Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2026-17459

PerwendelSpark5.3MEDIUM
Symlink Following Vulnerability in SparkJava by perwendel

A vulnerability identified in the SparkJava framework up to version 2.9.4 relates to the `staticFiles.externalLocation` function. This issue allows an attacker to exploit the symlink following behavior within the `ExternalResourceHandler` component. The flaw can be exploited remotely, posing a si...

Discovered 3 hours ago

PoC for CVE-2026-17458

Mf-yangOpenclaw-cn5.3MEDIUM
Server-Side Request Forgery Vulnerability in mf-yang's Openclaw-CN ...

A vulnerability exists in the mf-yang Openclaw-CN application, specifically within the Browser Control HTTP API. The flaw, located in the clickViaPlaywright function of the agent.act.ts file, allows attackers to carry out server-side request forgery (SSRF) attacks. This means that by manipulating...

PoC for CVE-2026-17457

Mf-yangOpenclaw-cn5.3MEDIUM
Information Disclosure Vulnerability in mf-yang's Openclaw-cn Software

A security vulnerability exists in the mf-yang openclaw-cn software, specifically in the function assertBrowserNavigationAllowed within the Scheme Handler component. This flaw can potentially lead to information disclosure when the argument 'url' is manipulated. The issue can be exploited remotel...

Discovered 10 hours ago

PoC for CVE-2026-17434

NanocoaiNanoclaw5.3MEDIUM
Improper Authorization in NanoClaw by nanocoai

A flaw in the function handleAddMcpServer of NanoClaw, specifically in the file src/modules/self-mod/request.ts, allows for improper authorization. This vulnerability enables attackers to potentially manipulate access controls, leading to unauthorized actions. The vulnerability is remotely exploi...

PoC for CVE-2026-17433

NanocoaiNanoclaw4.8MEDIUM
Improper Authorization in NanoClaw by Nanocoai

A vulnerability exists in the NanoClaw product by Nanocoai, specifically impacting the `createChatSdkBridge.setup` function within the `src/channels/chat-sdk-bridge.ts` file of the MCP Server Approval component. This flaw allows for unauthorized actions due to improper access control measures, ma...

Discovered 11 hours ago

PoC for CVE-2026-32194

MicrosoftMicrosoft Bing Images9.8CRITICAL
Command Injection Vulnerability in Microsoft Bing Images

A command injection vulnerability exists in Microsoft Bing Images that allows unauthorized attackers to execute arbitrary code over a network. This weakness arises from improper handling of special elements in commands, potentially exposing sensitive data or system integrity to exploitation. User...

PoC for CVE-2026-54121

MicrosoftWindows 10 Version 16078.8HIGH
Elevation of Privilege Vulnerability in Microsoft Active Directory ...

A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...

Discovered 12 hours ago

PoC for CVE-2026-17432

NousresearchHermes-agent2.3LOW
Access Control Vulnerability in NousResearch hermes-agent SimpleX G...

A security issue has been identified in NousResearch's hermes-agent, specifically within the SimpleX Gateway Authorization component. The vulnerability arises from the improper handling of the contactId argument in the file hermes-agent/plugins/platforms/simplex/adapter.py. This flaw may allow un...

PoC for CVE-2026-60206

OracleOracle Weblogic Server9.9CRITICAL
SAML Exploitation Vulnerability in Oracle WebLogic Server by Oracle

A vulnerability in Oracle WebLogic Server's Core component permits low-privileged attackers with network access to exploit SAML, potentially compromising the server's functionality. This can lead to unauthorized access, impacting not only the WebLogic Server but also additional interconnected pro...

Discovered 13 hours ago

PoC for CVE-2026-16723

AlibabaFastjson9CRITICAL
Remote Code Execution Vulnerability in fastjson by Alibaba

A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...

Discovered 16 hours ago

PoC for CVE-2026-65694

MicroweberMicroweber8.7HIGH
Path Traversal Vulnerability in Microweber CMS by Microweber

Microweber CMS, up to version 2.0.20, has a significant path traversal flaw in its static file controller. This vulnerability allows remote, unauthenticated attackers to exploit the failure of the normalize_path() function. By supplying specially crafted directory traversal sequences in the path ...

Discovered 19 hours ago

PoC for CVE-2026-54900

Ohler55Oj6.3MEDIUM
Heap Corruption Vulnerability in Oj Ruby Gem by Ohler55

The Oj Ruby gem, a JSON parser and object marshaller, is susceptible to a heap corruption issue when using create_id enabled with JSON object keys of exactly 65,535 bytes. This flaw arises from an integer truncation during the parsing process, leading to a negative-size argument being passed to t...

PoC for CVE-2026-50522

MicrosoftMicrosoft Sharepoint E...🟣 EPSS 57%9.8CRITICAL
Deserialization Vulnerability in Microsoft SharePoint by Microsoft

The vulnerability allows an attacker to send specially crafted payloads to Microsoft Office SharePoint, potentially resulting in unauthorized remote code execution. This security flaw occurs due to the improper handling of untrusted data. If exploited, it could enable malicious actors to execute ...

Discovered 20 hours ago

PoC for CVE-2020-5148

SonicwallDirectory Services Con...8.2HIGH
Credential Exposure in SonicWall's Single Sign-On Agent

The SonicWall Single Sign-On (SSO) Agent is found to have a vulnerability due to its default configuration, which utilizes NetAPI to probe associated IP addresses within a network. This probing method can be exploited by an attacker to capture the password hash of users with privileged access. Co...

PoC for CVE-2021-3262

TrisparkNovusedu9.8CRITICAL
SQL Injection Vulnerability in TripSpark VEO Transportation by Trip...

The TripSpark VEO Transportation and NovusEDU products are vulnerable due to improper handling of user inputs in POST body parameters. This allows malicious users to inject arbitrary SQL commands into the 'Student Busing Information' search queries. The lack of sanitization on server-side logic m...

PoC for CVE-2021-26837

FortraDelivernow9.8CRITICAL
SQL Injection Vulnerability in Fortra DeliverNow Software

An SQL Injection vulnerability exists in the SearchTextBox parameter of Fortra's DeliverNow software versions prior to 1.2.18. This flaw allows attackers to manipulate SQL queries, potentially enabling them to execute arbitrary code, escalate user privileges, and access sensitive information stor...

PoC for CVE-2026-12960

AsusRouter App6MEDIUM
Improper Export Vulnerability in ASUS Router App

The ASUS Router App contains a vulnerability that allows a malicious third-party application on the same device to initiate a crafted Intent. This can lead to the ASUS Router App opening a specified URL without proper validation, potentially compromising user privacy and security. For more detail...

Discovered 22 hours ago

PoC for CVE-2026-61946

WordPressEasy Appointments6.5MEDIUM
Insecure Direct Object Reference Vulnerability in Easy Appointments...

An unauthenticated Insecure Direct Object Reference (IDOR) vulnerability exists in the Easy Appointments plugin, affecting versions up to 3.12.27. This vulnerability allows attackers to access and manipulate sensitive data without proper authentication, potentially leading to unauthorized access ...

Discovered 1 day ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-9198

IBMLangflow Oss9.8CRITICAL
Remote Code Execution Vulnerability in IBM Langflow OSS by IBM

The vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0 allows unauthenticated attackers to chain two API endpoints. This exploitation can occur via the /api/v1/auto_login endpoint, which generates SUPERUSER tokens for any caller, in conjunction with the /api/v1/validate/code endpoint...

Discovered 2 days ago

PoC for CVE-2024-22019

NodejsNode7.5HIGH
Node.js HTTP Servers Vulnerable to Resource Exhaustion Attacks

A vulnerability exists within Node.js HTTP servers that permits attackers to send specially crafted HTTP requests utilizing chunked encoding. This manipulation can lead to resource exhaustion, as the server is induced to read an unbounded number of bytes from a single connection. The flaw takes a...

PoC for CVE-2025-71408

NtlkNtlk8.5HIGH
Eval Injection Vulnerability in NLTK Natural Language Toolkit

The Natural Language Toolkit (NLTK) version 3.9.3 and earlier are susceptible to an eval injection vulnerability within the nltk.collocations module. This security flaw arises when command-line arguments are directly passed to the eval() function in the __main__ block of collocations.py, lacking ...

PoC for CVE-2026-7228

SourcecodesterPizzafy Ecommerce System6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pizzafy Ecommerce System

A vulnerability exists in the Pizzafy Ecommerce System 1.0, specifically within the get_cart_count function located in the /admin/ajax.php file. This flaw allows attackers to manipulate the ID argument, enabling them to execute SQL injection attacks remotely. Exploiting this vulnerability could l...

PoC for CVE-2026-65711

NuxsminSyspass8.6HIGH
OS Command Injection Vulnerability in sysPass by sysPass

The sysPass application, specifically version 3.2.11, is susceptible to an OS command injection flaw. This vulnerability allows authenticated administrators to exploit the backup functionality by maliciously altering the backup path. When the FileBackupService concatenates this input to construct...

PoC for CVE-2026-65710

NuxsminSyspass7.1HIGH
Missing Authorization Vulnerability in sysPass by Caycon

The vulnerability in sysPass version 3.2.11 arises from insufficient authorization checks during public link creation, enabling users with the PUBLICLINK_CREATE profile flag to exploit this flaw. An attacker can trigger unauthorized decryption of vault account passwords by invoking the saveCreate...

PoC for CVE-2026-65709

NuxsminSyspass8.7HIGH
Missing Object-Level Authorization in sysPass JSON-RPC API

The sysPass version 3.2.11 vulnerability arises from a missing object-level authorization in its JSON-RPC API. This flaw permits API token holders to improperly enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without necessary per-account access contro...

PoC for CVE-2026-65708

NuxsminSyspass8.6HIGH
Insecure Direct Object Reference Vulnerability in sysPass by Caycon

The sysPass application version 3.2.11 has a vulnerability that enables authenticated users to exploit insecure direct object references. By manipulating file IDs through various actions such as download, view, delete, upload, and list, attackers can gain unauthorized access to account file attac...

PoC for CVE-2026-65707

Likeadmin-likeshopLikeshop8.5HIGH
Authenticated SQL Injection in Likeshop Product by Likeshop

Likeshop versions up to 3.0.5 are susceptible to an authenticated SQL injection vulnerability that allows admin users to extract arbitrary data from the database. The flaw occurs in the adjustAccount endpoint, where unsanitized POST parameters are processed without proper validation or parameter ...

PoC for CVE-2026-65693

MicroweberMicroweber8.6HIGH
Server-Side Template Injection Vulnerability in Microweber CMS

Microweber CMS up to version 2.0.20 contains a vulnerability allowing authenticated administrators to execute arbitrary operating system commands. This occurs through the injection of Twig expressions into unsanitized mail templates. Due to the absence of necessary security mechanisms like Sandbo...

PoC for CVE-2026-66027

Kortix-aiSuna8.7HIGH
Broken Access Control in Suna Messaging API by Kortix AI

The Suna messaging API in versions prior to 0.9.102 is susceptible to a broken access control vulnerability, enabling authenticated attackers to exploit inadequate isolation measures. Attackers can gain unauthorized access to message queues belonging to other users, which allows them to read pend...

PoC for CVE-2026-66007

HuggingfaceDatasets6.9MEDIUM
Path Traversal Vulnerability in Hugging Face Datasets Product

The vulnerability in Hugging Face Datasets allows attackers to exploit the file_name metadata field in folder-based dataset builders. Due to inadequate validation, an attacker can input crafted values that include directory traversal sequences. As a result, this could lead to unauthorized access ...

PoC for CVE-2026-66006

TreeverseLakefs6.9MEDIUM
Authentication Bypass Vulnerability in lakeFS by Treeverse

The lakeFS product by Treeverse contains an authentication bypass vulnerability located at the /setup_comm_prefs endpoint. This flaw allows unauthenticated attackers to overwrite critical operator metadata, including sensitive information like email, name, and company details, after the setup pha...

PoC for CVE-2026-66005

JanhqJan5.3MEDIUM
CORS Misconfiguration in Jan API Server Affects Local Network Security

The Jan API Server possesses a CORS misconfiguration that allows network-adjacent attackers to bypass trusted host restrictions via a flaw in the server’s handling of user-configured trusted hosts. This issue enables attackers to manipulate the server, replacing user-defined trusted hosts with a ...

PoC for CVE-2026-66004

AhujasidBlender-mcp6MEDIUM
Path Traversal Vulnerability in BlenderMCP Affects File Security

BlenderMCP prior to commit 30a3308 features a path traversal vulnerability within the download_polyhaven_asset method. This flaw enables attackers to write arbitrary files by injecting harmful traversal sequences into API response keys. If an attacker successfully executes a MITM (Man-In-The-Midd...

PoC for CVE-2026-60206

OracleOracle Weblogic Server9.9CRITICAL
SAML Exploitation Vulnerability in Oracle WebLogic Server by Oracle

A vulnerability in Oracle WebLogic Server's Core component permits low-privileged attackers with network access to exploit SAML, potentially compromising the server's functionality. This can lead to unauthorized access, impacting not only the WebLogic Server but also additional interconnected pro...

PoC for CVE-2026-14603

WordPressWowoptin: Next-gen Pop...7.5HIGH
Unauthorized Access Flaw in WowOptin Popup Plugin for WordPress

The WowOptin: Next-Gen Popup Maker plugin for WordPress, prior to version 1.4.38, is vulnerable due to insufficient authorization checks on a REST endpoint. This flaw allows unauthenticated users to disable all opt-in forms across the site and to inject new template-based opt-in entries into the ...

PoC for CVE-2026-12877

WordPressProject Management, Bu...9.1CRITICAL
SQL Injection Vulnerability in Project Management WordPress Plugin

The Project Management, Bug and Issue Tracking Plugin for WordPress, prior to version 5.1.0, is susceptible to SQL injection due to inadequate sanitization and escaping of user-supplied input in SQL queries. This vulnerability allows unauthenticated attackers to manipulate database queries, poten...

PoC for CVE-2026-12981

WordPressCafehaus Api7.5HIGH
Authentication Bypass in CAFEHAUS API Plugin for WordPress

The CAFEHAUS API WordPress plugin prior to version 1.0.0 is vulnerable to an authentication bypass issue that permits attackers to reset user passwords without any form of authentication or authorization. This flaw enables attackers to gain unauthorized access to any user's account, including tho...

PoC for CVE-2026-12690

WordPressProfilegrid3.8LOW
Insufficient License Management in ProfileGrid Plugin for WordPress

The ProfileGrid plugin for WordPress contains a vulnerability related to its license management functionality. This flaw arises from the absence of a proper capability check, as it solely relies on a nonce that is accessible to any logged-in user. Consequently, this allows authenticated users wit...

PoC for CVE-2026-12497

WordPressPaid Membership Plugin...7.5HIGH
Improper Role Restriction in Paid Membership Plugin for WordPress

The Paid Membership Plugin for WordPress prior to version 4.16.18 fails to consistently enforce role restrictions in its front-end registration process. This vulnerability arises because the role options presented to users and the roles accepted by the registration handler are evaluated by differ...

PoC for CVE-2026-12688

WordPressProfilegrid6.5MEDIUM
Improper Input Validation in ProfileGrid WordPress Plugin Allows Fo...

The ProfileGrid WordPress plugin prior to version 5.9.9.7 is susceptible to an improper input validation vulnerability. This flaw allows unauthenticated attackers to exploit the plugin's handling of PayPal Instant Payment Notification (IPN) messages. By forging a valid PayPal notification, an att...

PoC for CVE-2026-12689

WordPressProfilegrid5.4MEDIUM
Authorization Flaw in ProfileGrid WordPress Plugin by ProfileGrid

The ProfileGrid WordPress plugin prior to version 5.9.9.7 contains a significant authorization flaw that enables authenticated users with Subscriber-level access and higher to interact maliciously with others' private-message threads. This includes the ability to soft-delete threads, alter metada...

PoC for CVE-2026-45585

MicrosoftWindows 11 Version 24h26.8MEDIUM
Security Feature Bypass in Windows by Microsoft

A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...

PoC for CVE-2011-2523

VsftpdVsftpd🟣 EPSS 96%9.8CRITICAL
Backdoor Vulnerability in vsftpd 2.3.4 by Academy of Linux

A serious backdoor vulnerability was discovered in vsftpd 2.3.4, affecting downloads made between June 30 and July 3, 2011. This vulnerability allows an attacker to exploit the software and open a remote shell on port 6200/tcp, granting unauthorized access to the system. It poses significant risk...

PoC for CVE-2026-54121

MicrosoftWindows 10 Version 16078.8HIGH
Elevation of Privilege Vulnerability in Microsoft Active Directory ...

A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...

PoC for CVE-2026-59880

Immutable-jsImmutable-js8.7HIGH
Denial of Service in Immutable.js Affecting Data Structures

Immutable.js exhibits a vulnerability in its data structures, specifically in Immutable.Map and Immutable.Set. Prior to versions 4.3.9 and 5.1.8, these structures use a linear search method in a HashCollisionNode bucket containing keys with the same 32-bit hash. An attacker controlling the input ...

PoC for CVE-2026-58057

FlowiseFlowise2.3LOW
Custom MCP Environment Variable Bypass in Flowise by FlowiseAI

Flowise versions prior to 3.1.3 suffer from a vulnerability due to improper validation of Custom MCP standard input/output environment variables against a denylist. The case-sensitive nature of the comparison allows an authenticated user to exploit this flaw on Windows systems where environment v...

PoC for CVE-2020-1472

MicrosoftWindows Server Version...🟣 EPSS 100%5.5MEDIUM
Netlogon Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a...

Discovered 3 days ago

PoC for CVE-2026-16767

Ne-lexaPHP-zip6.9MEDIUM
Path Traversal Vulnerability in Ne-Lexa php-zip ZIP Handler

A vulnerability has been identified in Ne-Lexa's php-zip library versions up to 4.0.2. It occurs within the ZipFile::extractTo function located in src/ZipFile.php, where inadequate validation of the entryName argument allows for malicious path traversal attacks. This vulnerability can be exploite...