Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2026-44402

Voltronic PowerSnmp Web Pro9.3CRITICAL
Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malic...

PoC for CVE-2026-6958

Invicti Security ...Acunetix8.5HIGH
Local Privilege Escalation Vulnerability in Acunetix for Windows

A local privilege escalation vulnerability exists in Acunetix 25.11.251107123 due to the missing hardcoded directory path for OpenSSL-related files in the Web Vulnerability Scanning Engine (wvsc.exe). Low-privileged local attackers can exploit this flaw by creating the missing directory and placi...

PoC for CVE-2026-6958

Invicti Security ...Acunetix8.5HIGH
Local Privilege Escalation Vulnerability in Acunetix for Windows

A local privilege escalation vulnerability exists in Acunetix 25.11.251107123 due to the missing hardcoded directory path for OpenSSL-related files in the Web Vulnerability Scanning Engine (wvsc.exe). Low-privileged local attackers can exploit this flaw by creating the missing directory and placi...

Discovered 3 hours ago

PoC for CVE-2025-8518

GivanzVvveb5.1MEDIUM
Code Injection Vulnerability in Vvveb 1.0.5 by Givanz

A code injection vulnerability has been identified in the Vvveb 1.0.5 Code Editor component, specifically within the Save function of the file admin/controller/editor/code.php. This flaw allows an attacker to execute arbitrary code remotely, significantly compromising the security of affected sys...

Discovered 4 hours ago

PoC for CVE-2026-85522

Valkey-ioValkey6.9MEDIUM
Out-of-Bounds Read Vulnerability in Valkey Slot Migration by Valkey-IO

A security flaw has been identified in the Valkey component related to Slot Migration, specifically within the createSlotImportJob function of the src/cluster_migrateslots.c file. This vulnerability allows a malicious actor to manipulate the job_name argument, leading to out-of-bounds read condit...

PoC for CVE-2026-85517

Code-projectsVehicle Management System6.9MEDIUM
Information Disclosure in Code-Projects Vehicle Management System S...

A security flaw exists in the code-projects Vehicle Management System version 1.0, specifically within an unknown function related to the SQL Database Backup File Handler. This vulnerability allows for remote exploitation, leading to potential information disclosure. Malicious actors could manipu...

PoC for CVE-2026-85516

Code-projectsVehicle Management System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Vehicle Management System

A vulnerability has been identified in the Vehicle Management System version 1.0 developed by Code-Projects. An SQL injection flaw exists in an unspecified function within the file /busprofile.php. This vulnerability allows attackers to manipulate the 'busid' argument, enabling them to execute un...

Discovered 5 hours ago

PoC for CVE-2020-1938

ApacheApache Tomcat🟣 EPSS 99%9.8CRITICAL
Apache Tomcat AJP Connector Insecure Configuration Vulnerability

The Apache JServ Protocol (AJP) Connector in Apache Tomcat allowed for misconfigured connections that could be exploited by attackers. By default, the AJP Connector is enabled, listening on all configured IP addresses. This elevated trust can lead to unauthorized access and manipulation of files ...

PoC for CVE-2026-85514

StackstormSt25.3MEDIUM
Improper Privilege Management in StackStorm API Key Handler

A vulnerability has been identified in the StackStorm st2 API Key Handler, affecting versions up to 3.9.0. This issue arises from an unidentified flaw in the file st2api/st2api/controllers/v1/auth.py, specifically concerning the manipulation of the api_key_api.user argument, leading to improper p...

PoC for CVE-2026-85513

StackstormSt25.3MEDIUM
Improper Privilege Management in StackStorm st2 by OpenStack

A vulnerability has been identified in StackStorm st2 versions up to 3.9.0, specifically in the NoOp RBAC backend. The flaw lies within the function handling user privileges, which can be exploited remotely due to improper management of user authorization. Attackers can manipulate user query para...

Discovered 7 hours ago

PoC for CVE-2026-85512

SourcecodesterClass And Exam Timetab...6.9MEDIUM
Missing Authorization in SourceCodester Class and Exam Timetabling ...

The SourceCodester Class and Exam Timetabling System 1.0 contains a security flaw located in the /admin/session.php file, where improper handling of the argument ID leads to missing authorization. This vulnerability allows an attacker to exploit the system remotely, potentially gaining unauthoriz...

PoC for CVE-2026-31787

LinuxLinux
Double Free Vulnerability in Linux Kernel Affecting Xen Privileged ...

A vulnerability exists in the Linux kernel's privcmd module that can lead to a double free situation due to improper management of virtual memory areas (VMAs). When a partial unmap operation is performed on a privcmd mapping, the kernel can erroneously split the VMA without the necessary controls...

PoC for CVE-2026-84045

WordPressE-cab Taxi Booking Man...5.3MEDIUM
Input validation issue in E-cab Taxi Booking Manager for Woocommerc...

The E-cab Taxi Booking Manager for WooCommerce plugin prior to version 2.0.5 lacks necessary validation for client-supplied trip distance and base price values. This oversight permits unauthenticated users to exploit the system, allowing them to set the order total to zero. Consequently, attacker...

PoC for CVE-2026-84044

WordPressRestaurant Menu And Fo...5.3MEDIUM
Insufficient PayPal Payment Notification Verification in Restaurant...

The Restaurant Menu and Food Ordering WordPress plugin, prior to version 2.4.12, is vulnerable due to its failure to validate PayPal payment notifications. This oversight allows attackers to exploit the system by submitting fraudulent payment notifications, thereby marking their orders as paid wi...

PoC for CVE-2026-82923

WordPressAi Website Builder (gi...9.8CRITICAL
Authorization Bypass in AI Website Builder Plugin for WordPress

The AI Website Builder plugin for WordPress (version 1.0.0) is susceptible to an authorization bypass vulnerability due to the absence of authentication checks on its REST API routes. This flaw permits unauthenticated attackers to carry out a range of malicious activities, such as installing and ...

PoC for CVE-2026-84043

WordPressEpayco Payment Gateway...5.3MEDIUM
Payment Gateway Authentication Flaw in ePayco for WooCommerce by Wo...

The ePayco Payment Gateway for WooCommerce WordPress plugin prior to version 8.4.7 features a critical flaw in its payment confirmation request verification process. This vulnerability allows unauthenticated attackers to fraudulently mark orders as paid without a valid signature from the payment ...

Discovered 8 hours ago

PoC for CVE-2026-20212

CiscoCisco Nx-os Software9.8CRITICAL
Remote Code Execution Vulnerability in Cisco Nexus 9000 Series Swit...

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches permits unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability arises from the accessibility of TCP ports 43210 and 43211 within the default Layer 3 (L3) virtual routin...

Discovered 11 hours ago

PoC for CVE-2023-54391

Proxmox Server So...Proxmox Virtual Enviro...9.3CRITICAL
Authentication Bypass Vulnerability in Proxmox Virtual Environment

Proxmox Virtual Environment versions from 7.0 to 8.0 are affected by an authentication bypass vulnerability in the libpve-access-control component. Attackers can exploit this vulnerability by sending an arbitrary tfa-challenge value to the API login endpoint, which allows them to bypass password ...

PoC for CVE-2026-84146

WordPressXpro Addons — 140+ Wid...5.3MEDIUM
Information Exposure in Xpro Addons for Elementor Plugin by WordPress

The Xpro Addons for Elementor WordPress plugin prior to version 1.7.8 is susceptible to information exposure due to a lack of proper capability checks. This flaw permits unauthenticated users to access detailed information about WooCommerce products, including title, price, SKU, description, and ...

PoC for CVE-2026-84066

WordPressDirectorist: Ai-powere...3.1LOW
Insecure Permissions in Directorist Plugin for WordPress

The Directorist plugin for WordPress prior to version 8.9 has a security vulnerability that does not adequately verify whether a user requesting to modify a post's metadata is the actual owner of that post. This oversight allows users with subscriber-level permissions and above to modify image me...

PoC for CVE-2026-82194

WordPressWPvivid — Backup, Migr...5.5MEDIUM
File Deletion Vulnerability in WPvivid Backup WordPress Plugin

A vulnerability exists in the WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.134, allowing unauthorized file deletions. The plugin fails to properly validate user-supplied paths in its file deletion routine. As a result, an attacker, potentially an administrator, ca...

PoC for CVE-2026-82186

WordPressWPlp Cookie Consent4.1MEDIUM
SQL Injection Vulnerability in WPLP Cookie Consent Plugin by WordPress

The WPLP Cookie Consent plugin for WordPress prior to version 4.4.2 has a flaw in the validation of the pagination parameter utilized in SQL queries. This vulnerability enables users with administrative access to execute malicious SQL queries, potentially compromising the database. Administrators...

PoC for CVE-2026-82193

WordPressWPvivid — Backup, Migr...5.5MEDIUM
File Write Vulnerability in WPvivid Plugin by WPvivid Team

The WPvivid Backup, Migration & Staging plugin for WordPress allows an attacker with administrative access to exploit insufficient validation of user-supplied file names. This leads to arbitrary file write capabilities, permitting administrators to save files to unintended locations on the server...

PoC for CVE-2026-81347

WordPressFrontend Admin By Dyna...5.9MEDIUM
Directory Traversal Vulnerability in Frontend Admin by DynamiApps

The Frontend Admin plugin for WordPress, developed by DynamiApps, has a vulnerability that allows unauthenticated attackers to exploit improper validation of user-controllable directory paths. This flaw permits the deletion of critical files such as index.php and .htaccess, which can severely dis...

PoC for CVE-2026-80438

WordPressNinja Forms5.9MEDIUM
Access Control Flaw in Ninja Forms Plugin by WordPress

The Ninja Forms plugin for WordPress, up to version 3.15.2, has a significant access control issue that allows unauthorized users with specific capabilities to access sensitive data. This vulnerability enables such users to read the plugin's configuration settings and stored form submissions. Fur...

PoC for CVE-2026-79631

WordPressWPfunnels5.3MEDIUM
Access Control Vulnerability in WPFunnels WordPress Plugin

The WPFunnels plugin for WordPress prior to version 3.13.0 features an access control oversight, permitting unauthenticated users to download sensitive log files stored in a predictable location within the public uploads directory. This issue arises when logging is enabled, potentially exposing c...

PoC for CVE-2026-79632

WordPressWPfunnels5.3MEDIUM
Authorization Flaw in WPFunnels Plugin for WordPress

The WPFunnels WordPress plugin before version 3.13.0 has a significant vulnerability that lacks proper authorization or nonce checks in an opt-in submission handler. This oversight enables unauthenticated users to exploit the system, potentially sending emails to any recipient with a chosen subje...

PoC for CVE-2026-79630

WordPressWPfunnels5.3MEDIUM
Checkout Order Bump Exploit in WPFunnels WordPress Plugin

The WPFunnels plugin for WordPress, prior to version 3.13.0, contains a security issue where it fails to properly verify that the product selected through a checkout order bump corresponds to the product intended for the discount. As a result, this flaw allows unauthenticated users to exploit the...

PoC for CVE-2026-19224

WordPressHummingbird Performance7.2HIGH
Arbitrary Code Execution Vulnerability in Hummingbird Performance P...

The Hummingbird Performance plugin for WordPress is vulnerable due to improper restrictions on network-wide settings. This flaw enables an administrator of any individual site within a multisite network to execute arbitrary code, thereby compromising the entire network's security. This vulnerabil...

PoC for CVE-2026-74853

WordPressPods6.8MEDIUM
Vulnerability in Pods WordPress Plugin Allows Unauthorized File Access

The Pods WordPress plugin versions earlier than 3.3.9.2 have a vulnerability that permits users with the author role and higher to access unauthorized files on the server. This occurs due to insufficient restrictions on display callback functions, enabling the retrieval of arbitrary files, includ...

PoC for CVE-2026-16281

WordPressClassified Listing7.1HIGH
Improper Authorization in Classified Listing WordPress Plugin

The Classified Listing WordPress plugin before version 6.1.1 contains a vulnerability due to insufficient authorization checks. This flaw permits authenticated users, including those with minimal privileges such as subscribers, to execute AI image-editing actions via AJAX. Consequently, these use...

PoC for CVE-2026-17517

WordPressContent Views5.3MEDIUM
Access Control Flaw in Content Views WordPress Plugin by WordPress

The Content Views plugin for WordPress prior to version 4.5.1.2 is susceptible to an access control vulnerability. It fails to verify whether a user requesting a view has the appropriate permissions to access the posts it returns. As a result, unauthenticated attackers can gain access to the titl...

PoC for CVE-2025-15691

WordPressWPfunnels5.3MEDIUM
User Account Creation Vulnerability in WPFunnels Plugin by WordPress

The WPFunnels plugin for WordPress prior to version 3.13.0 has a vulnerability that permits unauthenticated attackers to create user accounts without verifying if user registration is enabled. This flaw stems from the plugin's reliance on request-supplied values, which compromises site security b...

Discovered 13 hours ago

PoC for CVE-2026-85409

EleveoQuality Management5.3MEDIUM
Path Traversal Vulnerability in Eleveo Quality Management Software

A security vulnerability exists in the Eleveo Quality Management software version 9.7.0, specifically within the QuestionnaireService.runDataExportNow function of the Questionnaire Service component. This flaw allows attackers to manipulate the 'file_name' argument, potentially enabling them to p...

PoC for CVE-2026-85408

EleveoQuality Management5.3MEDIUM
Eleveo Quality Management 9.7.0 Vulnerability in Conversation Handl...

A vulnerability exists in the Conversation Handler component of Eleveo Quality Management version 9.7.0. An argument manipulation related to the createdBy attribute allows attackers to access dynamically-determined object attributes. This flaw facilitates potential remote exploitation, posing sec...

PoC for CVE-2026-85407

EleveoQuality Management5.3MEDIUM
Denial of Service Vulnerability in Eleveo Quality Management by Eleveo

A significant vulnerability has been identified in Eleveo Quality Management 9.7.0, specifically located within the Conversation Handler component. The flaw resides in the handling of specific arguments within the file /enc-fwk-data/api/v3/conversations/<ID>/events. When manipulated, these argume...

Discovered 14 hours ago

PoC for CVE-2026-85406

EleveoQuality Management5.1MEDIUM
Cross Site Scripting Vulnerability in Eleveo Quality Management by ...

A cross site scripting (XSS) vulnerability has been identified in Eleveo Quality Management version 9.7.0, specifically within the Conversation Review component. This vulnerability allows attackers to execute arbitrary scripts in the context of users' browsers, potentially leading to session hija...

PoC for CVE-2026-85405

EleveoCall Recording Software5.1MEDIUM
Cross Site Scripting Vulnerability in Eleveo Call Recording Software

A vulnerability has been identified in Eleveo Call Recording Software version 9.7.0, affecting the file /callrec/roleAddAction.do. By manipulating the 'name' or 'username' argument, an attacker can execute cross site scripting (XSS) attacks remotely. This flaw poses a significant risk, as it allo...

PoC for CVE-2026-85403

Code-projectsDoctor Appointment System6.9MEDIUM
SQL Injection Vulnerability in Doctor Appointment System by Code-Pr...

A code vulnerability exists in the Doctor Appointment System version 1.0, specifically in the processing of the `/contactus.php` file. This vulnerability allows for SQL injection via manipulation of the `firstname` argument. An attacker can exploit this issue remotely, potentially leading to unau...

PoC for CVE-2026-85402

Code-projectsDoctor Appointment System6.9MEDIUM
SQL Injection Vulnerability in Doctor Appointment System by Code-Pr...

A vulnerability in the Doctor Appointment System version 1.0 has been identified, specifically within the /patient/booking.php file. The flaw arises from improper handling of the doc_id parameter, which enables attackers to execute SQL injection attacks. This vulnerability can be exploited remote...

Discovered 15 hours ago

PoC for CVE-2026-85401

DolibarrDolibarr5.3MEDIUM
Access Control Weakness in Dolibarr Legacy File Manager

A vulnerability has been identified in the Dolibarr Legacy File Manager affecting versions up to 21.0.4, 22.0.5, and 23.0.3. The flaw exists in the configuration file located at htdocs/core/filemanagerdol/connectors/php/config.inc.php, where improper access controls can be exploited remotely. Thi...

PoC for CVE-2026-85399

Code-projectsHospital Information S...6.9MEDIUM
SQL Injection Vulnerability in code-projects Hospital Information S...

A significant security flaw has been identified in the Hospital Information System 1.0 developed by code-projects, specifically within the function getSinglePresp located in includes/presp/PrespController.php. This vulnerability allows attackers to manipulate the argument ID, resulting in SQL inj...

PoC for CVE-2026-4813

LuteceLutece Core9.4CRITICAL
Remote Code Execution Vulnerability in Lutece Core Export Managemen...

A vulnerability in the Lutece Core XSL export management module allows authenticated administrators to execute arbitrary code remotely due to the absence of secure processing mode in XML/XSLT processing configuration. Attackers with administrator privileges can exploit this flaw by uploading a cr...

PoC for CVE-2026-85398

Code-projectsHospital Information S...6.9MEDIUM
SQL Injection Vulnerability in Hospital Information System by Code-...

A flaw exists in the Hospital Information System 1.0, specifically within the viewReq function found in viewReq.php, which allows for SQL injection attacks. By manipulating the ID argument, attackers may execute arbitrary SQL queries against the database, leading to potential exposure of sensitiv...

PoC for CVE-2026-75604

VercelNext.js9CRITICAL
Remote Code Execution Vulnerability in Next.js Framework by Vercel

Next.js, a popular framework for building web applications, contains a vulnerability that allows an attacker to exploit improper escaping of backslashes in route segments. When an application accepts crafted remote requests on Windows-hosted servers, it can unintentionally construct incremental-c...

PoC for CVE-2026-85397

Code-projectsHospital Information S...6.9MEDIUM
SQL Injection Vulnerability in Hospital Information System by Code-...

A vulnerability exists in the Hospital Information System by Code-Projects that allows for SQL injection through the 'findBySearch' function in 'addReq.php'. This issue arises from improper handling of user input, which can be exploited remotely. As a result, an attacker could manipulate the sear...

Discovered 16 hours ago

PoC for CVE-2026-85383

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A security flaw has been identified in the itsourcecode Sales and Inventory System version 1.0, specifically within the /pages/inv_del.php file. An attacker can exploit this vulnerability by manipulating the argument ID, potentially allowing for SQL injection attacks that can be executed remotely...

PoC for CVE-2026-85382

Light0011Cms5.3MEDIUM
Cross-Site Scripting Vulnerability in light0011 CMS Chapter Content...

A vulnerability has been identified in the light0011 CMS specifically within the Chapter Content Output component. The issue lies in the function htmlspecialchars_decode located in the file App/Home/View/Default/Chapter/oneChapter.tpl. This flaw allows an attacker to manipulate the argument conte...

PoC for CVE-2026-85381

Light0011Cms6.9MEDIUM
Authorization Bypass in Light0011 CMS Chapter Controller

A security flaw has been identified in the Chapter Controller of Light0011 CMS due to improper processing of input arguments, which can result in authorization bypass. This vulnerability allows an attacker to manipulate content arguments remotely, potentially gaining unauthorized access to sensit...

Discovered 17 hours ago

PoC for CVE-2026-52810

GogsGogs7.1HIGH
Unauthorized Push Vulnerability in Gogs Git Service

Gogs, an open-source self-hosted Git service, is susceptible to an improper authorization vulnerability. Prior to version 0.14.3, the service's handling of Git smart HTTP requests permitted unauthorized users to perform push operations using the client-supplied service query string. This weakness...