Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 49 minutes ago

PoC for CVE-2026-8337

Concrete CmsConcrete Cms6.3MEDIUM
IDOR Vulnerability in Concrete CMS Product by Concrete5

Concrete CMS versions 9.5.0 and earlier contain a vulnerability that allows unauthenticated attackers to exploit insecure direct object references (IDOR) in survey functionalities. A malicious user can manipulate the public survey's endpoint to submit votes for private surveys, bypassing restrict...

Discovered 2 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 4 hours ago

PoC for CVE-2026-66066

RailsRails9.5CRITICAL
Active Storage Vulnerability in Rails Affects Image Upload Security

Active Storage, a framework component of Rails, has a vulnerability that affects versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1. This issue arises from the framework's failure to disable unsafe libvips operations when handling image uploads from untrusted users. An unauthenticated attacker can e...

Discovered 5 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 6 hours ago

PoC for CVE-2026-47668

DbgateDbgate10CRITICAL
Remote Code Execution Vulnerability in DbGate Database Manager

DbGate, a cross-platform database management tool, exhibits a vulnerability allowing remote code execution through code injection in the 'functionName' parameter of JSON script 'assign' commands. This security flaw is present in versions 7.1.8 and earlier, where untrusted input is directly incorp...

Discovered 9 hours ago

PoC for CVE-2026-32286

Github.com/jackc/...Github.com/jackc/pgpro...7.5HIGH
DataRow Message Vulnerability in PostgreSQL Server by Jackc

A vulnerability exists within the DataRow.Decode function of the PostgreSQL server, where it inadequately checks field lengths. An attacker utilizing a malicious PostgreSQL server could send a DataRow message with a negative field length, resulting in a slice bounds out of range panic condition. ...

Discovered 11 hours ago

PoC for CVE-2026-43284

LinuxLinux🟣 EPSS 93%8.8HIGH
Vulnerability in Linux Kernel Affects Shared skb Fragments

A vulnerability exists in the Linux kernel that concerns the handling of shared skb fragments during the decryption process in ESP-in-UDP packets. When pages are attached from a pipe directly to an skb using MSG_SPLICE_PAGES, the kernel marked these SKBs with SKBFL_SHARED_FRAG, which plays a cruc...

Discovered 12 hours ago

PoC for CVE-2026-8347

Concrete CmsConcrete Cms2.3LOW
IDOR Vulnerability in Concrete CMS by Concrete5

A vulnerability in Concrete CMS versions 9.5.0 and earlier allows an attacker to exploit IDOR (Insecure Direct Object Reference) and incorrect authorization levels in the Express association Reorder dialog. This could enable a malicious user to manipulate state across entities with view-only perm...

Discovered 13 hours ago

PoC for CVE-2026-54121

MicrosoftWindows 10 Version 16078.8HIGH
Elevation of Privilege Vulnerability in Microsoft Active Directory ...

A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...

PoC for CVE-2026-16723

AlibabaFastjson9CRITICAL
Remote Code Execution Vulnerability in fastjson by Alibaba

A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...

Discovered 14 hours ago

PoC for CVE-2026-54121

MicrosoftWindows 10 Version 16078.8HIGH
Elevation of Privilege Vulnerability in Microsoft Active Directory ...

A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...

Discovered 15 hours ago

PoC for CVE-2021-1931

QualcommSnapdragon Auto, Snapd...6.7MEDIUM
Buffer Overflow Vulnerability in Qualcomm Snapdragon Products

This security vulnerability is caused by improper validation of the buffer length when processing fast boot commands across various Qualcomm Snapdragon products. An attacker could exploit this flaw to execute arbitrary code or cause unintended behavior, potentially compromising the affected devices.

Discovered 23 hours ago

PoC for CVE-2022-24903

RsyslogRsyslog8.1HIGH
Buffer overflow in TCP syslog server (receiver) components in rsyslog

Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execu...

Discovered 1 day ago

PoC for CVE-2026-14919

WordPressShopmonitor.io9.8CRITICAL
Email Rerouting Vulnerability in ShopMonitor.io WordPress Plugin

The ShopMonitor.io plugin for WordPress before version 1.2.0 contains a flaw that allows unauthorized users to exploit the email rerouting feature. This security gap allows attackers to redirect sensitive outgoing emails, such as password reset notifications for the WordPress administrator accoun...

PoC for CVE-2026-14862

WordPressSupport Genix3.7LOW
Improper Access Control in Support Genix WordPress Plugin

The Support Genix plugin for WordPress versions prior to 1.4.48 is vulnerable to an improper access control issue that permits unauthenticated users to download private ticket attachments. This flaw occurs due to insufficient checks on access rights, allowing individuals who know the stored attac...

PoC for CVE-2026-12697

WordPressWPforo Forum5.4MEDIUM
Improper Access Control in wpForo Forum Plugin by WordPress

The wpForo Forum plugin for WordPress, prior to version 3.1.2, lacks adequate verification to confirm whether an AI chat conversation belongs to the user making the request. This oversight allows individuals with just a subscriber-level account to delete the AI chat message histories of other use...

PoC for CVE-2026-12695

WordPressMiniorange 2fa8.1HIGH
Bypass Vulnerability in miniOrange Two-Factor Authentication Plugin...

The miniOrange Two-Factor Authentication plugin for WordPress, prior to version 6.2.6, is vulnerable to an authentication bypass. This vulnerability allows an unauthenticated attacker, who is aware of a user's password, to bypass the two-factor authentication mechanism. The flaw exists because th...

PoC for CVE-2026-13609

WordPressFrontend Admin By Dyna...8.8HIGH
Stored Cross-Site Scripting Vulnerability in Frontend Admin by Dyna...

The Frontend Admin by DynamiApps WordPress plugin prior to version 3.29.9 contains a vulnerability where HTML entities are decoded in form field submissions after being sanitized. This flaw allows a double-encoded malicious payload submitted by an unauthenticated user to be stored as executable H...

PoC for CVE-2026-12376

WordPressAcademy Lms4.3MEDIUM
Access Control Flaw in Academy LMS Plugin for WordPress

The Academy LMS WordPress plugin prior to version 3.8.2 contains an access control vulnerability that permits authenticated users with subscriber-level access or higher to view quiz attempt records belonging to other users. This oversight allows anyone enrolled in any course to access sensitive i...

PoC for CVE-2026-13393

WordPressElementskit Elementor ...3.5LOW
Cross-Site Scripting Vulnerability in ElementsKit Elementor Addons ...

The ElementsKit Elementor Addons for WordPress prior to version 3.10.01 contains a vulnerability that allows users with administrative privileges to execute stored Cross-Site Scripting (XSS) attacks. This flaw arises due to the failure to properly sanitize and escape certain settings related to m...

PoC for CVE-2026-12721

WordPressKirki8.6HIGH
SQL Injection Vulnerability in Kirki WordPress Plugin by Aristeides...

The Kirki WordPress plugin prior to version 6.0.13 fails to adequately sanitize and escape user input before incorporating it into SQL statements. This oversight exposes the plugin to SQL injection attacks, which allow unauthenticated attackers to manipulate database queries, potentially leading ...

PoC for CVE-2026-13392

WordPressElementskit Elementor ...7.2HIGH
Arbitrary Code Execution in ElementsKit Elementor Addons Plugin for...

The ElementsKit Elementor Addons for WordPress prior to version 3.10.01 allows users with administrative privileges to define custom widgets that are saved directly into a generated PHP file. This flaw leads to the execution of arbitrary PHP code on the server. In a multisite environment, a subsi...

PoC for CVE-2026-12251

WordPressUltimate Member8.1HIGH
Administrator Role Bypass in Ultimate Member Plugin for WordPress

The Ultimate Member plugin for WordPress before version 2.12.1 allows unauthenticated users to exploit a flaw that does not properly filter administrator-level capabilities from selectable roles during registration. Additionally, the default configuration lacks crucial safeguards against account ...

PoC for CVE-2026-12720

WordPressKirki7.5HIGH
PHP Object Injection in Kirki WordPress Plugin by DevJunkie

The Kirki WordPress plugin, prior to version 6.0.13, fails to adequately restrict the classes that can be instantiated when it deserializes data stored by unauthenticated users. This oversight creates a path for PHP Object Injection, which can be exploited when an administrator later reviews the ...

PoC for CVE-2026-8155

WordPressBuddypress5.4MEDIUM
Authorization Flaw in BuddyPress Plugin Allows Unauthorized Messagi...

The BuddyPress plugin for WordPress prior to version 14.5.0 possesses an authorization flaw that fails to restrict access to private messaging endpoints. As a result, any authenticated user, including Subscribers, can interact with other users' private messages—allowing them to read, modify, or e...

PoC for CVE-2026-14931

WordPressJs Help Desk6.5MEDIUM
Authorization Oversight in JS Help Desk Plugin Allows User Enumeration

The JS Help Desk WordPress plugin prior to version 3.1.4 mistakenly assigns support-agent capabilities to the Contributor role upon activation. Additionally, it lacks proper capability checks in a user-listing handler, which permits users with Contributor-level access to enumerate the email addre...

PoC for CVE-2026-15209

WordPressJs Help Desk6.5MEDIUM
User Ticket Access Flaw in JS Help Desk Plugin for WordPress

The JS Help Desk plugin for WordPress prior to version 3.1.5 contains an access control vulnerability that allows low-privileged authenticated users to access and read content of tickets they do not own. By manipulating ticket IDs, an attacker can gain unauthorized access to sensitive information...

PoC for CVE-2026-15258

WordPressProduct Feed Manager F...8.1HIGH
SQL Injection Vulnerability in Product Feed Manager for WooCommerce...

The Product Feed Manager for WooCommerce plugin, prior to version 7.6.1, fails to properly sanitize and escape product-feed custom filter rules when utilized in SQL queries. This oversight enables users with Contributor roles and higher to execute SQL injection attacks, potentially compromising t...

PoC for CVE-2026-15048

WordPressGeeky Bot7.5HIGH
Authentication Issue in Geeky Bot WordPress Plugin

The Geeky Bot WordPress plugin versions prior to 1.2.8 exhibit a serious flaw by failing to properly execute an authorization check for specific AJAX actions. This oversight permits unauthenticated users to access sensitive chat-history metadata. Such unauthorized access includes retrieving cruci...

PoC for CVE-2026-15381

WordPressWP Go Maps3.7LOW
SQL Injection Vulnerability in WP Go Maps Plugin

The WP Go Maps plugin for WordPress contains a significant security flaw where inadequate sanitization and escaping of parameters in SQL queries allow unauthenticated users to exploit this vulnerability. This SQL injection risk can enable attackers to access sensitive data and manipulate the data...

PoC for CVE-2026-14927

WordPressFluentcart A New Era O...3.7LOW
Authorization Issues in FluentCart eCommerce Plugin for WordPress

The FluentCart WordPress plugin prior to version 1.5.3 is susceptible to an authorization bypass vulnerability. Due to the lack of authorization or ownership checks, unauthorized users can access and disclose sensitive customer information, such as names, email addresses, shipping and billing add...

PoC for CVE-2026-14922

WordPressWP Photo Album Plus6.1MEDIUM
Stored Cross-Site Scripting Vulnerability in WP Photo Album Plus by...

WP Photo Album Plus is exposed to a stored Cross-Site Scripting vulnerability due to a double-encoding flaw within its photo-comment feature. This issue allows an attacker to exploit the comment submission process by sending a specially crafted HTML-encoded payload. The comment sanitation process...

PoC for CVE-2026-14930

WordPressJs Help Desk7.5HIGH
Unauthorized File Upload in JS Help Desk WordPress Plugin

The JS Help Desk WordPress plugin prior to version 3.1.4 allows unauthenticated users to upload files by bypassing necessary authorization checks. This vulnerability enables the unintended attachment of uploaded files to any support ticket, potentially leading to misuse or unauthorized access to ...

PoC for CVE-2026-14929

WordPressJs Help Desk4.3MEDIUM
Input Validation Flaw in JS Help Desk Plugin for WordPress

The JS Help Desk WordPress plugin prior to version 3.1.4 contains an input validation flaw that allows any authenticated user, including Subscribers, to overwrite the content of support-ticket replies. This issue arises because the plugin fails to verify the ownership of the targeted reply before...

PoC for CVE-2026-14928

WordPressJs Help Desk6.5MEDIUM
Authorization Bypass in JS Help Desk Plugin for WordPress

The JS Help Desk WordPress plugin prior to version 3.1.4 has a security flaw that allows authenticated users, including Subscribers, to access the content of support tickets belonging to other users. This vulnerability occurs due to the absence of proper authorization checks in the nonce-gated se...

PoC for CVE-2026-14921

WordPressUltimate Addons For WP...6.1MEDIUM
Link Rendering Vulnerability in Ultimate Addons for WPBakery Page B...

A link rendering vulnerability exists in the Ultimate Addons for WPBakery Page Builder WordPress plugin prior to version 3.21.5. This vulnerability is related to the shared link-rendering function, 'Ultimate_VC_Addons::uavc_link_init()'. Through this weakness, an attacker may exploit the plugin t...

PoC for CVE-2026-14845

WordPressNewstatpress6.1MEDIUM
Stored Cross-Site Scripting Vulnerability in NewStatPress Plugin by...

The NewStatPress plugin for WordPress, prior to version 1.4.5, fails to properly sanitize and escape user data obtained from unauthenticated visitor inputs. This oversight allows attackers to exploit the plugin by injecting malicious scripts into stored data. When users view the affected widget, ...

PoC for CVE-2026-14834

WordPressMailgun For WordPress6.5MEDIUM
Unauthorized Enrollment in Mailing Lists for Mailgun Plugin by Word...

The Mailgun for WordPress plugin prior to version 2.2.1 lacks necessary checks for capabilities and nonces on a specific unauthenticated AJAX action. This flaw allows attackers to add arbitrary email addresses to the website owner's mailing lists, leveraging stored API credentials. This vulnerabi...

PoC for CVE-2026-14843

WordPressEvents Made Easy5.3MEDIUM
Unauthenticated Data Modification Vulnerability in Events Made Easy...

The Events Made Easy plugin for WordPress is susceptible to a data manipulation vulnerability that occurs due to inadequate authorization checks for unauthenticated data modification requests. Specifically, prior to version 3.1.4, attackers can leverage a public nonce without any verification of ...

PoC for CVE-2026-14847

WordPressPaid Membership Subscr...4.3MEDIUM
Authentication Bypass Vulnerability in Paid Membership Subscription...

The Paid Membership Subscriptions plugin for WordPress before version 3.0.7 contains a vulnerability that allows authenticated users with Subscriber-level access and above to exploit a lack of capability and nonce checks on specific payment-related AJAX actions. This oversight enables these users...

PoC for CVE-2026-14849

WordPressPaid Membership Subscr...3.7LOW
Data Exposure Vulnerability in Paid Membership Subscriptions Plugin...

The Paid Membership Subscriptions plugin for WordPress lacks adequate security measures, allowing exposed member and payment export files to be accessed by unauthenticated users. This vulnerability arises from the predictable location of the export files in the uploads directory, which could lead...

PoC for CVE-2026-14830

WordPressFlxwoo7.5HIGH
Payment Processing Flaw in FlxWoo Plugin for WordPress

The FlxWoo WordPress plugin prior to version 3.1.1 is susceptible to a vulnerability that fails to verify payment status with the payment processor. This oversight allows unauthenticated attackers to mark WooCommerce orders as paid, potentially leading to unauthorized purchases without actual pay...

PoC for CVE-2026-14554

WordPressCheck & Log Email6.5MEDIUM
SQL Injection Vulnerability in Check & Log Email WordPress Plugin

The Check & Log Email WordPress plugin prior to version 2.0.15 has a serious vulnerability due to inadequate sanitization and escaping of parameters used in SQL queries. This flaw permits users with administrator privileges to execute SQL injection attacks, potentially allowing unauthorized acces...

PoC for CVE-2026-14833

WordPressLightbox With Photoswipe6.8MEDIUM
Cross-Site Scripting in Lightbox with PhotoSwipe Plugin Affects Wor...

The Lightbox with PhotoSwipe plugin for WordPress, prior to version 5.9.0, introduces a security flaw that fails to properly sanitize or escape link data attributes in the image lightbox caption. This oversight permits users with author-level access or higher, who typically lack the unfiltered_ht...

PoC for CVE-2026-14333

WordPressDemi7.5HIGH
Publicly Accessible Backup Vulnerability in Demi WordPress Plugin b...

The Demi WordPress plugin prior to version 0.0.7 has a significant vulnerability that allows unauthenticated users to download complete backups from a publicly accessible directory. These backups may contain sensitive information, including the site's database and hashed user passwords, posing a ...

PoC for CVE-2026-14317

WordPressGiveWP5.3MEDIUM
Improper Input Validation in GiveWP Plugin Affects WordPress Donations

The GiveWP plugin prior to version 4.16.3 for WordPress has a vulnerability that fails to restrict access to payment gateways based on the administrator's settings. This flaw allows unauthenticated users to initiate donations using payment gateways that the administrator has explicitly disabled, ...

PoC for CVE-2026-14319

WordPressGiveWP7.5HIGH
Unauthorized Data Exposure in GiveWP WordPress Plugin

The GiveWP plugin for WordPress, prior to version 4.16.3, has a serious flaw that enables unauthorized users to access a REST API endpoint responsible for delivering recurring donation records. This lack of proper access restrictions allows attackers to retrieve sensitive information about anonym...

PoC for CVE-2026-33937

Handlebars-langHandlebars.js9.8CRITICAL
Remote Code Execution Vulnerability in Handlebars by Handlebars.js

In Handlebars versions 4.0.0 through 4.7.8, a vulnerability exists where `Handlebars.compile()` can accept a pre-parsed AST object directly. This leads to the potential injection of arbitrary JavaScript into the generated code because the `value` field of a `NumberLiteral` AST node is emitted dir...

PoC for CVE-2025-64446

FortinetFortiweb🟣 EPSS 92%9.4CRITICAL
Relative Path Traversal Vulnerability in Fortinet FortiWeb Products

A relative path traversal vulnerability exists in Fortinet FortiWeb products versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.4, 7.4.0 to 7.4.9, 7.2.0 to 7.2.11, and 7.0.0 to 7.0.11. This vulnerability allows an attacker to potentially execute unauthorized administrative commands on the system by sending sp...

PoC for CVE-2022-24355

Tp-linkTl-wr940n8.8HIGH
Arbitrary Code Execution Vulnerability in TP-Link Router

This vulnerability exists in the TP-Link TL-WR940N router, allowing attackers in the network vicinity to execute arbitrary code due to insufficient validation of user-supplied data lengths when parsing file name extensions. This flaw can be exploited without authentication, enabling attackers to ...