Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-33032

0xjackyNginx-ui9.8CRITICAL
Vulnerability in Nginx UI Web Interface for Nginx Server

The Nginx UI web interface, specifically versions 2.3.5 and earlier, is susceptible to a serious flaw due to improper authentication in its MCP (Model Context Protocol) integration. This vulnerability allows attackers, without any authentication, to exploit the /mcp_message endpoint. Although the...

Discovered 21 minutes ago

PoC for CVE-2026-39842

OpenremoteOpenremote10CRITICAL
Expression Injection Vulnerabilities in OpenRemote IoT Platform

The OpenRemote IoT platform, specifically versions 1.21.0 and below, is impacted by two related expression injection vulnerabilities. These flaws exist within the rules engine, allowing unauthorized users to execute arbitrary code on the server. The JavaScript rules engine processes user-defined ...

Discovered 3 hours ago

PoC for CVE-2026-6497

PrasathmaniTinyfilemanager5.3MEDIUM
Server-Side Request Forgery in TinyFileManager by prasathmani

A vulnerability exists in TinyFileManager, specifically in the file upload functionality located at /filemanager.php?p=ajax=true&type=upload. This flaw allows an attacker to manipulate the uploadurl parameter, potentially leading to a server-side request forgery (SSRF) attack. Such an attack can ...

Discovered 4 hours ago

PoC for CVE-2026-6496

PrasathmaniTinyfilemanager5.3MEDIUM
Path Traversal Vulnerability in TinyFileManager by prasathmani

A vulnerability exists in prasathmani TinyFileManager versions up to 2.6, specifically within the POST Parameter Handler found in the file /filemanager.php. This issue arises from inadequate input validation, allowing attackers to manipulate the 'file[]' parameter to perform path traversal attack...

Discovered 5 hours ago

PoC for CVE-2026-6493

LukevellaRallly5.1MEDIUM
Cross-Site Scripting Vulnerability in Rallly by Lukevella

A security flaw has been identified in Rallly versions up to 4.7.4, specifically within the Reset Password Handler component. This vulnerability arises from improper handling of the 'redirectTo' argument, which may allow attackers to execute cross-site scripting (XSS) attacks remotely. If exploit...

PoC for CVE-2026-6492

Arnobt78Hotel Booking Manageme...6.9MEDIUM
Information Disclosure Vulnerability in arnobt78 Hotel Booking Mana...

A vulnerability exists in the arnobt78 Hotel Booking Management System, specifically within the health check endpoint, where an unknown function can be exploited to disclose sensitive information. This vulnerability allows remote attackers to perform unauthorized access, leading to potential info...

PoC for CVE-2026-6491

libvipsLibvips4.8MEDIUM
Heap-based Buffer Overflow in libvips Affects Local Applications

A security vulnerability exists in the libvips library prior to version 8.19, specifically within the im_minpos_vec function in the deprecated vips7compat.c file. This vulnerability allows for heap-based buffer overflow due to inadequate handling of the argument n, requiring local access for expl...

Discovered 6 hours ago

PoC for CVE-2026-6490

QuerymineSms6.9MEDIUM
SQL Injection Vulnerability in QueryMine SMS Product by Unknown Vendor

A SQL injection vulnerability exists in the QueryMine sms component, specifically within the admin/deletecourse.php file. This issue arises due to improper handling of the GET request parameter 'ID', allowing attackers to manipulate the input and execute unauthorized SQL queries. The attack can b...

PoC for CVE-2026-6489

QuerymineSms5.3MEDIUM
Unrestricted File Upload Vulnerability in QueryMine sms Background ...

A security flaw has been identified in QueryMine sms, specifically affecting the admin/addteacher.php file within the Background Management Page component. The vulnerability allows attackers to manipulate the image argument, leading to unrestricted file uploads. This can be exploited remotely, po...

PoC for CVE-2026-6488

QuerymineSms5.3MEDIUM
SQL Injection Vulnerability in QueryMine sms by QueryMine

A SQL injection vulnerability has been discovered in QueryMine sms that impacts the GET Request Parameter Handler in the editcourse.php file. This vulnerability arises from improper handling of the ID argument, allowing remote attackers to manipulate SQL queries. Due to the continuous delivery an...

PoC for CVE-2026-0740

WordPressNinja Forms - File Upl...9.8CRITICAL
Arbitrary File Upload Vulnerability in Ninja Forms File Uploads Plu...

The Ninja Forms - File Uploads plugin for WordPress contains a vulnerability allowing unauthenticated attackers to upload arbitrary files due to inadequate file type validation in the upload handling function. This oversight affects all versions upto and including 3.3.26, potentially enabling att...

PoC for CVE-2026-6487

QihuiJtbc5 Cms5.3MEDIUM
Path Traversal Vulnerability in Qihui jtbc5 CMS by Shanghai Qihui N...

A vulnerability exists in the Qihui jtbc5 CMS, specifically in the Code Endpoint component located in manage.php. This flaw allows attackers to manipulate input parameters related to file paths, leading to unauthorized access to files outside of the intended directory. The exploit can be executed...

Discovered 7 hours ago

PoC for CVE-2026-6486

ClassroombookingsClassroombookings5.1MEDIUM
Cross-Site Scripting Vulnerability in Classroom Bookings by Classro...

A cross-site scripting vulnerability was identified in Classroom Bookings versions up to 2.17.0, specifically within the User Display Name Handler component. The vulnerability arises from improper handling of the 'displayname' argument in the file crbs-core/application/views/layout.php, allowing ...

Discovered 8 hours ago

PoC for CVE-2026-6483

WavlinkWl-wn530h48.6HIGH
OS Command Injection in Wavlink Wireless Router

A vulnerability has been identified in the Wavlink WL-WN530H4 model, specifically within the strcat and snprintf functions of the /cgi-bin/internet.cgi file. This security flaw enables remote attackers to inject operating system commands, potentially leading to unauthorized access and control ove...

Discovered 10 hours ago

PoC for CVE-2025-8110

GogsGogs🟣 EPSS 20%8.7HIGH
Improper Symbolic Link Handling in Gogs Product by Gogs Team

The vulnerability in the PutContents API of Gogs arises from improper handling of symbolic links, potentially allowing local execution of arbitrary code. This misconfiguration may expose sensitive data and facilitate unauthorized access to critical systems. Users and administrators are urged to u...

Discovered 13 hours ago

PoC for CVE-2024-30088

MicrosoftWindows 10 Version 1809🟣 EPSS 85%7HIGH
Windows Kernel Elevation of Privilege Vulnerability

This vulnerability allows an attacker to execute arbitrary code with elevated privileges, potentially gaining control over the affected system. By exploiting the fault in the Windows Kernel, the attacker could leverage this to manipulate system processes and escalate privileges, making it a signi...

Discovered 14 hours ago

PoC for CVE-2026-33555

HaproxyHaproxy4MEDIUM
Request Smuggling Vulnerability in HAProxy HTTP/3 Parser

An issue has been identified in HAProxy's HTTP/3 parser prior to version 3.3.6, where the parser fails to ensure that the content length of received bodies corresponds with the previously set content-length. This oversight can lead to desynchronization with backend servers when the stream is term...

PoC for CVE-2026-21858

N8n-ioN8n10CRITICAL
Vulnerability in n8n Workflow Automation Platform Could Lead to Sen...

The n8n workflow automation platform has a vulnerability in versions ranging from 1.65.0 to just below 1.121.0, which allows potential attackers to exploit specific form-based workflows. This flaw can enable unauthorized remote access to sensitive files on the underlying server, posing a signific...

Discovered 16 hours ago

PoC for CVE-2026-37749

CodeAstroSimple Attendance Mana...9.8CRITICAL
SQL Injection Vulnerability in CodeAstro Simple Attendance Manageme...

A SQL injection vulnerability exists in CodeAstro's Simple Attendance Management System version 1.0. This flaw allows remote, unauthenticated attackers to bypass authentication mechanisms by exploiting the username parameter in the index.php file. Successful exploitation of this vulnerability ena...

Discovered 19 hours ago

PoC for CVE-2025-15602

Grokability, Inc.Snipe-it8.7HIGH
Mass Assignment Vulnerability in Snipe-IT Software by Grokability

A significant vulnerability in Snipe-IT affects versions prior to 8.3.7, where sensitive user attributes are inadequately protected against mass assignment attacks. This flaw enables an authenticated, low-privileged user to manipulate API requests, altering restricted fields within another user's...

Discovered 23 hours ago

PoC for CVE-2026-1880

AsusDriverhub5.4MEDIUM
Privilege Escalation Vulnerability in ASUS DriverHub

An issue in the ASUS DriverHub update process stems from incorrect permission assignments, which can lead to privilege escalation. During the validation phase of the update process, inadequate protection of critical execution resources allows a local user to modify these resources without appropr...

Discovered 1 day ago

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-34220

Mikro-ormMikro-orm9.3CRITICAL
SQL Injection Vulnerability in MikroORM TypeScript ORM by Mikro

MikroORM, a TypeScript Object-Relational Mapper for Node.js, has a vulnerability that can lead to SQL injection. This issue arises when specially crafted objects are treated as raw SQL fragments, potentially allowing attackers to manipulate database queries. The vulnerability has been addressed i...

PoC for CVE-2026-0827

LenovoDiagnostics6.9MEDIUM
Arbitrary File Write Vulnerability in Lenovo Diagnostics and Hardwa...

A potential vulnerability was identified in Lenovo Diagnostics and its associated HardwareScanAddin used in the Lenovo Vantage application. This flaw may allow a local authenticated user to write arbitrary files with elevated privileges during installation or when executing a hardware scan, poten...

PoC for CVE-2025-49113

RoundcubeWebmail🟣 EPSS 91%9.9CRITICAL
Remote Code Execution Vulnerability in Roundcube Webmail by Roundcube

A vulnerability in Roundcube Webmail prior to version 1.5.10 and 1.6.x before 1.6.11 allows authenticated users to exploit the _from parameter in the URL. This issue arises from a lack of validation in program/actions/settings/upload.php, leading to the potential for PHP Object Deserialization at...

PoC for CVE-2025-27591

Meta Platforms, IncBelow6.8MEDIUM
Privilege Escalation Vulnerability in Below Service by Facebook

A privilege escalation vulnerability was identified in the Below service prior to version 0.9.0. This vulnerability arises from the creation of a world-writable directory located at /var/log/below. As a result, local unprivileged users can exploit this flaw through symlink attacks, potentially ma...

PoC for CVE-2025-24893

XwikiXwiki-platform🟣 EPSS 94%9.8CRITICAL
Remote Code Execution Vulnerability in XWiki Platform by XWiki SAS

The XWiki Platform is vulnerable due to improper handling of inputs, allowing unauthenticated users to execute arbitrary code via the `SolrSearch` endpoint. This can result in significant breaches of confidentiality, integrity, and availability of the XWiki installation. Users are encouraged to u...

Discovered 2 days ago

PoC for CVE-2024-12029

Invoke-aiInvoke-ai/invokeai🟣 EPSS 44%9.8CRITICAL
Remote Code Execution Vulnerability in InvokeAI by Invoke AI

A vulnerability exists in InvokeAI versions 5.3.1 through 5.4.2, allowing remote code execution through the /api/v2/models/install endpoint. This vulnerability is due to the unsafe deserialization of model files with torch.load, lacking proper validation of input data. Attackers can exploit this ...

PoC for CVE-2026-34621

AdobeAcrobat Reader8.6HIGH
Prototype Pollution Vulnerability in Adobe Acrobat Reader

Adobe Acrobat Reader is impacted by a Prototype Pollution vulnerability that allows attackers to execute arbitrary code within the context of the current user. This flaw is triggered only when a user interacts with a malicious file, making user awareness essential. It is crucial for users to keep...

PoC for CVE-2025-58060

OpenprintingCups8HIGH
Authentication Bypass in OpenPrinting CUPS Affects Multiple Unix-li...

OpenPrinting CUPS, an open-source printing system utilized across various Linux and Unix-like operating systems, is subject to a critical vulnerability that allows an authentication bypass. Specifically, in versions 2.4.12 and earlier, if the `AuthType` is set to anything other than `Basic`, the ...

PoC for CVE-2022-35650

MoodleMoodle7.5HIGH
Directory Traversal Vulnerability in Moodle Affecting Teachers and ...

A vulnerability exists in Moodle that stems from an input validation error occurring during the importation of lesson questions. This flaw allows for insufficient path checks, which can lead to arbitrary file reading via directory traversal attacks. It is important to note that access to this fea...

PoC for CVE-2026-39808

FortinetFortisandbox9.1CRITICAL
OS Command Injection Vulnerability in Fortinet FortiSandbox

An OS command injection vulnerability exists in Fortinet FortiSandbox versions 4.4.0 through 4.4.8. This flaw arises from improper neutralization of special elements used in operating system commands. An attacker can exploit this vulnerability to execute unauthorized commands, potentially comprom...

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-40500

ProcesswireProcesswire6.1MEDIUM
Server-Side Request Forgery in ProcessWire CMS by ProcessWire

The ProcessWire CMS versions 3.0.255 and earlier are susceptible to a server-side request forgery (SSRF) vulnerability found in the admin panel's 'Add Module From URL' feature. Authenticated administrators can input arbitrary URLs in the module download parameter, resulting in the server making u...

PoC for CVE-2024-26229

MicrosoftWindows 10 Version 1809🟣 EPSS 83%7.8HIGH
Windows CSC Service Elevation of Privilege Vulnerability

The CVE-2024-26229 vulnerability in the Windows CSC Service is being exploited with proof-of-concept (PoC) exploit code available on GitHub. This high-severity vulnerability could allow attackers to gain SYSTEM privileges on a Windows system, posing a significant risk. This type of elevation of p...

PoC for CVE-2021-4034

Polkit ProjectPolkit🟣 EPSS 88%7.8HIGH
Local Privilege Escalation Vulnerability in polkit's pkexec Utility

A local privilege escalation vulnerability exists within the pkexec utility of polkit, a setuid tool that allows unprivileged users to execute commands as privileged users based on predetermined policies. Due to insufficient handling of the calling parameters, pkexec can misinterpret environment ...

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-34486

ApacheApache Tomcat7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

PoC for CVE-2026-1357

WordPressWPvivid — Backup, Migr...🟣 EPSS 19%9.8CRITICAL
Unauthenticated Arbitrary File Upload in WPvivid Backup & Migration...

The WPvivid Backup & Migration plugin for WordPress is susceptible to an unauthenticated arbitrary file upload vulnerability due to improper error handling in the RSA decryption process and inadequate path sanitization during file uploads. This allows malicious attackers to exploit the system by ...

Discovered 3 days ago

PoC for CVE-2025-24000

WordPressPost Smtp8.8HIGH
Authentication Bypass Vulnerability in WPExperts Post SMTP Plugin

The WPExperts Post SMTP plugin contains an authentication bypass vulnerability that allows attackers to exploit alternate pathways for gaining unauthorized access. This issue affects versions from n/a up to 3.2.0, potentially compromising the security of WordPress installations using this plugin....

PoC for CVE-2025-48561

GoogleAndroid5.5MEDIUM
Data Exposure Vulnerability in Android Framework by Google

A vulnerability has been identified in the Android Framework that allows for potential exposure of sensitive information displayed on the screen. This may occur without the need for user interaction or elevated execution privileges, resulting in local information disclosure risks. The issue arise...

PoC for CVE-2026-40499

RadareorgRadare28.4HIGH
Command Injection Vulnerability in radare2 PDB Parser

radare2, prior to version 6.1.4, is susceptible to a command injection vulnerability located in the PDB parser's print_gvars() function. This vulnerability allows attackers to execute arbitrary commands by inserting a newline byte into the PE section header name field of a maliciously crafted PDB...

PoC for CVE-2026-6042

MuslLibc4.8MEDIUM
Security Flaw in musl libc Affects GB18030 4-byte Decoder Function

A flaw has been identified in the GB18030 4-byte Decoder function within musl libc, specifically in the iconv implementation located in src/locale/iconv.c. This vulnerability manifests as inefficient algorithmic complexity that can be exploited through localized interactions. Attackers can manipu...

PoC for CVE-2026-40175

AxiOSAxiOS4.8MEDIUM
Prototype Pollution and Remote Code Execution Vulnerability in Axio...

The Axios library, a popular promise-based HTTP client used in web applications and Node.js, has a significant vulnerability that enables a 'Gadget' attack chain. This flaw allows Prototype Pollution to exploit third-party dependencies, leading to potential Remote Code Execution (RCE). Attackers ...

PoC for CVE-2026-40175

AxiOSAxiOS4.8MEDIUM
Prototype Pollution and Remote Code Execution Vulnerability in Axio...

The Axios library, a popular promise-based HTTP client used in web applications and Node.js, has a significant vulnerability that enables a 'Gadget' attack chain. This flaw allows Prototype Pollution to exploit third-party dependencies, leading to potential Remote Code Execution (RCE). Attackers ...

Discovered 4 days ago

PoC for CVE-2025-59528

FlowiseaiFlowise🟣 EPSS 84%10CRITICAL
Remote Code Execution Vulnerability in Flowise by FlowiseAI

Flowise, a user-friendly platform for creating customized large language model flows, has a significant vulnerability in version 3.0.5 that allows for remote code execution. The flaw lies within the CustomMCP node, where user input is inadequately sanitized. Specifically, the mcpServerConfig stri...

PoC for CVE-2026-39987

Marimo-teamMarimo9.3CRITICAL
Pre-Authentication Remote Code Execution in Marimo Python Notebook

Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...

PoC for CVE-2026-6224

NocobasePlugin-workflow-javasc...6.9MEDIUM
Sandbox Vulnerability in Nocobase Plugin-Workflow-Javascript

A critical security flaw exists in the Nocobase plugin-workflow-javascript up to version 2.0.23. The vulnerability arises from the createSafeConsole function in the Vm.js file, where improper handling potentially allows attackers to exploit the sandbox environment. This issue facilitates remote c...

PoC for CVE-2026-6220

HummerRiskHummerrisk5.1MEDIUM
Server-Side Request Forgery Vulnerability in HummerRisk Video Downl...

In versions of HummerRisk up to 1.5.0, a server-side request forgery (SSRF) vulnerability was discovered in the ServerService.addServer function within the ServerService.java file. This security flaw enables remote exploitation by manipulating the streamIp argument during server operations. As a ...

PoC for CVE-2026-6219

Aandrew-meYtdownloader4.8MEDIUM
Command Injection Vulnerability in aandrew-me ytDownloader by aandr...

A command injection vulnerability exists in aandrew-me ytDownloader versions up to 3.20.2, specifically affecting the child_process.exec function in src/compressor.js. This vulnerability allows malicious users to execute arbitrary commands on the local system. Although the attack must be executed...