Publicly Disclosed
PoC Exploits

πŸ”΄ Alway take caution when working with PoC Exploits πŸ”΄

Discovered 2 hours ago

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 87%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

Discovered 4 hours ago

PoC for CVE-2025-7771

TecHPowerupThrottlestop8.7HIGH
Privilege Escalation Vulnerability in ThrottleStop Driver by TechPo...

The ThrottleStop driver, a legitimate component from TechPowerUp, presents a vulnerability due to insecure IOCTL interfaces that permit arbitrary read and write access to the physical memory through the MmMapIoSpace function. This flaw can be exploited by malicious applications running in user mo...

Discovered 5 hours ago

PoC for CVE-2026-1555

WordPressWebstack9.8CRITICAL
Arbitrary File Upload Vulnerability in WebStack Theme for WordPress

The WebStack theme for WordPress contains a vulnerability that permits arbitrary file uploads due to insufficient file type validation in the io_img_upload() function. Any attacker, even those without authentication, can exploit this weakness to upload malicious files to the server hosting the af...

Discovered 6 hours ago

PoC for CVE-2026-33671

MicromatchPicomatch7.5HIGH
ReDoS Vulnerability in Picomatch Library by Micromatch

The Picomatch library, used for glob pattern matching in JavaScript, is prone to a Regular Expression Denial of Service (ReDoS) attack when processing specially crafted extglob patterns. Specifically, versions before 4.0.4, 3.0.2, and 2.3.2 can become susceptible to catastrophic backtracking on c...

Discovered 7 hours ago

PoC for CVE-2007-2447

SambaSamba🟣 EPSS 77%
Remote Command Execution Vulnerability in Samba by The Samba Team

The MS-RPC functionality within the Samba server allows attackers to execute arbitrary commands remotely due to improper handling of shell metacharacters. When the 'username map script' configuration option is enabled, a malicious user can exploit the SamrChangePassword function to inject command...

Discovered 8 hours ago

PoC for CVE-2026-26980

TryghostGhost🟣 EPSS 33%9.4CRITICAL
Unauthenticated Database Read Vulnerability in Ghost CMS

Ghost CMS, a widely used Node.js content management system, contains a vulnerability that enables unauthenticated attackers to execute arbitrary reads from its database. This security flaw affects versions 3.24.0 through 6.19.0, posing a significant risk to the confidentiality of sensitive data s...

Discovered 13 hours ago

PoC for CVE-2019-0708

MicrosoftWindows🟣 EPSS 94%9.8CRITICAL
Remote Code Execution Vulnerability in Microsoft Remote Desktop Ser...

A remote code execution vulnerability in Microsoft Remote Desktop Services allows an unauthenticated attacker to connect to the target system via RDP and execute arbitrary code by sending specially crafted requests. This exploitation can lead to significant security breaches if not mitigated adeq...

Discovered 17 hours ago

PoC for CVE-2026-33032

0xjackyNginx-ui9.8CRITICAL
Vulnerability in Nginx UI Web Interface for Nginx Server

The Nginx UI web interface, specifically versions 2.3.5 and earlier, is susceptible to a serious flaw due to improper authentication in its MCP (Model Context Protocol) integration. This vulnerability allows attackers, without any authentication, to exploit the /mcp_message endpoint. Although the...

Discovered 18 hours ago

PoC for CVE-2026-39842

OpenremoteOpenremote10CRITICAL
Expression Injection Vulnerabilities in OpenRemote IoT Platform

The OpenRemote IoT platform, specifically versions 1.21.0 and below, is impacted by two related expression injection vulnerabilities. These flaws exist within the rules engine, allowing unauthorized users to execute arbitrary code on the server. The JavaScript rules engine processes user-defined ...

Discovered 21 hours ago

PoC for CVE-2026-6497

PrasathmaniTinyfilemanager5.3MEDIUM
Server-Side Request Forgery in TinyFileManager by prasathmani

A vulnerability exists in TinyFileManager, specifically in the file upload functionality located at /filemanager.php?p=ajax=true&type=upload. This flaw allows an attacker to manipulate the uploadurl parameter, potentially leading to a server-side request forgery (SSRF) attack. Such an attack can ...

Discovered 22 hours ago

PoC for CVE-2026-6496

PrasathmaniTinyfilemanager5.3MEDIUM
Path Traversal Vulnerability in TinyFileManager by prasathmani

A vulnerability exists in prasathmani TinyFileManager versions up to 2.6, specifically within the POST Parameter Handler found in the file /filemanager.php. This issue arises from inadequate input validation, allowing attackers to manipulate the 'file[]' parameter to perform path traversal attack...

PoC for CVE-2026-6493

LukevellaRallly5.1MEDIUM
Cross-Site Scripting Vulnerability in Rallly by Lukevella

A security flaw has been identified in Rallly versions up to 4.7.4, specifically within the Reset Password Handler component. This vulnerability arises from improper handling of the 'redirectTo' argument, which may allow attackers to execute cross-site scripting (XSS) attacks remotely. If exploit...

PoC for CVE-2026-6492

Arnobt78Hotel Booking Manageme...6.9MEDIUM
Information Disclosure Vulnerability in arnobt78 Hotel Booking Mana...

A vulnerability exists in the arnobt78 Hotel Booking Management System, specifically within the health check endpoint, where an unknown function can be exploited to disclose sensitive information. This vulnerability allows remote attackers to perform unauthorized access, leading to potential info...

PoC for CVE-2026-6491

libvipsLibvips4.8MEDIUM
Heap-based Buffer Overflow in libvips Affects Local Applications

A security vulnerability exists in the libvips library prior to version 8.19, specifically within the im_minpos_vec function in the deprecated vips7compat.c file. This vulnerability allows for heap-based buffer overflow due to inadequate handling of the argument n, requiring local access for expl...

Discovered 23 hours ago

PoC for CVE-2026-6490

QuerymineSms6.9MEDIUM
SQL Injection Vulnerability in QueryMine SMS Product by Unknown Vendor

A SQL injection vulnerability exists in the QueryMine sms component, specifically within the admin/deletecourse.php file. This issue arises due to improper handling of the GET request parameter 'ID', allowing attackers to manipulate the input and execute unauthorized SQL queries. The attack can b...

PoC for CVE-2026-6489

QuerymineSms5.3MEDIUM
Unrestricted File Upload Vulnerability in QueryMine sms Background ...

A security flaw has been identified in QueryMine sms, specifically affecting the admin/addteacher.php file within the Background Management Page component. The vulnerability allows attackers to manipulate the image argument, leading to unrestricted file uploads. This can be exploited remotely, po...

PoC for CVE-2026-6488

QuerymineSms5.3MEDIUM
SQL Injection Vulnerability in QueryMine sms by QueryMine

A SQL injection vulnerability has been discovered in QueryMine sms that impacts the GET Request Parameter Handler in the editcourse.php file. This vulnerability arises from improper handling of the ID argument, allowing remote attackers to manipulate SQL queries. Due to the continuous delivery an...

Discovered 1 day ago

PoC for CVE-2026-0740

WordPressNinja Forms - File Upl...9.8CRITICAL
Arbitrary File Upload Vulnerability in Ninja Forms File Uploads Plu...

The Ninja Forms - File Uploads plugin for WordPress contains a vulnerability allowing unauthenticated attackers to upload arbitrary files due to inadequate file type validation in the upload handling function. This oversight affects all versions upto and including 3.3.26, potentially enabling att...

PoC for CVE-2026-6487

QihuiJtbc5 Cms5.3MEDIUM
Path Traversal Vulnerability in Qihui jtbc5 CMS by Shanghai Qihui N...

A vulnerability exists in the Qihui jtbc5 CMS, specifically in the Code Endpoint component located in manage.php. This flaw allows attackers to manipulate input parameters related to file paths, leading to unauthorized access to files outside of the intended directory. The exploit can be executed...

PoC for CVE-2026-6486

ClassroombookingsClassroombookings5.1MEDIUM
Cross-Site Scripting Vulnerability in Classroom Bookings by Classro...

A cross-site scripting vulnerability was identified in Classroom Bookings versions up to 2.17.0, specifically within the User Display Name Handler component. The vulnerability arises from improper handling of the 'displayname' argument in the file crbs-core/application/views/layout.php, allowing ...

PoC for CVE-2026-6483

WavlinkWl-wn530h48.6HIGH
OS Command Injection in Wavlink Wireless Router

A vulnerability has been identified in the Wavlink WL-WN530H4 model, specifically within the strcat and snprintf functions of the /cgi-bin/internet.cgi file. This security flaw enables remote attackers to inject operating system commands, potentially leading to unauthorized access and control ove...

PoC for CVE-2025-8110

GogsGogs🟣 EPSS 20%8.7HIGH
Improper Symbolic Link Handling in Gogs Product by Gogs Team

The vulnerability in the PutContents API of Gogs arises from improper handling of symbolic links, potentially allowing local execution of arbitrary code. This misconfiguration may expose sensitive data and facilitate unauthorized access to critical systems. Users and administrators are urged to u...

PoC for CVE-2024-30088

MicrosoftWindows 10 Version 1809🟣 EPSS 85%7HIGH
Windows Kernel Elevation of Privilege Vulnerability

This vulnerability allows an attacker to execute arbitrary code with elevated privileges, potentially gaining control over the affected system. By exploiting the fault in the Windows Kernel, the attacker could leverage this to manipulate system processes and escalate privileges, making it a signi...

PoC for CVE-2026-33555

HaproxyHaproxy4MEDIUM
Request Smuggling Vulnerability in HAProxy HTTP/3 Parser

An issue has been identified in HAProxy's HTTP/3 parser prior to version 3.3.6, where the parser fails to ensure that the content length of received bodies corresponds with the previously set content-length. This oversight can lead to desynchronization with backend servers when the stream is term...

PoC for CVE-2026-21858

N8n-ioN8n10CRITICAL
Vulnerability in n8n Workflow Automation Platform Could Lead to Sen...

The n8n workflow automation platform has a vulnerability in versions ranging from 1.65.0 to just below 1.121.0, which allows potential attackers to exploit specific form-based workflows. This flaw can enable unauthorized remote access to sensitive files on the underlying server, posing a signific...

PoC for CVE-2026-37749

CodeAstroSimple Attendance Mana...9.8CRITICAL
SQL Injection Vulnerability in CodeAstro Simple Attendance Manageme...

A SQL injection vulnerability exists in CodeAstro's Simple Attendance Management System version 1.0. This flaw allows remote, unauthenticated attackers to bypass authentication mechanisms by exploiting the username parameter in the index.php file. Successful exploitation of this vulnerability ena...

Discovered 2 days ago

PoC for CVE-2025-15602

Grokability, Inc.Snipe-it8.7HIGH
Mass Assignment Vulnerability in Snipe-IT Software by Grokability

A significant vulnerability in Snipe-IT affects versions prior to 8.3.7, where sensitive user attributes are inadequately protected against mass assignment attacks. This flaw enables an authenticated, low-privileged user to manipulate API requests, altering restricted fields within another user's...

PoC for CVE-2026-1880

AsusDriverhub5.4MEDIUM
Privilege Escalation Vulnerability in ASUS DriverHub

An issue in the ASUS DriverHub update process stems from incorrect permission assignments, which can lead to privilege escalation. During the validation phase of the update process, inadequate protection of critical execution resources allows a local user to modify these resources without appropr...

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-34220

Mikro-ormMikro-orm9.3CRITICAL
SQL Injection Vulnerability in MikroORM TypeScript ORM by Mikro

MikroORM, a TypeScript Object-Relational Mapper for Node.js, has a vulnerability that can lead to SQL injection. This issue arises when specially crafted objects are treated as raw SQL fragments, potentially allowing attackers to manipulate database queries. The vulnerability has been addressed i...

PoC for CVE-2026-0827

LenovoDiagnostics6.9MEDIUM
Arbitrary File Write Vulnerability in Lenovo Diagnostics and Hardwa...

A potential vulnerability was identified in Lenovo Diagnostics and its associated HardwareScanAddin used in the Lenovo Vantage application. This flaw may allow a local authenticated user to write arbitrary files with elevated privileges during installation or when executing a hardware scan, poten...

PoC for CVE-2025-49113

RoundcubeWebmail🟣 EPSS 91%9.9CRITICAL
Remote Code Execution Vulnerability in Roundcube Webmail by Roundcube

A vulnerability in Roundcube Webmail prior to version 1.5.10 and 1.6.x before 1.6.11 allows authenticated users to exploit the _from parameter in the URL. This issue arises from a lack of validation in program/actions/settings/upload.php, leading to the potential for PHP Object Deserialization at...

PoC for CVE-2025-27591

Meta Platforms, IncBelow6.8MEDIUM
Privilege Escalation Vulnerability in Below Service by Facebook

A privilege escalation vulnerability was identified in the Below service prior to version 0.9.0. This vulnerability arises from the creation of a world-writable directory located at /var/log/below. As a result, local unprivileged users can exploit this flaw through symlink attacks, potentially ma...

PoC for CVE-2025-24893

XwikiXwiki-platform🟣 EPSS 94%9.8CRITICAL
Remote Code Execution Vulnerability in XWiki Platform by XWiki SAS

The XWiki Platform is vulnerable due to improper handling of inputs, allowing unauthenticated users to execute arbitrary code via the `SolrSearch` endpoint. This can result in significant breaches of confidentiality, integrity, and availability of the XWiki installation. Users are encouraged to u...

PoC for CVE-2024-12029

Invoke-aiInvoke-ai/invokeai🟣 EPSS 44%9.8CRITICAL
Remote Code Execution Vulnerability in InvokeAI by Invoke AI

A vulnerability exists in InvokeAI versions 5.3.1 through 5.4.2, allowing remote code execution through the /api/v2/models/install endpoint. This vulnerability is due to the unsafe deserialization of model files with torch.load, lacking proper validation of input data. Attackers can exploit this ...

PoC for CVE-2026-34621

AdobeAcrobat Reader8.6HIGH
Prototype Pollution Vulnerability in Adobe Acrobat Reader

Adobe Acrobat Reader is impacted by a Prototype Pollution vulnerability that allows attackers to execute arbitrary code within the context of the current user. This flaw is triggered only when a user interacts with a malicious file, making user awareness essential. It is crucial for users to keep...

Discovered 3 days ago

PoC for CVE-2025-58060

OpenprintingCups8HIGH
Authentication Bypass in OpenPrinting CUPS Affects Multiple Unix-li...

OpenPrinting CUPS, an open-source printing system utilized across various Linux and Unix-like operating systems, is subject to a critical vulnerability that allows an authentication bypass. Specifically, in versions 2.4.12 and earlier, if the `AuthType` is set to anything other than `Basic`, the ...

PoC for CVE-2022-35650

MoodleMoodle7.5HIGH
Directory Traversal Vulnerability in Moodle Affecting Teachers and ...

A vulnerability exists in Moodle that stems from an input validation error occurring during the importation of lesson questions. This flaw allows for insufficient path checks, which can lead to arbitrary file reading via directory traversal attacks. It is important to note that access to this fea...

PoC for CVE-2026-39808

FortinetFortisandbox9.1CRITICAL
OS Command Injection Vulnerability in Fortinet FortiSandbox

An OS command injection vulnerability exists in Fortinet FortiSandbox versions 4.4.0 through 4.4.8. This flaw arises from improper neutralization of special elements used in operating system commands. An attacker can exploit this vulnerability to execute unauthorized commands, potentially comprom...

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-40487

GitroomhqPostiz-app8.9HIGH
File Upload Validation Bypass in Postiz AI Social Media Tool

Prior to version 2.21.6, the Postiz AI social media scheduling tool contained a vulnerability that allowed authenticated users to exploit a file upload validation bypass. By manipulating the `Content-Type` header, it became possible for users to upload potentially harmful files, such as HTML and ...

PoC for CVE-2026-40500

ProcesswireProcesswire6.1MEDIUM
Server-Side Request Forgery in ProcessWire CMS by ProcessWire

The ProcessWire CMS versions 3.0.255 and earlier are susceptible to a server-side request forgery (SSRF) vulnerability found in the admin panel's 'Add Module From URL' feature. Authenticated administrators can input arbitrary URLs in the module download parameter, resulting in the server making u...

PoC for CVE-2024-26229

MicrosoftWindows 10 Version 1809🟣 EPSS 83%7.8HIGH
Windows CSC Service Elevation of Privilege Vulnerability

The CVE-2024-26229 vulnerability in the Windows CSC Service is being exploited with proof-of-concept (PoC) exploit code available on GitHub. This high-severity vulnerability could allow attackers to gain SYSTEM privileges on a Windows system, posing a significant risk. This type of elevation of p...

PoC for CVE-2021-4034

Polkit ProjectPolkit🟣 EPSS 88%7.8HIGH
Local Privilege Escalation Vulnerability in polkit's pkexec Utility

A local privilege escalation vulnerability exists within the pkexec utility of polkit, a setuid tool that allows unprivileged users to execute commands as privileged users based on predetermined policies. Due to insufficient handling of the calling parameters, pkexec can misinterpret environment ...

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-1357

WordPressWPvivid β€” Backup, Migr...🟣 EPSS 19%9.8CRITICAL
Unauthenticated Arbitrary File Upload in WPvivid Backup & Migration...

The WPvivid Backup & Migration plugin for WordPress is susceptible to an unauthenticated arbitrary file upload vulnerability due to improper error handling in the RSA decryption process and inadequate path sanitization during file uploads. This allows malicious attackers to exploit the system by ...

PoC for CVE-2025-24000

WordPressPost Smtp8.8HIGH
Authentication Bypass Vulnerability in WPExperts Post SMTP Plugin

The WPExperts Post SMTP plugin contains an authentication bypass vulnerability that allows attackers to exploit alternate pathways for gaining unauthorized access. This issue affects versions from n/a up to 3.2.0, potentially compromising the security of WordPress installations using this plugin....

PoC for CVE-2025-48561

GoogleAndroid5.5MEDIUM
Data Exposure Vulnerability in Android Framework by Google

A vulnerability has been identified in the Android Framework that allows for potential exposure of sensitive information displayed on the screen. This may occur without the need for user interaction or elevated execution privileges, resulting in local information disclosure risks. The issue arise...

PoC for CVE-2026-40499

RadareorgRadare28.4HIGH
Command Injection Vulnerability in radare2 PDB Parser

radare2, prior to version 6.1.4, is susceptible to a command injection vulnerability located in the PDB parser's print_gvars() function. This vulnerability allows attackers to execute arbitrary commands by inserting a newline byte into the PE section header name field of a maliciously crafted PDB...