Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2026-78250

Bytebot-aiBytebot5.3MEDIUM
Infinite Loop Vulnerability in Bytebot by Bytebot AI

A vulnerability exists in Bytebot AI's Bytebot 0.0.1, specifically within the Agent Execution Workflow component. This issue allows an attacker to execute a remote exploit that induces an infinite loop, causing server unresponsiveness. The vulnerability primarily affects versions that are no long...

PoC for CVE-2026-78248

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A SQL injection vulnerability exists in the SourceCodester Simple Online Food Ordering System version 1.0 within the file /fos/admin/ajax.php when the 'Name' argument is manipulated. This flaw allows remote attackers to execute arbitrary SQL commands, potentially compromising the integrity and se...

PoC for CVE-2026-78247

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A security vulnerability has been identified in the Simple Online Food Ordering System version 1.0 by SourceCodester. This flaw is located in the /fos/admin/ajax.php file, specifically in the confirm_order action. By manipulating the ID parameter, an attacker can execute SQL injection, potentiall...

Discovered 3 hours ago

PoC for CVE-2026-78246

ItsourcecodeOnline Clinic Manageme...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Clinic Managemen...

A SQL injection vulnerability has been identified in version 1.0 of the itsourcecode Online Clinic Management System, specifically within the Admin Login feature's login.php file. By manipulating the Username parameter, an attacker could exploit this flaw to execute arbitrary SQL commands remotel...

Discovered 4 hours ago

PoC for CVE-2026-78245

ItsourcecodeOnline Pharmacy System6.9MEDIUM
Unrestricted File Upload Vulnerability in itsourcecode Online Pharm...

A vulnerability exists in itsourcecode Online Pharmacy System 1.0 due to an improper handling of file uploads in the User Registration component. Specifically, the flaw lies within the 'move_uploaded_file' function in 'all_users/register.php', where manipulation of the 'photo' argument enables un...

PoC for CVE-2026-78244

ItsourcecodeReal Estate Management...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Real Estate Management ...

A SQL injection vulnerability exists in the search.php file of the itsourcecode Real Estate Management System 1.0. This flaw allows attackers to manipulate parameters such as search/delivery_type/search_price/property_type, potentially leading to unauthorized access to the database. The exploit c...

Discovered 9 hours ago

PoC for CVE-2026-78202

ItsourcecodePayroll System6.9MEDIUM
Unrestricted Upload Vulnerability in itsourcecode Payroll System 1.0

A significant vulnerability has been discovered in the itsourcecode Payroll System 1.0, specifically within the save_settings function of the admin_class.php file. This weakness allows attackers to manipulate the 'img' argument, which results in an unrestricted upload capability. The vulnerabilit...

PoC for CVE-2026-78201

ItsourcecodePayroll System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Payroll System Login Fu...

A SQL injection vulnerability exists in the login function of the admin_class.php file within itsourcecode Payroll System 1.0, allowing attackers to manipulate the Username argument. This manipulation can be executed remotely, posing significant risks to data integrity and system security. The vu...

PoC for CVE-2026-78200

ItsourcecodeLibrary Management System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Library Management System

A significant security flaw exists in the itsourcecode Library Management System version 1.0, specifically within an unidentified function in the editbooks.php file. This issue allows an attacker to manipulate the argument ID for SQL injection attacks, which can be executed remotely. Given the ex...

PoC for CVE-2026-78199

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A significant SQL injection vulnerability has been identified in the SourceCodester Simple Online Food Ordering System, specifically affecting the view_prod.php file. This vulnerability occurs due to improper handling of the ID argument, allowing attackers to manipulate SQL queries and potentiall...

Discovered 10 hours ago

PoC for CVE-2026-78198

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in Simple Online Food Ordering System b...

A security vulnerability has been identified in the Simple Online Food Ordering System developed by SourceCodester, specifically relating to the processing of the file /fos/admin/ajax.php with the action parameter set to add_to_cart. Unsanitized input for the 'pid' argument can lead to SQL inject...

PoC for CVE-2026-78197

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A SQL injection vulnerability exists in the SourceCodester Simple Online Food Ordering System found in the /fos/admin/ajax.php file's save_user action. By manipulating the Username parameter, an attacker can execute arbitrary SQL queries on the database. This vulnerability can be exploited remote...

PoC for CVE-2026-78187

PiwigoPiwigo2.3LOW
Cross Site Scripting Vulnerability in Piwigo Public Authentication ...

A vulnerability has been identified in Piwigo 16.3.0 that affects the Public Authentication Page component, allowing attackers to exploit an unknown function via manipulation of the lang parameter. This can lead to cross site scripting (XSS), where malicious scripts can be executed in the user's ...

Discovered 11 hours ago

PoC for CVE-2026-78186

Open5GSOpen5gs5.3MEDIUM
Remote Vulnerability in Open5GS HSS Component Affecting User-Name A...

A vulnerability has been identified in Open5GS within the HSS component, specifically in the src/hss/hss-cx-path.c file. This issue allows for a manipulation of the User-Name argument, leading to a reachable assertion that can be exploited remotely. The vulnerability could allow attackers to exec...

PoC for CVE-2026-78185

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory Sys...

An SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0 due to improper handling of input in the /pages/cust_edit.php file. By manipulating the ID argument, an attacker can execute remote commands, potentially leading to unauthorized access to the database...

PoC for CVE-2026-78182

Shenzhen Gongji T...Xbrother Dynamic Envir...6.9MEDIUM
SQL Injection Vulnerability in Shenzhen Gongji Technology XBROTHER ...

A security flaw has been discovered in the function PlanController.getImmediatePlans of the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System, specifically affecting versions up to 300R004C00B300. This vulnerability allows an attacker to manipulate the order and sort of ar...

PoC for CVE-2026-78181

RactivejsRactive6.9MEDIUM
Prototype Pollution Vulnerability in Ractive.js by Ractive

A vulnerability exists in Ractive.js, affecting version 1.4.4 and earlier, specifically in the Keypath Handler's Ractive#set function. This weakness allows attackers to manipulate object prototype attributes, potentially leading to unauthorized modifications. The vulnerability can be exploited re...

Discovered 12 hours ago

PoC for CVE-2020-5504

PHPmyadminPHPmyadmin🟣 EPSS 39%8.8HIGH
SQL Injection Vulnerability in phpMyAdmin by phpMyAdmin Project

In versions prior to 4.9.4 for phpMyAdmin 4 and 5.0.1 for phpMyAdmin 5, an SQL injection vulnerability exists on the user accounts page. This flaw allows an attacker with a valid MySQL account to inject malicious SQL statements by altering their username input when querying the user accounts. Suc...

PoC for CVE-2026-78177

TanstackDevtools-vite2LOW
OS Command Injection in TanStack Development Devtools for Vite

A vulnerability exists in TanStack's devtools-vite, specifically in version 0.7.0, where the 'installPackage' function of the Development Devtools Event Bus component is susceptible to OS command injection. This occurs through improper handling of the 'packageName' argument, allowing an attacker ...

Discovered 13 hours ago

PoC for CVE-2026-78171

ItsourcecodeSales And Inventory Sy...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory Sys...

A vulnerability exists in the itsourcecode Sales and Inventory System 1.0, specifically within the file /pages/processlogin.php. This security issue allows for SQL injection through manipulation of the 'User' argument, enabling a remote attacker to exploit the system. As the exploit has been publ...

PoC for CVE-2026-78170

UttHiper 1200gw8.7HIGH
Buffer Overflow Vulnerability in UTT HiPER 1200GW Router

A significant vulnerability has been identified in the UTT HiPER 1200GW router, specifically within the strcpy function in the /goform/formConfigFastDirectionW file. The flaw allows an attacker to execute arbitrary manipulation of the 'ssid' argument, potentially leading to a buffer overflow cond...

PoC for CVE-2026-78169

UttHiper 1250gw9.4CRITICAL
Stack-Based Buffer Overflow in UTT HiPER 1250GW HTTP Request Handler

A vulnerability exists in the UTT HiPER 1250GW that affects its HTTP Request Handler, specifically in the function 'strcpy' utilized within the file '/goform/aspRemoteApConfTempSend'. An attacker can exploit a manipulation of the 'Profile' argument leading to a stack-based buffer overflow. This v...

PoC for CVE-2026-78168

EfmIptime T24000m9.3CRITICAL
Improper Authentication in EFM ipTIME T24000M Devices

A vulnerability in the EFM ipTIME T24000M model compromises the function responsible for checking session URLs, leading to improper authentication. This flaw can be exploited remotely, posing a significant risk as it allows potential attackers to manipulate the authentication process without prop...

Discovered 14 hours ago

PoC for CVE-2026-78167

EfmIptime T16000m10CRITICAL
Improper Authentication Flaw in EFM ipTIME T16000M Router

A significant weakness has been identified in the EFM ipTIME T16000M router due to a flaw in the session validation handler, specifically in the function httpcon_check_session_url. This vulnerability allows attackers to exploit the device remotely, leading to improper authentication and potential...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-15718

MozillaFirefox4.3MEDIUM
Remote Code Execution Vulnerability in Mozilla Firefox

A security flaw in Mozilla Firefox allows for potential remote code execution exploits. Although the exploit code for this vulnerability is publicly available, there have been no confirmed instances of its exploitation in the wild. Users are advised to upgrade to Firefox version 152.0.6 or later ...

PoC for CVE-2026-78166

ProvectusKafka-ui5.3MEDIUM
Code Injection Vulnerability in Provectus Kafka-UI by Provectus

A security flaw exists in the Apache Kafka user interface provided by Provectus, specifically in the executeSmartFilterTest function within the Groovy Code Handler. This vulnerability permits an attacker to inject malicious code remotely, leading to potential unauthorized access and manipulation ...

PoC for CVE-2026-78161

WarmcatLibwebsockets6.9MEDIUM
Out-of-Bounds Write Vulnerability in warmcat libwebsockets Product

A vulnerability exists in warmcat libwebsockets 4.5.0 within the report_raw_cbor function located in lib/misc/lecp.c, leading to the possibility of an out-of-bounds write. This issue allows for remote exploitation, which could potentially compromise the integrity and security of systems using thi...

PoC for CVE-2026-78161

WarmcatLibwebsockets6.9MEDIUM
Out-of-Bounds Write Vulnerability in warmcat libwebsockets Product

A vulnerability exists in warmcat libwebsockets 4.5.0 within the report_raw_cbor function located in lib/misc/lecp.c, leading to the possibility of an out-of-bounds write. This issue allows for remote exploitation, which could potentially compromise the integrity and security of systems using thi...

PoC for CVE-2026-10053

GitlabGitlab8.5HIGH
Path Traversal Vulnerability in GitLab CE/EE Products

GitLab has addressed a critical path traversal vulnerability present in GitLab CE/EE across multiple versions. Under certain conditions, this flaw could enable an authenticated user to execute arbitrary code remotely via the package registry. This vulnerability highlights the importance of timely...

Discovered 15 hours ago

PoC for CVE-2026-66917

Joomgalleryfriend...Joomgallery Extension ...8.6HIGH
Stored XSS in JoomGallery by Joomla Extensions Vendor

The JoomGallery extension for Joomla is susceptible to a stored cross-site scripting (XSS) vulnerability. This flaw allows authenticated users with the appropriate privileges to embed malicious JavaScript into uploaded images. When other users visit the affected page, the injected script executes...

PoC for CVE-2026-66916

Joomgalleryfriend...Joomgallery Extension ...6.9MEDIUM
Unauthenticated Access Control Bypass in JoomGallery by Joomla Exte...

An unauthenticated access control bypass vulnerability exists in the JoomGallery extension for Joomla. When a gallery category is secured with a password, the standard HTML view successfully enforces this password requirement. However, the JSON view does not enforce the same checking protocols, a...

Discovered 16 hours ago

PoC for CVE-2026-78145

CTFd Development ...Ctfd5.3MEDIUM
Open Redirect Vulnerability in CTFd by CTFd Development Team

A security flaw has been identified in CTFd versions up to 3.8.4, specifically within the _is_safe_url function located in CTFd/utils/validators/__init__.py. This vulnerability allows an attacker to manipulate the 'Next' parameter, leading to an open redirect issue. Exploitation can be performed ...

PoC for CVE-2026-78144

Code-projectsBarangay Resident Prof...5.3MEDIUM
Authorization Bypass Vulnerability in Barangay Resident Profiling M...

An authorization bypass vulnerability exists in the Barangay Resident Profiling Management System 1.0, specifically within the boarders.php file of the Boarder Management Module. This flaw allows attackers to manipulate the argument ID, leading to unauthorized actions. The vulnerability can be ex...

Discovered 17 hours ago

PoC for CVE-2026-78143

Code-projectsBarangay Resident Prof...6.9MEDIUM
SQL Injection Vulnerability in Barangay Resident Profiling Manageme...

A security vulnerability exists within the Barangay Resident Profiling Management System 1.0, specifically in the residents.php file associated with its Resident Search functionality. This flaw enables attackers to manipulate search arguments, leading to potential SQL injection attacks. Such expl...

PoC for CVE-2026-78142

Code-projectsBarangay Resident Prof...5.3MEDIUM
Authorization Bypass Vulnerability in Barangay Resident Profiling M...

A vulnerability exists in the Barangay Resident Profiling Management System, specifically affecting the Restore/Delete component located in the archived_records.php file. This issue arises due to improper handling of the resident_id parameter, allowing for an authorization bypass. The flaw can be...

PoC for CVE-2026-78141

TendaCh225.3MEDIUM
Command Injection Vulnerability in Tenda CH22 Router

A command injection vulnerability exists in the Tenda CH22 router version 1.0.0.1 within the formexeCommand function found in the /goform/exeCommand file. This vulnerability allows attackers to manipulate input arguments, specifically 'cmdinput', potentially enabling them to execute arbitrary com...

Discovered 19 hours ago

PoC for CVE-2024-9264

GrafanaGrafana🟣 EPSS 95%9.4CRITICAL
Grafana SQL Expressions Vulnerability: Command Injection and Local ...

The experimental SQL Expressions feature in Grafana enables users to evaluate `duckdb` queries which can contain user input. However, the queries are inadequately sanitized prior to being processed by `duckdb`, creating a vulnerability that could lead to command injection and local file inclusion...

PoC for CVE-2026-78140

DromaraUjcms5.1MEDIUM
Server-Side Template Injection in Dromara UJCMS Web-File-Template E...

A vulnerability exists in Dromara UJCMS versions up to 10.1.3, specifically in the update function of the WebFileTemplateController.java file. The flaw enables a server-side template injection, allowing attackers to manipulate special elements within the template engine. This vulnerability can be...

Discovered 1 day ago

PoC for CVE-2026-78115

SourcecodesterClass And Exam Timetab...5.3MEDIUM
Improper Authorization Vulnerability in SourceCodester Class and Ex...

A security issue has been identified in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the User Account Update functionality located in /admin/edit_user_account.php. This vulnerability allows attackers to manipulate the 'id' or 'username' parameters, leading...

PoC for CVE-2026-78112

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management Sys...

A vulnerability has been identified in the itsourcecode Hospital Management System Project in PHP version 1.0, specifically within the /viewservicetype.php file. This weakness allows for SQL injection attacks through the manipulation of the 'delid' argument, potentially exposing sensitive data an...

PoC for CVE-2026-77003

WordPressContent Mask2.7LOW
Improper Capabilities in Content Mask Plugin for WordPress

The Content Mask plugin for WordPress prior to version 1.8.5.5 contains a vulnerability that fails to validate user permissions when creating post types. This oversight permits users with minimal roles, such as Contributor, to publish posts and pages without possessing the required publish capabi...

PoC for CVE-2026-77116

BraveBrave4.3MEDIUM
Access Control Flaw in Brave Popup Builder by Brave

The Brave Popup Builder plugin suffers from a broken access control vulnerability that affects versions up to 0.8.5. This flaw allows any logged-in user, including those with Subscriber or WooCommerce Customer roles, to access popup content by manipulating the post ID in the URL. Such unauthorize...

PoC for CVE-2026-77115

BraveBrave7.1HIGH
Reflected XSS Vulnerability in Brave Popup Builder by Brave

The Brave Popup Builder plugin allows for the reflection of UTM query parameters into the popup form HTML without proper escaping. This vulnerability can be exploited by attackers to execute malicious scripts in the context of the user's browser, potentially leading to unauthorized actions or dat...

PoC for CVE-2026-13598

WordPressRestrictmate
Role Restriction Bypass in RestrictMate Plugin Affects WordPress Sites

The RestrictMate plugin for WordPress prior to version 1.3.0 contains a flaw that fails to properly restrict the user role during the account registration process. This oversight permits unauthenticated attackers to create a new account with administrative privileges, enabling them to gain unauth...

PoC for CVE-2026-14853

WordPressWooCommerce Bookings4.3MEDIUM
Improper Access Control in WooCommerce Bookings Plugin by Automattic

The WooCommerce Bookings plugin for WordPress prior to version 3.9.0 contains an improper access control vulnerability. It lacks adequate checks on an AJAX action, enabling users with Subscriber-level roles or higher to create draft bookable products by bypassing the nonce verification process. T...

PoC for CVE-2026-75616

Tp-link Systems Inc.Archer C20 V68.5HIGH
OS Command Injection Vulnerability in TP-Link Archer C20 Web Manage...

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when handling specific WAN-related configuration operations. An authenticated administrator can exploit this issue due to inadequate input validation, enabling them to execute arbitrary system c...

PoC for CVE-2026-47630

NvidiaTriton Inference Server5.5MEDIUM
Path Traversal Vulnerability in NVIDIA Triton Inference Server for ...

The NVIDIA Triton Inference Server for Linux has a vulnerability that allows an attacker to exploit an absolute path traversal. By successfully executing this exploit, an attacker could potentially execute arbitrary code, compromising the integrity and security of the system. It highlights the im...

PoC for CVE-2026-78063

TendaCh225.3MEDIUM
Command Injection Vulnerability in Tenda CH22 Router

A command injection vulnerability exists in the Tenda CH22 router, specifically in the formeditFileName function located in the /goform/editFileName file. This flaw allows an attacker to manipulate the editNameMit argument, enabling the execution of arbitrary commands remotely. The exploit has be...

PoC for CVE-2026-78060

SourcecodesterStock Management System5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Stock Manageme...

A significant cross-site scripting vulnerability has been detected in the SourceCodester Stock Management System, specifically affecting the file /php_action/getOrderReport.php. This flaw allows attackers to manipulate the parameters clientName and clientContact to inject malicious scripts. The v...