugin, prior to version 2.8.9, contains a vulnerability that fails to properly sanitize and escape certain bundle configuration values before rendering them in an admin interface. This oversight allows users with translator capabilities and higher to exploit the vuln...

PoC for CVE-2026-94238

WordPressLoco Translate6.8MEDIUM
File Path Exposure in Loco Translate Plugin for WordPress

The Loco Translate plugin for WordPress, prior to version 2.8.9, contains a vulnerability that permits users with translator capabilities to access and read sensitive files from arbitrary paths on the server. This flaw allows unauthorized access to information outside the intended web root, poten...

PoC for CVE-2026-88783

WordPressKubio Ai Page Builder8.8HIGH
HTML Injection Vulnerability in Kubio AI Page Builder by WordPress

The Kubio AI Page Builder plugin for WordPress before version 2.9.3 is susceptible to an HTML injection vulnerability. This flaw arises because the plugin fails to restrict the allowed HTML elements strictly to the editor context. Consequently, when unauthenticated users submit content, the plugi...

PoC for CVE-2026-88782

WordPressKubio Ai Page Builder6.8MEDIUM
Improper URI Validation in Kubio AI Page Builder for WordPress

The Kubio AI Page Builder plugin for WordPress versions prior to 2.9.3 is vulnerable due to improper validation of the URI scheme for user-supplied values. This allows users with roles of contributor and above to store payloads that can be executed in the browsers of anyone who interacts with the...

PoC for CVE-2026-86832

WordPressMetform5.3MEDIUM
Access Control Flaw in MetForm WordPress Plugin by WPMet

The MetForm WordPress plugin, prior to version 4.3.1, contains a security flaw that fails to adequately restrict access to form submission data. This vulnerability allows unauthenticated attackers to exploit the REST API, potentially revealing sensitive user information submitted through the form...

PoC for CVE-2026-86834

WordPressMetform3.7LOW
Unauthorized Access in MetForm WordPress Plugin Allows Data Exposure

The MetForm WordPress plugin prior to version 4.3.1 contains a security flaw that fails to sufficiently restrict access to a debug file created in the web root during form submissions, especially when the HubSpot Forms integration is active. This oversight permits unauthorized attackers to retrie...

PoC for CVE-2026-80517

WordPressWP Ultimate Csv Importer3.5LOW
Stored Cross-Site Scripting Vulnerability in WP Ultimate CSV Import...

The WP Ultimate CSV Importer plugin for WordPress prior to version 9.2 features a significant security flaw. This vulnerability arises from inadequate validation of file types within uploaded archives, coupled with a failure to sanitize their content before storing them in publicly accessible dir...

PoC for CVE-2026-85568

WordPressUnlimited Elements For...6.8MEDIUM
SQL Injection Vulnerability in Unlimited Elements for Elementor Plu...

The Unlimited Elements for Elementor plugin prior to version 2.0.21 is susceptible to an SQL injection vulnerability. This issue stems from an improper handling of search values, which allows unauthenticated users to manipulate SQL statements. If certain widget options are set to values other tha...

PoC for CVE-2026-85015

WordPressUnlimited Elements For...6.6MEDIUM
File Path Vulnerability in Unlimited Elements for Elementor WordPre...

The Unlimited Elements for Elementor plugin prior to version 2.0.21 has a significant flaw where it fails to properly sanitize file paths contained within uploaded archives. This oversight permits authenticated users, typically Administrators or Editors under certain configurations, to exploit th...

PoC for CVE-2026-80518

WordPressWP Ultimate Csv Importer3.7LOW
Insecure File Access in WP Ultimate CSV Importer Plugin

The WP Ultimate CSV Importer plugin for WordPress, prior to version 9.2, presents a security risk by failing to implement a site-specific secret to manage the storage of import logs. This oversight allows unauthenticated attackers to access sensitive user data stored in these logs, which are loca...

PoC for CVE-2026-103514

WordPressWP 2fa7.5HIGH
Bypass of Two-Factor Authentication in WP 2FA Plugin by WordPress

The WP 2FA plugin for WordPress prior to version 4.1.0 allows for a critical security issue where a time-based one-time passcode (TOTP) remains valid even after being used. This flaw enables an attacker with knowledge of a user's password and access to a valid TOTP within its active period to rep...

PoC for CVE-2026-103293

WordPressMpg6.8MEDIUM
Remote File Inclusion in MPG WordPress Plugin by MPG

The MPG WordPress plugin, in versions before 4.2.3, contains a vulnerability where it fails to validate the source of a dataset provided during the import process. Specifically, it allows users with Editor roles and above to manipulate file imports, treating remote URLs as local file paths. This ...

PoC for CVE-2026-101162

WordPressWP Ultimate Review6.4MEDIUM
Stored Cross-Site Scripting Vulnerability in WP Ultimate Review Plugin

The WP Ultimate Review plugin for WordPress prior to version 2.4.4 is vulnerable due to inadequate escaping of review overview settings. This flaw allows users with author permissions to potentially execute stored cross-site scripting attacks, especially when author reviews are enabled. Attackers...

PoC for CVE-2026-101161

WordPressWP Ultimate Review7.5HIGH
Persistent Denial of Service in WP Ultimate Review Plugin by WordPress

The WP Ultimate Review plugin for WordPress, prior to version 2.4.4, is susceptible to exploitation by unauthenticated users. These attackers can submit specially crafted review content that causes the website to generate a fatal error upon each visit. This leads to a persistent denial of service...

PoC for CVE-2026-101160

WordPressWP Ultimate Review7.5HIGH
Numeric Input Validation Flaw in WP Ultimate Review Plugin by WordP...

The WP Ultimate Review WordPress plugin, prior to version 2.4.4, contains a significant input validation vulnerability. It fails to ensure that user-submitted review ratings are numeric before processing them. This oversight allows unauthenticated users to submit malicious input, potentially caus...

PoC for CVE-2026-101159

WordPressWP Ultimate Review7.5HIGH
Stored Cross-Site Scripting Vulnerability in WP Ultimate Review Plu...

The WP Ultimate Review plugin for WordPress, prior to version 2.4.4, fails to adequately sanitize and escape user-generated reviews submitted via its public review form, which is accessible to unauthenticated users. This oversight allows potential attackers to execute stored Cross-Site Scripting ...

PoC for CVE-2026-43284

LinuxLinux8.8HIGH
Vulnerability in Linux Kernel Affects Shared skb Fragments

A vulnerability exists in the Linux kernel that concerns the handling of shared skb fragments during the decryption process in ESP-in-UDP packets. When pages are attached from a pipe directly to an skb using MSG_SPLICE_PAGES, the kernel marked these SKBs with SKBFL_SHARED_FRAG, which plays a cruc...

PoC for CVE-2026-4480

Red HatRed Hat Enterprise Lin...🟣 EPSS 14%9CRITICAL
Samba Printing Subsystem Vulnerability in Samba Software

A vulnerability exists in the Samba printing subsystem that allows remote attackers to execute arbitrary commands on affected systems. The flaw occurs due to improper handling of the client-controlled job description string, which is passed directly to the configured print command without escapin...

Discovered 2 days ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-55559

YamcsYamcs9.8CRITICAL
Yamcs Mission Control Framework Vulnerability in Service Account Ex...

The Yamcs Mission Control Framework is exposed to a vulnerability where template arguments from POST and PATCH requests can be inserted into YAML without proper context escaping. This flaw exists in versions preceding 5.12.8 and 5.13.2. An attacker can exploit this vulnerability to inject malicio...