Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 1 hour ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 3 hours ago

PoC for CVE-2026-103687

RhuksterDom-sanitizer6.9MEDIUM
SVG Sanitization Flaw in Rhukster DOM-Sanitizer Affects Multiple Ve...

A vulnerability exists in the Rhukster DOM-Sanitizer component related to SVG sanitization. The flaw lies in the handling of the function 'url' in the src/DOMSanitizer.php file, which creates an incomplete blacklist for input validation. This allows a potential attacker to exploit the vulnerabili...

PoC for CVE-2024-58388

Sharp CorporationMultiple Multifunction...8.7HIGH
Unauthenticated Local File Inclusion Vulnerability in Sharp Multifu...

Sharp and Toshiba Tec multifunction printers are susceptible to an unauthenticated local file inclusion vulnerability. This issue arises from improper validation of user input in the installed_emanual_down.html endpoint. By manipulating the path parameter, attackers can execute directory traversa...

Discovered 4 hours ago

PoC for CVE-2026-103686

RhuksterDom-sanitizer5.1MEDIUM
Cross-Site Scripting Vulnerability in rhukster dom-sanitizer URL Va...

A security flaw exists in rhukster's dom-sanitizer component, specifically in the URL validation functionality. The issue lies within the DOMSanitizer::isDangerousUrl method, which can be exploited for cross-site scripting attacks. This vulnerability can allow attackers to initiate remote exploit...

PoC for CVE-2024-55591

FortinetFortiOS🟣 EPSS 94%9.6CRITICAL
Remote Attackers Can Gain Super-Admin Privileges via Crafted Reques...

A vulnerability exists in FortiOS and FortiProxy that allows a remote attacker to exploit an authentication bypass through crafted requests targeting the Node.js websocket module. This weakness could enable unauthorized users to attain super-admin privileges, compromising system security. Users o...

Discovered 6 hours ago

PoC for CVE-2026-88771

Citrix NetscalerAdc9.5CRITICAL
Improper Input Validation in Citrix NetScaler ADC and Gateway

An improper input validation vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway, enabling unauthenticated attackers to execute arbitrary commands. This potentially compromises system integrity and security, allowing unauthorized control over the affected product.

Discovered 7 hours ago

PoC for CVE-2026-59310

VmwareCloud Foundation9.8CRITICAL
Directory Traversal Vulnerability in VMware vCenter by VMware

VMware vCenter features a directory traversal vulnerability in its Syslog server component. This flaw allows attackers with network access to exploit the vulnerability, potentially leading to unauthorized execution of arbitrary code. Proper safeguards and patching are essential to mitigate the ri...

PoC for CVE-2026-103585

The Wikimedia Fou...Mediawiki Mediasearch ...1.2LOW
XSS Vulnerability in Wikimedia Foundation's MediaWiki MediaSearch E...

A Cross-Site Scripting (XSS) vulnerability exists in the MediaWiki MediaSearch extension, allowing attackers to inject malicious scripts through improperly neutralized HTML tags in web pages. This affects versions 1.46, 1.45, and 1.43, posing a risk to users by enabling the execution of harmful s...

PoC for CVE-2026-103584

The Wikimedia Fou...Mediawiki Commonsmetad...1.1LOW
Cross-Site Scripting Vulnerability in Wikimedia Foundation MediaWik...

The Wikimedia Foundation MediaWiki CommonsMetadata extension is susceptible to a Cross-Site Scripting vulnerability due to improper neutralization of script-related HTML tags. This flaw permits attackers to inject malicious scripts into web pages viewed by users, which can lead to unauthorized ac...

Discovered 11 hours ago

PoC for CVE-2026-103544

Datadrivenconstru...Openconstructionerp5.3MEDIUM
Improper Access Control in OpenConstructionERP by DataDrivenConstru...

A significant vulnerability affects the OpenConstructionERP software, specifically in the Al Provider Configuration Handler. An unknown function within the ai_client.py file can lead to improper access control, allowing data elements to be exposed to unauthorized sessions. This vulnerability is r...

PoC for CVE-2026-96173

WordPressPayments For Hubtel5.3MEDIUM
Authorization Flaw in Payments for Hubtel Plugin Enhances Attack Ex...

The Payments for Hubtel WordPress plugin, prior to version 1.0.2, is susceptible to an authorization flaw that fails to validate whether the requester is authorized to access order information. This vulnerability permits unauthenticated attackers to redirect public payment-callback requests, ther...

PoC for CVE-2026-92412

WordPressFive Star Restaurant R...7.1HIGH
Cross-Site Scripting Risks in Five Star Restaurant Reviews Plugin b...

The Five Star Restaurant Reviews plugin for WordPress, prior to version 2.3.14, is vulnerable to Cross-Site Scripting (XSS). This vulnerability arises from improper escaping of user-supplied input, allowing unauthenticated attackers to inject malicious scripts. As a result, any user, including lo...

PoC for CVE-2026-90974

WordPressWP Fusion Lite6.5MEDIUM
Authentication Bypass in WP Fusion Lite Plugin Affects WordPress Users

The WP Fusion Lite plugin for WordPress, prior to version 3.48.0, is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated users to access critical settings within the WordPress admin area. By exploiting this weakness, attackers can manipulate the site's CRM inte...

PoC for CVE-2026-90972

WordPressWP Fusion Lite5.4MEDIUM
Unauthorized Data Exposure in WP Fusion Lite Plugin

The WP Fusion Lite plugin for WordPress prior to version 3.48.0 has a significant security flaw where it fails to conduct proper capability checks on two of its admin AJAX handlers. This oversight enables any authenticated subscriber to access other users' email addresses, leading to unauthorized...

PoC for CVE-2026-96255

WordPressPayments For Hubtel7.5HIGH
Unrestricted Access to Sensitive Payment Data in Hubtel WordPress P...

The Payments for Hubtel WordPress plugin prior to version 1.0.2 has a serious flaw that permits unauthorized public access to a debug log. This log stores sensitive information, including the API credentials for the payment gateway, in an unsecured plain text format. As a result, unauthenticated ...

PoC for CVE-2026-96200

WordPressPayments For Hubtel5.3MEDIUM
Security Flaw in Payments for Hubtel Plugin Paves Way for Unauthori...

The Payments for Hubtel WordPress plugin prior to version 1.0.2 is susceptible to a vulnerability that lacks verification of payment notifications received through its payment callback mechanism. This oversight permits unauthenticated attackers to falsely mark arbitrary orders as paid, leading to...

PoC for CVE-2026-87973

WordPressIf-so Dynamic Content3.1LOW
JavaScript Injection Vulnerability in If-So Dynamic Content Plugin ...

The If-So Dynamic Content plugin for WordPress prior to version 1.10.2 is susceptible to a JavaScript injection vulnerability. This issue arises because the plugin fails to properly sanitize conversion names before saving them and does not escape content during the rendering of the analytics page...

PoC for CVE-2026-81809

WordPressPaytm Payment Gateway7.5HIGH
SQL Injection Vulnerability in Paytm Payment Gateway Plugin for Wor...

The Paytm Payment Gateway WordPress plugin versions before 2.8.9 is susceptible to SQL injection due to improper data escaping from payment callbacks. Malicious users can exploit this vulnerability, particularly when the gateway operates without the required credentials, enabling them to manipula...

PoC for CVE-2026-89296

WordPressPro Like Button8.6HIGH
SQL Injection Vulnerability in Pro Like Button Plugin for WordPress

The Pro Like Button plugin for WordPress prior to version 2.0 contains a vulnerability that fails to properly sanitize and escape input parameters used in SQL queries. This flaw allows unauthenticated attackers to manipulate the queries, potentially executing arbitrary SQL commands. As a result, ...

PoC for CVE-2026-86610

WordPressDownload Manager6.4MEDIUM
Stored Cross-Site Scripting Vulnerability in Download Manager Plugi...

The Download Manager plugin for WordPress prior to version 3.3.71 has a vulnerability that arises from inadequate sanitization of user inputs. This allows users with the Author role or higher to exploit the system by injecting malicious scripts into the package settings. When a visitor accesses t...

PoC for CVE-2026-87970

WordPressIf-so Dynamic Content4.7MEDIUM
Improper Validation in If-So Dynamic Content Plugin for WordPress

The If-So Dynamic Content plugin for WordPress prior to version 1.10.2 is susceptible to an improper input validation vulnerability. This flaw arises from the plugin's failure to adequately escape user-supplied values in AJAX responses. As a consequence, unauthenticated attackers can inject and e...

PoC for CVE-2026-101147

WordPressFeatured Image From Ur...8.8HIGH
Cross-Site Request Forgery in Featured Image from URL Plugin for Wo...

The Featured Image from URL (FIFU) plugin for WordPress is susceptible to Cross-Site Request Forgery due to improper enforcement of the REST API nonce in versions prior to 6.0.8 and 8.2.8 for the Premium variant. This security flaw enables attackers to exploit the vulnerability through crafted UR...

PoC for CVE-2026-19253

WordPressCache Enabler8.7HIGH
Improper URL Validation in Cache Enabler Plugin for WordPress

The Cache Enabler WordPress plugin, prior to version 1.8.17, contains a vulnerability that allows unauthenticated users to exploit the URL handling in its cache purge process. By failing to validate a user-supplied URL, the plugin can generate a filesystem path that extends beyond its intended ca...

PoC for CVE-2026-101148

WordPressBackupsheep WordPress ...10CRITICAL
Unauthenticated Site Backup Issues in BackupSheep WordPress Plugin

The BackupSheep WordPress Backup Plugin, prior to version 1.8, fails to impose adequate validation checks on its integration key, mistakenly allowing an unset or blank key to be treated as valid. This loophole enables unauthenticated users to access sensitive functionalities, such as creating and...

PoC for CVE-2026-81739

WordPressPaytm Payment Gateway7.5HIGH
Unsecured Payment Gateway Plugin for WordPress Exposes Administrato...

The Paytm Payment Gateway plugin for WordPress prior to version 2.8.9 is vulnerable due to the lack of proper sanitization and escaping of payment callback data. This allows unauthenticated users to manipulate the data stored on admin pages, potentially injecting malicious scripts. Furthermore, t...

PoC for CVE-2026-103543

ItsourcecodeLeave Management System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Leave Management System...

A vulnerability exists in the itsourcecode Leave Management System 1.0 that allows attackers to exploit an unknown function within the /module/leavetype/controller.php file. By manipulating the LEAVTID argument, an attacker can execute SQL injection attacks remotely. This vulnerability has been d...

Discovered 12 hours ago

PoC for CVE-2026-103542

Formtools.orgForm Tools5.3MEDIUM
Server-Side Request Forgery Vulnerability in Form Tools by Formtool...

A security flaw has been identified in Form Tools, specifically within the smart_fill function located in the AJAX Endpoint's actions.php file. This vulnerability allows attackers to manipulate the 'url' argument, leading to server-side request forgery (SSRF). It poses a significant risk as the a...

PoC for CVE-2026-103541

Formtools.orgForm Tools5.3MEDIUM
Unrestricted File Upload Vulnerability in Form Tools by formtools.org

A vulnerability was discovered in Form Tools that allows for unrestricted file uploads due to a flaw in the uploadFile function within the Ajax Handler component. This issue is present in versions up to 3.1.1. The flaw enables remote attackers to exploit the vulnerability and upload arbitrary fil...

PoC for CVE-2026-103540

Formtools.orgForm Tools5.3MEDIUM
Server-Side Template Injection Vulnerability in FormTools by formto...

A security vulnerability has been identified in the Form Tools application, specifically impacting versions up to 3.1.1. This flaw affects the function 'Clients::updateClientSettingsTab' within the Client Settings component, located in 'global/code/Clients.class.php'. The issue arises from the im...

PoC for CVE-2026-103539

ZongxrSupermarket5.3MEDIUM
Missing Authentication Vulnerability in ZongXR SuperMarket Product

A vulnerability has been identified in the ZongXR SuperMarket version 1.0.0.0, specifically within the Instant Buy component. This weakness allows for a manipulation of the 'Username' argument during the execution of the 'startBuy' function located in the InstantBuyController.java file. As a resu...

Discovered 13 hours ago

PoC for CVE-2026-103538

ZongxrSupermarket6.9MEDIUM
Authentication Vulnerability in ZongXR SuperMarket Product

A significant security vulnerability has been identified in the ZongXR SuperMarket version 1.0.0.0, specifically within the Order Deletion Endpoint function. This flaw arises from improper handling of the orderId parameter in the OrderController.deleteOrder method, leading to a situation where au...

PoC for CVE-2026-103536

ZongxrSupermarket6.9MEDIUM
Missing Authentication Flaw in ZongXR Supermarket's Order Processin...

A significant security flaw has been identified in the ZongXR Supermarket application, specifically within the OrderController component. The issue lies in the addOrder function, located in the order/src/main/java/com/supermarket/order/controller/OrderController.java file. This vulnerability allo...

Discovered 14 hours ago

PoC for CVE-2026-103446

The Wikimedia Fou...Mediawiki Wikilambda E...7.4HIGH
Authorization Bypass Vulnerability in Wikimedia Foundation's MediaW...

An authorization bypass vulnerability exists in the WikiLambda extension of MediaWiki, allowing unauthorized users to bypass authentication mechanisms. This flaw is triggered by user-controlled keys, enabling potentially malicious actions. The vulnerability affects the MediaWiki WikiLambda extens...

PoC for CVE-2026-103445

The Wikimedia Fou...Mediawiki Page Forms E...1.2LOW
Stored XSS Vulnerability in MediaWiki Page_Forms Extension by Wikim...

The MediaWiki Page_Forms extension from Wikimedia Foundation contains a vulnerability that allows for stored cross-site scripting (XSS). This issue arises from the improper neutralization of script-related HTML tags within web pages, potentially enabling attackers to inject malicious scripts that...

PoC for CVE-2026-103442

The Wikimedia Fou...Mediawiki Centralauth ...7.2HIGH
Code Injection Vulnerability in MediaWiki CentralAuth Extension by ...

A vulnerability exists in the MediaWiki CentralAuth extension that allows external entities to manipulate system or configuration settings, leading to potential code injection. This issue impacts versions 1.46, 1.45, and 1.43. Users of affected versions are encouraged to update their installation...

PoC for CVE-2026-103441

The Wikimedia Fou...Mediawiki Wikibase Ext...7.2HIGH
Deserialization Vulnerability in Wikimedia Foundation MediaWiki Wik...

A deserialization of untrusted data vulnerability exists in the Wikimedia Foundation MediaWiki Wikibase extension, potentially enabling the execution of executable code in files that are not typically executable. This issue raises significant security concerns as it affects multiple versions of t...

PoC for CVE-2026-103440

The Wikimedia Fou...Mediawiki Pagetriage E...1.2LOW
Sensitive Information Exposure in MediaWiki PageTriage by Wikimedia...

A vulnerability in the MediaWiki PageTriage extension enables the exposure of sensitive information through improper data queries. Attackers can potentially elicit data that should be protected, impacting user privacy and system integrity. This issue affects specific versions of the PageTriage ex...

PoC for CVE-2026-103437

The Wikimedia Fou...Mediawiki Readinglists...1.1LOW
Reflected XSS Vulnerability in Wikimedia Foundation’s MediaWiki Rea...

A reflected XSS vulnerability exists in the MediaWiki ReadingLists extension developed by Wikimedia Foundation. This vulnerability stems from improper neutralization of script-related HTML tags in web pages, allowing attackers to execute malicious scripts in the context of a user's browser. Users...

PoC for CVE-2026-103534

David-crtyDatabasement5.3MEDIUM
Improper Access Control in David-Crty Databasement Product

A vulnerability has been identified in David-Crty databasement that affects versions up to 1.7.1. Specifically, the issue lies within the SnapshotPolicy.viewAny and SnapshotPolicy.view functions in the /api/v1/snapshots component of the Snapshot Model. This flaw may allow unauthorized users to by...

PoC for CVE-2026-12227

WordPressVisual Composer Websit...9.8CRITICAL
Local File Inclusion Vulnerability in Visual Composer Website Build...

The Visual Composer Website Builder plugin for WordPress allows local file inclusion through the `vcv-template` parameter in all versions up to and including 45.16.0. This vulnerability enables unauthenticated attackers to include and execute arbitrary files on the server, potentially leading to ...

PoC for CVE-2026-102427

Ordasoft.comOrdasoft Joomla Cck10CRITICAL
Unauthenticated Remote Code Execution in OrdaSoft Joomla Extension ...

The OrdaSoft Joomla CCK extension prior to version 8.3.16 is susceptible to unauthenticated remote code execution due to inadequate handling of file uploads. The vulnerability allows attackers to upload malicious files disguised as images, which can then be executed on the server. This occurs bec...

PoC for CVE-2025-29927

VercelNext.js🟣 EPSS 99%9.1CRITICAL
Authorization Bypass in Next.js Framework by Vercel

A security flaw exists in the Next.js framework that allows an attacker to bypass authorization checks if such checks are implemented in middleware. This vulnerability arises in versions prior to 14.2.25 and 15.2.3. To mitigate risk, it is recommended to restrict incoming requests that include th...

Discovered 15 hours ago

PoC for CVE-2026-103533

David-crtyDatabasement2.1LOW
Path Traversal Vulnerability in David-Crty Databasement Database-Se...

A path traversal vulnerability in David-Crty Databasement affects versions up to 1.7.1. It arises from improper validation of the 'schema_name' argument in the database-servers API Endpoint, allowing attackers to potentially access unauthorized files. This type of exploit may be performed remotel...

Discovered 17 hours ago

PoC for CVE-2026-94545

VercelSatori5.3MEDIUM
Cross-Site Scripting Vulnerability in Satori Library by Vercel

The Satori library, developed by Vercel for converting HTML and CSS into SVG, contains a vulnerability in versions prior to 0.33.5. In these affected versions, the library fails to properly escape certain values before embedding them in the generated SVG output. This oversight can lead to the exe...

Discovered 21 hours ago

PoC for CVE-2023-54403

YonyouU8 Crm8.7HIGH
Arbitrary File Read Vulnerability in Yonyou U8 CRM Products

The Yonyou U8 CRM software versions before V16.5 and V18 contain a vulnerability in the /ajax/getemaildata.php file, which allows unauthenticated users to bypass authentication by manipulating the DontCheckLogin parameter. This vulnerability permits the reading of arbitrary files through an unval...

PoC for CVE-2024-58387

InspurHaiyue Hcm Cloud8.7HIGH
Arbitrary File Read Vulnerability in Inspur Haiyue HCM Cloud

Inspur Haiyue HCM Cloud features a vulnerability that allows remote attackers to read arbitrary files through the /api/model_report/file/download endpoint. By exploiting unvalidated parameters such as 'index' and 'ext', attackers can craft malicious requests that enable directory traversal, leadi...

Discovered 22 hours ago

PoC for CVE-2026-103387

GarycourtUri-js5.3MEDIUM
Weakness in Mailto Header Handler of garycourt uri-js by garycourt

A weakness exists in the Mailto Header Handler of garycourt's uri-js library up to version 4.4.1, specifically in the URI.parse function located in src/schemes/mailto.ts. This vulnerability can lead to uncaught exceptions due to improper handling of parsed arguments. An attacker may exploit this ...

Discovered 1 day ago

PoC for CVE-2026-103241

Vllm-projectVllm6.9MEDIUM
Denial of Service Vulnerability in vLLM by vllm-project

A flaw has been identified in the vLLM software by vllm-project, specifically within the Gemma4UnifiedParser component. This vulnerability allows for a denial of service, which can be exploited remotely through manipulation of certain code segments within the parser. The vulnerable versions of vL...

PoC for CVE-2026-103233

AdithyayellojuRestaurant-management-...5.3MEDIUM
Authorization Bypass Vulnerability in AdithyaYelloju Restaurant Man...

A security vulnerability exists in the AdithyaYelloju Restaurant Management System, affecting the admin area. This vulnerability allows an attacker to manipulate the argument ID, resulting in an unauthorized access control condition. The issue can be exploited remotely, leading to potential unaut...

PoC for CVE-2026-103232

AdithyayellojuRestaurant-management-...6.9MEDIUM
SQL Injection Vulnerability in AdithyaYelloju Restaurant-Management...

A vulnerability has been detected in the AdithyaYelloju Restaurant-Management-System that could be exploited to perform SQL injection attacks through the mysqli_query function in the admin/table_booking.php file. This flaw allows attackers to manipulate input parameters, particularly the argument...