Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 5 hours ago
PoC for CVE-2024-7971
A type confusion vulnerability resides in the V8 engine of Google Chrome, making it possible for remote attackers to execute a malicious payload that could lead to heap corruption. By exploiting this vulnerability, an attacker can craft a specific HTML page that, when interacted with by a user, m...
PoC for CVE-2019-2215
A use-after-free vulnerability exists in the Android Binder service, which could allow attackers to elevate privileges from an application to the Linux Kernel. Exploitation of this vulnerability does not require any interaction from the user; however, it necessitates either the installation of a ...
PoC for CVE-2026-43284
A vulnerability exists in the Linux kernel that concerns the handling of shared skb fragments during the decryption process in ESP-in-UDP packets. When pages are attached from a pipe directly to an skb using MSG_SPLICE_PAGES, the kernel marked these SKBs with SKBFL_SHARED_FRAG, which plays a cruc...
Discovered 8 hours ago
PoC for CVE-2026-93355
LiteLLM is impacted by a vulnerability that permits attackers to utilize a valid JSON Web Token (JWT) from a designated identity provider to impersonate any existing user. The flaw arises from an email-based fallback lookup process in the authentication flow which bypasses verification of the ema...
Discovered 9 hours ago
PoC for CVE-2026-107166
A vulnerability has been reported in Open5GS versions up to 2.7.7 in the GTP-U Receive Path function ogs_pfcp_xact_local_create, which allows remote attackers to manipulate resource allocations. This issue can potentially be exploited without authentication, making it critical to address. Users a...
Discovered 10 hours ago
PoC for CVE-2026-107273
Gophish versions 0.11.0 to 0.12.1 are prone to a server-side request forgery vulnerability that can be exploited by authenticated low-privileged users. Through the endpoint POST /api/import/site, attackers are able to submit internal URLs that are not blocked by the default dialer deny list. This...
Discovered 11 hours ago
PoC for CVE-2026-102422
The shell-quote library's `quote()` function poses a security risk by improperly handling comment tokens within command strings. Specifically, when a `{ comment }` token is included, it generates a line starting with `#`, which comments out subsequent input that follows it, including the opening ...
PoC for CVE-2026-82531
Smarty prior to version 4.5.8 and 5.x before 5.8.5 has a code injection vulnerability that arises due to improper handling of the nocache_hash during template inheritance. This oversight allows attackers to introduce malicious code through crafted assigned data containing a forged SmartyNocache m...
Discovered 12 hours ago
PoC for CVE-2026-107181
Telegram Desktop prior to version 7.2.9 is susceptible to an IPC record-separator injection vulnerability present in Core::Sandbox. This flaw permits remote attackers to craft tg:// links embedded with unescaped semicolons. By exploiting this vulnerability, an attacker can manipulate the interpre...
Discovered 14 hours ago
PoC for CVE-2026-33439
OpenIdentityPlatform's OpenAM, an access management solution, is susceptible to a pre-authentication Remote Code Execution vulnerability due to unsafe Java deserialization. This issue arises from the handling of the jato.clientSession HTTP parameter, allowing unauthenticated attackers to execute ...
Discovered 19 hours ago
PoC for CVE-2026-82211
The Nexi XPay Build plugin for WordPress, up to version 7.6.2, is susceptible to an improper input validation vulnerability. This issue allows attackers to manipulate the payment results supplied to several unauthenticated routes within the plugin. As a result, malicious actors can mark orders as...
PoC for CVE-2026-82212
The Nexi XPay Build plugin for WordPress, in versions up to 7.6.2, is susceptible to improper authentication due to inadequate validation of security tokens on its payment notification route. This vulnerability enables unauthenticated attackers to manipulate order statuses by either marking arbit...
PoC for CVE-2026-105322
The Magee Shortcodes WordPress plugin, up to version 2.1.1, is susceptible to an exploit that allows unauthenticated users to send unauthorized emails to any address via the site's contact form. This vulnerability occurs due to insufficient restrictions in the plugin's form actions, enabling pote...
PoC for CVE-2026-86833
The MetForm plugin for WordPress prior to version 4.3.1 is susceptible to Cross-Site Scripting (XSS) attacks. It allows adversaries to exploit a lack of sanitization and escaping of form-field values before they are embedded into the HTML body of email notifications. This oversight permits unauth...
PoC for CVE-2026-97354
The PowerPress Podcasting plugin by Blubrry for WordPress, in versions prior to 11.17.11, is vulnerable to Server-Side Request Forgery attacks. This issue arises due to improper validation of redirect destinations while fetching user-supplied media URLs. As a result, users with the contributor ro...
PoC for CVE-2026-96530
The Optimole plugin for WordPress prior to version 4.2.15 has a security flaw that allows authenticated users, including those with limited permissions such as Subscribers, to access sensitive account data stored within the plugin. This issue arises due to a lack of proper capability checks befor...
PoC for CVE-2026-97188
The String Locator plugin for WordPress prior to version 2.6.8 is vulnerable due to insufficient restrictions on classes allowed during deserialization of database content. This flaw enables unauthenticated attackers to store serialized PHP objects within database rows through the plugin's databa...
PoC for CVE-2026-97331
The User Private Files plugin for WordPress prior to version 2.1.9 contains a vulnerability that fails to restrict access based on user permissions. This allows any authenticated user, including those with minimal roles such as Subscriber, to retrieve the email addresses of other registered accou...
PoC for CVE-2026-87971
The If-So Dynamic Content WordPress plugin prior to version 1.10.2 fails to validate the URL scheme of user-supplied values. This oversight allows attackers to inject arbitrary JavaScript code into admin pages. If a logged-in user clicks on a crafted link, it could lead to the execution of malici...
PoC for CVE-2026-86816
The WPCafe WordPress plugin prior to version 3.0.21 has a significant flaw in its REST API, where it fails to adequately restrict access to certain endpoints. This oversight allows unauthenticated users to infiltrate sensitive areas of the site, thereby gaining access to critical WooCommerce prod...
PoC for CVE-2026-87782
The Koinonia Link plugin for WordPress, versions before 1.1.5, fails to properly verify user permissions when altering role selections during profile updates. This oversight can be exploited by any authenticated user, such as a subscriber, allowing them to upgrade their own role to Administrator,...
PoC for CVE-2026-105316
The Magee Shortcodes plugin for WordPress versions up to 2.1.1 is vulnerable due to improper sanitization and escaping of user input in certain AJAX actions. This lack of sanitization allows unauthenticated users to inject malicious scripts, leading to reflected cross-site scripting (XSS) attacks...
PoC for CVE-2026-104678
The CP Media Player plugin for WordPress, prior to version 1.3.4, suffers from an access control vulnerability. This issue arises because the plugin fails to implement proper capability checks on its settings-page handler. As a result, users with only Contributor-level permissions can create, mod...
PoC for CVE-2026-104953
The MPG WordPress plugin versions prior to 4.2.3 contains a vulnerability that fails to adequately validate the structure of imported project data before utilizing it in database queries. This oversight allows users with Editor roles or higher permissions to execute SQL injection attacks. Consequ...
PoC for CVE-2026-104651
The Yaad Sarig Payment Gateway for WooCommerce plugin prior to version 2.2.13 contains an authorization bypass vulnerability that allows any authenticated user to access and modify orders belonging to other customers. This flaw arises from the plugin's failure to properly verify that the user req...
PoC for CVE-2026-104677
The WP Coder plugin for WordPress prior to version 4.5.2 allows users with Editor-level access to execute arbitrary PHP code due to improper access controls. This vulnerability enables unauthorized users to exploit the PHP code-execution feature, potentially compromising the entire website by sav...
PoC for CVE-2026-104653
The Envira Gallery WordPress plugin prior to version 1.16.1 is vulnerable due to improper sanitization and escaping of user-provided gallery display configuration values. This flaw enables users with Author role or higher to inject arbitrary web scripts. These scripts are executed when any site v...
PoC for CVE-2026-104667
The Animated Number Counters WordPress plugin, prior to version 3.1, contains a serious security flaw that allows an Editor-level user to inject unsanitized values into SQL queries. This vulnerability enables unauthorized access to sensitive information, such as password hashes, through second-or...
PoC for CVE-2026-104652
The Envira Gallery plugin for WordPress prior to version 1.16.1 is susceptible to an injection vulnerability. This issue arises because the plugin fails to properly sanitize and escape gallery item identifiers before rendering them in image tag attributes. As a result, users with the Author role ...
PoC for CVE-2026-104050
The Academy LMS WordPress plugin prior to version 4.0.0 exposes a flaw where it fails to confirm whether a quiz question is associated with the course that a requesting user is allowed to access. This oversight allows any authenticated user, such as an enrolled student, to retrieve answers for qu...
PoC for CVE-2026-103378
The Geliver Akıllı Kargo Pazaryeri WordPress plugin prior to version 3.1.1 contains a serious vulnerability that allows unauthorized access to a log file stored in its web-accessible directory. This log file includes the site's carrier integration key, which can be exploited by attackers to alter...
PoC for CVE-2026-103681
The Frontend Dashboard plugin for WordPress prior to version 3.0.0 is susceptible to improper access control due to its failure to enforce capability checks during AJAX actions. This oversight permits authenticated users with lower privileges, such as subscribers, to delete crucial settings assoc...
PoC for CVE-2026-103323
The Epos Now integration for WooCommerce WordPress plugin versions prior to 4.11.2 lacks sufficient authorization checks on a critical REST API endpoint. This vulnerability allows unauthenticated users to access sensitive information, including details of scheduled background tasks and their para...
PoC for CVE-2026-104049
The Academy LMS plugin for WordPress prior to version 4.0.0 contains a vulnerability that fails to adequately verify user enrollment and ownership of course materials when utilizing its REST API. This oversight permits users with self-registerable student accounts to access and retrieve content f...
Discovered 21 hours ago
PoC for CVE-2026-57967
A vulnerability exists in Apache Artemis and ActiveMQ that allows an unauthenticated remote attacker to exploit the CORE protocol SESSION_REATTACH packet. This exploitation can potentially lead to unauthorized access by seizing control of an ongoing authenticated session. Users are urged to upgra...
PoC for CVE-2026-102489
A session hijacking vulnerability exists in Zammad versions 6.3.0 through 6.5.4, enabling potential attackers to execute remote code under the context of the zammad user. Although versions 7.0.0 to 7.1.3 are indicated to contain this vulnerability, they are not exploitable due to specific environ...
Discovered 22 hours ago
PoC for CVE-2011-4825
The static code injection vulnerability in the Ajax File and Image Manager allows remote attackers to exploit crafted parameters to inject arbitrary PHP code into the data.php file. This can lead to unauthorized manipulation of the server environment, potentially compromising sensitive data and a...
Discovered 1 day ago
PoC for CVE-2026-3888
A local privilege escalation vulnerability in Snapd on Linux systems allows attackers to exploit the automatic cleanup of Snap's private /tmp directory. By re-creating this directory under certain configurations of systemd-tmpfiles, an attacker can potentially gain root privileges. This issue imp...
PoC for CVE-2026-59265
A vulnerability in the Java integration of Apache OpenOffice versions 4.1.16 and earlier allows attackers to execute arbitrary code through carefully crafted untrusted documents. This can lead to unauthorized actions being performed on the user's system upon opening the compromised document. To m...
PoC for CVE-2026-63277
LibreOffice Calc allows users to link cell ranges to external data sources. This feature poses a risk, as documents can specify a Java database driver that points to a remote location. Consequently, when users open the document, Java code from that external source can be executed on their system,...
PoC for CVE-2026-43805
A race condition vulnerability has been identified in Apple iOS and macOS products, where improper state handling could lead to unexpected system terminations or allow an app to write unauthorized kernel memory. This flaw has been addressed in recent updates across various Apple platforms, includ...
PoC for CVE-2026-97286
The Strong Testimonials plugin for WordPress contains a Cross Site Scripting (XSS) vulnerability that affects versions up to 3.3.11. An attacker could exploit this weakness to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions or data theft. Websi...
PoC for CVE-2025-6867
A vulnerability exists within the SourceCodester Simple Company Website 1.0, specifically affecting the processing of the file /admin/services/manage.php. An attacker can exploit this vulnerability through a manipulation of the argument ID, enabling SQL injection attacks. This issue poses a risk ...
PoC for CVE-2025-21479
This vulnerability allows unauthorized command execution in the GPU micronode, leading to potential memory corruption when a specific sequence of commands is executed. Attackers could exploit this weakness to disrupt system functionality or gain access to sensitive areas of memory, posing risks t...
PoC for CVE-2026-105957
A vulnerability affecting the SourceCodester Performance Indicator System 1.0 has been identified, which allows for SQL injection through the manipulation of the 'Category' argument in the /opils/admin/view_product.php file. This flaw facilitates remote exploitation, raising significant security ...
PoC for CVE-2026-105922
A security flaw has been identified in the vLLM product of vllm-project, affecting versions up to 0.31.0. This vulnerability is rooted in the function get_token_bin_counts_and_mask located in the utils.py file of the Penalty Handler component. An attacker could exploit this issue to manipulate th...
PoC for CVE-2026-105921
A vulnerability exists in the Kusalkasilva Learning-Management-System that allows an attacker to manipulate the argument 'school_year' via the file search_class.php. This SQL injection vulnerability can be exploited remotely, potentially leading to unauthorized access or modification of the syste...
PoC for CVE-2025-55182
A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...
PoC for CVE-2026-105920
The Kusalkasilva Learning-Management-System is subject to a SQL injection vulnerability in the student_signup.php file within the Student Registration Endpoint component. This vulnerability enables an attacker to execute arbitrary SQL queries, potentially compromising sensitive data. The vulnerab...
Discovered 2 days ago
PoC for CVE-2026-105919
A SQL injection vulnerability has been identified in the Kusalkasilva Learning-Management-System, specifically within the Administrator Login Endpoint function mysql_query located in admin/login.php. By manipulating the arguments for the username and password, attackers can exploit this vulnerabi...