Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 2 hours ago

PoC for CVE-2026-72898

MetabaseMetabase🟣 EPSS 79%10CRITICAL
SQL Injection Vulnerability in Metabase by Metabase, Inc.

Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...

PoC for CVE-2026-38526

WebkulKrayin CRM9.9CRITICAL
Arbitrary File Upload Vulnerability in Webkul Krayin CRM

An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...

PoC for CVE-2026-19478

GitlabGitlab9.4CRITICAL
Remote Code Modification Vulnerability in GitLab CE/EE

A flaw in GitLab CE/EE allows unauthenticated users to exploit specific GraphQL directives, potentially resulting in unauthorized modification or deletion of public projects and user data. This vulnerability impacts various versions, necessitating immediate user awareness and prompt application o...

Discovered 4 hours ago

PoC for CVE-2026-20303

CiscoCisco Catalyst Sd-wan ...9.9CRITICAL
Improper Input Validation in Cisco Catalyst SD-WAN

Cisco's Catalyst SD-WAN product has been identified with vulnerabilities stemming from improper input validation, as revealed during an internal security review. These issues can potentially expose the system to various security risks, underscoring the importance of implementing software hardenin...

Discovered 5 hours ago

PoC for CVE-2026-77542

Ubiquiti IncUid Enterprise Agent9.1CRITICAL
Improper Input Validation in UID Enterprise Agent by Ubiquiti

A security flaw has been identified in the UID Enterprise Agent developed by Ubiquiti, where improper input validation can be exploited by malicious actors with network access and elevated privileges. This vulnerability enables the execution of command injection on the host device, potentially al...

PoC for CVE-2026-18431

WordPressAvada (fusion) Builder9.8CRITICAL
Avada Theme for WordPress Vulnerable to Arbitrary File Write

The Avada theme for WordPress presents a significant security risk due to an arbitrary file write vulnerability that affects all versions up to 7.16 when paired with an active Fusion Builder plugin (up to version 3.16). This flaw stems from a combination of authorization issues and inadequate inp...

Discovered 6 hours ago

PoC for CVE-2026-81562

AlexgladkovClaude-in-mobile4.8MEDIUM
OS Command Injection Vulnerability in AlexGladkov claude-in-mobile

A security flaw has been identified in AlexGladkov's claude-in-mobile, specifically affecting the execSync function in src/adb/client.ts. This vulnerability allows for OS command injection, requiring local access to the system for exploitation. An upgrade to version 3.10.3 is necessary to mitigat...

PoC for CVE-2026-8467

PhenixdigitalPhoenix Storybook9.5CRITICAL
Code Injection Vulnerability in Phoenix Storybook by Phenix Digital

A vulnerability exists in Phenix Digital's Phoenix Storybook that allows unauthenticated remote code execution due to unsanitized attribute value interpolation during HEEx template generation. The psb-assign WebSocket event handler permits arbitrary attribute names and values from unauthenticated...

Discovered 7 hours ago

PoC for CVE-2026-74233

ZbtlinkWe13269.3CRITICAL
Command Injection Vulnerability in Zbtlink Firmware Products

A security flaw in the Zbtlink firmware for multiple wireless devices allows remote attackers to exploit the infosrvd service via crafted UDP packets. This vulnerability bypasses authentication mechanisms, as it employs a hardcoded salt, enabling unprivileged users to execute arbitrary commands a...

PoC for CVE-2026-81560

BlackmsAistack6.9MEDIUM
Path Traversal in blackms aistack Affecting Static File Handler Fun...

A vulnerability exists in blackms aistack up to version 1.6.1, impacting the Static File Handler component located in src/web/server.ts. This flaw allows for path traversal due to improper handling of the req.url argument, which can be exploited remotely. The exploit code is publicly accessible, ...

Discovered 12 hours ago

PoC for CVE-2026-78333

WordPress12 Step Meeting List
Stored Cross-Site Scripting Vulnerability in 12 Step Meeting List P...

The 12 Step Meeting List WordPress plugin prior to version 3.19.17 allows unauthenticated users to submit unsanitized input, which is stored in the activity log. This input is later displayed back to users in the admin area without adequate escaping, making it possible for an attacker to execute ...

PoC for CVE-2026-77018

WordPressWorkeera
Arbitrary File Upload Vulnerability in Workeera Plugin for WordPress

The Workeera plugin for WordPress prior to version 1.0.6 lacks adequate restrictions on profile value submissions by candidates. It fails to validate the file types uploaded, allowing users with minimal privileges, such as subscribers, to upload arbitrary files. Consequently, this can lead to rem...

PoC for CVE-2026-78138

WordPressFinale Lite
Unauthorized Access Vulnerability in Finale Lite Plugin by WordPress

The Finale Lite plugin for WordPress prior to version 2.21.0 contains a security flaw that allows authenticated users, including those with Subscriber roles and above, to access sensitive campaign configuration data through an unprotected AJAX action. This oversight enables users to retrieve conf...

PoC for CVE-2026-78137

WordPressStoregrowth
Price Manipulation Vulnerability in StoreGrowth Plugin for WordPress

The StoreGrowth WordPress plugin prior to version 2.1.2 is vulnerable due to insufficient validation of browser-supplied product prices on certain unauthenticated actions. This flaw permits attackers to specify arbitrary prices when adding products to the shopping cart, especially when the 'Buy O...

PoC for CVE-2026-77017

WordPressWorkeera
File Access Vulnerability in Workeera WordPress Plugin

The Workeera WordPress plugin versions prior to 1.0.6 allows users with minimal permissions, such as a subscriber, to submit any profile values without restrictions. This lack of input validation leads to unauthorized access where these users can read arbitrary files stored on the server. This in...

PoC for CVE-2026-78125

WordPressLearnpress
REST API Vulnerability in LearnPress Plugin by WordPress

A critical vulnerability in the LearnPress WordPress plugin allows unauthorized attackers to access sensitive information. This flaw exists in the plugin's REST API, where no authorization checks are performed on certain endpoints. As a result, attackers can exploit this weakness to disclose the ...

PoC for CVE-2026-78139

WordPressNotifima
Authorization Bypass Vulnerability in Notifima WordPress Plugin

The Notifima WordPress plugin before version 3.1.4 lacks proper validation of subscription ownership on its REST endpoints. This oversight allows authenticated users with Subscriber-level access to manipulate subscription settings, specifically the ability to unsubscribe any customer from receivi...

PoC for CVE-2026-77016

WordPressWorkeera
File Deletion Vulnerability in Workeera WordPress Plugin Affects Users

The Workeera WordPress plugin prior to version 1.0.6 allows users with minimal permissions, such as subscribers, to delete arbitrary files from the server. This vulnerability arises due to the lack of restrictions on the values that can be written to a user's candidate profile, coupled with inade...

PoC for CVE-2026-76549

WordPressUpdraftplus: WP Backup...
CSRF Vulnerability in UpdraftPlus Backup Plugin for WordPress

The UpdraftPlus: WP Backup & Migration Plugin for WordPress, prior to version 1.26.7, lacks proper CSRF checks in a critical backup management operation. This vulnerability can potentially allow an attacker to trick an authenticated admin into restoring a backup without their consent, effectively...

PoC for CVE-2026-19715

WordPressWP Oauth Server ( Logi...
Unauthorized Access to Debug Log in WP OAuth Server Plugin by WordP...

The WP OAuth Server plugin for WordPress, prior to version 6.3.1, contains a flaw that allows unauthenticated users to access the debug log. This log, stored in a publicly accessible location, may contain sensitive information including OAuth tokens, authorization codes, and user records, such as...

PoC for CVE-2026-19225

WordPressDefender Security
Arbitrary Code Execution Vulnerability in Defender Security Plugin ...

The Defender Security plugin for WordPress before version 6.2.0 contains a vulnerability that permits an administrator of any single site within a multisite network to execute arbitrary code across the entire network. This flaw arises from the failure to restrict a critical network-wide setting e...

PoC for CVE-2026-19454

WordPressJetbackup
Security Flaw in JetBackup Plugin for WordPress Exposes Sensitive N...

The JetBackup plugin for WordPress prior to version 3.1.23.5 fails to properly enforce multisite authorization checks when serving backup archives and job logs. This oversight enables a network administrator—who does not possess Super Admin privileges—to download complete backups of the entire mu...

PoC for CVE-2026-16569

WordPressMobile App For WooComm...
Insufficient User Capability Check in WooCommerce Mobile App Builde...

The ShopApper Mobile App Builder Service for WooCommerce up to version 0.4.62 has a significant security issue where it does not properly verify user capabilities for stock-update operations. This oversight allows any authenticated user, including customers and subscribers, to alter the stock qua...

PoC for CVE-2026-19223

WordPressSmush
Arbitrary Code Execution Vulnerability in Smush Plugin for WordPress

The Smush plugin for WordPress, prior to version 4.3.2, is susceptible to a security flaw that enables an administrator of any individual site within a multisite network to execute arbitrary code across the entire network. This flaw arises from insufficient restrictions placed on network-wide set...

PoC for CVE-2026-16568

WordPressMobile App For WooComm...
Access Control Vulnerability in ShopApper Mobile App Builder for Wo...

The ShopApper Mobile App Builder Service for WooCommerce has a vulnerability where the plugin does not correctly verify user ownership of customer profiles accessed via its REST API endpoints. This oversight enables authenticated users, such as customers or subscribers, to potentially gain unauth...

PoC for CVE-2026-16567

WordPressDocument Embedder
Unauthorized Document Download Vulnerability in Document Embedder P...

The Document Embedder plugin for WordPress prior to version 2.3.1 has a significant security flaw that allows unauthenticated users to exploit the file download feature. This vulnerability arises because the plugin fails to validate the status of documents before generating a download token. As a...

PoC for CVE-2026-13414

WordPressCmp
Authorization Bypass Vulnerability in CMP WordPress Plugin

The CMP WordPress plugin prior to version 4.1.18 is susceptible to an authorization bypass vulnerability due to inadequate checks on several AJAX actions. This flaw allows unauthenticated attackers to bypass intended restrictions and disable the maintenance or coming-soon mode. Notably, some acti...

PoC for CVE-2026-13416

WordPressCmp
Arbitrary Web Script Injection Vulnerability in CMP Plugin for Word...

The CMP WordPress plugin prior to version 4.1.18 lacks adequate sanitization and escaping of settings values. This flaw permits users assigned the Editor role, if granted access to the admin-bar controls of the plugin, to inject malicious web scripts. These scripts can execute when a visitor view...

PoC for CVE-2026-13415

WordPressCmp
Privilege Escalation Vulnerability in CMP WordPress Plugin by CMP

The CMP WordPress plugin prior to version 4.1.18 lacks robust checks on setting imports, specifically failing to enforce an option-name allow-list when settings are imported via AJAX actions. This oversight can enable users with Editor permissions, if granted access by an administrator, to modify...

Discovered 14 hours ago

PoC for CVE-2026-45585

MicrosoftWindows 11 Version 24h26.8MEDIUM
Security Feature Bypass in Windows by Microsoft

A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...

Discovered 15 hours ago

PoC for CVE-2026-81491

BoxpositronWith-context-mcp6.9MEDIUM
Path Traversal Vulnerability in Boxpositron's With-Context-MCP Product

A flaw in Boxpositron's With-Context-MCP (version up to 3.0.7) exposes a path traversal vulnerability through the ingest_notes, teleport_notes, sync_notes, and project_folder functions contained in the src/index.ts file. This allows remote attackers to manipulate the file paths, potentially leadi...

Discovered 16 hours ago

PoC for CVE-2026-18080

WordPressErp: Complete Hr, Acco...9.8CRITICAL
Unrestricted File Upload Vulnerability in ERP: Complete HR, Account...

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is susceptible to an unrestricted file type upload due to insufficient validation of file extensions and improper path normalization in its save_attachments() function. This vulnerability allows unauthenticate...

PoC for CVE-2026-63520

MicrosoftMicrosoft Sharepoint E...8.1HIGH
Remote Code Execution Vulnerability in Microsoft Office SharePoint

A vulnerability exists in Microsoft Office SharePoint due to improper input validation, which could allow an unauthorized attacker to execute arbitrary code over a network. This can lead to significant security breaches if exploited, making it essential for affected users to apply security patche...

PoC for CVE-2026-81486

Bsmi021Mcp-file-context-server6.9MEDIUM
Path Traversal Vulnerability in bsmi021 mcp-file-context-server

A vulnerability has been identified in bsmi021's mcp-file-context-server version 1.0.0, specifically in the read_context function located in src/index.ts. This flaw allows attackers to manipulate the argument path, leading to potential path traversal attacks. This vulnerability can be exploited r...

Discovered 17 hours ago

PoC for CVE-2026-81485

DanielpopamdLinkedin-ads-mcp6.9MEDIUM
Path Traversal Vulnerability in danielpopamd Linkedin Ads MCP Media...

A security vulnerability has been identified in the danielpopamd Linkedin Ads MCP version 1.0.0. This vulnerability arises from an unsafe implementation in the function fs.readFileSync located in the file src/tools/campaign-management.ts, which handles media uploads. An attacker can manipulate th...

Discovered 18 hours ago

PoC for CVE-2026-19912

KalturaKaltura Html5 Video Pl...
Remote Code Execution Vulnerability in Kaltura HTML5 Player

The Kaltura HTML5 player is susceptible to a remote code execution vulnerability due to the unsafe handling of user-supplied data. Specifically, when the mwEmbedLoader.php script processes the ServiceUrl provided by an attacker, it performs deserialization without adequate validation. This exploi...

Discovered 19 hours ago

PoC for CVE-2026-19632

WordPressTranslatepress – Trans...9.8CRITICAL
Sensitive Information Exposure in TranslatePress Plugin for WordPress

The TranslatePress plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit the 'trp_get_translations_regular' AJAX action. This can lead to the unauthorized extraction of the raw administrator password-reset URL, including sensitive parameters such as the pl...

PoC for CVE-2026-81203

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A SQL injection vulnerability has been identified in the SourceCodester Simple Online Food Ordering System version 1.0, specifically within the login function located at /admin/ajax.php?action=login2. By manipulating the email parameter, attackers can execute arbitrary SQL queries, potentially co...

Discovered 20 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-81202

ItsourcecodePayroll System6.9MEDIUM
Missing Authentication Flaw in itsourcecode Payroll System

A security flaw exists in the itsourcecode Payroll System 1.0 that compromises the integrity of CRUD operations through the ajax.php file. An attacker can exploit this vulnerability by manipulating the 'action' argument, resulting in missing authentication checks. This raises significant security...

Discovered 1 day ago

PoC for CVE-2026-19632

WordPressTranslatepress – Trans...9.8CRITICAL
Sensitive Information Exposure in TranslatePress Plugin for WordPress

The TranslatePress plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit the 'trp_get_translations_regular' AJAX action. This can lead to the unauthorized extraction of the raw administrator password-reset URL, including sensitive parameters such as the pl...

PoC for CVE-2026-12684

WordPressCustomer Reviews For W...
Media Upload Vulnerability in Customer Reviews for WooCommerce Plug...

The Customer Reviews for WooCommerce WordPress plugin, prior to version 5.113.0, lacks necessary authentication and nonce checks in its AJAX actions related to media uploads. When the review media attachment feature is activated, this flaw permits unauthorized users to upload files to the Media L...

PoC for CVE-2026-72530

TrueconfTrueconf Server9.5CRITICAL
Remote Code Execution Vulnerability in TrueConf Server by TrueConf

A vulnerability in TrueConf Server allows remote unauthorized attackers with access to port 4307/TCP to exploit the server versions 5.3.X up to 5.3.9, 5.4.X up to 5.4.9, and 5.5.X up to 5.5.5. By using a crafted script, the attacker can break out of the isolated execution environment and execute ...

PoC for CVE-2026-78146

WordPressSimple Newsletter Plugin6.5MEDIUM
Data Disclosure Vulnerability in Simple Newsletter Plugin for WordP...

The Simple Newsletter Plugin for WordPress, prior to version 4.3.3, has a security flaw that allows unauthenticated users to access and disclose personal data of subscribers. This occurs due to the plugin's failure to validate that a requester is indeed the authorized subscriber before presenting...

PoC for CVE-2026-77789

WordPressStripe Payment Forms B...4.3MEDIUM
Authorization Flaw in Stripe Payment Forms Plugin by WP Full Pay

The Stripe Payment Forms plugin by WP Full Pay for WordPress prior to version 8.5.1 contains an authorization flaw that allows a user with a valid session to manipulate subscriptions that do not belong to them. Specifically, this vulnerability permits unauthorized actions such as canceling, react...

PoC for CVE-2026-77758

WordPressStripe Payment Forms B...5.3MEDIUM
Vulnerability in Stripe Payment Forms by WP Full Pay Plugin from Wo...

The Stripe Payment Forms by WP Full Pay plugin for WordPress prior to version 8.5.1 contains a vulnerability where it fails to accurately verify the completion of a customer portal session. This oversight allows unauthenticated users to access sensitive information, such as subscription and billi...

PoC for CVE-2026-77790

WordPressRegistrationmagic
SQL Injection Vulnerability in RegistrationMagic WordPress Plugin

The RegistrationMagic plugin for WordPress, prior to version 6.0.9.4, is susceptible to SQL injection due to improper sanitization and escaping of input parameters in SQL statements. This vulnerability enables users with high privileges, such as administrators, to execute malicious SQL queries, p...

PoC for CVE-2026-75798

WordPressAi Engine5.3MEDIUM
Improper Authorization in AI Engine Plugin for WordPress

The AI Engine plugin for WordPress prior to version 3.7.2 lacks essential authorization checks on specific administrative features. Instead of validating permissions, it issues a token to anonymous users. This design flaw permits unauthenticated attackers to execute AI queries on behalf of the si...

PoC for CVE-2026-77694

WordPressEventin5.3MEDIUM
Unauthenticated Order Manipulation Vulnerability in Eventin Plugin ...

The Eventin WordPress plugin prior to version 4.1.19 contains a security flaw that permits unauthorized users to exploit the guest checkout token mechanism. This vulnerability enables unauthenticated individuals to manipulate their own unpaid orders, marking them as completed and receiving valid ...

PoC for CVE-2026-77757

WordPressDirectorist: Ai-powere...5.4MEDIUM
File Manipulation Vulnerability in Directorist AI-Powered Business ...

The Directorist plugin for WordPress, designed for business directory listings, can be exploited due to insufficient sanitization of user-supplied image references. This flaw permits users with subscriber-level accounts to manipulate server-readable image files, allowing them to move these files ...