Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 4 hours ago
PoC for CVE-2026-86321
A vulnerability has been identified in the URL Validation functionality of the java-json-tools jackson-coreutils library, specifically within the 'JsonLoader.fromURL' method. This flaw could allow an attacker to perform server-side request forgery (SSRF), which enables the attacker to exploit the...
Discovered 5 hours ago
PoC for CVE-2026-86319
A vulnerability exists within the json-patch component from java-json-tools, specifically in the JsonPatch.apply function located at src/main/java/com/github/fge/jsonpatch/JsonPatch.java. This vulnerability allows for excessive resource consumption, enabling remote attacks that could lead to Deni...
PoC for CVE-2026-86318
A vulnerability exists in the json-patch component of java-json-tools up to version 1.13, specifically in the JsonMergePatch.fromJson function located in JsonMergePatchDeserializer.java. This flaw can lead to a stack-based buffer overflow, which may be exploited remotely, allowing an attacker to ...
PoC for CVE-2026-86310
A significant SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System 1.0, specifically within an unknown function of the 'cust_edit1.php' file. This flaw allows attackers to manipulate the argument ID, enabling remote exploitation. Such vulnerabilities pose...
Discovered 6 hours ago
PoC for CVE-2026-86309
An SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0 within an unvalidated function in the file /pages/pro_searchfrm.php. This weakness allows attackers to manipulate the ID argument, potentially leading to unauthorized database access and exposure of s...
PoC for CVE-2026-86308
A vulnerability exists in light0011 CMS that allows for remote exploitation through manipulation of the DB_DEBUG argument within the App/Common/Conf/config.php file. This security flaw leads to the unintentional exposure of sensitive information, potentially compromising system security. The issu...
PoC for CVE-2026-86307
A security vulnerability in light0011 CMS has been identified, allowing for potential cross-site request forgery attacks. This flaw enables attackers to initiate unauthorized actions on behalf of authenticated users, posing a significant risk to users' data and system integrity. The issue has bee...
PoC for CVE-2026-86306
A vulnerability has been discovered in the light0011 CMS, specifically within the Cookie Helper component. An issue in the UserModel.class.php file allows attackers to manipulate the Username argument, leading to improper authentication. This issue can potentially be exploited remotely. The affec...
Discovered 7 hours ago
PoC for CVE-2026-86305
A significant vulnerability has been identified in the light0011 CMS, specifically within the Upload::upload function of the ThinkPHP library. This weakness permits unauthorized users to upload files without proper restrictions, potentially leading to unauthorized code execution. The flaw can be ...
PoC for CVE-2026-86302
A security flaw has been identified in the Hospital Information System 1.0 developed by code-projects. This vulnerability is linked to the SQL Database Backup File Handler, specifically in the his.sql file. By manipulating this functionality, unauthorized users may gain access to sensitive inform...
Discovered 8 hours ago
PoC for CVE-2026-86301
A cross-site scripting vulnerability exists in the Hospital Information System (HIS) 1.0, particularly within the Patient Management component found at /HIS/src/patients/editPatient.php. The vulnerability allows attackers to manipulate the 'ID' argument, potentially enabling remote exploitation t...
PoC for CVE-2026-86300
A security flaw has been identified in the Tenda AC9 version 15.03.05.14, specifically in the R7WebsSecurityHandler component of its web management interface. This flaw allows for improper authentication, potentially enabling remote attackers to manipulate access controls. It is essential for use...
PoC for CVE-2026-86299
A vulnerability in the Linksys RE7000 version 2.0.15 allows for OS command injection through the PingTest Handler. Specifically, the manipulation of the pingTestIp, pingTestPktSize, and pingTestTimes parameters in the /cgi-bin/json.cgi?PingTest endpoint can enable an attacker to execute arbitrary...
PoC for CVE-2025-54136
In Cursor Code Editor versions prior to 1.3, a significant vulnerability exists allowing attackers to execute arbitrary code remotely. This occurs through manipulation of a trusted MCP configuration file either within a shared GitHub repository or on the target machine. If an attacker can alter t...
PoC for CVE-2026-86298
A security flaw has been identified in the Class and Exam Timetabling System developed by SourceCodester. Specifically, an SQL injection vulnerability exists within the /delete_subject.php file, where manipulation of the argument ID allows attackers to execute unauthorized database commands. This...
Discovered 9 hours ago
PoC for CVE-2026-86297
A vulnerability has been identified in the D-Link DIR-605 router, specifically within the L2TP Control Message Parser's tunnel_set_params function. This issue arises from improper manipulation of the peer_hostname argument, leading to an off-by-one condition that can allow remote attackers to exp...
PoC for CVE-2026-86296
A vulnerability exists in the D-Link DIR-822A A_101 router related to the strcpy function within the udhcpcd/serverpacket.c file. This weakness can lead to a stack-based buffer overflow, allowing attackers to exploit the vulnerability remotely. The potential risks include unauthorized access and ...
PoC for CVE-2026-86295
A command injection vulnerability has been identified in the D-Link DIR-895L router, specifically in the udhcpcd component's sendACK function within the serverpacket.c file. This flaw allows an attacker to manipulate the Hostname argument to inject and execute arbitrary commands remotely. Given t...
PoC for CVE-2026-86294
A cross-site scripting (XSS) vulnerability exists in the SourceCodester Simple Traffic Offense System 1.0. The issue arises from improper handling of input in the save-settings.php file of the Settings Update Endpoint. By manipulating the parameters site_name or site_desc, an attacker could injec...
Discovered 10 hours ago
PoC for CVE-2026-86293
A vulnerability exists in SourceCodester's Simple Traffic Offense System version 1.0, specifically in the delete-user.php file of the Deletion Endpoint. An attacker can manipulate the argument ID, allowing for unauthorized access and actions due to missing authentication checks. This flaw can be ...
PoC for CVE-2026-86292
A vulnerability in the SourceCodester Simple Traffic Offense System 1.0 was discovered, specifically within the user creation functionality located in the saveuser.php file. This vulnerability arises when the argument position is manipulated, leading to a situation where proper user authenticatio...
PoC for CVE-2026-86291
A vulnerability has been uncovered in the itsourcecode Sales and Inventory System, specifically in the file /pages/us_edit1.php. This flaw allows attackers to exploit an insecure function which processes the 'ID' argument, resulting in SQL injection. Such an exploit enables unauthorized access to...
PoC for CVE-2026-86290
A vulnerability has been discovered in the SourceCodester Online Voting System 1.0, specifically affecting the /voting/ajax.php file when the action 'save_category' is invoked. This flaw allows for SQL injection through the manipulation of the 'Category' argument. Attackers can exploit this vulne...
Discovered 11 hours ago
PoC for CVE-2026-86289
A vulnerability has been identified in the Ollama GGUF Decoder, affecting versions up to 0.31.1. This issue arises from the function readGGUFV1String located in the file fs/ggml/gguf.go. An integer overflow can be triggered through remote manipulation. The exploit details have been made public, h...
PoC for CVE-2026-86288
A significant vulnerability exists in ModelCloud's GPTQModel software, specifically within the Triton dequantization kernel located in the gptqmodel/nn_modules/qlinear/tritonv2.py file. This flaw allows for out-of-bounds read due to improper handling of the argument g_idx, potentially enabling re...
PoC for CVE-2026-86285
A vulnerability has been identified in BookStack impacting versions up to 26.05.2, specifically within the Attachment Edit Endpoint's AttachmentController.php file. The flaw resides in the function AttachmentController::getUpdateForm, where improper access control mechanisms are in place. This vu...
PoC for CVE-2026-86284
A security vulnerability has been identified in the getOption function of the jaychouchannel Tourism-Management-System, specifically in the file travel/src/main/java/com/controller/CommonController.java. This flaw arises from improper handling of the tableName/columnName arguments, potentially le...
Discovered 12 hours ago
PoC for CVE-2026-86282
A vulnerability exists in the jaychouchannel Tourism-Management-System, specifically in the `CommonController.java` file, allowing remote attackers to perform SQL injection attacks through manipulated table and column arguments. This flaw, which does not have public versioning details, poses a se...
PoC for CVE-2026-42559
A vulnerability exists in the RMCP Rust SDK that allows for improper validation of the incoming Host header in its Streamable HTTP server transport. This flaw can be exploited through a DNS rebinding attack, enabling a malicious public website to send authenticated requests to an MCP server runni...
PoC for CVE-2026-86281
A security flaw exists in the SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0, allowing for cross-site request forgery (CSRF) attacks. This vulnerability impacts an unspecified function, enabling unauthorized actions on behalf of authenticated users. The explo...
PoC for CVE-2024-7804
A deserialization vulnerability exists in Pytorch's RPC framework, specifically in the `torch.distributed.rpc` module. The flaw stems from inadequate security verifications during the deserialization of PythonUDF objects, potentially enabling malicious actors to execute arbitrary code remotely. B...
PoC for CVE-2026-86280
A vulnerability identified in the Syllabus-Aligned Learning Management & Examination System 1.0 allows unauthorized manipulation of the file cict_portal.sql. This exploitation results in the cleartext storage of sensitive information, which poses significant risks to data integrity and confidenti...
PoC for CVE-2026-86279
A vulnerability exists in the SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The issue lies within the 'auth_process.php' file, specifically in its unknown functions related to user login. This flaw allows an attacker to manipulate session identifiers, leading to po...
Discovered 13 hours ago
PoC for CVE-2026-86278
A cross-site scripting (XSS) vulnerability exists in the SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability arises from improper handling of user-supplied input in the file manage_subjects.php, specifically within the parameters msg, title, and conten...
PoC for CVE-2026-79698
A command injection vulnerability has been discovered in the Advantech WISE-6610 series devices, specifically affecting the Node-RED Library's function, nodered_lib_apply. An attacker can exploit this vulnerability by manipulating the 'act' argument, allowing for remote command execution. The vul...
PoC for CVE-2026-79697
A command injection vulnerability affects the Advantech WISE-6610 series due to improper handling of input in the basicstation_apply function of the Basic Station Certificate-Deletion Handler. This security flaw allows unauthorized remote exploitation, enabling an attacker to execute arbitrary co...
PoC for CVE-2026-86277
A vulnerability exists within the SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0, specifically in the delete_exam.php file. This issue arises from improper handling of the ID argument, allowing unauthorized users to bypass normal authentication mechanisms and execute...
Discovered 14 hours ago
PoC for CVE-2026-86276
A security flaw has been identified in the SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0, specifically affecting the processing of the db.php file. This vulnerability allows for the potential exploitation of hard-coded credentials, which can be leveraged rem...
PoC for CVE-2026-86275
A vulnerability in the SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0 affects the register function within auth.php. This flaw enables attackers to manipulate the role argument, resulting in improper privilege assignment. The vulnerability allows for potential remote...
PoC for CVE-2026-86274
A vulnerability has been identified in the Authentication Flow of projeto-siga affecting versions up to 11.0.2.10, 11.0.2.13, and 11.1.1. The flaw resides in the ExAutenticacaoController.autenticar function, where improper handling of the cod/jwt argument can lead to unauthorized access. This iss...
PoC for CVE-2026-86273
A security weakness has been discovered in the projeto-siga software, particularly affecting the HTML-to-PDF endpoint. The flaw lies in the function DownloadExterno.getUrl, located in the ExUtilController.java file. This vulnerability allows remote attackers to perform server-side request forgery...
Discovered 15 hours ago
PoC for CVE-2026-86272
A vulnerability has been identified in the U+Smart Enjoyment WebSite, specifically within the /Report/Upload/UploadFormImg.ashx file, where an unrestricted file upload is possible. By manipulating the 'File' argument, an attacker could upload potentially harmful files to the server, leading to se...
PoC for CVE-2026-86271
A security vulnerability was identified in FluentCMS versions up to 0.0.5, specifically within the GetAccessible function located in the PermissionManager.cs file. This flaw results in inadequate authorization checks, allowing unauthorized access when exploited. The vulnerability is particularly ...
PoC for CVE-2026-18963
A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...
PoC for CVE-2026-86270
A SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0, particularly in the settings_edit.php file. An attacker can exploit this vulnerability by manipulating the argument ID, allowing for unauthorized database queries and potential exposure of sensitive i...
PoC for CVE-2026-86269
A vulnerability has been identified in itsourcecode Sales and Inventory System 1.0, specifically within an undisclosed function located in the /pages/emp_edit1.php file. This flaw allows for SQL injection attacks due to improper handling of the argument ID, which can be exploited remotely. Attack...
Discovered 16 hours ago
PoC for CVE-2026-86268
A vulnerability affecting the itsourcecode School Management System 1.0 has been identified, where an unknown function in the User_Login.php file allows for SQL injection through the manipulation of the email argument. This flaw can be exploited remotely, raising concerns about unauthorized datab...
PoC for CVE-2026-86267
A security vulnerability has been identified in the itsourcecode Information System Society Membership System version 1.0, specifically in the file /society/check_student.php. This flaw allows an attacker to manipulate the student_id parameter, leading to potential SQL injection attacks. Such vul...
PoC for CVE-2026-86265
A remote code execution vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0. Specifically, the issue lies within an unknown functionality of the file /pages/us_transac.php, where inadequate sanitization of user input allows for SQL injection through manipu...
PoC for CVE-2026-86264
A cross site scripting vulnerability exists in the ssm_pro application from Sfturing due to an issue in the Order Endpoint functionality. Specifically, the flaw lies in the handling of input parameters such as hospitalName, officesName, and doctorName in the OrderController.java file. This weakne...