Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 2 hours ago
PoC for CVE-2026-89265
MoguBlog versions up to 6.2 are vulnerable to an authorization bypass via the POST /pictureSort/getPictureSortByUid endpoint. This vulnerability arises from the omission of the @AuthorityVerify annotation necessary for enforcing role-based permissions. As a result, authenticated back-office users...
PoC for CVE-2026-89264
MoguBlog versions up to 6.2 contain a vulnerability that improperly validates the identity of the comment author. This issue is present in the POST /web/comment/add endpoint, where authenticated users can exploit the system to post comments that appear to be from any user, including administrator...
PoC for CVE-2026-89262
MoguBlog versions up to 6.2 are exposed to an authorization bypass vulnerability in the comment deletion endpoint. This vulnerability arises from insufficient ownership checks which rely on request-body fields rather than the authenticated user. As a result, attackers are able to delete arbitrary...
PoC for CVE-2026-89263
The MoguBlog platform, through version 6.2, contains a critical flaw where it fails to properly authenticate requests made to the /web/comment/closeEmailNotification endpoint. This vulnerability permits unauthenticated attackers to disable email notifications for any user, simply by modifying a s...
PoC for CVE-2026-89261
The MoguBlog platform, specifically versions up to 6.2, exposes critical Elasticsearch index management endpoints via the mogu_search service without any authentication checks. This oversight allows remote attackers to manipulate the blog's search index in harmful ways, such as deleting entire se...
PoC for CVE-2026-89261
The MoguBlog platform, specifically versions up to 6.2, exposes critical Elasticsearch index management endpoints via the mogu_search service without any authentication checks. This oversight allows remote attackers to manipulate the blog's search index in harmful ways, such as deleting entire se...
PoC for CVE-2026-89261
The MoguBlog platform, specifically versions up to 6.2, exposes critical Elasticsearch index management endpoints via the mogu_search service without any authentication checks. This oversight allows remote attackers to manipulate the blog's search index in harmful ways, such as deleting entire se...
PoC for CVE-2026-89261
The MoguBlog platform, specifically versions up to 6.2, exposes critical Elasticsearch index management endpoints via the mogu_search service without any authentication checks. This oversight allows remote attackers to manipulate the blog's search index in harmful ways, such as deleting entire se...
PoC for CVE-2026-89260
MoguBlog versions up to 6.2 are susceptible to an XML external entity injection vulnerability found in the WeChat callback handler. The WechatRestApi.index() method allows unauthenticated attackers to manipulate request bodies and take advantage of the flawed SignUtil.xmlToMap() implementation, w...
Discovered 3 hours ago
PoC for CVE-2026-89010
WAVLINK WN535M1 and WN535M3 routers with firmware versions earlier than M35M1_V250922 are susceptible to an OS command injection vulnerability. This flaw allows attackers, without authentication, to execute arbitrary commands with root privileges by sending maliciously crafted filenames to the sy...
Discovered 5 hours ago
PoC for CVE-2026-18351
The Drag and Drop File Upload for Elementor Forms plugin for WordPress contains a vulnerability that allows arbitrary file uploads due to inadequate file type validation. Exploitation of the issue occurs via the elementor_file_upload function, where the is_file_type_valid() method improperly vali...
Discovered 6 hours ago
PoC for CVE-2026-81861
A vulnerability exists within Schneider Electric's RTU functionality, exposing authentication information due to insufficiently protected credentials. This could allow unauthorized users to gain access and control over the affected systems, potentially compromising security and operational integr...
PoC for CVE-2022-29900
This vulnerability arises due to mis-trained branch predictions for return instructions in certain AMD processors, potentially allowing attackers to execute arbitrary speculative code under specific microarchitecture-dependent conditions. This could lead to unauthorized information disclosure or ...
Discovered 7 hours ago
PoC for CVE-2026-86813
The MetForm plugin for WordPress versions prior to 4.1.9 contains a vulnerability that fails to neutralize newline characters in user-submitted values. This flaw permits unauthenticated attackers to inject additional headers, such as Bcc, into outgoing notification emails. This can result in unau...
PoC for CVE-2026-85116
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin is vulnerable due to how it processes shortcode parsing across the entire rendered Contact Form 7 form. This vulnerability allows unauthenticated users to execute arbitrary shortcodes that have been registered on the site, potentially ...
PoC for CVE-2026-86809
The Persian Elementor WordPress plugin versions prior to 2.8.2 exhibit a critical flaw in their handling of payment authority returned from ZarinPal payment callbacks. This vulnerability allows unauthorized attackers to exploit a lack of verification, enabling them to finalize orders using valid ...
PoC for CVE-2026-82215
The PayPay for WooCommerce WordPress plugin versions ranging from 0.5 to 0.9.3 is vulnerable due to its failure to authenticate payment notifications effectively. This oversight allows malicious actors, who possess the store's merchant identifier, to manipulate order statuses at will. Attackers c...
PoC for CVE-2026-82213
The Nexi XPay Build WordPress plugin versions 7.6.1 and 7.6.2 are vulnerable due to a flaw that fails to ensure the saved payment token requested is associated with the current user. This issue permits unauthorized individuals to access and retrieve stored card token references, complete with an ...
Discovered 11 hours ago
PoC for CVE-2026-41089
A stack-based buffer overflow vulnerability in Windows Netlogon permits an unauthorized attacker to execute arbitrary code over a network. This flaw may allow attackers to compromise systems by sending specially crafted requests to the affected service, leading to potential system control and dat...
Discovered 12 hours ago
PoC for CVE-2026-86815
The BackWPup WordPress plugin, prior to version 5.7.5, contains an access control vulnerability that inadequately restricts access to multiple REST API endpoints. This flaw allows users with limited roles, assigned by an administrator, to create and execute backup jobs. Consequently, hostile acto...
PoC for CVE-2026-86812
The WPCafe plugin for WordPress prior to version 3.0.18 has a vulnerability that compromises access control for specific order-management REST endpoints. This issue arises from incorrect permission callbacks that fail to appropriately restrict access. As a result, unauthenticated users may gain a...
PoC for CVE-2026-86782
The Visualizer WordPress plugin prior to version 4.0.6 contains an access control weakness that allows unauthorized users with the Contributor role and higher to manipulate content. This includes the ability to publish, rename, or overwrite posts and pages, even affecting private drafts owned by ...
PoC for CVE-2026-86781
The SSL Zen – SSL Certificate Installer & HTTPS Redirects plugin for WordPress is impacted by a privilege escalation vulnerability that allows authenticated users, including those with minimal access such as Subscribers, to download sensitive TLS private keys, certificates, and diagnostic logs. T...
PoC for CVE-2026-85677
The Gutenverse News plugin for WordPress versions prior to 3.3.3 allows attackers to inject arbitrary JavaScript into the comment section. This vulnerability arises from improper sanitization of extra HTML elements, which can enable unauthenticated users to submit malicious comments that will exe...
PoC for CVE-2026-85678
The AI Builder WordPress plugin, prior to version 2.7.8, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw allows users with contributor level access and higher to submit unsanitized custom JavaScript code. When this code is executed within a script tag on the front end, it ...
PoC for CVE-2026-86779
The Visualizer WordPress plugin prior to version 4.0.6 contains a significant authorization flaw that permits users with the Contributor role and above to delete any chart from the site without proper verification of ownership. The vulnerability arises from the plugin's single site-wide capabilit...
PoC for CVE-2026-86780
The Featured Image with URL plugin for WordPress, prior to version 1.0.6, has a flaw where it does not properly sanitize and escape stored image attribute values before outputting them. This oversight allows users with minimal permissions, such as Contributors, to execute Stored Cross-Site Script...
PoC for CVE-2026-82305
The YITH WooCommerce Wishlist plugin prior to version 4.18.1 has a significant flaw where it fails to properly verify user authorization when renaming wishlists. This vulnerability permits unauthenticated users to rename any wishlist available on the site, exploiting the lack of access controls. ...
PoC for CVE-2026-14565
The Advanced-Customized-Prompts WordPress plugin versions up to 1.0.1 is susceptible to a cross-site scripting vulnerability. This issue arises due to insufficient checks on user capabilities, ownership, and nonce verification before storing popup configurations. As a result, authenticated users,...
PoC for CVE-2026-74925
The MultiVendorX WordPress plugin prior to version 5.0.16 contains a critical vulnerability that allows users with the vendor role to modify role and capability settings without restriction. This exploitation can enable them to grant themselves administrator-level permissions, potentially leading...
PoC for CVE-2026-14566
The Advanced-Customized-Prompts plugin for WordPress, specifically versions up to 1.0.1, exhibits an improper access control issue. It fails to implement necessary checks for capability, ownership, or nonces before updating metadata for WooCommerce order items. This oversight permits any authenti...
PoC for CVE-2026-83546
The CoolClock plugin for WordPress before version 4.3.8 contains a vulnerability that fails to properly escape a skin setting before rendering it within an HTML attribute. This oversight permits users with contributor-level access or higher to inject arbitrary web scripts into the page. When the ...
PoC for CVE-2026-14563
The Advanced Customized Prompts plugin for WordPress up to version 1.0.1 contains an authentication bypass vulnerability. This flaw allows unauthenticated users to initiate an authenticated session for any registered user by providing just an email address, without the need for a valid password. ...
PoC for CVE-2026-14562
The teddy-bear-customize-addon plugin for WordPress, specifically up to version 1.0.5, suffers from a vulnerability that allows unauthenticated users to access sensitive WooCommerce order metadata. This includes the URLs of customer-uploaded attachments due to the lack of proper authorization and...
PoC for CVE-2025-15695
The GTranslate WordPress plugin prior to version 3.0.10 contains a security vulnerability that permits users with administrative privileges to manipulate settings without proper validation. This flaw exposes the site to potential cross-site scripting (XSS) attacks, as malicious JavaScript code ca...
PoC for CVE-2026-14560
The Teddy Bear Customize Addon for WordPress, up to version 1.0.5, fails to validate uploaded files adequately. By relying on client-supplied content types and preserving the original filename, the plugin permits unauthorized individuals to upload arbitrary PHP files. This issue can lead to the e...
PoC for CVE-2026-14559
The Teddy Bear Customize Addon for WordPress, up to version 1.0.5, contains a significant vulnerability as it fails to verify users' passwords before authentication. This flaw enables attackers to gain unauthorized access by simply entering the email address of any registered user, potentially co...
PoC for CVE-2026-83545
The CoolClock WordPress plugin prior to version 4.3.8 contains a vulnerability that allows users with contributor-level access and above to inject malicious JavaScript code. This occurs due to improper escaping of a custom skin setting before its output in an inline script. If exploited, this vul...
Discovered 15 hours ago
PoC for CVE-2024-37890
The ws library, an open-source WebSocket client and server for Node.js, is susceptible to a vulnerability that can lead to server crashes when excessive headers are sent in a request. When headers exceed the threshold defined by server.maxHeadersCount, the server may become unresponsive. This iss...
Discovered 20 hours ago
PoC for CVE-2026-0303
Palo Alto Networks Checkov is susceptible to a code execution vulnerability that enables an attacker to execute arbitrary code when the tool scans a directory containing a configuration file under their control. This flaw can expose systems to potential threats, making it crucial for users to ass...
Discovered 23 hours ago
PoC for CVE-2026-73786
A vulnerability exists in the web-based management interface of HPE's CPPM, enabling unauthenticated remote attackers to perform Denial-of-Service (DoS) attacks. This could lead to a degradation in performance and instability of the CPPM server, impacting availability and reliability for users.
Discovered 1 day ago
PoC for CVE-2026-73699
FileRun versions before 2026.3.0 are susceptible to a PHP object injection flaw, which allows authenticated attackers to execute arbitrary code. This vulnerability arises from incorrect options being supplied to the unserialize() function within the Perms::getPerms() method. Instead of using the ...
PoC for CVE-2026-88898
The AppFlowy-Cloud product from AppFlowy has a security flaw in its bulk publish endpoint, which does not adequately verify the authorization of users against workspaces. This oversight allows authenticated users to publish content to other tenants' namespaces. As a result, attackers could potent...
PoC for CVE-2026-86060
MikroTik's RouterOS is vulnerable due to an argument-handling flaw in the SSH login process, specifically affecting usernames that start with a prohibited character. This flaw allows an attacker to manipulate the trusted RouterOS policy mask, facilitating privilege escalation. The exploitation of...
PoC for CVE-2016-3223
This vulnerability occurs in several versions of Microsoft Windows where LDAP authentication is improperly managed. It allows attackers to exploit the way group-policy updates are processed. By manipulating this data stream within a domain controller, an attacker can escalate privileges, potentia...
PoC for CVE-2019-18394
A security flaw exists in the FaviconServlet.java component of Openfire, allowing attackers to exploit the Server Side Request Forgery (SSRF) vulnerability. This enables unauthorized HTTP GET requests to be sent, potentially exposing sensitive data or enabling further attacks on the network. User...
PoC for CVE-2026-78361
The zipMoney Payments Plugin for WooCommerce prior to version 2.4.0 contains a flaw that allows unauthenticated users to bypass authorization checks. This vulnerability enables unauthorized deletion of WordPress options which can compromise site configuration and access controls. Attackers could ...
PoC for CVE-2026-82925
The Site Reviews WordPress plugin prior to version 8.3.0 is vulnerable to a serious deserialization flaw that allows unauthenticated users to inject arbitrary PHP objects. This vulnerability arises from the plugin's failure to properly secure request data during deserialization. It computes a key...
PoC for CVE-2026-81431
The WooCommerce plugin for WordPress, prior to version 1.1.3, contains a vulnerability in its Registration Form functionality. It fails to properly validate the legitimacy of the registration form, inadvertently allowing users with post-creation capabilities (Contributors and above) to register w...
PoC for CVE-2026-77771
The miniOrange 2FA plugin for WordPress prior to version 6.3.1 and 19.3 allows an attacker with knowledge of a victim's password to bypass authentication limits. This occurs because the plugin does not properly associate second-factor authentication attempt limits with user accounts, enabling unl...