Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-96940
A weakness in the authorization mechanisms of Microsoft Exchange Server can be exploited by authenticated attackers, allowing them to gain elevated privileges over the network. This vulnerability poses significant risks as it can enable attackers to manipulate sensitive data or compromise additio...
Discovered 2 hours ago
PoC for CVE-2026-105809
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be...
PoC for CVE-2026-105808
A vulnerability was determined in SourceCodester Simple Student Information System 1.0. This vulnerability affects the function clean of the file searchresults.php. Executing a manipulation of the argument searchbox can lead to cross site scripting. The attack can be launched remotely. The exploi...
Discovered 4 hours ago
PoC for CVE-2026-105778
A vulnerability has been identified in the Tenda AC5 router, specifically within the Wifi Handler component at the /goform/setWifi endpoint. This flaw allows for manipulation of the wifiPwd argument, potentially leading to a stack-based buffer overflow. The exploitation of this vulnerability can ...
PoC for CVE-2026-86786
The Slider Pro plugin for WordPress, up to version 1.0.0, contains a vulnerability that allows unauthenticated users to exploit an AJAX action without any capability or authorization checks. This could enable these users to access sensitive information such as the titles, excerpts, and permalinks...
PoC for CVE-2026-89289
The Fast Courier WordPress plugin, up to version 5.2.3, contains a significant security flaw that exposes a REST API endpoint without proper authentication. This vulnerability allows unauthorized attackers to modify order fulfillment data, including the courier status and customer-facing tracking...
PoC for CVE-2026-94278
The File Media Renamer plugin for WordPress has a flaw that fails to validate user authorization for modifying media attachments. This vulnerability allows any user with file-upload privileges to rename media files belonging to other users, including site administrators. As a result, it can lead ...
PoC for CVE-2026-94270
The Deema Payment Gateway plugin for WordPress, up to version 1.1.2, has a significant security issue due to its failure to verify the authenticity of incoming payment provider notifications. This vulnerability occurs because the verification feature is disabled by default, enabling unauthorized ...
PoC for CVE-2026-94271
The Deema Payment Gateway for WordPress, up to version 1.1.2, contains a vulnerability that permits unauthenticated users to mark orders as paid without any legitimate payment verification with the payment provider. This occurs due to the plugin's failure to verify the payment status or amount wh...
PoC for CVE-2026-94299
The elegro Crypto Payment WordPress plugin prior to version 1.0.1 has a serious security flaw that allows attackers to deceive the payment system. Specifically, it fails to enforce the requirement for a shared secret, enabling unauthorized individuals to send fraudulent payment notifications. As ...
PoC for CVE-2026-105776
A vulnerability has been identified in the Employee-Movement-Tracking-and-Monitoring-Website developed by bhagya3929, specifically within the /admin_transaction.php file. The vulnerability arises from improper handling of the 'Username' argument, allowing remote attackers to exploit the system th...
Discovered 5 hours ago
PoC for CVE-2026-105775
A security vulnerability has been identified in the vLLM software developed by vllm-project, specifically within the Completions Request Handler's conv_ssm_forward function. The flaw allows for out-of-bounds reading of memory, posing a significant security risk. This vulnerability can be exploite...
PoC for CVE-2026-105708
A vulnerability exists in imgproxy versions up to 4.0.17, specifically within the sanitizeElement function of the SVG Handler module located in the file processing/svg/svg.go. This flaw facilitates a cross site scripting (XSS) attack, enabling attackers to execute malicious scripts remotely. The ...
PoC for CVE-2026-105707
A security vulnerability has been identified in the Uptrace product, specifically in the 'Login' function within the file pkg/org/user_handler.go. This issue allows for information exposure through error messages, potentially enabling remote attackers to gain sensitive information. Despite report...
Discovered 6 hours ago
PoC for CVE-2026-105706
A vulnerability has been detected in SourceCodester Drug Recommendation System 1.0, which allows for cross-site request forgery (CSRF) attacks. This weakness occurs in an undisclosed function, enabling an attacker to manipulate requests from a remote location. The exploit is publicly available, p...
PoC for CVE-2026-105705
A security flaw has been identified in the SourceCodester Drug Recommendation System version 1.0, specifically targeting an unknown function within the file Admin/add_drug.php. This vulnerability allows attackers to perform cross site scripting (XSS) attacks, which can be executed remotely. The e...
PoC for CVE-2026-105704
The SourceCodester Drug Recommendation System 1.0 is vulnerable due to an improper authentication flaw in the Auth Guard component. An attacker can manipulate the user_id argument, allowing for unauthorized access. This vulnerability can be exploited remotely, with existing public exploits making...
PoC for CVE-2026-105703
A vulnerability was identified in the PHPGurukul User Registration & Login and User Management System version 3.3, specifically within the Change Password Handler located in loginsystem/admin/change-password.php. The flaw arises from the improper handling of the currentpassword argument, leading ...
Discovered 7 hours ago
PoC for CVE-2026-105621
A security flaw has been identified in the jishenghua jshERP software, specifically within the Financial Receipt Update Handler. The vulnerability resides in the updateAccountHeadAndDetail function of the AccountHeadService.java class. It allows an attacker to perform unauthorized actions remotel...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-105611
A vulnerability has been identified in Chillzhuang's SpringBlade framework that affects the User Detail Endpoint within the RoleController.java file. This vulnerability arises from improper handling of argument ID manipulation, allowing remote attackers to gain unauthorized access to user details...
PoC for CVE-2026-105610
A security vulnerability has been identified in the Chillzhuang SpringBlade framework, specifically within the Parameter Submit Management component. An improper authorization issue arises from the manipulation of the 'initPassword' argument in the ParamController.java file. This flaw allows for ...
Discovered 8 hours ago
PoC for CVE-2026-105573
A vulnerability exists in the Newbee-Mall's Shopping Cart Quantity Handler, affecting versions up to 2.7.5. This flaw lies within the updateAccountHeadAndDetail function, where improper handling of the 'goodsCount' argument can lead to unintended business logic errors. It poses a security risk as...
PoC for CVE-2026-93687
The Micromatch braces library up to version 3.0.3 is susceptible to a stack overflow due to insufficient depth guarding in its recursive Abstract Syntax Tree (AST) walkers. Attackers can exploit this vulnerability by providing deeply nested brace patterns within the character limit, which may lea...
PoC for CVE-2026-105572
A significant vulnerability in PickMall's Lilishop, specifically in the Buyer Invoice List component, allows for an authorization bypass via manipulation of the 'memberId' parameter. This weakness enables attackers to potentially gain unauthorized access to sensitive functionalities, which can be...
PoC for CVE-2021-1931
This security vulnerability is caused by improper validation of the buffer length when processing fast boot commands across various Qualcomm Snapdragon products. An attacker could exploit this flaw to execute arbitrary code or cause unintended behavior, potentially compromising the affected devices.
PoC for CVE-2026-105571
A vulnerability in the PickMall Lilishop application version 4.2.4 and earlier has been identified, affecting the Mobile Binding component. The issue arises from an unspecified function within the '/buyer/passport/member/bindMobile' file, where inappropriate handling of the 'Username' argument ca...
PoC for CVE-2020-23546
IrfanView 4.54 has a vulnerability that allows attackers to trigger a denial of service or potentially other unspecified effects by using specially crafted XBM files. This issue arises when the application mishandles problematic data during processing, particularly at the point where it reads a m...
Discovered 9 hours ago
PoC for CVE-2026-105487
A vulnerability exists in the yogeshojha reNgine, particularly within the listTargets Endpoint's subdomain_discovery function in tasks.py. This flaw allows for OS command injection through improper argument handling. Attackers can exploit this vulnerability remotely, leading to potential unauthor...
PoC for CVE-2026-105486
A vulnerability in OSSRS srs versions up to 7.0-a1 was identified that allows for missing authentication within the System API component, specifically in the function systemAPI.Run located at internal/proxy/api.go. This issue enables unauthorized remote access, which could be exploited by attacke...
Discovered 10 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 11 hours ago
PoC for CVE-2026-105471
A security vulnerability has been identified in the girishsaraf Online-Appointment-Booking-System, particularly affecting the signup.php file within its Registration Handler component. This flaw allows attackers to manipulate the 'fname' parameter, leading to SQL injection vulnerabilities. As a r...
Discovered 12 hours ago
PoC for CVE-2026-105470
A vulnerability has been discovered in the Online-Appointment-Booking-System created by girishsaraf. This security flaw is present in the Doctor Search Endpoint's locateus.php file, specifically within its mysqli_query function. An attacker can manipulate the 'doctorname' argument, potentially le...
PoC for CVE-2026-105469
A vulnerability exists in the girishsaraf Online-Appointment-Booking-System that affects the AJAX Endpoint component. The flaw is found in the get_town.php file, where improper handling of parameters like countryid, townid, cid, didval, and cidval can lead to SQL injection attacks. Attackers may ...
Discovered 13 hours ago
PoC for CVE-2026-105468
A critical vulnerability exists in the girishsaraf Online-Appointment-Booking-System that could allow attackers to execute arbitrary SQL queries via the 'uname' and 'pass' parameters in the Admin/mlogin.php file. This SQL injection vulnerability may be exploited remotely, putting user data at ris...
Discovered 14 hours ago
PoC for CVE-2026-105438
A vulnerability has been identified in the O2OA General Module, specifically in the action function responsible for uploading Excel files through a URL. This issue revolves around improper validation of the 'fileUrl' parameter, which could be exploited to carry out a server-side request forgery (...
PoC for CVE-2026-77226
An incorrect authorization flaw in the Camunda Admin web application's first-run setup endpoint allows an unauthenticated remote attacker to exploit the system when the camunda-admin group is empty. The vulnerability arises from the SetupResource's failure to accurately assess setup availability,...
Discovered 15 hours ago
PoC for CVE-2026-105392
A security flaw exists in the JWT Signing configuration of Lybbn Django-Vue-Lyadmin up to version 3.2.12, where the SECRET_KEY argument is hard-coded within the backend/application/settings.py file. This weakness allows for potential remote exploitation, as the hard-coded key can be manipulated. ...
PoC for CVE-2026-105389
A security flaw has been identified in the file UploadController.class.php of the UploadTicketFile Endpoint in Feelcrm-os version 1.0.0. This vulnerability enables unauthorized file uploads due to improper handling of the 'cmd' argument. The issue can be exploited remotely, allowing attackers to ...
PoC for CVE-2026-105388
A vulnerability has been detected in the Feelcrm-os product version 1.0.0, specifically in the index function of MemberController.class.php. This flaw enables attackers to manipulate the 'group_id' argument, resulting in SQL injection attacks that can be executed remotely. The exploit is publicly...
Discovered 16 hours ago
PoC for CVE-2026-105387
A security flaw has been identified in the Online-Appointment-Booking-System developed by girishsaraf, particularly affecting the Patient Login Handler in the cover.php file. The vulnerability allows attackers to manipulate the uname and psw parameters through the mysqli_query function, which can...
PoC for CVE-2026-105386
A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem, specifically in the 'get' function of the file print.php. This vulnerability allows for SQL injection through manipulation of the 'transaction_id' argument, which can be exploited remotely. The exploit is publ...
Discovered 17 hours ago
PoC for CVE-2026-105385
A vulnerability exists in the onetwothreeneth HospitalManagementSystem's transaction_details.php file that allows attackers to exploit SQL injection techniques via manipulation of the transaction_id argument. This flaw poses a risk for remote exploitation, making it critical for users to take pre...
PoC for CVE-2026-105384
A vulnerability exists in the UNION HospitalManagementSystem, specifically affecting the patient_info.php file, where improper validation of the patient_id argument can lead to SQL injection attacks. Remotely exploitable, this flaw enables malicious actors to manipulate database queries, potentia...
PoC for CVE-2026-105383
A SQL injection vulnerability was identified in the onetwothreeneth HospitalManagementSystem, specifically impacting the php/controller.php file. This flaw arises from improper handling of the transaction_idS argument, allowing attackers to manipulate SQL queries. The vulnerability can be exploit...
Discovered 18 hours ago
PoC for CVE-2026-105382
A vulnerability has been identified in the Hospital Management System by onetwothreeneth, specifically affecting the function update_subaccount in php/controller.php related to account administration. An issue with the user_id argument allows for improper authorization, enabling remote exploitati...
PoC for CVE-2025-48617
A permissions bypass vulnerability exists in the CarrierConfigLoader component of Android, specifically within the overrideConfig method. This flaw could allow an attacker to circumvent user identifier checks, resulting in local escalation of privileges without requiring any additional execution ...
Discovered 19 hours ago
PoC for CVE-2026-105329
A code injection vulnerability exists in TallCMS versions up to 4.8.0 within the PluginManager component, specifically in the ThemeManager.php file. This vulnerability allows an attacker to manipulate a certain function, potentially enabling remote execution of arbitrary code. The exploit has bee...
Discovered 22 hours ago
PoC for CVE-2026-105315
A security issue has been identified in django-haystack versions up to 3.3.0, specifically in the _to_python function found in the haystack/backends/elasticsearch_backend.py file. The vulnerability arises from improper handling of the 'result_class' argument, potentially allowing for the executio...
PoC for CVE-2011-2523
A serious backdoor vulnerability was discovered in vsftpd 2.3.4, affecting downloads made between June 30 and July 3, 2011. This vulnerability allows an attacker to exploit the software and open a remote shell on port 6200/tcp, granting unauthorized access to the system. It poses significant risk...