Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2023-31902

MobilemouseMobile Mouse9.8CRITICAL
Remote Code Execution Flaw in RPA Technology Mobile Mouse

RPA Technology's Mobile Mouse version 3.6.0.4 has a vulnerability that allows attackers to execute arbitrary code remotely. This risk poses a serious concern for users of the application, potentially enabling unauthorized access and control over the affected system. It is crucial for users to upd...

PoC for CVE-2026-23479

RedisRedis7.7HIGH
Use-After-Free Vulnerability in Redis Server by Redis Labs

Redis, an in-memory data structure store, has a vulnerability in the unblock client flow within versions from 7.2.0 to 8.6.3. When re-executing a blocked command, the system fails to handle an error return, which may lead to a scenario where an authenticated attacker can exploit this flaw. If a b...

PoC for CVE-2026-58048

WebprosCpanel9.4CRITICAL
SQL Injection Vulnerability in cPanel Database Management

The vulnerability allows an attacker to execute arbitrary SQL commands in the root context due to insufficient handling of SQL mode settings during database renaming operations in cPanel. This could potentially lead to unauthorized access and manipulation of sensitive data within the database. Pr...

Discovered 3 hours ago

PoC for CVE-2026-18718

National Security...Ghidra7.1HIGH
Arbitrary Code Execution in Ghidra's Swift Demangler Analyzer by Na...

Ghidra features a flaw in its Swift demangler analyzer that enables attackers to execute arbitrary code. By creating a malicious Ghidra project with a crafted Swift tool directory path, an attacker can manipulate the context from which binaries are restored and executed. Upon opening the compromi...

Discovered 5 hours ago

PoC for CVE-2026-16547

WordPressRest Api Log
REST API Log Vulnerability in WordPress Plugin

The REST API Log plugin for WordPress, prior to version 1.7.1, has security weaknesses where the token intended to protect the log download feature does not adequately bind to the requested log entry. Furthermore, it fails to verify the requester's permissions. This oversight permits unauthentica...

PoC for CVE-2026-16548

WordPressChat Widget: Floating ...
File Upload Vulnerability in Chat Widget Plugin for WordPress

The Chat Widget plugin for WordPress versions prior to 1.8.2 is susceptible to a file upload vulnerability. This flaw allows unauthenticated users to upload arbitrary files to the public response endpoint without proper validation of file type, extension, content, or size. Files are stored in the...

PoC for CVE-2026-16546

WordPressWired Impact Volunteer...
Authorization Flaw in Wired Impact Volunteer Management Plugin by W...

The Wired Impact Volunteer Management plugin for WordPress, prior to version 2.8.2, contains an authorization flaw in one of its AJAX actions. This vulnerability allows authenticated users with minimal roles, such as Subscribers, to remove RSVPs associated with any volunteer opportunities regardl...

PoC for CVE-2026-16069

WordPressBrizy
Cross-Site Scripting Vulnerability in Brizy WordPress Plugin

The Brizy WordPress plugin prior to version 2.8.19 is susceptible to a Cross-Site Scripting (XSS) vulnerability due to inadequate sanitization and escaping of focal-point coordinates for featured images. This weakness allows users with Contributor privileges or higher to inject malicious scripts ...

PoC for CVE-2026-16296

WordPressClearfy Cache
Unvalidated Redirect Vulnerability in Clearfy Cache Plugin for Word...

The Clearfy Cache plugin for WordPress prior to version 2.4.3 contains a vulnerability that arises from the lack of validation for the redirect target in its old-URL redirect handler, known as Cyrlitera. This deficiency permits unauthenticated attackers to manipulate the redirect mechanism, allow...

PoC for CVE-2026-16070

WordPressBrizy
Authorization Flaw in Brizy WordPress Plugin Affects Template Manag...

The Brizy WordPress plugin versions prior to 2.8.19 contains a significant authorization flaw. This vulnerability enables users with Contributor-level access and higher to improperly modify the template-type assignments of templates that they do not own. The plugin fails to accurately verify the ...

PoC for CVE-2026-16293

WordPressPowerpress Podcasting ...
Stored Cross-Site Scripting Vulnerability in PowerPress Podcasting ...

The PowerPress Podcasting plugin by Blubrry fails to properly sanitize and escape several settings related to Podcast Episodes. This oversight allows attackers with low-level roles, such as Contributor, to craft malicious scripts that can be stored and executed within the applications of unsuspec...

PoC for CVE-2026-16295

WordPressClearfy Cache
Admin Access Bypass in Clearfy Cache Plugin for WordPress

The Clearfy Cache Plugin for WordPress, prior to version 2.4.3, is susceptible to a vulnerability where it fails to implement adequate capability checks in its admin-page routing. This oversight enables any authenticated user, including those with minimal permissions like Subscribers, to access r...

PoC for CVE-2026-16056

WordPressContest Gallery
Unauthorized Access Vulnerability in Contest Gallery WordPress Plugin

The Contest Gallery plugin for WordPress prior to version 30.0.7 lacks necessary capability and nonce validation in one of its handlers. This oversight permits any authenticated user, including those with minimal permissions such as Subscribers, to access the entire stored OpenAI prompt history o...

PoC for CVE-2026-16035

WordPressMiniorange 2fa
Excessive OTP Sending Vulnerability in miniOrange 2FA WordPress Plugin

The miniOrange 2FA WordPress plugin, prior to version 6.2.7, contains a vulnerability that allows low-privileged users to send one-time passcode (OTP) emails to any arbitrary recipient. This oversight does not enforce restrictions on who may trigger the OTP configuration process, nor does it bind...

PoC for CVE-2026-15958

WordPressEasy Integration For D...
File Management Vulnerability in Easy Integration for Dropbox WordP...

The Easy Integration for Dropbox plugin for WordPress prior to version 2.2.0 lacks proper authorization checks on its file-management AJAX actions. This oversight enables unauthenticated attackers to exploit the system, potentially allowing them to list, download, and upload arbitrary files acros...

PoC for CVE-2026-16068

WordPressBrizy
Insufficient Access Control in Brizy Plugin for WordPress

The Brizy plugin for WordPress prior to version 2.8.19 exhibits poor access control, failing to restrict modifications to site-global design data effectively. This oversight allows authenticated users with Author-level permissions or higher to input arbitrary JavaScript code. The plugin does not ...

PoC for CVE-2026-15233

WordPressNested Pages
XSS Vulnerability in Nested Pages WordPress Plugin Affects Administ...

The Nested Pages plugin for WordPress prior to version 3.2.15 contains a vulnerability where post titles are not properly escaped before being rendered into HTML attributes. This oversight allows users with roles such as Editor, Contributor, or Author to inject arbitrary JavaScript into the admin...

PoC for CVE-2026-14872

WordPressDatabase For Contact F...
SQL Injection Vulnerability in Contact Form 7, WPforms, and Element...

The Contact Form 7, WPforms, and Elementor Forms plugins for WordPress prior to version 1.5.5 contain a vulnerability due to improper sanitization and escaping of parameters in SQL statements. This flaw allows attackers, even with limited user permissions typically assigned to administrators, to ...

PoC for CVE-2026-14848

WordPressPaid Membership Subscr...
Unauthorized Access Vulnerability in Paid Membership Subscriptions ...

The Paid Membership Subscriptions plugin for WordPress prior to version 3.0.8 allows authenticated users with Subscriber-level access or higher to modify another user's subscription. This vulnerability stems from the plugin's failure to verify subscription ownership during the change-subscription...

PoC for CVE-2026-14939

WordPressVisualizer
Server-Side Request Forgery Risk in Visualizer Plugin for WordPress

The Visualizer plugin for WordPress before version 4.0.6 is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This weakness occurs because the plugin does not adequately limit user-supplied URLs to safe ranges before fetching them on the server side. This oversight permits users ...

PoC for CVE-2026-14816

WordPressThe Gdpr Framework By ...
Authorization Flaw in GDPR Framework Plugin for WordPress by Data443

The GDPR Framework plugin for WordPress, developed by Data443, allows unauthenticated attackers to bypass authorization checks when recording cookie-consent choices and processing privacy requests. This vulnerability could lead to the forging of consent records associated with arbitrary email add...

PoC for CVE-2026-11366

WordPressMonsterinsights
Unauthenticated AJAX Signature Forgery in MonsterInsights Plugin by...

The MonsterInsights plugin for WordPress before version 11.1.0 is vulnerable to a security flaw that allows unauthenticated attackers to bypass validation checks on an unauthenticated AJAX action. When the plugin is not connected to Google Analytics, the HMAC signing key is empty, which enables a...

PoC for CVE-2026-12698

WordPressWPforo Forum
User Account Manipulation in wpForo Forum Plugin for WordPress

The wpForo Forum WordPress plugin, prior to version 3.1.3, suffers from an authorization flaw that permits users with a subscriber role to modify restricted profile fields. This could lead to unauthorized changes, such as altering account status, reputation scores, and potentially reactivating ba...

PoC for CVE-2026-14824

WordPressQuiz And Survey Master...
Cross-Site Scripting Vulnerability in Quiz and Survey Master Plugin...

The Quiz and Survey Master plugin for WordPress, prior to version 11.2.2, is susceptible to a cross-site scripting (XSS) vulnerability. This issue arises due to insufficient escaping of question settings before rendering them in unquoted HTML attributes. As a result, users with contributor-level ...

PoC for CVE-2026-10526

WordPressEmbedpress
Server-Side Request Forgery Vulnerability in EmbedPress Plugin for ...

The EmbedPress plugin for WordPress, prior to version 4.6.1, suffers from a security flaw that leads to unvalidated user-supplied URLs being processed. This vulnerability enables unauthenticated attackers to exploit the system, causing the server to make unintended HTTP requests to internal servi...

PoC for CVE-2026-16623

WordPressCreate Block Theme
PHP Code Injection Vulnerability in Create Block Plugin for WordPress

The Create Block WordPress plugin prior to version 2.10.0 is susceptible to a PHP code injection vulnerability. Due to insufficient escaping of user-supplied text when creating a PHP pattern file, this flaw allows a multisite subsite administrator to inject and execute arbitrary PHP code on the s...

PoC for CVE-2026-16536

WordPressSimple Google Calendar...
Server-Side Request Forgery Vulnerability in Simple Google Calendar...

The Simple Google Calendar Outlook Events Widget plugin for WordPress prior to version 3.1.0 is prone to a security vulnerability due to improper validation of user-supplied URLs. This oversight allows unauthenticated attackers to execute Server-Side Request Forgery (SSRF) attacks, which may enab...

PoC for CVE-2026-16618

WordPressImprove Seo
File Upload Vulnerability in Improve SEO Plugin for WordPress

The Improve SEO WordPress plugin versions up to 2.0.11 has a critical issue where it fails to effectively validate uploaded files. The plugin only checks the content type of the file during the upload process. This insufficient validation allows untrusted users to upload files with malicious exte...

Discovered 8 hours ago

PoC for CVE-2026-18723

DiaowenDwsurvey5.3MEDIUM
Improper Authorization Vulnerability in DWSurvey by diaowen

A serious security flaw in DWSurvey by diaowen, specifically in the Survey Status Handler's `/api/dwsurvey/app/survey/up-survey-status.do`, allows for improper authorization. This vulnerability can be exploited remotely, posing a risk for unauthorized access to sensitive survey data. Although the...

PoC for CVE-2026-18722

DiaowenDwsurvey5.3MEDIUM
Authorization Bypass in diaowen DWSurvey by diaowen

A vulnerability exists in diaowen DWSurvey prior to version 6.14.0, specifically in the DwDeisgnSurveyController.devSurvey function. This flaw allows attackers to bypass authorization controls, enabling unauthorized access to sensitive functions of the Survey Handler component. The vulnerability ...

PoC for CVE-2026-18721

KalcaddleKodbox5.3MEDIUM
Open Redirect Vulnerability in kalcaddle kodbox 1.67 Build 02

A security flaw has been detected in kalcaddle kodbox version 1.67 Build 02 involving the SSO API Login component. The vulnerability allows remote attackers to manipulate the 'callbackUrl' parameter within the '/user/sso/apiLogin' endpoint, leading to potential open redirect scenarios. This issue...

Discovered 9 hours ago

PoC for CVE-2026-18720

KalcaddleKodbox6.9MEDIUM
Improper Authorization in kalcaddle kodbox Affected by msgWarning P...

A vulnerability has been identified in kalcaddle kodbox version 1.67 Build 02, specifically within the msgWarning Plugin located at /index.php?plugin/msgWarning/action. This flaw permits unauthorized actions due to insufficient access control checks. The manipulation can be executed remotely, whi...

PoC for CVE-2022-22965

VmwareSpring Framework🟣 EPSS 100%9.8CRITICAL
Remote Code Execution Vulnerability in Spring Framework Products by...

A vulnerability in the Spring Framework could allow unauthorized remote code execution (RCE) when an application is running on JDK 9+ with Spring MVC or Spring WebFlux deployed as a WAR on a Tomcat server. If the application is executed as a Spring Boot executable JAR, it is not susceptible to th...

Discovered 10 hours ago

PoC for CVE-2026-3891

WordPressPix For WooCommerce9.8CRITICAL
Arbitrary File Upload Vulnerability in Pix for WooCommerce Plugin b...

The Pix for WooCommerce plugin for WordPress is susceptible to arbitrary file uploads due to a lack of capability checks and insufficient file type validation within the 'lkn_pix_for_woocommerce_c6_save_settings' function. This vulnerability exists across all versions through 1.5.0. An unauthenti...

Discovered 11 hours ago

PoC for CVE-2026-15409

SonicwallSma1000🟣 EPSS 78%10CRITICAL
Server-Side Request Forgery in SonicWall SMA1000 Appliance Work Pla...

A Server-side Request Forgery (SSRF) vulnerability has been identified within the Work Place interface of the SMA1000 Appliance. This security flaw allows a remote attacker, without authentication, to exploit the appliance, enabling it to make requests to unintended and potentially malicious loca...

Discovered 12 hours ago

PoC for CVE-2026-18685

Gl.inetGl-mt30009.3CRITICAL
Command Injection Vulnerability in GL.iNet GL-MT3000 Router Software

A command injection vulnerability has been identified in the GL.iNet GL-MT3000 router’s firmware versions up to 4.4.5. The issue resides in the 'set_upgrade' function located in the 'modem.so' component of the '/cgi-bin/glc' file. This flaw enables an attacker to execute arbitrary commands remote...

PoC for CVE-2026-18684

Gl.inetGl-mt30009.3CRITICAL
Command Injection Vulnerability in GL.iNet GL-MT3000 Router

A security weakness has been discovered in the GL.iNet GL-MT3000 router affecting versions up to 4.4.5. This vulnerability resides in the 'remove_profile' function within the '/cgi-bin/glc' component of the modem.so file. Through this flaw, attackers can perform command injection remotely, potent...

PoC for CVE-2026-26114

MicrosoftMicrosoft Sharepoint E...8.8HIGH
Remote Code Execution Vulnerability in Microsoft Office SharePoint

In Microsoft Office SharePoint, a vulnerability exists that enables an authorized attacker to manipulate untrusted data, leading to potential remote code execution. This flaw allows the attacker to send serialized data that can be improperly processed by the SharePoint server. If successfully exp...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 13 hours ago

PoC for CVE-2026-67617

MicroweberMicroweber4.8MEDIUM
Stored Cross-Site Scripting Vulnerability in Microweber CMS

Microweber CMS versions up to 2.0.20 are vulnerable to a stored cross-site scripting flaw in the content tagging system. Authenticated administrators can exploit this weakness by injecting arbitrary JavaScript code through the tag_names parameter of the GET /api/save_content_admin endpoint. This ...

PoC for CVE-2026-18682

OpenAkitaOpenakita2.3LOW
Cross Site Scripting Vulnerability in OpenAkita File Upload API

A security vulnerability has been identified in versions of OpenAkita up to 1.27.12, affecting its File Upload API. The flaw allows attackers to manipulate the 'File' argument, resulting in cross site scripting (XSS) vulnerabilities. This can be exploited remotely with significant complexity. Pub...

Discovered 14 hours ago

PoC for CVE-2023-30547

PatriksimekVm2🟣 EPSS 72%9.8CRITICAL
Sandbox Escape in vm2

The vm2 sandbox environment, designed for executing untrusted Node.js code, contains a vulnerability in its exception handling mechanism. Versions up to 3.9.16 are susceptible to an attack that allows an unsanitized host exception to be raised within the `handleException()` function. This flaw ca...

PoC for CVE-2026-18648

BlixEmail Blue Mail Calend...4.8MEDIUM
Path Traversal Vulnerability in Blix Email Blue Mail Calendar App

A vulnerability has been identified in the Blix Email Blue Mail Calendar App affecting version 2.2.305. This issue resides in the FileDirectory.getDataColumn and FileDirectory.getFileFromUri functions within the react-native-receive-sharing-intent component. An adversary with local access can exp...

PoC for CVE-2023-36874

MicrosoftWindows 10 Version 1809🟣 EPSS 43%7.8HIGH
Windows Error Reporting Service Elevation of Privilege Vulnerability

The Windows Error Reporting Service contains a vulnerability that can allow attackers to elevate their privileges. This weakness may enable an unauthorized user to take control of affected systems, potentially leading to further exploits. It is essential for users to apply security updates and pa...

PoC for CVE-2026-18647

Jina-aiReader6.9MEDIUM
Server-Side Request Forgery in Jina-AI Reader Crawler Component

A security vulnerability in the Jina-AI Reader's Crawler component allows for server-side request forgery due to improper validation in the isValidTLD function within the crawler.ts file. This weakness can potentially lead to unauthorized access and exploitation by remote attackers. The flaw was ...

PoC for CVE-2026-9848

WordPressCustomer Support Ticke...7.5HIGH
SQL Injection Vulnerability in WP Ticket Plugin for WordPress

The WP Ticket plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit SQL Injection through the search query parameter. This occurs when the plugin processes search requests without properly sanitizing inputs, leading to potential exposure of sensitive informatio...

PoC for CVE-2026-18646

DanprosHtmly6.9MEDIUM
Path Traversal Vulnerability in danpros HTMLy Affecting Author Name...

A path traversal vulnerability has been discovered in the danpros HTMLy application up to version 3.1.1, specifically impacting the Author Name Handler component. This flaw resides within the /system/htmly.php file, allowing an attacker to manipulate the 'Name' argument to conduct unauthorized re...

PoC for CVE-2026-64531

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in Open vSwitch Related to Nested Action...

A vulnerability in Open vSwitch allows for oversized nested action attributes which can disrupt the intended processing of generated actions. This occurs when the total size of flow actions exceeds 64 KiB due to a recent modification that lifted previous restrictions. If an oversized action is no...

Discovered 15 hours ago

PoC for CVE-2026-18645

DanprosHtmly5.3MEDIUM
Path Traversal Vulnerability in danpros HTMLy Up to Version 3.1.1

A security flaw has been identified in danpros HTMLy, specifically within the add_content function found in /system/admin/admin.php. This vulnerability allows an attacker to manipulate the 'oldfile' argument, leading to potential unauthorized access through path traversal. Exploitation of this fl...

PoC for CVE-2026-43637

PreferredaiCornac8.8HIGH
Path Traversal Vulnerability in Cornac Library by PreferredAI

The Cornac library prior to version 2.6.0 is susceptible to a path traversal vulnerability, enabling malicious actors to exploit file writing practices. By delivering a specially crafted TAR archive that includes '../' sequences or absolute path definitions, attackers can manipulate the _extract_...