Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 7 minutes ago
PoC for CVE-2026-64640
An issue has been identified in Apache Polaris where it fails to consistently validate storage locations during table and view registration. Authenticated users with the necessary permissions can leverage this vulnerability to allow Polaris to access Iceberg metadata files from user-defined locat...
Discovered 1 hour ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 2 hours ago
PoC for CVE-2026-19212
A vulnerability exists in the TraderATP Cash Trade Conversion component of WonderTrader, specifically affecting the function within the file src/Includes/WTSTradeDef.hpp. This issue arises from the manipulation of the m_offsetType argument, leading to the use of an uninitialized variable, which c...
PoC for CVE-2026-19211
A SQL injection vulnerability has been identified in the SourceCodester Photo Share Website version 1.0. This issue is triggered when manipulating the email parameter in the /social/ajax.php?action=signup file. Unsanctioned input can lead to unauthorized access, allowing attackers to execute remo...
Discovered 3 hours ago
PoC for CVE-2026-39987
Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...
PoC for CVE-2026-19210
A vulnerability has been discovered in the SourceCodester Photo Share Website 1.0, specifically targeting an unknown function in the file /social/ajax.php with the action parameter set to save_upload. This flaw allows attackers to manipulate the img[] and imgName[] arguments, leading to unrestric...
PoC for CVE-2026-19209
A vulnerability has been identified in version 1.0 of the SourceCodester Photo Share Website, specifically affecting the function in /social/index.php?page=home. This flaw allows attackers to perform cross site scripting (XSS) by manipulating the Comment argument, potentially enabling remote expl...
Discovered 4 hours ago
PoC for CVE-2026-19208
A vulnerability has been identified in the WonderTrader application which affects the function TraderDD::queryTrades located in the source file TraderDD.cpp. This flaw arises from improper handling of the FID_JYLB argument, leading to potential manipulation of the behavioral workflow. Threat acto...
PoC for CVE-2026-19207
A security vulnerability exists in the PHPGurukul Visitor Management System 1.0 that allows an attacker to exploit a flaw in the processing of the 'fullname' argument in the file /manage-newvisitors.php. This manipulation leads to cross-site scripting (XSS) attacks that can be executed remotely. ...
PoC for CVE-2022-4995
Weaver (Fanwei) E-cology versions prior to 10.52 are impacted by a file upload vulnerability that allows unauthorized remote attackers to upload arbitrary files, notably JSP webshells. By sending a multipart/form-data POST request to the uploaderOperate.jsp endpoint with manipulated secId and pla...
PoC for CVE-2022-4995
Weaver (Fanwei) E-cology versions prior to 10.52 are impacted by a file upload vulnerability that allows unauthorized remote attackers to upload arbitrary files, notably JSP webshells. By sending a multipart/form-data POST request to the uploaderOperate.jsp endpoint with manipulated secId and pla...
Discovered 5 hours ago
PoC for CVE-2026-19206
A vulnerability has been identified in MZ Automation's libiec61850 library, specifically within the ASDU Element Handler. This flaw stems from the function SVReceiver_stopThreadless located in src/sampled_values/sv_subscriber.c, leading to a heap-based buffer overflow. The vulnerability necessita...
PoC for CVE-2026-44613
A cross-site request forgery (CSRF) vulnerability was identified in Apache Zeppelin that could allow an attacker to impersonate authenticated users. The vulnerability arises due to the application's default CORS configuration, which permits cross-origin state-changing requests. By enticing a user...
Discovered 8 hours ago
PoC for CVE-2026-64561
A flaw in the Linux kernel's KVM module relates to improper handling of invalid or obsolete root pages after making MMU pages available. The issue arises when the system fails to check for stale page faults, resulting in an attempt to map memory to an invalid root. This can occur when reclaiming ...
Discovered 10 hours ago
PoC for CVE-2024-1086
A use-after-free vulnerability exists in the nf_tables component of the Linux kernel, specifically within the nft_verdict_init() function. This vulnerability can be exploited when a drop error is incorrectly handled, resulting in a potential double free situation during packet verdict processing....
Discovered 11 hours ago
PoC for CVE-2026-15239
The Simple CAPTCHA with Cloudflare Turnstile plugin for WordPress prior to version 1.42.0 is vulnerable to an improper token validation issue. The plugin fails to properly bind its Turnstile validation cache to the unique challenge token in its Forminator integration. This oversight allows attack...
PoC for CVE-2026-15211
The Subscriptions for WooCommerce plugin prior to version 2.0.1 fails to adequately validate the payment amounts during the order completion process. This vulnerability allows an unauthenticated attacker, particularly in scenarios where guest checkout is enabled, to exploit the system by substitu...
PoC for CVE-2026-15148
The WP Events Manager plugin prior to version 2.2.5 contains a security flaw where it fails to authenticate payment notifications. This oversight permits unauthenticated users to manipulate booking statuses, marking them as paid without genuine payment confirmation. As a result, unauthorized book...
Discovered 13 hours ago
PoC for CVE-2026-16263
The WP Maps plugin for WordPress prior to version 4.9.7 is vulnerable due to a lack of capability checks in its AJAX actions. This flaw enables users with Subscriber-level permissions to exploit the plugin's functionality, allowing them to include and execute arbitrary PHP files from the server's...
PoC for CVE-2026-16262
The Estatik Real Estate Plugin for WordPress prior to version 4.3.3 exhibits a critical flaw in its OAuth social login implementation. This vulnerability allows unauthenticated attackers to manipulate the login process by binding the OAuth flow to a session not associated with the initiating user...
PoC for CVE-2026-16265
The WP Maps plugin for WordPress, prior to version 4.9.7, lacks proper capability checks in its AJAX actions. This weakness allows users with a Subscriber account to execute uncontrolled recursive functions, subsequently exhausting server resources and leading to a Denial of Service. It is crucia...
PoC for CVE-2026-16258
The Ajax Search Lite plugin for WordPress, prior to version 4.14.5, is vulnerable due to its failure to properly validate deserialized input. This weakness allows unauthenticated attackers to exploit PHP Object Injection, especially when an appropriate Properties Object Payload (POP) chain is ava...
PoC for CVE-2026-16041
The MStore API plugin for WordPress, prior to version 4.21.0, lacks proper authorization checks on its REST endpoint for creating product reviews. This vulnerability allows unauthenticated attackers to submit product reviews to WooCommerce stores, impersonating any reviewer by specifying arbitrar...
PoC for CVE-2026-16030
The MStore API WordPress plugin prior to version 4.21.0 fails to properly validate the cryptographic signature of the token used for phone-based login. This flaw enables unauthorized attackers, who are aware of a registered user's phone number, to create a forged token, potentially allowing them ...
PoC for CVE-2026-16038
The MStore API plugin for WordPress prior to version 4.21.0 features a critical flaw where it fails to authenticate payment through the payment gateway before marking orders as paid. This allows an unauthenticated attacker to manipulate payment statuses, enabling them to falsely mark any order as...
PoC for CVE-2026-16039
The MStore API WordPress plugin versions prior to 4.21.0 are vulnerable as it fails to enforce proper restrictions on its vendor-orders endpoint. This oversight permits any authenticated user, even those with lower privileges such as Subscribers, to access and read all WooCommerce orders in the s...
PoC for CVE-2026-15361
The Content Views plugin for WordPress, prior to version 4.5, is susceptible to a SQL injection vulnerability due to insufficient capability checks on specific AJAX operations. This flaw allows authenticated users, including those with minimal privileges like Subscribers, to execute unauthorized ...
PoC for CVE-2026-15359
The Templately WordPress plugin prior to version 3.7.1 is susceptible to an authorization bypass. This vulnerability allows unauthorized attackers to exploit a lack of proper checks on certain request handlers. By leveraging this flaw, an attacker can replace the legitimate administrator's stored...
PoC for CVE-2026-15386
The Meow Gallery plugin for WordPress, prior to version 5.5.2, is susceptible to a JavaScript injection vulnerability. The plugin fails to properly escape the alt text of attachments when generating output for linked galleries. As a result, users with Author roles or higher are able to store a po...
PoC for CVE-2026-15245
The BNE Testimonials plugin for WordPress prior to version 2.0.8.2 contains a vulnerability that fails to properly escape a shortcode attribute within a JavaScript context. This flaw permits users with contributor privileges and higher to inject arbitrary JavaScript code, leading to potential exe...
PoC for CVE-2026-15214
The Subscriptions for WooCommerce WordPress plugin prior to version 2.0.1 lacks proper verification of subscription ownership. This oversight enables any authenticated user to access another user's subscription details, including product information, status, and important dates, by merely providi...
PoC for CVE-2026-15215
The Subscriptions for WooCommerce plugin for WordPress has a security flaw where it fails to validate user permissions when installing and activating the plugin via a nonce-protected AJAX action. This oversight allows users with the Shop Manager role, who ordinarily lack sufficient management cap...
PoC for CVE-2026-14943
The Password Protected plugin for WordPress, prior to version 2.8.4, has a significant vulnerability that fails to secure REST API access for unauthenticated users when a specific option is enabled. This oversight allows unauthorized visitors to access protected content and account identifiers, e...
PoC for CVE-2026-14331
The Subscribe2 WordPress plugin prior to version 10.46 has a security flaw where it fails to properly escape user-supplied data. This flaw allows an attacker to craft a malicious link that, when clicked by an unauthenticated visitor, results in the execution of arbitrary JavaScript in the visitor...
PoC for CVE-2026-15032
The Comments plugin for WordPress, prior to version 7.6.60, fails to properly sanitize user-supplied URLs when outputting them within HTML attributes. This vulnerability enables unauthenticated users to inject malicious JavaScript payloads into the plugin's comments section. When any user, includ...
PoC for CVE-2026-14205
The WP Events Manager plugin prior to version 2.2.5 is susceptible to an authentication bypass vulnerability. This flaw allows authenticated users to manipulate the quantity of event tickets during the registration process. As a result, attackers can create legitimate bookings for paid events wit...
Discovered 14 hours ago
PoC for CVE-2026-19196
A SQL injection vulnerability exists in the SourceCodester Photo Share Website 1.0 within the login function located in the file /social/ajax.php. This flaw allows an attacker to manipulate the 'email' parameter, potentially leading to unauthorized access and data breaches. The vulnerability can ...
PoC for CVE-2026-19195
A notable access control vulnerability has been identified in the V-Secure Jingyun Antivirus version 2.4.2.39. This flaw occurs in the ZyArk.sys library of its Kernel Driver component and can be exploited locally, allowing unauthorized access to sensitive functions. The weakness stems from improp...
PoC for CVE-2026-19193
A vulnerability has been identified in Jiangmin Antivirus 21 that affects the MessageNotifyCallback function within the kvcore.sys library of the Minifilter Port. This flaw allows for improper access controls, enabling local attackers to potentially exploit the system through unauthorized manipul...
Discovered 15 hours ago
PoC for CVE-2026-19192
A vulnerability exists in DeepCool DisplayService version 1.2.12 that allows for improper access controls related to the handling of the executable file DeepCoolDisplayService.exe. This flaw can be exploited locally, potentially enabling an attacker to manipulate the service and gain unauthorized...
PoC for CVE-2026-19191
A security flaw has been identified in StableBit DrivePool version 2.3.13.1687, affecting the DrivePoolService component. This vulnerability enables local users to manipulate permissions within the application, potentially leading to unauthorized access and control over sensitive operations. The ...
Discovered 16 hours ago
PoC for CVE-2026-19190
A local execution vulnerability has been discovered in StableBit Scanner version 2.6.13.4088, which affects the ScannerService component located in C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe. This issue can lead to permission manipulation, allowing unauthorized access to...
PoC for CVE-2026-18649
A vulnerability exists in the GStreamer gst-plugins-good package where the rtph264depay and rtph265depay RTP depayloader elements fail to enforce a limit on the size of the reassembly buffer utilized during the processing of fragmented RTP packets. This flaw permits a remote, unauthenticated atta...
Discovered 17 hours ago
PoC for CVE-2026-19189
A security vulnerability has been identified in Power Software's PowerISO version 9.3.0.0, which affects the kernel driver component found at C:\Windows\System32\drivers\scdemu.sys. This flaw enables improper privilege management, allowing attackers with local access to exploit the issue. The pot...
Discovered 20 hours ago
PoC for CVE-2025-8045
A use after free vulnerability exists in the Valhall GPU Kernel Driver and the Arm 5th Gen GPU Architecture Kernel Driver. This flaw allows local non-privileged user processes to execute improper GPU processing operations, potentially leading to unauthorized access to freed memory regions. Affect...
PoC for CVE-2026-56164
A vulnerability exists in Microsoft Office SharePoint where a critical function lacks proper authentication. This flaw allows unauthorized attackers to gain elevated privileges over a network, potentially leading to unauthorized actions and data exposure. Microsoft has released guidance for mitig...
Discovered 21 hours ago
PoC for CVE-2026-0300
A buffer overflow vulnerability exists within the User-ID™ Authentication Portal of Palo Alto Networks PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by manipulating specially crafted packets. To miti...
PoC for CVE-2026-70636
Flowise versions up to 3.1.4 have a significant security vulnerability that allows unauthenticated attackers to exploit the OAuth2 credential refresh endpoint. This is achieved through a flaw in the prefix-based whitelist matching within the authentication middleware. By sending a specifically cr...
PoC for CVE-2026-67622
The Flowise OpenAI Assistants integration, particularly in version 3.1.4, is susceptible to an insecure direct object reference vulnerability. This flaw enables authenticated attackers to gain unauthorized access to sensitive credentials linked to other workspaces. By exploiting this vulnerabilit...
PoC for CVE-2026-67621
The Flowise product versions up to 3.1.4 exhibit a significant vulnerability due to missing authorization checks. This flaw enables authenticated users with mere view-level permissions to carry out unauthorized actions on the document store. By exploiting unprotected mutation endpoints, an attack...