Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-41091

MicrosoftMicrosoft Malware Prot...7.8HIGH
Elevation of Privilege Vulnerability in Microsoft Defender

An issue has been identified in Microsoft Defender that could allow an authorized attacker to gain elevated privileges through improper link resolution before file access, also known as link following. This vulnerability could enable attackers to manipulate file paths, potentially leading to unau...

Discovered 8 hours ago

PoC for CVE-2022-50972

WooCommerceWooCommerce9.3CRITICAL
Remote Code Execution Vulnerability in WooCommerce by Automattic

WooCommerce version 7.1.0 has a vulnerability that allows remote code execution. This flaw enables attackers to execute arbitrary PHP code by injecting untrusted shell commands through the product-type parameter. By sending crafted requests to the class-wc-meta-box-product-images.php endpoint, at...

PoC for CVE-2020-37255

WordPressTime Capsule Plugin8.7HIGH
Authentication Bypass in Time Capsule Plugin for WordPress

The Time Capsule Plugin version 1.21.16 for WordPress has a significant authentication bypass vulnerability. This allows unauthenticated attackers to gain administrative access by sending specially crafted POST requests that leverage the IWP_JSON_PREFIX header. Exploiting this weakness grants att...

PoC for CVE-2019-25763

WordPressUltimate Addons For Be...9.3CRITICAL
Authentication Bypass Vulnerability in Ultimate Addons for Beaver B...

The Ultimate Addons for Beaver Builder version 1.2.4.1 is affected by an authentication bypass vulnerability that allows attackers to gain unauthorized access. This can be achieved through exploiting the social media login form functionality, specifically by sending a crafted POST request to the ...

Discovered 9 hours ago

PoC for CVE-2026-12673

LiquidfilesLiquidfiles5.9MEDIUM
Broken Access Control Vulnerability in Liquidfiles by Liquidfiles

Liquidfiles versions prior to 4.2.12 exhibit a broken access control vulnerability that allows for privilege escalation. An attacker with Admin privileges in a secondary domain can exploit this vulnerability to gain Sysadmin access by manipulating group settings within their managed non-default g...

Discovered 16 hours ago

PoC for CVE-2022-0543

DebianRedis🟣 EPSS 100%10CRITICAL
Lua Sandbox Escape in Redis Affected by Debian Packaging Issue

The vulnerability in Redis arises from a packaging issue specific to Debian, which exposes the system to a Lua sandbox escape. This flaw could potentially allow attackers to execute arbitrary code remotely, compromising the security and integrity of applications that rely on Redis as a persistent...

Discovered 18 hours ago

PoC for CVE-2021-3560

Polkit ProjectPolkit🟣 EPSS 22%7.8HIGH
Privilege Escalation Vulnerability in Polkit Affecting Linux Systems

A flaw in Polkit allows an unprivileged local attacker to bypass credential checks for D-Bus requests. This can lead to the elevation of privileges to that of the root user, enabling the attacker to execute commands with elevated permissions. This vulnerability poses a significant threat to the c...

PoC for CVE-2023-6019

ray-projectray-project/ray🟣 EPSS 75%9.8CRITICAL
Ray Command Injection in cpu_profile Parameter

A security flaw was identified in the Ray dashboard, specifically within the cpu_profile URL parameter, which is vulnerable to command injection. This allows remote attackers to execute arbitrary OS commands on the machine running the dashboard without requiring authentication. The issue has been...

Discovered 1 day ago

PoC for CVE-2026-10523

IvantiSentry9.9CRITICAL
Authentication Bypass Vulnerability in Ivanti Sentry

An authentication bypass vulnerability exists in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1, enabling remote unauthenticated attackers to create arbitrary administrative accounts. This flaw compromises the security model of the application, allowing malicious users full adminis...

PoC for CVE-2023-54357

ArtioJoomla! Com Booking Co...8.7HIGH
Information Disclosure Vulnerability in Joomla com_booking Componen...

The com_booking component for Joomla version 2.4.9 suffers from an information disclosure vulnerability that permits unauthenticated users to enumerate user accounts. By leveraging the getUserData function within the customer controller, attackers can send crafted GET requests to the index.php fi...

PoC for CVE-2019-25762

JoomboostJoomproject8.7HIGH
Information Disclosure in Joomla! Component JoomProject by Joomla

The Joomla! Component JoomProject 1.1.3.2 is vulnerable to an information disclosure flaw. This vulnerability enables unauthenticated attackers to access sensitive information, including user IDs, names, and email addresses. By manipulating requests to the relevant projects endpoint, attackers ca...

PoC for CVE-2019-25761

JoomboostJoomcrm7.1HIGH
SQL Injection Vulnerability in JoomCRM by Joomla!

JoomCRM version 1.1.1 is susceptible to an SQL injection vulnerability due to improper validation of user input within the deal_id parameter. Authenticated attackers can exploit this flaw by crafting GET requests to index.php with specific parameters that allow them to execute arbitrary SQL queri...

PoC for CVE-2019-25760

JoomtechEasy Shop6.9MEDIUM
Local File Inclusion Vulnerability in Easy Shop by Joomla!

The Easy Shop component for Joomla! version 1.2.3 has a local file inclusion flaw that enables unauthenticated attackers to read arbitrary files from the server. This vulnerability arises when an attacker encodes file paths in base64 format and manipulates the application's parameters in a GET re...

PoC for CVE-2019-25759

WdmtechVbizz7.1HIGH
SQL Injection in Joomla! Component by vBizz

The Joomla! Component vBizz version 1.0.7 is susceptible to an SQL injection vulnerability that allows authenticated individuals to manipulate SQL queries. This vulnerability is exploited via crafted POST requests containing malicious payid array values, enabling attackers to access sensitive inf...

PoC for CVE-2019-25758

WdmtechVbizz8.7HIGH
Unrestricted File Upload Vulnerability in vBizz Component for Jooml...

The vBizz component for Joomla! version 1.0.7 suffers from an unrestricted file upload vulnerability that enables authenticated attackers to upload harmful PHP files through the profile_pic parameter. By exploiting this flaw, attackers can send malicious files via POST requests to the employee vi...

PoC for CVE-2019-25757

WdmtechVwishlist7.1HIGH
SQL Injection Vulnerability in Joomla vWishlist by Joomla

Joomla vWishlist version 1.0.1 is susceptible to an SQL injection vulnerability that enables authenticated attackers to manipulate SQL queries. By exploiting this flaw, attackers can send crafted POST requests with malicious inputs in the vproductid and userid parameters. This can lead to the exe...

PoC for CVE-2019-25756

WdmtechVaccount8.8HIGH
SQL Injection Vulnerability in Joomla! vAccount Component

The vAccount component for Joomla! version 2.0.2 is susceptible to an SQL injection vulnerability. This flaw enables unauthorized attackers to manipulate SQL queries by injecting malicious code through the 'vid' parameter in GET requests directed to the vaccount-dashboard/expense endpoint. By exp...

PoC for CVE-2019-25755

WdmtechVreview8.8HIGH
SQL Injection Vulnerability in Joomla vReview Component by Joomla

The Joomla vReview component version 1.9.11 is susceptible to an SQL injection attack due to improper handling of the cmId parameter. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code. The attacker can exploit this by sending speciall...

PoC for CVE-2019-25754

WdmtechVrestaurant8.8HIGH
SQL Injection Vulnerability in Joomla Component vRestaurant 1.9.4

The Joomla component vRestaurant version 1.9.4 is susceptible to an SQL injection flaw that permits unauthenticated attackers to execute arbitrary SQL statements. By injecting malicious payloads through the keysearch parameter in POST requests to the menu-listing-layout endpoint, attackers may ga...

PoC for CVE-2019-25753

WdmtechVmap8.8HIGH
SQL Injection Vulnerability in Joomla! Component VMap by Joomla

The Joomla! Component VMap version 1.9.6 is susceptible to an SQL injection vulnerability that enables unauthorized users to execute arbitrary SQL queries. By targeting the 'latlngbound' parameter through manipulated GET requests to 'index.php' with predefined parameters, attackers can inject har...

PoC for CVE-2019-25752

CmsjunkieJ-businessdirectory8.8HIGH
SQL Injection Vulnerability in J-BusinessDirectory Component by Joo...

The J-BusinessDirectory component for Joomla! version 4.9.7 is susceptible to SQL injection, allowing unauthenticated attackers to execute arbitrary SQL commands. By manipulating the 'type' parameter via a GET request, attackers can inject UNION-based SQL statements. This vulnerability enables th...

PoC for CVE-2019-25751

CmsjunkieClassifiedsmanager8.8HIGH
SQL Injection Vulnerability in Joomla J-ClassifiedsManager by Joomla

The Joomla component J-ClassifiedsManager version 3.0.5 is susceptible to an SQL injection flaw, which enables unauthenticated attackers to execute arbitrary SQL commands. This vulnerability arises from the improper handling of user input in parameters such as categorySearch, adType, and citySear...

PoC for CVE-2026-7515

WordPressBetterdocs Pro9.8CRITICAL
Local File Inclusion Vulnerability in BetterDocs Pro Plugin for Wor...

The BetterDocs Pro plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit a Local File Inclusion (LFI) flaw through the 'doc_style' parameter. This security issue affects versions up to and including 3.8.0, enabling attackers to include and execute arbitrar...

PoC for CVE-2019-25750

CmsjunkieMultiplehotelreservation8.8HIGH
SQL Injection in J-MultipleHotelReservation Component by Joomla

The J-MultipleHotelReservation component for Joomla version 6.0.7 is susceptible to an SQL injection vulnerability. This flaw enables unauthenticated attackers to manipulate the hotel_id parameter and execute arbitrary SQL commands. By crafting specific POST requests to the search-hotels endpoint...

PoC for CVE-2019-25749

CmsjunkieJ-cruiseportal7.1HIGH
SQL Injection Vulnerability in Joomla J-CruisePortal by CMS Junkie

The Joomla J-CruisePortal version 6.0.4 has a SQL injection flaw that enables authenticated attackers to execute arbitrary SQL commands. By manipulating the 'guest_adult' parameter through crafted POST requests to the cruises endpoint, attackers can potentially access sensitive database contents ...

PoC for CVE-2019-25748

CmsjunkieJhotelreservation8.8HIGH
SQL Injection Vulnerability in Joomla's JHotelReservation by Joomla

Joomla JHotelReservation version 6.0.7 is susceptible to an SQL injection flaw that enables unauthenticated attackers to execute arbitrary SQL queries through the 'rooms' parameter. By sending specially crafted POST requests to the 'search-hotels' endpoint, attackers can manipulate the SQL execut...

PoC for CVE-2017-20282

Soft-PHPJcart For Opencart8.8HIGH
SQL Injection Vulnerability in jCart for OpenCart by Joomla!

The jCart component for OpenCart version 2.0, developed by Joomla!, is susceptible to an SQL injection vulnerability that permits unauthenticated attackers to manipulate database queries. By sending specially crafted GET requests to the index.php endpoint with the option=com_jcart&route=product/p...

PoC for CVE-2017-20281

JoomlaboatExtra Search8.8HIGH
SQL Injection Vulnerability in Joomla! Component Extra Search by Jo...

The Joomla! Component Extra Search version 2.2.8 is susceptible to an SQL injection flaw, allowing attackers who are not authenticated to execute unauthorized SQL code. By sending specially crafted GET requests to index.php with the option=com_extrasearch parameter, they can manipulate the establ...

PoC for CVE-2017-20280

MyportfolioMyportfolio8.8HIGH
SQL Injection in Myportfolio Component by Joomla

The Myportfolio component for Joomla version 3.0.2 contains a significant SQL injection vulnerability, allowing attackers to exploit the pid parameter. By sending specially crafted GET requests to index.php with malicious pid values at the task=project&view=grid endpoint, unauthorized individuals...

PoC for CVE-2017-20279

ExtensionsJoomla Payage8.8HIGH
SQL Injection Vulnerability in Joomla Payage Payment Plugin

The Joomla Payage 2.05 version is affected by a SQL injection vulnerability that occurs through the 'aid' parameter in the make_payment task. This flaw enables unauthenticated attackers to inject malicious SQL code via crafted GET requests to index.php. By manipulating these requests, attackers c...

PoC for CVE-2017-20278

JoomboostJoomrecipe8.8HIGH
SQL Injection Vulnerability in Joomla JoomRecipe by Joomla

The JoomRecipe component version 1.0.3 for Joomla is affected by an SQL injection vulnerability that can be exploited by unauthenticated attackers. By sending specially-crafted GET requests to the all-recipes endpoint, attackers can inject malicious SQL code through the category parameter, enabli...

PoC for CVE-2017-20277

JoomboostJoomla Joomrecipe8.8HIGH
Blind SQL Injection Vulnerability in Joomla JoomRecipe Component

The Joomla JoomRecipe 1.0.4 component is susceptible to a blind SQL injection vulnerability via the search_author parameter on the search results page. This flaw allows attackers to send specially crafted POST requests that can manipulate SQL queries, enabling them to retrieve sensitive database ...

PoC for CVE-2017-20276

SimbunchSimgenealogy8.8HIGH
SQL Injection Vulnerability in SIMGenealogy Component for Joomla!

The SIMGenealogy component for Joomla! version 2.1.5 is susceptible to an SQL injection vulnerability. Malicious actors can exploit this flaw by sending crafted GET requests to index.php, allowing them to manipulate database queries through the vulnerable type parameter. This could lead to unauth...

PoC for CVE-2017-20275

HenryschorradtBridge8.8HIGH
SQL Injection Vulnerability in Joomla! Component PHP-Bridge by Joomla!

The PHP-Bridge component for Joomla! version 1.2.3 is susceptible to an SQL injection vulnerability. This flaw enables unauthenticated attackers to execute arbitrary SQL commands by exploiting the 'id' parameter in GET requests directed at index.php with specific options. By injecting malicious S...

PoC for CVE-2017-20274

King-productsLms King Professional8.8HIGH
SQL Injection Vulnerability in Joomla LMS King Professional by Joomla

The Joomla LMS King Professional version 3.2.4.0 is susceptible to an SQL injection vulnerability that enables unauthenticated attackers to alter database queries. By injecting malicious SQL code through the cp_id parameter, an attacker can issue crafted GET requests to index.php, exploiting spec...

PoC for CVE-2017-20273

JoomlashowroomEvent Registration Pro...8.8HIGH
SQL Injection Vulnerability in Joomla Event Registration Pro Calend...

Joomla Event Registration Pro Calendar version 4.1.3 contains a vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands. By crafting specific GET requests that manipulate the id parameter, attackers can inject malicious SQL code. This exposes the database to unauthor...

PoC for CVE-2017-20272

FabobaUltimate Property Listing8.8HIGH
SQL Injection Vulnerability in Joomla Ultimate Property Listing by ...

The Joomla Ultimate Property Listing version 1.0.2 is susceptible to an SQL injection vulnerability that enables unauthenticated attackers to execute arbitrary SQL commands. By manipulating the sf_selectuser_id parameter in the request, attackers can send specially crafted GET requests to index.p...

PoC for CVE-2017-20271

NordmographStreetguessr Game8.8HIGH
SQL Injection Vulnerability in Joomla StreetGuessr Game by Joomla

The Joomla StreetGuessr Game version 1.1.8 is susceptible to an SQL injection vulnerability that permits unauthenticated users to perform arbitrary SQL commands. By manipulating the 'catid' parameter within GET requests directed at 'index.php' with the parameters 'option=com_streetguess&view=maps...

PoC for CVE-2017-20270

RaindropsinfotechTwitch Tv8.8HIGH
SQL Injection Vulnerability in Twitch TV Component for Joomla!

The Twitch TV Component for Joomla! version 1.1 is susceptible to SQL injection, allowing attackers to execute arbitrary SQL queries by manipulating the 'username' and 'id' parameters. By sending specially crafted GET requests to index.php with the parameters 'option=com_twitchtv' and 'view', att...

PoC for CVE-2017-20269

TerrywcarterKissgallery8.8HIGH
SQL Injection Vulnerability in Joomla! Component KissGallery

The Joomla! Component KissGallery 1.0.0 has a significant SQL injection vulnerability that enables unauthorized attackers to inject SQL statements through the component's URL. This flaw allows malicious users to manipulate database queries, potentially leading to unauthorized data extraction and ...

PoC for CVE-2017-20268

ZcontentZap Calendar Lite8.8HIGH
SQL Injection Vulnerability in Zap Calendar Lite by Joomla!

The Joomla! Component Zap Calendar Lite version 4.3.4 is impacted by an SQL injection vulnerability that permits unauthenticated attackers to execute arbitrary SQL commands. By exploiting the 'eid' parameter via crafted GET requests targeting the RSVP plugin endpoint, attackers can inject malicio...

PoC for CVE-2017-20267

JoomlathatCalendar Planner8.8HIGH
SQL Injection Vulnerability in Joomla! Component Calendar Planner b...

The Joomla! Component Calendar Planner version 1.0.1 is susceptible to an SQL injection vulnerability that enables unauthenticated attackers to execute arbitrary SQL queries via the category_id parameter. By manipulating this parameter in GET requests to the events view, attackers can potentially...

PoC for CVE-2017-20266

JoomshaperSp Movie Database8.8HIGH
SQL Injection Vulnerability in Joomla SP Movie Database by Joomla

The Joomla SP Movie Database version 1.3 contains a SQL injection vulnerability that can be exploited by unauthenticated attackers. By injecting malicious SQL code through the searchword parameter, attackers can manipulate search queries and potentially access sensitive information stored in the ...

PoC for CVE-2017-20265

PulseextensionsFlip Wall7.1HIGH
SQL Injection Vulnerability in Joomla! Component Flip Wall 8.0

The Joomla! Component Flip Wall version 8.0 is affected by an SQL injection vulnerability that enables unauthorized attackers to conduct arbitrary SQL queries by exploiting the wallid parameter. By sending specifically crafted GET requests to the index.php file with the parameters option=com_flip...

PoC for CVE-2017-20264

PulseextensionsSponsor Wall7.1HIGH
SQL Injection Vulnerability in Joomla! Component Sponsor Wall by Jo...

The Joomla! Component Sponsor Wall version 8.0 is susceptible to an SQL injection vulnerability. This flaw allows attackers, without authentication, to craft malicious GET requests targeting the wallid parameter. By including SQL injection payloads in the request, attackers can execute arbitrary ...

PoC for CVE-2017-20263

FocalpointxFocalpoint Pro / Free8.8HIGH
SQL Injection Vulnerability in Joomla! Component FocalPoint Pro/Free

The Joomla! Component FocalPoint Pro/Free 1.2.3 is susceptible to SQL injection attacks via the 'id' parameter. This flaw allows unauthenticated assailants to manipulate SQL queries, potentially leading to the extraction of sensitive information from the database. Attackers can exploit this vulne...

PoC for CVE-2017-20262

WebkulAjax Quiz8.8HIGH
SQL Injection Vulnerability in Joomla! Component Ajax Quiz by Joomla

The Joomla! Component Ajax Quiz 1.8 is susceptible to an SQL injection vulnerability. This security issue enables unauthorized attackers to execute arbitrary SQL queries by manipulating the 'cid' parameter in GET requests. By exploiting the vulnerability, an attacker can leverage the 'option=com_...

PoC for CVE-2017-20261

WeborangeBargain Product Vm38.8HIGH
SQL Injection Vulnerability in Joomla! Component Bargain Product VM...

The Joomla! Component Bargain Product VM3 1.0 is susceptible to SQL injection, which allows unauthenticated attackers to execute arbitrary SQL commands through the product_id parameter. By manipulating GET requests to specific views, such as brainy and alice, attackers can extract sensitive infor...

PoC for CVE-2017-20260

WeborangePrice Alert8.8HIGH
SQL Injection Flaw in Joomla! Component Price Alert from Joomla!

The Joomla! Component Price Alert version 3.0.2 is susceptible to an SQL injection vulnerability that can be exploited by unauthenticated attackers. By manipulating the product_id parameter in requests sent to the subscribeajax view, attackers can inject malicious SQL code. This could allow them ...

PoC for CVE-2017-20259

JoomlashackOsdownloads8.8HIGH
SQL Injection Vulnerability in Joomla OSDownloads by Joomla

Joomla OSDownloads 1.7.4 is susceptible to an SQL injection vulnerability, enabling unauthorized attackers to inject and execute arbitrary SQL commands via the 'id' parameter. By constructing a specific GET request to index.php with parameters such as option=com_osdownloads&view=item&id=[SQL], at...