Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 4 hours ago

PoC for CVE-2024-58349

WordPressTravelscape9.3CRITICAL
WordPress Theme Travelscape 1.0.3 Arbitrary File Upload

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them...

PoC for CVE-2024-58348

WordPressBackground Image Cropper9.3CRITICAL
WordPress Background Image Cropper 1.2 Remote Code Execution

WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to execute arbitrary...

PoC for CVE-2023-54351

WordPressSonaar Music Plugin5.1MEDIUM
WordPress Sonaar Music Plugin 4.7 Stored XSS via Comments

WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php which are stored an...

PoC for CVE-2023-54352

WordPressTravelscape9.3CRITICAL
WordPress Seotheme Remote Code Execution Unauthenticated

WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands ...

PoC for CVE-2023-54350

WordPressAugmented Reality8.7HIGH
WordPress Augmented-Reality Plugin Remote Code Execution Unauthenti...

WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to creat...

PoC for CVE-2022-50953

WordPressAdmin-word-count-column6.9MEDIUM
WordPress Plugin admin-word-count-column 2.2 Local File Read

WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting null byte injection in the path parameter. Attackers can send GET requests to download-csv.php with a crafted path parameter containing...

PoC for CVE-2021-47984

WordPressWP24 Domain Check5.1MEDIUM
WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS

WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the fieldnameDomain parameter. Attackers can inject JavaScript payloads through the plugin settings form at ...

PoC for CVE-2021-47983

WordPressAccept Stripe Payments5.1MEDIUM
WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_code

WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script ...

PoC for CVE-2021-47982

WordPressWP-paginate5.1MEDIUM
WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset

WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter...

PoC for CVE-2026-11477

Hs-webHsweb-framework5.3MEDIUM
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client...

A vulnerability was detected in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in op...

Discovered 5 hours ago

PoC for CVE-2026-11476

Kushan2kStudent-management-system5.3MEDIUM
Kushan2k student-management-system Profile Update Endpoint AdminCon...

A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this issue is the function edit-admin of the file controllers/AdminController.php of the component Profile Update Endpoint. The manipulation of the argument...

PoC for CVE-2026-11475

Kushan2kStudent-management-system5.3MEDIUM
Kushan2k student-management-system Certificate Verification Endpoin...

A weakness has been identified in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this vulnerability is the function getStatus of the file controllers/GradeController.php of the component Certificate Verification Endpoint. Executing a manipulation of...

PoC for CVE-2026-11474

Kushan2kStudent-management-system6.9MEDIUM
Kushan2k student-management-system Registration Endpoint RegisterSe...

A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown function of the file service/RegisterService.php of the component Registration Endpoint. Performing a manipulation of the argument stimg results in unre...

Discovered 6 hours ago

PoC for CVE-2026-11472

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SourceCodester Class and Exam Timetabling System index1.php sql inj...

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /index1.php. This manipulation of the argument Password causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may ...

PoC for CVE-2026-11471

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SourceCodester Class and Exam Timetabling System index2.php sql inj...

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /index2.php. The manipulation of the argument Password results in sql injection. It is possible to launch the attack remotely. The exploit has been made publi...

PoC for CVE-2026-11470

Hs-webHsweb-framework5.3MEDIUM
hs-web hsweb-framework File Upload FileUploadProperties.java denied...

A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-system-file/src/main/java/org/hswebframework/web/file/FileUploadProperties.java of the component File Upload. The manipulation of the argument filename ...

Discovered 7 hours ago

PoC for CVE-2026-11468

SourcecodesterHospitals Patient Reco...4.8MEDIUM
SourceCodester Hospitals Patient Records Management System page roo...

A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /admin/?page=room_types. Performing a manipulation of the argument room results in cross site scripting. The attack is possible to be carried out ...

PoC for CVE-2026-11467

JishenghuaJsherp5.3MEDIUM
jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadServi...

A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component addAccountHeadAndDetail Endpoint. Such manipulation of the ...

PoC for CVE-2026-11466

ZilliztechDeep-searcher5.3MEDIUM
zilliztech deep-searcher collection_router.py CollectionRouter.invo...

A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. T...

PoC for CVE-2026-11465

SongquanpengOne-api2.3LOW
songquanpeng one-api Redemption Code Top-Up Endpoint redemption.go ...

A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component Redemption Code Top-Up Endpoint. The manipulation results in business logic errors. The attack may be launched remotel...

Discovered 8 hours ago

PoC for CVE-2026-11464

Jeecgboot2.3LOW
JeecgBoot User List Endpoint SysUserController.java queryPageList i...

A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipulation of the argument salt leads to informatio...

PoC for CVE-2026-11463

UscilabCereal6.3MEDIUM
USCiLab Cereal Shared Pointer type confusion

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a manipulation can lead to type confusion. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor ...

PoC for CVE-2026-11462

Chengdu Everbrite...Beikeshop6.9MEDIUM
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin Stripe...

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authoriz...

PoC for CVE-2026-11461

NousresearchHermes-agent5.3MEDIUM
NousResearch hermes-agent resume Endpoint hermes_state.py resolve_s...

A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack rem...

Discovered 10 hours ago

PoC for CVE-2026-4480

Red HatRed Hat Enterprise Lin...9CRITICAL
Samba Printing Subsystem Vulnerability in Samba Software

A vulnerability exists in the Samba printing subsystem that allows remote attackers to execute arbitrary commands on affected systems. The flaw occurs due to improper handling of the client-controlled job description string, which is passed directly to the configured print command without escapin...

Discovered 11 hours ago

PoC for CVE-2026-11460

BoostSerialization6.3MEDIUM
Boost Serialization improper validation of specified type of input

A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has been published and may be used. The maintainer was notifie...

Discovered 18 hours ago

PoC for CVE-2026-49494

ComodoComodo Internet Security8.7HIGH
Comodo Internet Security Inspect.sys IPv6 Integer Underflow Remote ...

Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length value (taken from the IPv6 fixed header's payload length field) by the size of each IPv6 extension header without validating it, ...

Discovered 22 hours ago

PoC for CVE-2026-11458

ErzhongxmuJeewms6.9MEDIUM
erzhongxmu JeeWMS Boot Actuator Endpoint actuator information discl...

A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the file /base-boot/actuator of the component Boot Actuator Endpoint. Executing a manipulation can lead to information disclosure. The attack can be ex...

PoC for CVE-2026-11457

ErzhongxmuJeewms6.9MEDIUM
erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnectio...

A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the component JimuReport test-connection Endpoint. Performing a manipulation of the argument dbType/db...

Discovered 23 hours ago

PoC for CVE-2026-11456

ChanjetCrm6.9MEDIUM
Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection

A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php of the component HTTP GET Request Handler. Such manipulation of the argument gblOrgID leads to sql injection. The attack may be launched remotely. The exploit is publicly avail...

PoC for CVE-2019-5513

VmwareVmware Horizon Connect...5.3MEDIUM
Information Disclosure Vulnerability in VMware Horizon Connection S...

VMware Horizon Connection Server prior to version 7.8, including versions 7.5.2 and 6.2.8, has a vulnerability that may lead to the disclosure of sensitive internal information. Successful exploitation could expose internal domain names, the internal name of the Connection Server, or the internal...

PoC for CVE-2026-11455

FoundationagentsMetagpt2.3LOW
FoundationAgents MetaGPT common.py check_cmd_exists command injection

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd_exists of the file metagpt/utils/common.py. This manipulation of the argument mermaid.path causes command injection. The attack may be initiated remotely. A high degree of comp...

Discovered 1 day ago

PoC for CVE-2026-11453

TiobonEmployee Self-service ...5.3MEDIUM
Tiobon Employee Self-Service System Login Endpoint BlogSearch.aspx ...

A vulnerability was found in Tiobon Employee Self-Service System up to 7.2. Affected by this vulnerability is an unknown functionality of the file /Blog/BlogSearch.aspx of the component Login Endpoint. The manipulation of the argument Keyword results in sql injection. The attack can be launched r...

PoC for CVE-2026-42926

F5Nginx Open Source6.3MEDIUM
HTTP/2 Traffic Injection Vulnerability in NGINX Open Source by F5 N...

A vulnerability exists in NGINX Open Source when configured to proxy HTTP/2 traffic using the proxy_http_version set to 2 in conjunction with proxy_set_body. An attacker could exploit this configuration to inject frame headers and payload bytes directed at the upstream server, potentially leading...

PoC for CVE-2024-54887

TP-LinkTl-wr940n Firmware8HIGH
Buffer Overflow in TP-Link Routers Allowing Code Execution

The TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier are susceptible to a buffer overflow vulnerability through the dnsserver1 and dnsserver2 parameters located at /userRpm/Wan6to4TunnelCfgRpm.htm. An authenticated attacker can exploit this vulnerability to execute arbitrary code on t...

PoC for CVE-2026-45585

MicrosoftWindows 11 Version 24h26.8MEDIUM
Security Feature Bypass in Windows by Microsoft

A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...

PoC for CVE-2026-24061

GnuInetutils🟣 EPSS 92%9.8CRITICAL
Remote Authentication Bypass in GNU Inetutils Telnetd

The GNU Inetutils telnet daemon (telnetd) is vulnerable to a remote authentication bypass that can occur when an attacker manipulates the USER environment variable by specifying a '-f root' value. This flaw allows unauthorized users to gain access without proper authentication. Affected users sho...

Discovered 2 days ago

PoC for CVE-2026-11437

PerfreeGo-fastdfs-web6.9MEDIUM
perfree go-fastdfs-web Installation Endpoint checkServer server-sid...

A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been pu...

PoC for CVE-2026-11436

Mage Ai5.3MEDIUM
Mage AI Sign-in Flow index.tsx useMutation cross site scripting

A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend/components/Sessions/SignForm/index.tsx of the component Sign-in Flow. Performing a manipulation of the argument query.redirect_url results in cross site scripting. Remote explo...

PoC for CVE-2026-11435

JinherOa6.9MEDIUM
Jinher OA nextselectplan.aspx sql injection

A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor...

PoC for CVE-2026-42588

ApacheApache ActiveMQ Broker8.1HIGH
Code Injection Vulnerability in Apache ActiveMQ Broker by Apache

Apache ActiveMQ Classic has a vulnerability due to improper input validation. The Jolokia JMX-HTTP bridge allows authenticated attackers to perform exec operations on ActiveMQ MBeans by using a crafted discovery URI. This manipulation could trigger arbitrary code execution on the broker's JVM by ...

PoC for CVE-2026-11434

Fluentcms4.8MEDIUM
FluentCMS Blocks Plugin blocks cross site scripting

A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks of the component Blocks Plugin. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could...

PoC for CVE-2026-23744

McpjamInspector🟣 EPSS 30%9.8CRITICAL
Remote Code Execution Vulnerability in MCPJam Inspector by MCP

MCPJam Inspector, designed for local-first development on MCP servers, has a vulnerability allowing remote code execution (RCE) due to improper binding settings. In versions 1.4.2 and earlier, the platform listens on 0.0.0.0 by default, enabling attackers to exploit this configuration through cra...

PoC for CVE-2026-20245

CiscoCisco Catalyst Sd-wan ...7.8HIGH
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation...

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied inp...

PoC for CVE-2026-11413

JingdongJd Cloud Box Ax66008.7HIGH
JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based o...

A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the file /sbin/jdcweb_rpc. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disc...

PoC for CVE-2026-11412

JinherOa5.3MEDIUM
Jinher OA GetFormSn.aspx sql injection

A weakness has been identified in Jinher OA C6. The affected element is an unknown function of the file /C6/JHSoft.Web.ModuleCount/GetFormSn.aspx. Executing a manipulation of the argument queryID can lead to sql injection. The attack may be performed from remote. The exploit has been made availab...

PoC for CVE-2026-11411

Iai LabPDF Ai App4.8MEDIUM
iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal

A security flaw has been discovered in iAI Lab PDF AI App 4.21.0 on Android. Impacted is the function getExternalCacheDir of the component chatpdf.pro. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit has been rel...

PoC for CVE-2026-11408

Vertex-appVertex5.3MEDIUM
vertex-app vertex Log Viewer Endpoint LogMod.js os command injection

A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of the component Log Viewer Endpoint. Such manipulation of the argument req.query leads to os command injection. The attack can be executed remotely. Th...

PoC for CVE-2026-11406

Gl.inetMt30005.3MEDIUM
GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command...

A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly...

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 83%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...