Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2026-26342

Tattile S.r.l.Smart+8.7HIGH
Tattile Smart+ / Vega / Basic <= 1.181.5 Insufficient Session Token...

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to ...

PoC for CVE-2026-26341

Tattile S.r.l.Smart+9.3CRITICAL
Tattile Smart+ / Vega / Basic <= 1.181.5 Default Credentials

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain admi...

PoC for CVE-2026-26340

Tattile S.r.l.Smart+8.7HIGH
Tattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticated RTSP Strea...

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of survei...

Discovered 3 hours ago

PoC for CVE-2026-25755

ParallaxJsPDF8.1HIGH
JavaScript PDF Library jsPDF Vulnerability Exposes Users to Documen...

The jsPDF library, widely used for generating PDFs in JavaScript, is subject to a security flaw that allows attackers to control the parameters of the `addJS` method. This oversight enables the injection of arbitrary PDF objects, which can lead to execution of malicious actions or manipulation of...

Discovered 6 hours ago

PoC for CVE-2026-3101

IntelbrasTip 635g5.3MEDIUM
OS Command Injection Vulnerability in Intelbras TIP 635G

A critical security vulnerability has been identified in the Intelbras TIP 635G version 1.12.3.5, specifically affecting the Ping Handler component. This weakness allows for remote attackers to execute arbitrary operating system commands on the affected device, posing a serious risk of unauthoriz...

Discovered 11 hours ago

PoC for CVE-2023-27372

SpipSpip🟣 EPSS 93%9.8CRITICAL
Remote Code Execution Vulnerability in SPIP Product by SPIP

The latest vulnerability in SPIP allows attackers to execute arbitrary code remotely due to improper handling of data serialization in form inputs within the public area. This flaw could enable unauthorized access and manipulation of the system, highlighting the need for immediate updates to the ...

Discovered 15 hours ago

PoC for CVE-2025-15386

WordPressResponsive Lightbox & ...8.8HIGH
Unauthenticated Stored XSS Vulnerability in Responsive Lightbox & G...

The Responsive Lightbox & Gallery WordPress plugin is susceptible to an Unauthenticated Stored-XSS attack due to inadequate regex replacement rules. Attackers can exploit this vulnerability by submitting a comment containing a malicious link when lightbox comments are enabled. If the comment is s...

PoC for CVE-2025-15589

MuYuCMSMuyucms5.1MEDIUM
Path Traversal Vulnerability in MuYuCMS Template Management Component

A path traversal vulnerability exists in MuYuCMS version 2.7, specifically within the delete_dir_file function of the Template Management Page's controller. This issue arises due to improper handling of user-supplied input, allowing an attacker to manipulate the 'temn/tp' argument and potentially...

PoC for CVE-2025-67733

Valkey-ioValkey8.5HIGH
Scripting Commands Vulnerability in Valkey Distributed Key-Value Da...

The Valkey distributed key-value database has a vulnerability that allows a malicious user to inject arbitrary data into the response stream using scripting commands. This can lead to the corruption of data or tampered responses affecting other users connected to the same session. The issue arise...

Discovered 16 hours ago

PoC for CVE-2026-3070

SourcecodesterModern Image Gallery App5.3MEDIUM
Cross Site Scripting Vulnerability in SourceCodester Modern Image G...

The SourceCodester Modern Image Gallery App version 1.0 is susceptible to a cross site scripting vulnerability through its upload.php file. An attacker can exploit this by manipulating the 'filename' parameter, potentially launching the attack remotely. This exploit is now publicly available, hig...

Discovered 17 hours ago

PoC for CVE-2026-3069

ItsourcecodeDocument Management Sy...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Document Management System

A security vulnerability has been identified in itsourcecode Document Management System 1.0, specifically within an unknown function of the file /edtlbls.php. This vulnerability allows for SQL injection through the manipulation of the argument 'field1'. Attackers can exploit this flaw remotely, p...

PoC for CVE-2026-3068

ItsourcecodeDocument Management Sy...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Document Management System

A vulnerability has been discovered in itsourcecode's Document Management System version 1.0 that affects the deluser.php file. An improper handling of the 'user2del' argument can lead to SQL injection attacks, which can be executed remotely. The exploit has been publicly disclosed, making it cru...

PoC for CVE-2026-3067

HummerRiskHummerrisk5.3MEDIUM
Path Traversal Vulnerability in HummerRisk Archive Extraction Funct...

A vulnerability has been identified in HummerRisk's Archive Extraction functionality, specifically within the 'extractTarGZ/extractZip' methods in the CommandUtils.java file. This issue enables an attacker to manipulate the file path used during archive extraction, leading to a path traversal con...

Discovered 18 hours ago

PoC for CVE-2026-3066

HummerRiskHummerrisk5.3MEDIUM
Remote Command Injection Vulnerability in HummerRisk Cloud Complian...

A command injection vulnerability exists in the HummerRisk Cloud Compliance Scanning component, specifically within the fixedCommand function located in the PlatformUtils.java file. This flaw allows remote attackers to execute arbitrary commands on the affected system, potentially leading to unau...

PoC for CVE-2026-3065

HummerRiskHummerrisk5.3MEDIUM
Command Injection Vulnerability in HummerRisk Cloud Task Component

A command injection vulnerability has been identified in the HummerRisk software affecting the Cloud Task Dry-run component. Specifically, the issue resides in the function CommandUtils.commonExecCmdWithResult located in CloudTaskService.java. An attacker can manipulate the argument 'fileName' to...

PoC for CVE-2026-3064

HummerRiskHummerrisk5.3MEDIUM
Command Injection Vulnerability in HummerRisk Cloud Task Scheduler

A security vulnerability has been identified in HummerRisk Cloud Task Scheduler affecting versions up to 1.5.0, specifically in the file ResourceCreateService.java. This vulnerability arises from improper handling of the argument 'regionId', allowing attackers to execute arbitrary commands. The e...

PoC for CVE-2021-20038

SonicwallSonicwall Sma100🟣 EPSS 94%9.8CRITICAL
Stack-Based Buffer Overflow in SMA100 Apache httpd Server by SonicWall

A stack-based buffer overflow vulnerability in the Apache httpd server's mod_cgi module on SonicWall's SMA100 appliances could allow a remote, unauthenticated attacker to execute arbitrary code with the privileges of the 'nobody' user. This issue affects multiple SMA appliance models, specificall...

Discovered 19 hours ago

PoC for CVE-2026-3057

A54552239Pearprojectapi5.3MEDIUM
SQL Injection Vulnerability in pearProjectApi Backend Interface

A security flaw exists in the backend interface of pearProjectApi, specifically within the 'dateTotalForProject' function in the Task.php file. This vulnerability allows attackers to manipulate the 'projectCode' argument, potentially leading to unauthorized SQL commands being executed against the...

PoC for CVE-2026-3053

DatalinkdcDinky6.9MEDIUM
OpenAPI Endpoint Vulnerability in DataLinkDC Dinky Affects Multiple...

A security vulnerability exists in the OpenAPI Endpoint of DataLinkDC Dinky prior to version 1.2.6, particularly in the addInterceptors function within AppConfig.java. This flaw allows unauthorized access due to missing authentication checks. An attacker can remotely exploit this vulnerability, p...

PoC for CVE-2026-3052

DatalinkdcDinky5.3MEDIUM
Server-Side Request Forgery in DataLinkDC dinky up to 1.2.5

A vulnerability exists in the DataLinkDC dinky where the function proxyUba of the Flink Proxy Controller can be manipulated, leading to server-side request forgery (SSRF). This flaw allows attackers to initiate remote attacks, potentially exposing sensitive server resources. The vulnerability has...

Discovered 20 hours ago

PoC for CVE-2026-3051

DatalinkdcDinky5.3MEDIUM
Path Traversal Vulnerability in DataLinkDC dinky by DataLinkDC

A path traversal vulnerability exists in the DataLinkDC dinky product, specifically in the function getProjectDir within the GitRepository.java file. This vulnerability allows attackers to manipulate the projectName argument, potentially accessing files outside the intended directory. The exploit...

PoC for CVE-2026-3050

Horilla-opensourceHorilla5.1MEDIUM
Cross Site Scripting Vulnerability in Horilla CRM by Horilla Open S...

A security flaw has been identified in the Horilla CRM platform, specifically within the Leads Module. This vulnerability allows attackers to manipulate input in the 'Notes' function found in static/assets/js/global.js, leading to potential cross site scripting (XSS) exploits. The attack can be e...

PoC for CVE-2025-54100

MicrosoftWindows 10 Version 16077.8HIGH
Command Injection Vulnerability in Windows PowerShell by Microsoft

This vulnerability arises from the improper handling of special elements in command execution within Windows PowerShell. An attacker could exploit this flaw to execute arbitrary code locally on affected systems, potentially leading to unauthorized access and system compromise. Users of Windows Po...

PoC for CVE-2026-3049

Horilla-opensourceHorilla5.3MEDIUM
Open Redirect Vulnerability in Horilla CRM by Horilla Open Source

A security flaw has been identified in the Horilla CRM software impacting versions up to 1.0.2. Specifically, the `get` function in the Query Parameter Handler component, located in the `horilla_generics/global_search.py` file, is susceptible to manipulation through the `prev_url` argument. This ...

PoC for CVE-2026-3046

ItsourcecodeE-logbook With Health ...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode E-Logbook with Health M...

A vulnerability has been identified in the itsourcecode E-Logbook with Health Monitoring System for COVID-19 version 1.0, specifically affecting the file /check_profile_old.php. This vulnerability allows an attacker to manipulate the profile_id argument, leading to SQL injection attacks. Such vul...

Discovered 21 hours ago

PoC for CVE-2026-3044

TendaAc88.7HIGH
Stack-based Buffer Overflow in Tenda AC8 Router's Httpd Service

A critical security vulnerability has been identified in the Tenda AC8 router version 16.03.34.06, specifically within the Httpd Service. The function webCgiGetUploadFile located in the /cgi-bin/UploadCfg file is susceptible to manipulation of the argument boundary, leading to a stack-based buffe...

Discovered 22 hours ago

PoC for CVE-2026-3043

ItsourcecodeEvent Management System5.3MEDIUM
Cross-Site Scripting Vulnerability in itsourcecode Event Management...

A vulnerability has been discovered in the itsourcecode Event Management System version 1.0, specifically in the file /admin/navbar.php. This flaw allows attackers to manipulate the 'page' argument, leading to the potential execution of cross-site scripting (XSS) attacks. Such attacks are executa...

PoC for CVE-2026-3042

ItsourcecodeEvent Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Event Management System...

A security flaw was identified in the itsourcecode Event Management System version 1.0, specifically within an unknown function located in /admin/index.php. This vulnerability allows an attacker to manipulate the argument ID, leading to SQL injection. As a result, malicious users may exploit this...

Discovered 23 hours ago

PoC for CVE-2026-3041

XingfuggzBaykeshop4.8MEDIUM
Cross-Site Scripting Vulnerability in BaykeShop by xingfuggz

A cross-site scripting vulnerability exists in the Article Sidebar Module of xingfuggz BaykeShop, specifically in the file located at src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html. This issue arises from improper handling of the sidebar.content argument, allowing attackers...

PoC for CVE-2026-3040

DraytekVigor 300b5.1MEDIUM
OS Command Injection Vulnerability in DrayTek Vigor 300B Web Manage...

A vulnerability exists in the DrayTek Vigor 300B's web management interface, specifically within the cgiGetFile function of the /cgi-bin/mainfunction.cgi/uploadlangs component. This security flaw allows for OS command injection through the manipulation of the File parameter, enabling remote attac...

PoC for CVE-2026-3028

ErzhongxmuJeewms5.3MEDIUM
Cross-Site Scripting Vulnerability in erzhongxmu JEEWMS Product

A cross-site scripting vulnerability exists in the erzhongxmu JEEWMS web application, specifically in the 'doAdd' function of the JeecgListDemoController.java file. This flaw allows an attacker to manipulate the 'Name' argument, enabling the execution of malicious scripts in the context of users'...

Discovered 1 day ago

PoC for CVE-2026-3027

ErzhongxmuJeewms5.3MEDIUM
Cross Site Scripting Vulnerability in erzhongxmu JEEWMS's UEditor C...

A cross site scripting vulnerability has been identified in the erzhongxmu JEEWMS platform, specifically within the UEditor component. This vulnerability resides in the 'getContent.jsp' file, where improper handling of the 'myEditor' argument can lead to the execution of arbitrary JavaScript in t...

PoC for CVE-2026-3026

ErzhongxmuJeewms6.9MEDIUM
Server-Side Request Forgery Vulnerability in erzhongxmu JEEWMS UEdi...

A vulnerability exists in the erzhongxmu JEEWMS version 3.7, specifically in the UEditor component via the file /plug-in/ueditor/jsp/getRemoteImage.jsp. This security flaw allows attackers to manipulate the 'upfile' argument, which can lead to unauthorized server-side request forgery (SSRF). Expl...

PoC for CVE-2026-3016

UttHiper 810g8.7HIGH
Buffer Overflow Vulnerability in UTT HiPER 810G by UTT

A buffer overflow vulnerability exists in the UTT HiPER 810G device, specifically in the strcpy function of the /goform/formP2PLimitConfig file. This flaw arises when an attacker manipulates the input parameters, leading to potential remote exploitation. The vulnerability is known to be actively ...

PoC for CVE-2026-3015

UttHiper 810g8.7HIGH
Buffer Overflow Vulnerability in UTT HiPER 810G by UTT

A buffer overflow vulnerability exists in the UTT HiPER 810G product, specifically affecting the 'strcpy' function located in the /goform/formPolicyRouteConf file. This vulnerability is exploitable through remote attacks by manipulating the GroupName argument. Given that details about this exploi...

PoC for CVE-2026-2985

TiandyVideo Surveillance Sys...5.3MEDIUM
Server-Side Request Forgery in Tiandy Video Surveillance System

In the Tiandy Video Surveillance System version 7.17.0, a vulnerability has been identified within the downloadImage function of the file /com/tiandy/easy7/core/bo/CLSBODownLoad.java. This flaw allows an attacker to manipulate the urlPath argument, leading to server-side request forgery (SSRF). T...

PoC for CVE-2026-2984

SourcecodesterStudent Result Managem...6.9MEDIUM
Denial of Service Vulnerability in SourceCodester Student Result Ma...

A denial of service vulnerability has been discovered in the SourceCodester Student Result Management System 1.0. The issue arises due to improper handling of the ID argument in the file /admin/core/drop_user.php. An attacker can exploit this vulnerability remotely, leading to service unavailabil...

PoC for CVE-2026-2983

SourcecodesterStudent Result Managem...6.9MEDIUM
Improper Access Control in SourceCodester Student Result Management...

A vulnerability exists in the SourceCodester Student Result Management System version 1.0, specifically within the Bulk Import functionality found in /admin/core/import_users.php. This flaw arises due to inadequate access controls, allowing unauthorized users to manipulate the file import process...

PoC for CVE-2026-2981

UttHiper 810g8.7HIGH
Buffer Overflow Vulnerability in UTT HiPER 810G by UTT

A buffer overflow vulnerability exists in the UTT HiPER 810G, specifically within the strcpy function located in the '/goform/formTaskEdit_ap' file. By manipulating the 'txtMin2' argument, an attacker can exploit this vulnerability remotely, potentially compromising the integrity and security of ...

Discovered 2 days ago

PoC for CVE-2026-25747

ApacheApache Camel
Deserialization Vulnerability in Apache Camel LevelDB Component by ...

A deserialization vulnerability exists in the LevelDB component of Apache Camel, allowing attackers to inject crafted serialized Java objects. This occurs when the DefaultLevelDBSerializer class deserializes data from the LevelDB repository using java.io.ObjectInputStream without proper filtering...

PoC for CVE-2026-23552

ApacheApache Camel9.1CRITICAL
Cross-Realm Token Acceptance Bypass in Apache Camel Keycloak Component

The KeycloakSecurityPolicy in the Apache Camel Keycloak component is vulnerable to a bypass that allows JWT tokens from one Keycloak realm to be accepted by policies configured for different realms, thus compromising tenant isolation. This results in the potential for unauthorized access and acti...

PoC for CVE-2026-2980

UttHiper 810g8.6HIGH
Buffer Overflow in UTT HiPER 810G Functionality

A buffer overflow vulnerability exists in the UTT HiPER 810G device, specifically within the strcpy function in the /goform/setSysAdm file. Malicious users can exploit this vulnerability by manipulating the passwd1 argument, potentially leading to unauthorized access or control over the affected ...

PoC for CVE-2023-43208

NextgenMirth Connect🟣 EPSS 94%9.8CRITICAL
Unauthenticated Remote Code Execution Vulnerability Affects NextGen...

CVE-2023-43208 is an unauthenticated remote code execution vulnerability that affects NextGen Healthcare Mirth Connect before version 4.4.1. The vulnerability stems from an incomplete patch of a previous vulnerability, making it a patch bypass issue. It allows for the insecure use of the Java XSt...

PoC for CVE-2026-2979

FastApiFastapiadmin5.3MEDIUM
Unrestricted Upload Vulnerability in FastApiAdmin by FastApi

A vulnerability has been identified in FastApiAdmin versions up to 2.2.0, where the function user_avatar_upload_controller, located in /backend/app/api/v1/module_system/user/controller.py, is susceptible to unrestricted file uploads. This flaw allows an attacker to manipulate the upload functiona...

PoC for CVE-2026-2978

FastApiFastapiadmin5.3MEDIUM
Unrestricted File Upload Vulnerability in FastApiAdmin by FastApi

A vulnerability has been identified in FastApiAdmin versions up to 2.2.0 which affects the upload_file_controller function found in the Scheduled Task API. This flaw allows attackers to perform unrestricted file uploads, enabling potential remote exploitation. The vulnerability is now public and ...

PoC for CVE-2026-2977

EudatFastapiadmin5.3MEDIUM
Unrestricted File Upload Vulnerability in FastApiAdmin by Eudat

A vulnerability has been identified in FastApiAdmin versions up to 2.2.0 within the Scheduled Task API, specifically in the upload_controller function located in the controller.py file. This issue allows for unrestricted file uploads, permitting attackers to exploit this vulnerability remotely. A...

PoC for CVE-2026-2976

Community CreatorFastapiadmin5.3MEDIUM
Information Disclosure Vulnerability in FastApiAdmin by Community C...

A vulnerability has been identified in FastApiAdmin versions up to 2.2.0 that allows attackers to disclose sensitive information. This issue exists due to improper handling of the argument file_path in the download_controller function located in /backend/app/api/v1/module_common/file/controller.p...

PoC for CVE-2026-2975

CC-TFastapiadmin6.9MEDIUM
Information Disclosure Vulnerability in FastApiAdmin by CC-T

A security flaw in FastApiAdmin versions up to 2.2.0 affects the reset_api_docs function located in the /backend/app/plugin/init_app.py file. This vulnerability allows unauthorized access to sensitive system information via the Custom Documentation Endpoint. Attackers can exploit this vulnerabili...

PoC for CVE-2026-2974

AliasVaultAliasvault App2LOW
Insecure Storage Vulnerability in AliasVault App for Android/iOS

A vulnerability has been identified in the AliasVault App versions up to 0.25.3 for Android and iOS, originating from inadequate handling of sensitive information in the backup process. Specifically, this flaw involves the manipulation of the accessToken, refreshToken, metadata, and key derivatio...

PoC for CVE-2026-2972

A466350665Smart-sso4.8MEDIUM
Cross-Site Scripting Vulnerability in a466350665 Smart-SSO Role Edi...

A cross-site scripting vulnerability has been identified in the a466350665 Smart-SSO product, specifically affecting the Save function within the UserController of the Role Edit Page. This flaw allows attackers to manipulate input fields, which can be exploited remotely to execute arbitrary scrip...