Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 7 hours ago

PoC for CVE-2025-13588

LkinderbuenoStreamity Xtream Iptv ...5.3MEDIUM
Server-Side Request Forgery in lKinderBueno Streamity Xtream IPTV P...

A vulnerability in lKinderBueno Streamity Xtream IPTV Player versions up to 2.8 allows for server-side request forgery due to flaws in the public/proxy.php file. Attackers can remotely exploit this weakness, resulting in unauthorized server requests. To mitigate this risk, users should upgrade to...

PoC for CVE-2025-13586

SourcecodesterOnline Student Clearan...5.1MEDIUM
SQL Injection Vulnerability in SourceCodester Online Student Cleara...

A vulnerability exists in the SourceCodester Online Student Clearance System 1.0 that can be exploited through the hidden functionality in the /Admin/changepassword.php file. By manipulating the input argument 'txtconfirm_password', attackers can execute SQL injection attacks remotely, compromisi...

PoC for CVE-2025-12629

WordPressBroken Link Manager7.1HIGH
Reflected Cross-Site Scripting Vulnerability in Broken Link Manager...

The Broken Link Manager plugin for WordPress versions up to 0.6.5 is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper sanitization and escaping of parameters before they are output back to the web page. This weakness could be exploited by attackers to inject malicious scripts, p...

PoC for CVE-2025-12569

WordPressGuest Posting / Fronte...4.7MEDIUM
Open Redirect Vulnerability in Frontend Posting Plugin by WordPress

The Frontend Posting plugin for WordPress, prior to version 5.0.0, contains an Open Redirect vulnerability due to inadequate validation of user parameters. This flaw allows attackers to manipulate redirect URLs, potentially leading users to malicious domains without their knowledge. Such vulnerab...

PoC for CVE-2025-12394

WordPressBackup Migration5.9MEDIUM
Backup Migration Plugin Vulnerability in WordPress

The Backup Migration WordPress plugin suffers from a critical issue where it improperly generates the backup path under certain server configurations. This flaw permits unauthenticated users to access and download sensitive log files that disclose the backup filename. As a result, backup archives...

PoC for CVE-2024-14015

WordPressWordPress Ecommerce Pl...7.1HIGH
Reflected Cross-Site Scripting Vulnerability in WordPress eCommerce...

The WordPress eCommerce Plugin prior to version 2.9.0 is prone to a reflected cross-site scripting vulnerability due to improper sanitization and escaping of a user-supplied parameter. This flaw enables attackers to inject malicious scripts into web pages viewed by users, particularly affecting h...

Discovered 8 hours ago

PoC for CVE-2025-13585

Code-projectsCovid Tracking System6.9MEDIUM
SQL Injection Vulnerability in COVID Tracking System by Code-Projects

A security flaw has been identified in the COVID Tracking System 1.0 developed by Code-Projects, affecting the file /login.php. The vulnerability allows remote attackers to manipulate the 'code' parameter, resulting in SQL injection. This exploitation may lead to unauthorized access and potential...

PoC for CVE-2025-13584

EigenfocusEigenfocus5.1MEDIUM
Cross Site Scripting Vulnerability in Eigenfocus Software by Eigenf...

A security vulnerability has been identified in Eigenfocus software, specifically affecting versions up to 1.4.0. This issue arises from the improper handling of input in the Description Handler component, allowing malicious users to manipulate the 'entry.description' and 'time_entry.description'...

Discovered 9 hours ago

PoC for CVE-2025-13583

Code-projectsQuestion Paper Generator6.9MEDIUM
SQL Injection Vulnerability in code-projects Question Paper Generat...

A vulnerability exists in the code-projects Question Paper Generator 1.0 related to the POST Parameter Handler. Specifically, the file /signupscript.php is susceptible to SQL injection attacks when the argument Fname is manipulated. This vulnerability allows for remote attackers to execute unauth...

PoC for CVE-2025-13582

Code-projectsJonnys Liquor6.9MEDIUM
SQL Injection Vulnerability in Jonnys Liquor by Code-Projects

A security flaw has been identified in Jonnys Liquor 1.0 that allows for SQL injection through improper handling of GET parameters. Specifically, manipulating the 'Product' argument in the /detail.php file can lead to remote code execution vulnerabilities. This flaw poses a significant risk as it...

Discovered 10 hours ago

PoC for CVE-2025-13581

ItsourcecodeStudent Information Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Student Information Sys...

A vulnerability exists in the itsourcecode Student Information System 1.0 related to the manipulation of the 'schedule_id' parameter in the file /schedule_edit1.php. This flaw enables an attacker to execute SQL injection attacks, potentially compromising the database. The exploit can be conducted...

PoC for CVE-2025-13580

Code-projectsLibrary System5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Library System Mail Fu...

A vulnerability exists in the Code-Projects Library System 1.0, specifically in the mail.php file, where improper handling of the argument ID can lead to SQL injection attacks. This flaw allows attackers to manipulate SQL queries, potentially compromising sensitive data. The attack can be initiat...

Discovered 11 hours ago

PoC for CVE-2025-13579

Code-projectsLibrary System5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Library System

A vulnerability exists in Code-Projects Library System version 1.0, specifically in the /return.php file’s handling of the argument ID. This flaw allows attackers to manipulate SQL queries, leading to potential unauthorized data access and compromise. The SQL injection can be executed remotely, p...

PoC for CVE-2025-13578

Code-projectsLibrary System6.9MEDIUM
SQL Injection Vulnerability in code-projects Library System by code...

A security flaw exists in code-projects Library System version 1.0 that allows attackers to exploit the Login component via the /index.php file. Malicious manipulation of the Username argument can lead to SQL injection, which permits unauthorized access to the database. This vulnerability can be ...

Discovered 12 hours ago

PoC for CVE-2025-13576

Code-projectsBlog Site5.3MEDIUM
Improper Authorization Vulnerability in code-projects Blog Site 1.0

A vulnerability exists in code-projects Blog Site 1.0, specifically within a function in the /admin.php file, leading to improper authorization. This vulnerability allows attackers to manipulate requests for unauthenticated access to sensitive endpoints, potentially compromising the integrity and...

Discovered 13 hours ago

PoC for CVE-2025-13575

Code-projectsBlog Site5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Blog Site 1.0 by Code-...

A security issue has been identified in Code-Projects Blog Site 1.0, specifically within the Category Handler component. The vulnerability resides in the function 'category_exists' in the file '/resources/functions/blog.php'. An attacker can manipulate the argument name or field, leading to SQL i...

Discovered 15 hours ago

PoC for CVE-2025-24054

MicrosoftWindows 10 Version 1809🟣 EPSS 17%5.4MEDIUM
Spoofing Vulnerability in Windows NTLM by Microsoft

An external control of file name or path in Windows NTLM enables unauthorized attackers to exploit a vulnerability, leading to potential spoofing attacks over a network. This situation poses a significant threat as attackers may gain access to sensitive information or systems.

PoC for CVE-2025-13571

Code-projectsSimple Food Ordering S...5.3MEDIUM
SQL Injection Vulnerability in Simple Food Ordering System by Code-...

A vulnerability has been identified in the Simple Food Ordering System version 1.0, specifically within the functionality of the file /listorder.php. By manipulating the input argument ID, attackers can execute an SQL injection, potentially allowing them to compromise the database. The risk of th...

Discovered 16 hours ago

PoC for CVE-2025-13570

ItsourcecodeCovid Tracking System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode COVID Tracking System

A SQL injection vulnerability exists in the itsourcecode COVID Tracking System 1.0. The flaw arises from improper handling of user-supplied input in the /admin/?page=state file, particularly when manipulating the ID argument. This issue allows attackers to execute arbitrary SQL commands. Exploits...

PoC for CVE-2025-13569

ItsourcecodeCovid Tracking System5.3MEDIUM
SQL Injection in itsourcecode COVID Tracking System

A vulnerability exists in the itsourcecode COVID Tracking System 1.0 that allows for remote SQL injection through manipulation of the ID argument in the /admin/?page=city file. This weakness could be exploited by attackers to execute arbitrary SQL commands, potentially compromising the confidenti...

Discovered 17 hours ago

PoC for CVE-2025-13568

ItsourcecodeCovid Tracking System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode COVID Tracking System

A security flaw has been identified in the itsourcecode COVID Tracking System 1.0, specifically within an unspecified function of the /admin/?page=people endpoint. This vulnerability allows an attacker to manipulate the ID parameter, leading to a SQL injection. The issue can be exploited remotely...

PoC for CVE-2025-13567

ItsourcecodeCovid Tracking System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode COVID Tracking System

An SQL injection vulnerability has been identified in version 1.0 of the itsourcecode COVID Tracking System. The flaw resides in an undisclosed function located at /admin/?page=establishment, where improper handling of the input argument ID can be exploited. This vulnerability allows remote attac...

Discovered 18 hours ago

PoC for CVE-2025-13565

SourcecodesterInventory Management S...6.9MEDIUM
Weakness in SourceCodester Inventory Management System Password Rec...

A vulnerability has been identified in the SourceCodester Inventory Management System 1.0. This issue relates to an unknown function within the file /model/user/resetPassword.php, leading to a potential weakness in the password recovery process. Attackers may exploit this vulnerability remotely, ...

Discovered 19 hours ago

PoC for CVE-2025-13564

SourcecodesterPre-school Management ...5.3MEDIUM
Denial of Service Vulnerability in SourceCodester Pre-School Manage...

A security flaw has been identified in the SourceCodester Pre-School Management System 1.0, specifically within the 'removefile' function located in app/controllers/FilehelperController.php. This flaw allows attackers to manipulate the 'filepath' argument, potentially leading to a denial of servi...

PoC for CVE-2025-13562

D-linkDir-8526.9MEDIUM
Command Injection Vulnerability in D-Link DIR-852 Router

A command injection vulnerability exists in the D-Link DIR-852 1.00, specifically affecting the processing of the /gena.cgi file. This flaw allows attackers to manipulate the 'service' argument and execute arbitrary commands remotely. The exploit is publicly available, posing a significant threat...

Discovered 20 hours ago

PoC for CVE-2025-13561

SourcecodesterCompany Website Cms6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Company Website CMS

A security flaw exists in SourceCodester Company Website CMS 1.0 that allows for SQL injection via manipulation of the 'Username' argument in the /admin/index.php file. This vulnerability enables remote attackers to execute arbitrary SQL commands, potentially compromising sensitive data and leadi...

PoC for CVE-2025-13560

SourcecodesterCompany Website Cms6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Company Website CMS

An SQL injection vulnerability exists in SourceCodester Company Website CMS version 1.0, specifically within the reset-password.php file. This security flaw allows remote attackers to manipulate the email parameter, potentially leading to unauthorized access and data exposure. The exploit has bee...

Discovered 21 hours ago

PoC for CVE-2025-13557

CampcodesOnline Polling System6.9MEDIUM
SQL Injection Vulnerability in Campcodes Online Polling System

A security flaw has been identified in Campcodes Online Polling System version 1.0, specifically within the /registeracc.php file. The vulnerability arises from insufficient input validation on the email parameter, allowing attackers to execute arbitrary SQL code. This SQL injection vulnerability...

PoC for CVE-2025-13556

CampcodesOnline Polling System6.9MEDIUM
SQL Injection Vulnerability in Campcodes Online Polling System 1.0

A vulnerability has been identified in the Campcodes Online Polling System 1.0, specifically in the /admin/checklogin.php file. This flaw involves a manipulation of the 'myusername' argument, which can result in SQL injection. This type of attack can be executed remotely, making it a significant ...

Discovered 22 hours ago

PoC for CVE-2025-13555

CampcodesSchool File Management...6.9MEDIUM
SQL Injection Vulnerability in Campcodes School File Management Sys...

The Campcodes School File Management System 1.0 has a vulnerability in its login component found in the file /index.php. This issue arises from improper handling of the stud_no argument, allowing for SQL injection attacks. Attackers can manipulate input remotely, making the system susceptible to ...

PoC for CVE-2021-43267

LinuxLinux Kernel🟣 EPSS 73%9.8CRITICAL
Insufficient Validation in Linux Kernel TIPC Functionality

The Linux kernel's Transparent Inter-Process Communication (TIPC) functionality presents a security concern wherein remote attackers can exploit the system through insufficient validation of user-supplied sizes for the MSG_CRYPTO message type. This flaw could potentially allow unauthorized access...

PoC for CVE-2025-13554

CampcodesSupplier Management Sy...6.9MEDIUM
SQL Injection Vulnerability in Campcodes Supplier Management System

A security vulnerability has been identified in the Campcodes Supplier Management System (version 1.0). This flaw occurs within an unspecified function of the /index.php file related to the Login component. Attackers can exploit this vulnerability to manipulate the 'txtUsername' argument, which c...

Discovered 23 hours ago

PoC for CVE-2025-13553

D-linkDwr-m9208.7HIGH
Buffer Overflow Vulnerability in D-Link DWR-M920 Router

A vulnerability has been discovered in the D-Link DWR-M920 router, specifically in the function sub_41C7FC located in the /boafrm/formPinManageSetup file. This issue arises due to inadequate validation of the submit-url argument, leading to a potential buffer overflow condition. An attacker could...

Discovered 1 day ago

PoC for CVE-2025-13552

D-linkDir-822k8.7HIGH
Buffer Overflow Vulnerability in D-Link DIR-822K and DWR-M920 Routers

A security flaw has been identified in D-Link DIR-822K and DWR-M920 routers, specifically related to an unknown function in the /boafrm/formWlEncrypt file. The flaw arises when the argument submit-url is manipulated, leading to a buffer overflow condition. This vulnerability can be exploited remo...

PoC for CVE-2025-13551

D-linkDir-822k8.7HIGH
Buffer Overflow Vulnerability in D-Link DIR-822K and DWR-M920

A buffer overflow vulnerability has been discovered in the D-Link DIR-822K and DWR-M920 routers, specifically within the file /boafrm/formWanConfigSetup. This vulnerability can be exploited remotely by manipulating the submit-url argument, potentially allowing an unauthorized user to execute arbi...

PoC for CVE-2025-13550

D-linkDir-822k8.7HIGH
Buffer Overflow Vulnerability in D-Link DIR-822K and DWR-M920

A buffer overflow vulnerability has been identified in the D-Link DIR-822K and DWR-M920 routers, primarily affecting the submission of URLs via the /boafrm/formVpnConfigSetup interface. An attacker can exploit this vulnerability remotely by manipulating the 'submit-url' argument, potentially lead...

PoC for CVE-2025-13549

D-linkDir-822k8.7HIGH
Buffer Overflow in D-Link Router DIR-822K

A buffer overflow vulnerability exists in the D-Link DIR-822K router, specifically within the /boafrm/formNtp file. This flaw arises from improper handling of the 'submit-url' argument in the function 'sub_455524'. An attacker can exploit this weakness remotely, potentially leading to unauthorize...

PoC for CVE-2025-13548

D-linkDir-822k8.7HIGH
Buffer Overflow Vulnerability in D-Link DIR-822K and DWR-M920 Products

A significant buffer overflow vulnerability has been identified in D-Link DIR-822K and DWR-M920 devices. This vulnerability exists in the code handling the /boafrm/formFirewallAdv file, specifically related to an argument known as submit-url. Attackers can exploit this weakness remotely, potentia...

PoC for CVE-2025-13547

D-linkDir-822k8.7HIGH
Memory Corruption Vulnerability in D-Link Networking Products

A critical vulnerability has been identified in D-Link DIR-822K and DWR-M920 routers that can lead to memory corruption through an exploit in the /boafrm/formDdns component. The flaw is triggered by a manipulation of the submit-url argument, potentially allowing attackers to execute remote exploi...

PoC for CVE-2025-13546

Ashraf-kabirTravel-agency5.3MEDIUM
SQL Injection Vulnerability in Travel-Agency Web Application by Ash...

A vulnerability exists in the ashraf-kabir travel-agency web application, specifically within the /results.php file associated with the Search component. The flaw arises from improper handling of the 'user_query' parameter, allowing for SQL injection attacks. This vulnerability enables attackers ...

PoC for CVE-2025-13545

Ashraf-kabirTravel-agency5.1MEDIUM
SQL Injection Vulnerability in Ashraf-Kabir Travel Agency Product

A significant vulnerability has been identified in the Ashraf-Kabir Travel Agency product that could expose users to potential SQL injection attacks. This vulnerability is linked to the manipulation of the 'edit_pack' argument in the '/admin_area/index.php' file, enabling remote attackers to exec...

PoC for CVE-2025-13544

Ashraf-kabirTravel-agency5.3MEDIUM
Unrestricted File Upload Vulnerability in ashraf-kabir Travel Agenc...

A vulnerability has been discovered in the ashraf-kabir travel-agency software that allows for unrestricted file uploads through the /customer_register.php script. Malicious actors can exploit this weakness to upload unauthorized files remotely, potentially compromising the integrity and confiden...

Discovered 2 days ago

PoC for CVE-2025-11001

7-zip7-zip7HIGH
Directory Traversal Vulnerability in 7-Zip by 7-Zip Team

A directory traversal vulnerability exists in 7-Zip, allowing remote attackers to execute arbitrary code by exploiting symbolic link handling in ZIP files. By crafting specific data within ZIP files, hackers can manipulate the application to navigate to unintended directories. Successfully levera...

PoC for CVE-2023-22515

AtlassianConfluence Data Center🟣 EPSS 94%9.8CRITICAL
Unknown Vulnerability Affects Confluence instances, External Attack...

Atlassian has identified a vulnerability in its Confluence Data Center and Server products that allows external attackers to create unauthorized administrator accounts. This issue could enable malicious actors to gain unrestricted access to Confluence instances that are publicly accessible. It is...

PoC for CVE-2025-64459

DjangoprojectDjango9.1CRITICAL
SQL Injection Vulnerability in Django Software by Django

An SQL injection vulnerability exists in specific versions of Django prior to 5.1.14, 4.2.26, and 5.2.8. Through the use of specially crafted dictionaries, attackers can exploit the `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()` methods, as well as the `Q()` class, when utilizing...

PoC for CVE-2025-53770

MicrosoftMicrosoft Sharepoint E...🟣 EPSS 88%9.8CRITICAL
Deserialization Vulnerability in Microsoft SharePoint Server

A deserialization vulnerability in on-premises Microsoft SharePoint Server can be exploited by unauthorized attackers, allowing them to execute arbitrary code over a network. Microsoft is aware of exploits being used in the wild and is actively working on a comprehensive update to address this se...

PoC for CVE-2024-31317

GoogleAndroid7.8HIGH
Unpatched Deserialization Vulnerability in ZygoteProcess.java Could...

A vulnerability has been identified in the Android Framework that allows potential code execution through unsafe deserialization in multiple functions of ZygoteProcess.java. This flaw enables local privilege escalation, requiring user execution privileges but eliminating the need for user interac...

Discovered 3 days ago

PoC for CVE-2025-41115

GrafanaGrafana Enterprise10CRITICAL
User Identity Handling Vulnerability in Grafana Enterprise and Cloud

A security flaw in Grafana versions 12.x with SCIM provisioning enabled could allow malicious clients to provision users with numeric external IDs. If certain conditions are met, including the `enableSCIM` flag being true and the user sync option configured, this could lead to internal user ID ov...

PoC for CVE-2025-61757

OracleIdentity Manager🟣 EPSS 71%9.8CRITICAL
Unauthorized Access in Oracle Fusion Middleware's Identity Manager

This vulnerability in Oracle Fusion Middleware's Identity Manager could allow an unauthenticated attacker with network access through HTTP to exploit the system. By leveraging this flaw, attackers may gain the capability to take control of the Identity Manager, posing serious risks to the integri...

PoC for CVE-2025-11127

WordPressMstoreapp Mobile App9.8CRITICAL
Vulnerability in Mstoreapp Mobile App by Mstoreapp Allows Unauthent...

The Mstoreapp Mobile App and Mstoreapp Mobile Multivendor plugins have a critical security flaw that fails to properly verify user identities during AJAX actions. This vulnerability enables unauthenticated individuals to gain access to valid user sessions simply by providing a known email address...