Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 3 hours ago
PoC for CVE-2026-91782
A vulnerability exists in the GNU Binutils 2.47 specifically within the Dynamic Relocation Allocation component found in the elf_x86_allocate_dynrelocs function. This issue leads to a null pointer dereference, which can be exploited locally. The exploit is publicly known, and it is crucial to upg...
PoC for CVE-2014-0160
The vulnerability in the TLS and DTLS implementations of OpenSSL versions prior to 1.0.1g allows remote attackers to exploit crafted Heartbeat Extension packets. This exploitation results in a buffer over-read, potentially revealing sensitive information from the memory of the affected process. A...
PoC for CVE-2026-91781
A security vulnerability has been identified in GNU Binutils version 2.47, specifically within the elf_x86_64_common_section_index function of the ELF Section Handler. This flaw allows for a null pointer dereference, requiring local exploitation. The issue has been publicly disclosed, raising con...
Discovered 4 hours ago
PoC for CVE-2026-91780
A critical weakness has been identified in GNU Binutils 2.47, specifically within the elf_link_add_object_symbols function in bfd/elflink.c. This vulnerability can lead to null pointer dereference, posing risks for local exploitation. Despite early notification to the project team via a bug repor...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-91779
A security flaw has been identified in GNU Binutils 2.47, specifically in the function responsible for handling EH Frames. This vulnerability allows local attackers to exploit a null pointer dereference, potentially leading to application crashes or unexpected behaviors. The issue originated from...
PoC for CVE-2026-91091
A vulnerability affecting GPAC prior to version abi-16.23 has been identified in the Node Insertion component, specifically within the gf_node_list_insert_child function in the base_scenegraph.c file. This vulnerability can lead to memory corruption, allowing remote exploitation of the affected s...
Discovered 5 hours ago
PoC for CVE-2026-91090
A vulnerability has been identified in GPAC versions up to f1219cde, specifically in the gf_node_activate_ex function located in scenegraph/base_scenegraph.c. This flaw allows for a stack-based buffer overflow, which can be exploited by attackers on the local host. Given the public disclosure of ...
PoC for CVE-2026-91089
A use after free vulnerability has been identified in GPAC, specifically within the function gf_node_get_name_and_id located in the file scenegraph/base_scenegraph.c. This flaw allows remote attackers to exploit the software by manipulating memory usage, potentially leading to unauthorized access...
PoC for CVE-2026-91087
A vulnerability has been identified in GPAC's Compositor component, specifically within the gf_mo_get_od_id function located in media_object.c. This flaw allows for a use after free condition, which can be exploited remotely. Attackers can leverage this vulnerability to manipulate memory usage, p...
Discovered 6 hours ago
PoC for CVE-2026-91086
A security vulnerability has been identified in the MPEG Video Reframer function, specifically in the mpgviddmx_process of the filters/reframe_mpgvid.c file of GPAC up to version f1219cde. This vulnerability allows for heap-based buffer overflow, making it possible for attackers to execute remote...
PoC for CVE-2026-91005
A security flaw has been identified in the SourceCodester Online Faculty Clearance System 1.0, specifically within the Profile Picture Upload component located in the edit_picture.php file. This vulnerability arises from the misconfiguration of the move_uploaded_file function, enabling remote att...
PoC for CVE-2026-91004
A vulnerability exists in the SourceCodester Online Faculty Clearance System 1.0 that allows an attacker to execute a SQL injection via an unknown function in the file /delete_faculty1.php. By manipulating the argument ID, remote attackers can exploit this flaw to extract sensitive data or manipu...
PoC for CVE-2026-18232
The WP Directory Kit plugin for WordPress, version 1.5.7, is vulnerable due to inadequate security checks on its public AJAX actions. This flaw permits unauthenticated users to access and retrieve draft and unapproved listings that belong to other users, creating potential privacy and data exposu...
PoC for CVE-2026-16593
The WP Directory Kit plugin for WordPress, prior to version 1.5.7, is susceptible to SQL injection due to improper sanitization and escaping of certain widget settings. This flaw allows authenticated users with page builder access (Editor or higher) to manipulate SQL statements, potentially leadi...
PoC for CVE-2026-16592
The WP Directory Kit plugin for WordPress, up to version 1.5.7, exhibits an authorization flaw that allows users with low-level roles, such as Contributor, to access and disclose non-public content. This includes sensitive information like password-protected listings and hidden fields that should...
PoC for CVE-2026-91003
A security issue has been identified in the D-Link DI-8300 16.07, specifically within the CGI Service. The vulnerability resides in the function 'rzgl_asp' found in the '/rzgl.asp' file. An improper manipulation of the 'redirct_url' argument can trigger a stack-based buffer overflow. This flaw op...
Discovered 7 hours ago
PoC for CVE-2026-91002
A vulnerability has been detected in Stamparm Maltrail prior to version 3.1, specifically in the Blacklist Endpoint's _blacklist function located in core/httpd.py. This security flaw permits unauthorized users to manipulate the endpoint, leading to missed authentication checks. An attacker could ...
PoC for CVE-2026-91001
A security vulnerability has been identified in the D-Link DI-8400 router, specifically within the DDNS Configuration component. This vulnerability arises from a stack-based buffer overflow due to improper handling of the ddns_asp function located in the file /ddns.asp. A remote attacker can expl...
PoC for CVE-2026-90881
A vulnerability exists in the D-Link DIR-882 router affecting versions up to 20260814, specifically within the CGI Binary component in the 'dllog.cgi' file. This flaw allows for unauthorized information disclosure, making it possible for attackers to manipulate the system remotely. The exploit de...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-90880
A security flaw has been identified in the D-Link DSL-3782 router that permits remote command injection through the Diagnostics component. This vulnerability stems from improper handling of the Addr argument in the Diagnostics.asp script, allowing unauthorized execution of commands. Attackers can...
Discovered 8 hours ago
PoC for CVE-2026-90879
A SQL injection vulnerability has been discovered in zyx0814 FilePress, specifically within the Publish Module's search functionality. The flaw arises from improper handling of arguments in the search.php file, potentially allowing attackers to manipulate input parameters, resulting in unauthoriz...
PoC for CVE-2026-90878
A resource consumption vulnerability exists in vLLM by vllm-project, specifically affecting the Jinja Template Rendering component within the chat/completions endpoint. Attackers can exploit this vulnerability remotely by manipulating the chat_template argument, leading to significant resource de...
PoC for CVE-2026-90877
A security issue has been identified in the SourceCodester Online Faculty Clearance System version 1.0, where improper handling of the 'haydi' parameter in the /update_requirement_status.php file allows for SQL injection. This vulnerability can be exploited remotely, potentially compromising data...
PoC for CVE-2026-90876
A security vulnerability has been identified in SourceCodester's Online Faculty Clearance System version 1.0 that exposes the /delete_requirement.php file. This vulnerability arises from improper handling of user input, allowing attackers to manipulate the 'ID' argument. As a result, an SQL injec...
Discovered 9 hours ago
PoC for CVE-2026-90858
A vulnerability has been identified in the online clinic management system developed by Subhajitkhan, specifically in the 'session_start' function located in adminappview.php. This flaw arises from an improper handling of the 'adminmail' argument, which can allow attackers to bypass authenticatio...
PoC for CVE-2026-90857
A vulnerability exists in the SourceCodester College Notes Gallery Management System version 1.0 within an unspecified function of the /dashboard/userprofile.php file, part of the Profile Upload component. The vulnerability allows for an unrestricted file upload if an attacker manipulates the ima...
PoC for CVE-2026-90856
A security vulnerability has been identified in the College Notes Gallery Management System, specifically in the signup.php file within the Registration Flow component. This vulnerability allows for improper privilege management due to manipulation of the 'role' argument. Attackers can exploit th...
Discovered 10 hours ago
PoC for CVE-2026-90852
A vulnerability in Luben zstd-jni affects the ZstdCompressCtx.loadDict function within the Dictionary Sharing component, leading to potential use after free scenarios. The vulnerability can be exploited by an attacker remotely, allowing them to manipulate memory usage adversely. Immediate upgrade...
PoC for CVE-2026-90851
A security flaw has been identified in the PHPGurukul Hostel Management System 3.0, specifically within the /admin/includes/checklogin.php file. This issue arises from improper handling of the argument ID, which leads to inadequate access controls. As a result, an attacker may exploit this vulner...
PoC for CVE-2026-90850
A cross site scripting vulnerability has been identified in PHPGurukul Hostel Management System version 3.0, specifically in the manage-students.php file. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser. The attack can be i...
Discovered 11 hours ago
PoC for CVE-2026-90849
A security vulnerability has been identified in the College Notes Gallery Management System 1.0 developed by SourceCodester. This flaw is associated with the 'login.php' file, where improper handling of user inputs leads to SQL injection attacks. Exploitation can occur remotely, allowing an attac...
PoC for CVE-2026-86259
OpenMAIC versions prior to 1.0.1 are vulnerable to a server-side request forgery (SSRF) that permits unauthenticated attackers to bypass validation in non-production environments. By manipulating the x-base-url header or the baseUrl parameter, attackers can potentially access sensitive cloud inst...
PoC for CVE-2026-90847
A security flaw exists in the EFM ipTIME C200E router, specifically within the iux_set.cgi component of the System Setup functionality. This vulnerability allows for remote exploitation through OS command injection, which could permit unauthorized execution of commands on the affected system. Pot...
PoC for CVE-2026-60004
A serious vulnerability exists in Gitea prior to version 1.27.1, allowing attackers to perform remote code execution via manipulation of the diffpatch API. Exploiting this vulnerability can enable unauthorized users to install malicious Git hooks. It is crucial for users of Gitea to update to ver...
PoC for CVE-2026-88899
Versions of Known prior to 0.31.0 are susceptible to a vulnerability that allows remote attackers to manipulate the x-opencode-directory request header in the /api/opencode proxy endpoint. This flaw enables attackers to supply arbitrary directory paths, potentially executing unauthorized file ope...
PoC for CVE-2026-90846
A potential SQL injection vulnerability exists in the PHPGurukul Daily Expense Tracker System 1.1, specifically in the forgot-password.php file. This security flaw is caused by improper handling of user-supplied input in the email/contact number fields, allowing remote attackers to manipulate dat...
Discovered 12 hours ago
PoC for CVE-2026-90842
A weakness has been discovered in the PHPGurukul Blood Donor Management System version 1.0, specifically in the Login_Model.php file. This vulnerability allows for cleartext storage of sensitive information, including passwords and emails, in files or on disk. The manipulation of input parameters...
Discovered 13 hours ago
PoC for CVE-2026-90841
A security flaw has been identified in the PHPGurukul Blood Donor Management System, particularly within the Report Endpoint located at /application/controllers/admin/Report.php. This vulnerability allows attackers to manipulate input parameters such as 'fromdate' and 'todate', resulting in SQL i...
PoC for CVE-2026-90840
A vulnerability exists in the PHPGurukul Blood Donor Management System version 1.0, specifically within the __construct function of the Dashboard.php file located in the Admin Controllers. This flaw allows for improper authentication, which can be exploited remotely by malicious actors. The explo...
PoC for CVE-2026-90835
A vulnerability has been identified in the michaelliao itranswarp, impacting versions up to 2.19, specifically within the Markdown.toHtml function in the Markdown.java file of the Page Content Rendering component. This flaw allows attackers to initiate cross-site scripting (XSS) attacks remotely....
PoC for CVE-2026-90831
A vulnerability in GNU Binutils 2.47 has been identified within the ELF String Table function _bfd_elf_strtab_delref, leading to potential memory corruption. This flaw can be exploited through a local attack vector. The vulnerability has been publicly disclosed, and the responsible project has ye...
Discovered 14 hours ago
PoC for CVE-2026-90830
A vulnerability exists in GNU Binutils version 2.47 affecting the _bfd_write_merged_section function within the Section Merge component. This vulnerability can lead to a null pointer dereference, which requires local access to exploit. The issue was made public following a bug report; however, th...
PoC for CVE-2026-90829
A vulnerability has been detected in GNU Binutils 2.47, specifically within the bfd_elf_set_group_contents function located in the SHT_GROUP Section Handler. This flaw can result in a null pointer dereference, potentially leading to unexpected behaviors. The exploit requires local access to launc...
PoC for CVE-2026-90828
A security flaw has been identified in the GNU Binutils version 2.47, specifically in the ELF Orphan Section Handler's function elf_orphan_compatible. This vulnerability can lead to a null pointer dereference due to improper handling of certain inputs. Attackers situated locally could exploit thi...
PoC for CVE-2026-91143
The goproxy product prior to version 15.4 contains a flaw in its handling of HTTP proxy basic authentication. Specifically, it fails to enforce authentication for CONNECT tunnel requests, enabling unauthenticated clients to forge connections through the proxy. This vulnerability allows attackers ...
PoC for CVE-2026-90827
A vulnerability arises in GPAC's MP4Box version 26.07.0 due to a flaw in the gf_node_deactivate_ex function within the base_scenegraph.c file. This flaw could allow an attacker to exploit a use after free condition, enabling local manipulation of memory that could compromise system stability or s...
Discovered 15 hours ago
PoC for CVE-2026-90826
A vulnerability has been identified in GPAC version 26.07.0, specifically in the gf_node_del function within the scenegraph/base_scenegraph.c file of the MP4Box component. This vulnerability is characterized by out-of-bounds read manipulation, which may permit attackers to exploit the issue, alth...
PoC for CVE-2026-90825
A vulnerability discovered in GPAC version 26.07.0 affects the MP4Box component, specifically within the gf_node_unregister function in the base_scenegraph.c file. This vulnerability can lead to memory corruption through a use after free issue, which can only be exploited locally. An exploit has ...