Publicly Disclosed
PoC Exploits

๐Ÿ”ด Alway take caution when working with PoC Exploits ๐Ÿ”ด

Discovered just now...

PoC for CVE-2026-25050

VendurehqVendure2.7LOW
Timing Attack Vulnerability in Vendure Open-Source Commerce Platform

The Vendure open-source headless commerce platform has a vulnerability in the `NativeAuthenticationStrategy.authenticate()` method, which is susceptible to timing attacks. This flaw allows malicious actors to differentiate between valid and invalid usernames by exploiting the timing discrepancies...

PoC for CVE-2026-24061

GnuInetutils๐ŸŸฃ EPSS 30%9.8CRITICAL
Remote Authentication Bypass in GNU Inetutils Telnetd

The GNU Inetutils telnet daemon (telnetd) is vulnerable to a remote authentication bypass that can occur when an attacker manipulates the USER environment variable by specifying a '-f root' value. This flaw allows unauthorized users to gain access without proper authentication. Affected users sho...

Discovered 2 hours ago

PoC for CVE-2026-2070

Utt่ฟ›ๅ– 520w8.7HIGH
Buffer Overflow Vulnerability in UTT ่ฟ›ๅ– 520W Router Firmware

A buffer overflow vulnerability exists in the UTT ่ฟ›ๅ– 520W router, specifically in the strcpy function located in the /goform/formPolicyRouteConf file. This flaw allows an attacker to manipulate the GroupName argument, potentially leading to unauthorized access and exploitation. The vulnerability ...

Discovered 3 hours ago

PoC for CVE-2026-2069

Ggml-orgLlama.cpp4.8MEDIUM
Stack-based Buffer Overflow in ggml-org Llama.cpp by ggml-org

A significant vulnerability has been identified in the ggml-org llama.cpp, specifically in the function llama_grammar_advance_stack found in the GBNF Grammar Handler component. This vulnerability allows an attacker to exploit a stack-based buffer overflow, necessitating local access for successfu...

PoC for CVE-2026-2068

Utt่ฟ›ๅ– 520w8.7HIGH
Buffer Overflow Vulnerability in UTT ่ฟ›ๅ– 520W by UTT

A vulnerability exists in the UTT ่ฟ›ๅ– 520W version 1.7.7-180627 that allows an attacker to exploit the strcpy function in the /goform/formSyslogConf file. By manipulating the ServerIp argument, an attacker can trigger a buffer overflow, posing a significant risk of remote exploitation. This vulner...

Discovered 4 hours ago

PoC for CVE-2026-2067

Utt่ฟ›ๅ– 520w8.7HIGH
Buffer Overflow Vulnerability in UTT ่ฟ›ๅ– 520W Router

A security vulnerability has been identified in the UTT ่ฟ›ๅ– 520W router with version 1.7.7-180627. This flaw specifically lies within the strcpy function in the /goform/formTimeGroupConfig file, where improper handling of the 'year1' argument leads to a buffer overflow. This vulnerability can be e...

PoC for CVE-2026-2066

Utt่ฟ›ๅ– 520w8.7HIGH
Buffer Overflow Risk in UTT ่ฟ›ๅ– 520W by UTT

A vulnerability has been found in the UTT ่ฟ›ๅ– 520W device version 1.7.7-180627. The flaw resides in the strcpy function implemented in the /goform/formIpGroupConfig file. By manipulating the groupName argument, an attacker can trigger a buffer overflow, enabling a potential remote exploitation of ...

Discovered 5 hours ago

PoC for CVE-2026-25731

KovidgoyalCalibre7.8HIGH
Server-Side Template Injection in calibre E-book Manager by Kovid G...

The calibre e-book manager, developed by Kovid Goyal, is vulnerable to a Server-Side Template Injection (SSTI) issue in versions prior to 9.2.0. This flaw arises from its Templite templating engine, where users can execute arbitrary code by utilizing a malicious custom template file during ebook ...

PoC for CVE-2026-2065

Flycatcher ToysSmart Pixelator5.3MEDIUM
Bluetooth Low Energy Vulnerability in Flycatcher Toys smART Pixelat...

A significant security flaw has been identified in the Flycatcher Toys smART Pixelator 2.0 related to its Bluetooth Low Energy Interface. This vulnerability allows attackers on the local network to exploit functionalities that lack proper authentication measures. The potential for unauthorized ac...

PoC for CVE-2026-2064

PortabilisI-educar5.1MEDIUM
Cross Site Scripting Vulnerability in Portabilis i-Educar by Portab...

A cross site scripting vulnerability exists in Portabilis i-Educar versions up to 2.10, specifically in the User Data Page component located at /intranet/meusdadod.php. An attacker can exploit this vulnerability by manipulating file argument inputs, which allows for the execution of arbitrary scr...

Discovered 6 hours ago

PoC for CVE-2026-2063

D-linkDir-823x5.1MEDIUM
OS Command Injection Vulnerability in D-Link DIR-823X Web Managemen...

A significant security flaw has been identified in the D-Link DIR-823X router's web management interface, specifically within the /goform/set_ac_server file. This vulnerability allows attackers to manipulate the ac_server argument, leading to unauthorized OS command injection. Remote exploitation...

PoC for CVE-2026-2062

Open5GSOpen5gs6.9MEDIUM
Null Pointer Dereference in Open5GS PGW S5U Address Handler

A vulnerability identified in the Open5GS PGW S5U Address Handler can lead to a null pointer dereference through the functions sgwc_s5c_handle_modify_bearer_response and sgwc_sxa_handle_session_modification_response. This issue can be exploited remotely, potentially allowing attackers to cause a ...

Discovered 7 hours ago

PoC for CVE-2026-2061

D-linkDir-823x5.1MEDIUM
OS Command Injection Vulnerability in D-Link Router

The D-Link DIR-823X router contains a vulnerability within the function sub_424D20 located in the /goform/set_ipv6 file. This issue allows an attacker to perform OS command injection remotely, potentially compromising the device and the network it connects to. The exploit has been publicly disclo...

PoC for CVE-2026-2060

Code-projectsSimple Blood Donor Man...6.9MEDIUM
SQL Injection Vulnerability in Simple Blood Donor Management System...

An SQL injection vulnerability has been identified in the Simple Blood Donor Management System, specifically in the file /simpleblooddonor/editcampaignform.php. By manipulating the argument ID, an attacker can execute unauthorized SQL commands, potentially compromising the database. This vulnerab...

Discovered 8 hours ago

PoC for CVE-2026-2059

SourcecodesterMedical Center Portal ...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Medical Center Portal...

A SQL injection vulnerability was identified in the Medical Center Portal Management System 1.0, specifically within the emp_edit1.php file. This vulnerability arises from inadequacies in input validation, allowing attackers to manipulate the 'ID' argument remotely, leading to unauthorized access...

PoC for CVE-2019-25293

BluestacksBlue Stacks App Player8.5HIGH
Unquoted Service Path Vulnerability in BlueStacks App Player by Blu...

The BlueStacks App Player version 2.4.44.62.57 is susceptible to an unquoted service path vulnerability within the BstHdLogRotatorSvc service. This flaw allows local attackers to exploit the unquoted service path located in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe. By doing so, ...

PoC for CVE-2019-25304

IssivsIntelligent Security S...8.5HIGH
Unquoted Service Path Vulnerability in SecurOS Enterprise by Intell...

SecurOS Enterprise 10.2 by Intelligent Security System exposes an unquoted service path vulnerability in its SecurosCtrlService. This flaw enables local users to potentially execute arbitrary code with elevated privileges by exploiting the unquoted service path located in C:\Program Files (x86)\I...

PoC for CVE-2019-25305

InforprogramaJumpstart8.5HIGH
Unquoted Service Path Vulnerability in JumpStart by Infor

JumpStart 0.6.0.0 contains a significant security flaw due to an unquoted service path in the jswpbapi service, which operates with LocalSystem privileges. This vulnerability allows attackers to craft a path that injects and executes malicious code under elevated system permissions, potentially c...

PoC for CVE-2019-25302

AcerLaunch Manager8.5HIGH
Unquoted Service Path Vulnerability in Acer Launch Manager

Acer Launch Manager version 6.1.7600.16385 has a vulnerability in the DsiWMIService that stems from an unquoted service path. This oversight allows local users to exploit the unquoted path located at C:\Program Files (x86)\Launch Manager\dsiwmis.exe, enabling them to execute arbitrary code with e...

PoC for CVE-2019-25301

ThrsrossiMillhouse Project5.1MEDIUM
Persistent Cross-Site Scripting in Millhouse-Project by Thrsrossi

The Millhouse-Project version 1.414 is susceptible to a persistent cross-site scripting (XSS) vulnerability, primarily found in the comment submission feature. This flaw enables attackers to inject malicious JavaScript code via the 'content' parameter in the add_comment_sql.php file. As a result,...

PoC for CVE-2019-25303

ThejshenContentmanagementsystem7.1HIGH
SQL Injection Vulnerability in TheJshen Content Management System

TheJshen Content Management System version 1.04 is susceptible to an SQL injection vulnerability due to improper handling of the 'id' GET parameter. This flaw allows attackers to execute various SQL injection techniques, including boolean-based, time-based, and UNION-based methods, potentially co...

PoC for CVE-2019-25299

RimbalinuxAhadpos7.1HIGH
SQL Injection Vulnerability in RimbaLinux AhadPOS by RimbaLinux

RimbaLinux AhadPOS 1.11 is susceptible to SQL injection through the 'alamatCustomer' parameter. This vulnerability allows attackers to craft specific POST requests that can manipulate database queries. By leveraging time-based and boolean-based blind SQL injection techniques, attackers may extrac...

PoC for CVE-2019-25300

ThejshenGlobitek Cms7.1HIGH
SQL Injection Vulnerability in Globitek CMS by thejshen

The Globitek CMS version 1.4 developed by thejshen is susceptible to SQL injection via the 'id' GET parameter, allowing attackers to execute unauthorized database queries. This vulnerability enables the use of various techniques such as boolean-based, time-based, and UNION-based SQL injections, p...

PoC for CVE-2019-25294

Lolypop55Html5 Snmp5.1MEDIUM
Persistent Cross-Site Scripting in html5_snmp by LolyPop

html5_snmp version 1.11 is vulnerable to a persistent cross-site scripting (XSS) attack. This flaw allows attackers to inject malicious JavaScript through the 'Remark' parameter in the 'add_router_operation.php' file. By crafting a specific POST request containing a script payload in the Remark f...

PoC for CVE-2019-25298

Lolypop55Html5 Snmp7.1HIGH
SQL Injection Vulnerabilities in html5_snmp Product by LolyPop

The html5_snmp 1.11 product by LolyPop is susceptible to multiple SQL injection vulnerabilities that can be exploited via the Router_ID and Router_IP parameters. These vulnerabilities allow attackers to manipulate database queries using various techniques, including error-based, time-based, and u...

PoC for CVE-2019-25292

AlpsAlps Hid Monitor Service8.5HIGH
Unquoted Service Path Vulnerability in Alps HID Monitor Service 8.1...

The Alps HID Monitor Service version 8.1.0.10 is susceptible to an unquoted service path vulnerability. This issue allows local attackers to exploit the unquoted path in 'C:\Program Files\Apoint2K\HidMonitorSvc.exe'. By leveraging this vulnerability, attackers can potentially execute arbitrary co...

PoC for CVE-2019-25266

WondershareWondershare Applicatio...8.5HIGH
Unquoted Service Path Vulnerability in Wondershare Application Fram...

The Wondershare Application Framework Service version 2.4.3.231 is susceptible to an unquoted service path vulnerability. This issue enables local attackers to execute arbitrary code with elevated privileges. By placing malicious executables in designated directories, an attacker can exploit this...

PoC for CVE-2026-2058

MathurvishalCloudclassroom-PHP-pro...6.9MEDIUM
SQL Injection Vulnerability in CloudClassroom-PHP-Project by Mathur...

A vulnerability has been discovered in the CloudClassroom-PHP-Project developed by Mathurvishal, specifically within the /postquerypublic.php file. This flaw allows for SQL injection through manipulation of the 'gnamex' argument. The vulnerability enables remote attackers to execute arbitrary SQL...

Discovered 9 hours ago

PoC for CVE-2026-2057

SourcecodesterMedical Center Portal ...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Medical Center Portal...

A newly discovered SQL injection vulnerability in the SourceCodester Medical Center Portal Management System 1.0 compromises the /login.php file. This issue arises from improper handling of the User input parameter, allowing attackers to execute remote SQL commands. Given that details of this exp...

Discovered 11 hours ago

PoC for CVE-2026-2056

D-linkDir-605l6.9MEDIUM
Information Disclosure Vulnerability in D-Link DIR-605L and DIR-619...

A security flaw has been identified in D-Link DIR-605L and DIR-619L routers, specifically in the /wan_connection_status.asp file within the DHCP Connection Status Handler. This vulnerability can lead to unauthorized information disclosure, allowing remote attackers to exploit it. Notably, these p...

PoC for CVE-2024-32964

LobehubLobe-chat๐ŸŸฃ EPSS 54%9CRITICAL
Lobe Chat Server-Side Request Forgery Vulnerability

The Lobe Chat framework, designed for chatbot development with capabilities like speech synthesis and a multimodal plugin system, has a vulnerability in its /api/proxy endpoint prior to version 0.150.6. This flaw allows attackers to execute unauthorized Server-Side Request Forgery, enabling them ...

Discovered 12 hours ago

PoC for CVE-2026-2054

D-linkDir-605l6.9MEDIUM
Information Disclosure Vulnerability in D-Link Routers

A significant security flaw has been identified in D-Link DIR-605L and DIR-619L routers. This vulnerability affects the Wifi Setting Handler component, allowing attackers to manipulate specific functions, which may lead to unauthorized information disclosure. The exploitation of this vulnerabilit...

Discovered 13 hours ago

PoC for CVE-2026-2018

ItsourcecodeSchool Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode School Management System

A critical flaw has been identified in the itsourcecode School Management System version 1.0, specifically located within the /ramonsys/settings/controller.php file. This vulnerability arises from improper handling of the argument ID, enabling SQL injection attacks. As a result, attackers can pot...

Discovered 14 hours ago

PoC for CVE-2026-2016

Happyfish100Libfastcommon4.8MEDIUM
Stack-Based Buffer Overflow in Happyfish100's Libfastcommon

A security flaw in Happyfish100's libfastcommon affects the base64_decode function located in src/base64.c. This vulnerability allows for a stack-based buffer overflow, requiring local access for exploitation. Given that this issue has been publicly disclosed, it is crucial to apply the recommend...

PoC for CVE-2026-2015

PortabilisI-educar5.3MEDIUM
Improper Authorization in Portabilis i-Educar Affects Final Status ...

A vulnerability has been discovered in the Portabilis i-Educar system, specifically affecting the Final Status Import component and its FinalStatusImportService.php file. This vulnerability is due to improper authorization, which can be exploited by manipulating the school_id argument. The attack...

Discovered 15 hours ago

PoC for CVE-2026-2014

ItsourcecodeStudent Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Student Management System

A security vulnerability has been identified in the itsourcecode Student Management System 1.0, specifically in the /ramonsys/billing/index.php file. The issue arises from improper handling of the ID argument, allowing for SQL injection attacks. This vulnerability can be exploited remotely, poten...

PoC for CVE-2026-2013

ItsourcecodeStudent Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Student Management Syst...

A security flaw in the itsourcecode Student Management System version 1.0 allows for SQL injection through improper handling of the ID argument in the file /ramonsys/soa/index.php. This vulnerability can be exploited remotely, making it a significant risk since potential attackers can manipulate ...

Discovered 16 hours ago

PoC for CVE-2026-2012

ItsourcecodeStudent Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Student Management Syst...

A vulnerability exists in the itsourcecode Student Management System version 1.0 located in the file /ramonsys/facultyloading/index.php. This flaw allows for SQL injection through the manipulation of the argument ID, enabling attackers to execute arbitrary SQL commands. The exploitation can be pe...

PoC for CVE-2026-2011

ItsourcecodeStudent Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Student Management Syst...

A security flaw was discovered in the itsourcecode Student Management System 1.0, specifically impacting an unidentified function within the /ramonsys/enrollment/controller.php file. This vulnerability allows for SQL injection attacks through the manipulation of the argument ID. As the exploit is...

Discovered 17 hours ago

PoC for CVE-2026-2010

SanluanPubliccms2.3LOW
Improper Authorization in Sanluan PublicCMS Payment Handler

A vulnerability exists in the Trade Payment Handler of Sanluan PublicCMS that allows for improper authorization due to manipulation of the paymentId parameter in the function Paid within the TradePaymentService.java file. This can be exploited remotely, leading to unauthorized access to trade pay...

PoC for CVE-2026-2009

SourcecodesterGas Agency Management ...5.3MEDIUM
Improper Access Control in SourceCodester Gas Agency Management System

A vulnerability exists in the SourceCodester Gas Agency Management System version 1.0, specifically within the processing of the createUser.php file. This flaw allows for improper access control measures, making it possible for attackers to manipulate the system remotely. With the exploit made pu...

Discovered 18 hours ago

PoC for CVE-2026-2008

AbhiphileFermat-mcp5.3MEDIUM
Code Injection Vulnerability in abhiphile fermat-mcp Product

A vulnerability exists in the abhiphile fermat-mcp product affecting the eqn_chart function within the eqn_chart.py file. By manipulating the argument 'equations', attackers can execute arbitrary code, leading to potential unauthorized access and remote exploitation. The rolling release nature of...

PoC for CVE-2024-46987

Owen2345Camaleon-cms7.7HIGH
Camaleon CMS Vulnerability in Download Private File Method

Camaleon CMS, a robust content management system built on Ruby on Rails, has a path traversal vulnerability in the MediaController's download_private_file method. This flaw permits authenticated users to potentially download any file stored on the web server, depending on file permissions configu...

PoC for CVE-2026-2000

DcnDcme-3205.1MEDIUM
Command Injection Vulnerability in DCN DCME-320 Web Management Backend

A command injection vulnerability exists in the DCN DCME-320's web management backend. The issue lies within the apply_config function of the bridge_cfg.php file, where improper handling of the ip_list argument allows for unauthorized command execution. This vulnerability can be exploited remotel...

Discovered 19 hours ago

PoC for CVE-2026-1998

MicroPythonMicropython4.8MEDIUM
Memory Corruption in Micropython Affects Functionality

A vulnerability exists in MicroPython due to a flaw in the mp_import_all function located in py/runtime.c, which can lead to memory corruption. This issue requires local access for exploitation and has already been published. Users are advised to apply the available patch (commit 570744d06c5ba9db...

PoC for CVE-2026-1991

libuvcLibuvc4.8MEDIUM
Null Pointer Dereference in libuvc UVC Descriptor Handler

A vulnerability has been identified in libuvc up to version 0.0.7 that affects the function uvc_scan_streaming within the UVC Descriptor Handler located in the file src/device.c. This flaw leads to a null pointer dereference, which can potentially allow an attacker local access to disrupt operati...

Discovered 20 hours ago

PoC for CVE-2026-1990

Oat++ FrameworkOatpp4.8MEDIUM
ObjectWrapper Null Pointer Dereference in oatpp by Oat++ Framework

A vulnerability has been identified in the Oat++ framework, specifically within the function oatpp::data::type::ObjectWrapper::ObjectWrapper located in src/oatpp/data/type/Type.hpp. This issue can lead to a null pointer dereference when accessed locally, making it essential for developers to be a...

PoC for CVE-2026-1979

mrubyMruby4.8MEDIUM
Use After Free Flaw in mruby by mruby

A vulnerability exists in mruby versions up to 3.4.0, specifically in the mrb_vm_exec function within the JMPNOT-to-JMPIF Optimization component. This weakness allows an attacker to execute a manipulation that can result in a use after free condition. The attack needs to be launched locally, and ...

Discovered 21 hours ago

PoC for CVE-2018-13379

FortinetFortinet FortiOS, Fort...๐ŸŸฃ EPSS 94%9.8CRITICAL
Path Traversal Vulnerability in Fortinet FortiOS and FortiProxy Pro...

An improper limitation of a pathname to a restricted directory exists in Fortinet's FortiOS and FortiProxy products. This flaw, found in versions 6.0.0 through 6.0.4, 5.6.3 through 5.6.7, and 5.4.6 through 5.4.12 for FortiOS, as well as various versions of FortiProxy, allows unauthenticated attac...

PoC for CVE-2026-1978

Kalyan02Nanocms6.9MEDIUM
User Information Handler Vulnerability in kalyan02 NanoCMS

A vulnerability exists in kalyan02 NanoCMS up to version 0.4, specifically within the User Information Handler component. This flaw allows unauthorized manipulation of the file /data/pagesdata.txt, resulting in direct access to sensitive data. The exploitation of this vulnerability can be initiat...