Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 47 minutes ago

PoC for CVE-2026-34621

AdobeAcrobat Reader8.6HIGH
Prototype Pollution Vulnerability in Adobe Acrobat Reader

Adobe Acrobat Reader is impacted by a Prototype Pollution vulnerability that allows attackers to execute arbitrary code within the context of the current user. This flaw is triggered only when a user interacts with a malicious file, making user awareness essential. It is crucial for users to keep...

Discovered 1 hour ago

PoC for CVE-2025-58060

OpenprintingCups8HIGH
Authentication Bypass in OpenPrinting CUPS Affects Multiple Unix-li...

OpenPrinting CUPS, an open-source printing system utilized across various Linux and Unix-like operating systems, is subject to a critical vulnerability that allows an authentication bypass. Specifically, in versions 2.4.12 and earlier, if the `AuthType` is set to anything other than `Basic`, the ...

Discovered 2 hours ago

PoC for CVE-2022-35650

MoodleMoodle7.5HIGH
Directory Traversal Vulnerability in Moodle Affecting Teachers and ...

A vulnerability exists in Moodle that stems from an input validation error occurring during the importation of lesson questions. This flaw allows for insufficient path checks, which can lead to arbitrary file reading via directory traversal attacks. It is important to note that access to this fea...

PoC for CVE-2026-39808

FortinetFortisandbox9.1CRITICAL
OS Command Injection Vulnerability in Fortinet FortiSandbox

An OS command injection vulnerability exists in Fortinet FortiSandbox versions 4.4.0 through 4.4.8. This flaw arises from improper neutralization of special elements used in operating system commands. An attacker can exploit this vulnerability to execute unauthorized commands, potentially comprom...

Discovered 4 hours ago

PoC for CVE-2026-40500

ProcesswireProcesswire6.1MEDIUM
Server-Side Request Forgery in ProcessWire CMS by ProcessWire

The ProcessWire CMS versions 3.0.255 and earlier are susceptible to a server-side request forgery (SSRF) vulnerability found in the admin panel's 'Add Module From URL' feature. Authenticated administrators can input arbitrary URLs in the module download parameter, resulting in the server making u...

Discovered 5 hours ago

PoC for CVE-2024-26229

MicrosoftWindows 10 Version 1809🟣 EPSS 83%7.8HIGH
Windows CSC Service Elevation of Privilege Vulnerability

The CVE-2024-26229 vulnerability in the Windows CSC Service is being exploited with proof-of-concept (PoC) exploit code available on GitHub. This high-severity vulnerability could allow attackers to gain SYSTEM privileges on a Windows system, posing a significant risk. This type of elevation of p...

Discovered 8 hours ago

PoC for CVE-2021-4034

Polkit ProjectPolkit🟣 EPSS 88%7.8HIGH
Local Privilege Escalation Vulnerability in polkit's pkexec Utility

A local privilege escalation vulnerability exists within the pkexec utility of polkit, a setuid tool that allows unprivileged users to execute commands as privileged users based on predetermined policies. Due to insufficient handling of the calling parameters, pkexec can misinterpret environment ...

Discovered 9 hours ago

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

Discovered 11 hours ago

PoC for CVE-2026-1357

WordPressWPvivid — Backup, Migr...🟣 EPSS 19%9.8CRITICAL
Unauthenticated Arbitrary File Upload in WPvivid Backup & Migration...

The WPvivid Backup & Migration plugin for WordPress is susceptible to an unauthenticated arbitrary file upload vulnerability due to improper error handling in the RSA decryption process and inadequate path sanitization during file uploads. This allows malicious attackers to exploit the system by ...

Discovered 23 hours ago

PoC for CVE-2025-24000

WordPressPost Smtp8.8HIGH
Authentication Bypass Vulnerability in WPExperts Post SMTP Plugin

The WPExperts Post SMTP plugin contains an authentication bypass vulnerability that allows attackers to exploit alternate pathways for gaining unauthorized access. This issue affects versions from n/a up to 3.2.0, potentially compromising the security of WordPress installations using this plugin....

PoC for CVE-2025-48561

GoogleAndroid5.5MEDIUM
Data Exposure Vulnerability in Android Framework by Google

A vulnerability has been identified in the Android Framework that allows for potential exposure of sensitive information displayed on the screen. This may occur without the need for user interaction or elevated execution privileges, resulting in local information disclosure risks. The issue arise...

PoC for CVE-2026-40499

RadareorgRadare28.4HIGH
Command Injection Vulnerability in radare2 PDB Parser

radare2, prior to version 6.1.4, is susceptible to a command injection vulnerability located in the PDB parser's print_gvars() function. This vulnerability allows attackers to execute arbitrary commands by inserting a newline byte into the PE section header name field of a maliciously crafted PDB...

Discovered 1 day ago

PoC for CVE-2026-6042

MuslLibc4.8MEDIUM
Security Flaw in musl libc Affects GB18030 4-byte Decoder Function

A flaw has been identified in the GB18030 4-byte Decoder function within musl libc, specifically in the iconv implementation located in src/locale/iconv.c. This vulnerability manifests as inefficient algorithmic complexity that can be exploited through localized interactions. Attackers can manipu...

PoC for CVE-2026-40175

AxiOSAxiOS10CRITICAL
Prototype Pollution and Remote Code Execution Vulnerability in Axio...

The Axios library, a popular promise-based HTTP client used in web applications and Node.js, has a significant vulnerability that enables a 'Gadget' attack chain. This flaw allows Prototype Pollution to exploit third-party dependencies, leading to potential Remote Code Execution (RCE). Attackers ...

PoC for CVE-2026-40175

AxiOSAxiOS10CRITICAL
Prototype Pollution and Remote Code Execution Vulnerability in Axio...

The Axios library, a popular promise-based HTTP client used in web applications and Node.js, has a significant vulnerability that enables a 'Gadget' attack chain. This flaw allows Prototype Pollution to exploit third-party dependencies, leading to potential Remote Code Execution (RCE). Attackers ...

Discovered 2 days ago

PoC for CVE-2026-39987

Marimo-teamMarimo9.3CRITICAL
Pre-Authentication Remote Code Execution in Marimo Python Notebook

Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...

PoC for CVE-2026-6224

NocobasePlugin-workflow-javasc...6.9MEDIUM
Sandbox Vulnerability in Nocobase Plugin-Workflow-Javascript

A critical security flaw exists in the Nocobase plugin-workflow-javascript up to version 2.0.23. The vulnerability arises from the createSafeConsole function in the Vm.js file, where improper handling potentially allows attackers to exploit the sandbox environment. This issue facilitates remote c...

PoC for CVE-2026-6220

HummerRiskHummerrisk5.1MEDIUM
Server-Side Request Forgery Vulnerability in HummerRisk Video Downl...

In versions of HummerRisk up to 1.5.0, a server-side request forgery (SSRF) vulnerability was discovered in the ServerService.addServer function within the ServerService.java file. This security flaw enables remote exploitation by manipulating the streamIp argument during server operations. As a ...

PoC for CVE-2026-6219

Aandrew-meYtdownloader4.8MEDIUM
Command Injection Vulnerability in aandrew-me ytDownloader by aandr...

A command injection vulnerability exists in aandrew-me ytDownloader versions up to 3.20.2, specifically affecting the child_process.exec function in src/compressor.js. This vulnerability allows malicious users to execute arbitrary commands on the local system. Although the attack must be executed...

PoC for CVE-2025-59528

FlowiseaiFlowise🟣 EPSS 84%10CRITICAL
Remote Code Execution Vulnerability in Flowise by FlowiseAI

Flowise, a user-friendly platform for creating customized large language model flows, has a significant vulnerability in version 3.0.5 that allows for remote code execution. The flaw lies within the CustomMCP node, where user input is inadequately sanitized. Specifically, the mcpServerConfig stri...

PoC for CVE-2026-6218

Aandrew-meYtdownloader5.3MEDIUM
Cross Site Scripting Vulnerability in aandrew-me ytDownloader

A cross site scripting vulnerability exists in the 'createTextNode' function of the Error Details Panel in the aandrew-me ytDownloader, affecting versions up to 3.20.2. This flaw enables remote attackers to execute arbitrary scripts that may compromise user data or session information. The weakne...

PoC for CVE-2026-6202

Code-projectsEasy Blog Site5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Easy Blog Site by Code...

A security flaw exists in the Code-Projects Easy Blog Site version 1.0, particularly within the 'post.php' file. This vulnerability allows attackers to exploit an unknown function by manipulating the 'tags' argument, resulting in SQL injection attacks. The nature of the flaw enables remote exploi...

PoC for CVE-2026-6201

CodeastroOnline Job Portal5.3MEDIUM
Improper Access Controls in CodeAstro Online Job Portal

A vulnerability was discovered in the CodeAstro Online Job Portal 1.0, specifically targeting the Delete Job Posting Handler component. The issue arises from improper access controls within the job-delete.php file. By manipulating the ID parameter, an attacker can potentially bypass security meas...

PoC for CVE-2026-6200

TendaF4568.7HIGH
Stack-Based Buffer Overflow in Tenda F456 Router by Tenda

A vulnerability exists in the Tenda F456 router, specifically within the function 'formwebtypelibrary' located in the file '/goform/webtypelibrary'. This weakness is attributed to a stack-based buffer overflow caused by improper handling of the 'menufacturer/Go' argument. The vulnerability can be...

PoC for CVE-2026-6199

TendaF4568.7HIGH
Stack-Based Buffer Overflow in Tenda F456 Router

A stack-based buffer overflow vulnerability has been identified in the Tenda F456 router, specifically within the 'fromqossetting' function of the /goform/qossetting file. This vulnerability allows for remote exploitation, where an attacker can manipulate the 'page' argument, potentially leading ...

PoC for CVE-2026-6198

TendaF4568.7HIGH
Stack-based Buffer Overflow in Tenda F456 Router

A security flaw has been identified in the Tenda F456 router version 1.0.0.5, specifically in the fromNatStaticSetting function located in the /goform/NatStaticSetting file. This vulnerability allows for remote exploitation through the manipulation of the argument 'page', resulting in a stack-bas...

PoC for CVE-2026-6197

TendaF4568.7HIGH
Stack-based Buffer Overflow in Tenda F456 by Tenda

A security vulnerability has been identified in the Tenda F456 version 1.0.0.5, targeting the formWrlsafeset function within the /goform/AdvSetWrlsafeset file. Manipulating the 'mit_ssid' argument can lead to a stack-based buffer overflow, potentially allowing remote attackers to exploit the weak...

PoC for CVE-2026-6196

TendaF4568.7HIGH
Stack-Based Buffer Overflow in Tenda F456 Router

A stack-based buffer overflow vulnerability has been identified in the Tenda F456 router, specifically within the fromexeCommand function of the /goform/exeCommand file. This flaw can be exploited remotely by manipulating the cmdinput argument, potentially allowing unauthorized access or control ...

PoC for CVE-2026-6195

TotolinkA7100ru9.3CRITICAL
OS Command Injection in Totolink A7100RU by Totolink

A vulnerability has been identified in the Totolink A7100RU router, specifically within the function setPasswordCfg located in the CGI Handler component. This weakness allows an attacker to inject operating system commands through manipulation of the admpass argument. The exploitation can be perf...

PoC for CVE-2026-6194

TotolinkA3002mu8.7HIGH
Stack-based Buffer Overflow in Totolink A3002MU HTTP Request Handler

A vulnerability in the Totolink A3002MU model, specifically in the HTTP Request Handler function sub_410188, has been identified. This weakness is triggered through an improper manipulation of the wan-url argument, resulting in a stack-based buffer overflow. This type of vulnerability allows for ...

PoC for CVE-2026-6193

PHPgurukulDaily Expense Tracking...6.9MEDIUM
SQL Injection Vulnerability in PHPGurukul Daily Expense Tracking Sy...

A vulnerability has been identified in the PHPGurukul Daily Expense Tracking System version 1.1, specifically within the /register.php file. This flaw allows attackers to manipulate the 'email' argument, potentially leading to SQL injection attacks. The nature of the vulnerability enables remote ...

PoC for CVE-2026-6192

UclouvainOpenjpeg4.8MEDIUM
Integer Overflow Vulnerability in uclouvain OpenJPEG Library

The uclouvain OpenJPEG library is susceptible to an integer overflow vulnerability within the function opj_pi_initialise_encode located in src/lib/openjp2/pi.c. This local attack can lead to unauthorized manipulation and exploitation of the library's functionality. It is crucial for users to be a...

PoC for CVE-2026-6191

ItsourcecodeConstruction Managemen...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Construction Management...

A SQL injection vulnerability was found in itsourcecode's Construction Management System version 1.0, specifically within the handling of the 'Name' argument in the /equipments.php file. This flaw allows attackers to manipulate input parameters, leading to unauthorized database access and the pot...

PoC for CVE-2026-6190

ItsourcecodeConstruction Managemen...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Construction Management...

A vulnerability exists in version 1.0 of the itsourcecode Construction Management System, specifically located in the file /employees.php. An attacker can exploit this vulnerability remotely by manipulating the 'Name' argument, leading to SQL injection. This security flaw allows unauthorized acce...

PoC for CVE-2026-6189

SourcecodesterPharmacy Sales And Inv...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

A security flaw has been identified in the SourceCodester Pharmacy Sales and Inventory System 1.0, specifically within the /ajax.php?action=login endpoint. The improper handling of the 'Username' parameter could allow attackers to execute SQL injection attacks remotely. This vulnerability has bee...

PoC for CVE-2026-6188

SourcecodesterPharmacy Sales And Inv...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

A vulnerability has been identified in the SourceCodester Pharmacy Sales and Inventory System 1.0, specifically within the /ajax.php?action=delete_sales function. This flaw allows remote attackers to manipulate parameters, leading to SQL injection. Attackers exploiting this weakness can perform u...

PoC for CVE-2026-6187

SourcecodesterPharmacy Sales And Inv...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

A vulnerability exists within the SourceCodester Pharmacy Sales and Inventory System 1.0 that allows for SQL injection through the manipulation of the ID argument in the /ajax.php?action=chk_prod_availability file. This security flaw could be exploited remotely, allowing attackers to execute unau...

PoC for CVE-2026-6186

UttHiper 1200gw8.7HIGH
Buffer Overflow Vulnerability in UTT HiPER 1200GW Devices

A serious security issue exists within the UTT HiPER 1200GW, specifically in the strcpy function located in the /goform/formNatStaticMap file. This vulnerability can be exploited remotely through manipulation of the NatBind argument, leading to a buffer overflow that may compromise system integri...

PoC for CVE-2026-6184

Code-projectsSimple Content Managem...4.8MEDIUM
Cross-Site Scripting Vulnerability in Code-Projects Simple Content ...

A vulnerability exists in version 1.0 of Code-Projects' Simple Content Management System, specifically within the /web/admin/welcome.php file. By manipulating the 'News Title' argument, attackers can exploit this weakness to execute cross-site scripting attacks. Such exploits can be executed remo...

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 86%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

PoC for CVE-2026-6183

Code-projectsSimple Content Managem...6.9MEDIUM
SQL Injection Vulnerability in Simple Content Management System by ...

A security vulnerability has been identified in the Simple Content Management System 1.0 developed by Code-Projects. This flaw arises from improper handling of input parameters in the file /web/index.php, leading to SQL injection risks. Attackers may manipulate the argument ID, enabling them to e...

PoC for CVE-2025-8110

GogsGogs🟣 EPSS 20%8.7HIGH
Improper Symbolic Link Handling in Gogs Product by Gogs Team

The vulnerability in the PutContents API of Gogs arises from improper handling of symbolic links, potentially allowing local execution of arbitrary code. This misconfiguration may expose sensitive data and facilitate unauthorized access to critical systems. Users and administrators are urged to u...

PoC for CVE-2026-6182

Code-projectsSimple Content Managem...6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Simple Content Managem...

A vulnerability has been discovered in the code-projects Simple Content Management System version 1.0, specifically affecting the /web/admin/login.php file. This vulnerability allows attackers to manipulate the User argument, leading to potential SQL injection attacks. The exploit can be executed...

Discovered 3 days ago

PoC for CVE-2026-6204

LibrenmsLibrenms8.5HIGH
Authenticated Remote Code Execution in LibreNMS by Invoking Binary ...

An authenticated remote code execution vulnerability exists in LibreNMS versions prior to 26.3.0, which can be exploited by leveraging the Binary Locations configuration and the Netcommand functionality. Attackers with administrative privileges can exploit this flaw to execute arbitrary commands ...

PoC for CVE-2025-58434

FlowiseaiFlowise9.8CRITICAL
Password Reset Vulnerability in Flowise Affects User Accounts

The Flowise platform contains a significant vulnerability in its `forgot-password` endpoint, which can return sensitive information, including a valid password reset token, without the necessary authentication or verification. This flaw allows attackers to generate reset tokens for arbitrary user...

PoC for CVE-2026-2728

LibrenmsLibrenms4.6MEDIUM
Cross-site Scripting Vulnerability in LibreNMS Affected by Administ...

LibreNMS versions prior to 26.3.0 have a vulnerability that allows authenticated users with administrative privileges to exploit cross-site scripting (XSS) on the showconfig page. This flaw can lead to unauthorized actions being taken against other users accessing the page, as attackers can poten...

PoC for CVE-2025-15632

1panel-devMaxkb5.1MEDIUM
Cross-Site Scripting Vulnerability in 1Panel-dev MaxKB Product

A cross-site scripting vulnerability has been identified in the file ui/src/chat.ts of the MdPreview component of the MaxKB product by 1Panel-dev, specifically impacting versions up to 2.4.2. This flaw allows an attacker to execute arbitrary scripts in the context of the user's browser, potential...

PoC for CVE-2026-6168

TotolinkA7000r8.7HIGH
Stack-Based Buffer Overflow in TOTOLINK A7000R Router

A vulnerability has been identified in the TOTOLINK A7000R router, specifically within the function setWiFiEasyGuestCfg located in the /cgi-bin/cstecgi.cgi file. This vulnerability allows an attacker to exploit a stack-based buffer overflow by manipulating the ssid5g argument. Such an exploit pos...

PoC for CVE-2026-6167

Code-projectsFaculty Management System6.9MEDIUM
SQL Injection Vulnerability in Faculty Management System by Code-Pr...

A SQL injection vulnerability has been identified in the Faculty Management System 1.0 from Code-Projects. This flaw exists within the file /subject-print.php, where improper handling of the 'ID' argument can allow remote attackers to manipulate SQL queries. The ability to execute arbitrary SQL c...