Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2024-3094
The XZ utility has been compromised due to malicious code introduced in the upstream tarballs starting from version 5.6.0. A sophisticated obfuscation technique is employed where the liblzma build process extracts a prebuilt object file hidden within a disguised test file in the source code. This...
PoC for CVE-2026-45729
A null pointer dereference vulnerability was identified in the Thor Vector Graphics Engine (ThorVG) prior to version 1.0.5. This vulnerability can cause the engine to crash when untrusted SVG data is processed through the Picture::load() function via the SvgLoader::run(). Attackers can exploit th...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-56139
The Apache Camel Undertow Component contains a vulnerability that allows unauthorized clients to receive detailed error messages, including Java stack traces, during route processing failures. This occurs due to a misconfiguration of the muteException option, which defaults to false. This can lea...
PoC for CVE-2026-55994
In the Apache Camel framework, the Iggy component has a vulnerability that allows unauthorized actors to exploit improper input validation, resulting in Server-Side Request Forgery (SSRF) and exposure of sensitive information. The issue arises as the Iggy component does not filter Camel-internal ...
PoC for CVE-2026-55993
A vulnerability in the Atmosphere Websocket Component of Apache Camel allows attackers to exploit improper input validation in inbound WebSocket queries. The absence of a HeaderFilterStrategy enables clients to inject control headers into the Camel Exchange. This results in potential server-side ...
PoC for CVE-2025-64512
Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...
Discovered 5 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 7 hours ago
PoC for CVE-2026-50522
The vulnerability allows an attacker to send specially crafted payloads to Microsoft Office SharePoint, potentially resulting in unauthorized remote code execution. This security flaw occurs due to the improper handling of untrusted data. If exploited, it could enable malicious actors to execute ...
Discovered 9 hours ago
PoC for CVE-2026-25632
The EPyT-Flow Python package, which facilitates the generation of hydraulic and water quality scenario data for water distribution networks, contains a vulnerability that enables remote code execution. Prior to version 0.16.1, the package's REST API incorrectly processes attacker-manipulated JSON...
Discovered 11 hours ago
PoC for CVE-2024-27867
The CVE-2024-27867 vulnerability affects a wide range of Apple’s wireless audio devices, including AirPods (2nd generation and later), AirPods Pro (all models), AirPods Max, Powerbeats Pro, and Beats Fit Pro. It allows an attacker within Bluetooth range to spoof the intended source device and gai...
PoC for CVE-2026-12987
The Events Manager plugin for WordPress versions prior to 7.3.7 is vulnerable due to improper handling of booking-registration data in No-User-Account Booking Mode. Specifically, a registration field supplied by the booker is stored as booking metadata and later deserialized without restrictions ...
PoC for CVE-2026-14322
The Timetics WordPress plugin, prior to version 1.0.57, has a significant vulnerability that allows unauthorized users to create fully-approved bookings for paid appointments. This occurs due to the lack of enforcement of a pending or unpaid status for new bookings made through unsupported paymen...
PoC for CVE-2026-12968
The Product Addons and Product Options With Custom Fields plugin for WordPress prior to version 1.6.15 is susceptible to an unauthenticated file upload vulnerability. This flaw allows attackers to exploit a file-upload endpoint that fails to properly restrict access, letting an unauthenticated us...
Discovered 14 hours ago
PoC for CVE-2026-57588
A SQL injection vulnerability exists in Nessus that allows attackers to create a harmful scan result file. When a privileged user imports this file, it may result in malicious SQL being injected into the scan results database. This exploitation could lead to unauthorized access and potential data...
PoC for CVE-2026-60137
A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...
PoC for CVE-2026-60137
A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...
Discovered 15 hours ago
PoC for CVE-2025-32432
Craft CMS, a customizable content management system, has a remote code execution vulnerability present in specific versions. Attackers could exploit this flaw to execute arbitrary code on the server, posing a significant security risk. The affected versions span from 3.0.0-RC1 to just before 3.9....
Discovered 16 hours ago
PoC for CVE-2026-16492
A security weakness has been discovered in the GIT File Helper component of umijs. Specifically, the function git.getFileCreateInfo located in packages/utils/src/getFileGitIno.ts is susceptible to OS command injection. This vulnerability could enable attackers to execute arbitrary commands on the...
Discovered 17 hours ago
PoC for CVE-2026-16490
A security vulnerability has been identified in itsourcecode Hospital Management System 1.0, specifically within an unspecified function of the /prescription.php file. This flaw allows attackers to inject malicious SQL queries through the manipulation of the 'editid' argument, leading to potentia...
Discovered 18 hours ago
PoC for CVE-2026-16489
A vulnerability has been discovered in the jsforce library, specifically in the function _execCommand located in lib/registry/sfdx.js. This flaw allows for os command injection, posing a risk to local environments where the code is executed. Exploitation of this vulnerability can lead to unauthor...
PoC for CVE-2026-16488
A security flaw was identified in QUSETIONS MiniCode-Python version 0.1.0, specifically impacting the subprocess.Popen function within the Project File Handler component. This vulnerability allows for potential OS command injection, creating a pathway for attackers to execute arbitrary commands o...
PoC for CVE-2026-16486
A vulnerability exists in SourceCodester's Class and Exam Timetabling System 1.0 within the /BSIS.php file. This vulnerability enables an attacker to manipulate the 'day' argument, which can lead to Cross Site Scripting (XSS) attacks. Since the exploit can be initiated remotely, it poses a signif...
Discovered 19 hours ago
PoC for CVE-2026-16485
A cross site scripting vulnerability exists in the SourceCodester Class and Exam Timetabling System 1.0, specifically related to the manipulation of the 'day' argument in the /class.php file. This flaw enables an attacker to execute arbitrary scripts in the user's browser, which can compromise se...
PoC for CVE-2026-53913
The Apache Camel Keycloak Component contains a vulnerability where improper authentication leads to potential unauthorized access. The KeycloakSecurityPolicy’s default configuration may allow requests with invalid tokens to bypass checks entirely. This means that as long as a request carries a no...
Discovered 20 hours ago
PoC for CVE-2026-16484
A vulnerability has been identified in the SourceCodester Class and Exam Timetabling System 1.0, specifically within the /edit_subjecta.php file. This vulnerability allows for SQL injection attacks through manipulation of the argument ID, potentially enabling an attacker to execute arbitrary SQL ...
PoC for CVE-2026-8989
The Autel Maxi Charger Single firmware version V1.03.51 contains a significant vulnerability that allows unauthorized access to the NXP i.MX6 recovery mode via exposed hardware recovery pins. This flaw permits attackers with physical access to execute malicious code, enabling them to modify or ex...
PoC for CVE-2026-27654
A vulnerability exists within the ngx_http_dav_module of NGINX Open Source and NGINX Plus that can be exploited to trigger a buffer overflow in the NGINX worker process. This scenario is possible when configuration files utilize the DAV module's MOVE or COPY methods combined with specific prefix ...
PoC for CVE-2026-63080
A SQL injection vulnerability exists within Aptabase's ClickHouse query backend, stemming from commit 5a89368. This flaw enables authenticated attackers to exploit unsanitized filter parameters in Liquid SQL templates, allowing unauthorized access to event data across multiple tenants. By manipul...
PoC for CVE-2024-3094
The XZ utility has been compromised due to malicious code introduced in the upstream tarballs starting from version 5.6.0. A sophisticated obfuscation technique is employed where the liblzma build process extracts a prebuilt object file hidden within a disguised test file in the source code. This...
Discovered 21 hours ago
PoC for CVE-2026-64822
The djangoSIGE product, up to version 1.10, contains a vulnerability that allows unauthenticated attackers to exploit the ForgotPasswordView functionality. By interacting with the password reset endpoint, attackers can submit arbitrary usernames or email addresses and determine if they correspond...
Discovered 22 hours ago
PoC for CVE-2016-20096
Linknat VOS3000 and VOS2009 versions up to 2.1.2.0 are susceptible to an unauthenticated SQL injection vulnerability via the login endpoint's name parameter. This flaw allows remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data. By manip...
PoC for CVE-2016-20096
Linknat VOS3000 and VOS2009 versions up to 2.1.2.0 are susceptible to an unauthenticated SQL injection vulnerability via the login endpoint's name parameter. This flaw allows remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data. By manip...
PoC for CVE-2025-64512
Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...
PoC for CVE-2026-49365
A vulnerability exists in the Apache Camel Netty HTTP component, where error messages include sensitive internal information due to configuration settings. Specifically, the 'muteException' option defaults to false, leading to the exposure of detailed Java stack traces during processing errors. T...
Discovered 23 hours ago
PoC for CVE-2026-49099
The Apache Camel Salesforce Component is susceptible to an authorization bypass due to improper handling of special elements in output. This vulnerability allows an attacker to manipulate SOQL queries, SOSL searches, and other Salesforce operations by controlling the HTTP headers that are passed ...
Discovered 1 day ago
PoC for CVE-2026-6875
A remote code execution vulnerability has been identified in the ServiceNow AI platform, allowing an unauthenticated user to execute arbitrary code under specific conditions. The vendor has implemented a security update that addresses this vulnerability for all hosted instances and provided updat...
PoC for CVE-2026-16451
A security flaw exists in the ZS-Admin product developed by zsadmin2025, specifically affecting the file handling component com.zs.file.controller.SysFileController. This vulnerability allows for unrestricted file uploads through manipulation of the File argument in the /api/system/file/upload en...
PoC for CVE-2026-16450
A significant vulnerability has been detected in the ZS-Admin product by zsadmin2025, specifically within the MyBatis-Plus Tenant Plugin. The flaw resides in the getTenantId function of the /api/system/sys/dept/page file, where manipulation of the X-Tenant-Id argument allows unauthorized access t...
PoC for CVE-2026-16449
A vulnerability exists in ZS-Admin software that affects the functionality of the OrderItem.asc and OrderItem.desc methods within the SysDeptController component. This weakness arises from improper validation of user input in the orderField parameter, enabling attackers to execute SQL injection a...
PoC for CVE-2026-16448
A command injection vulnerability exists in D-Link NAS devices, including models such as DNS-120 and DNS-320. The flaw arises in the 'cgi_check_rsync_rw' function within the 'remote_backup.cgi' file. By manipulating the 'ip' argument, an attacker can execute arbitrary commands remotely. This vuln...
PoC for CVE-2026-16447
A security flaw has been identified in D-Link's DNS-320 version 1.0.2, specifically within the multi_uploadify.php file. This vulnerability allows attackers to manipulate the Filedata[] argument, leading to unrestricted file uploads. The potential for remote exploitation is significant, given tha...
PoC for CVE-2026-52910
A vulnerability exists in the Linux kernel's handling of UDP reuse ports which may lead to buffer overflow issues. When a cBPF program is replaced while another thread is sending a UDP packet to the reuse port group, improper resource management can occur. Specifically, the reuseport program is f...
PoC for CVE-2026-62183
An improper privilege management vulnerability in Apache Syncope allows users to misuse defined Roles through a compromised REST API call. When the all-Java or Flowable user workflow adapters are incorrectly configured, users may escalate their privileges by granting themselves roles without prop...
PoC for CVE-2026-8082
The bpost-shipping-platform WordPress plugin, prior to version 3.2.3, is susceptible to a SQL injection vulnerability due to improper parameter sanitization during WooCommerce order processing. This flaw permits unauthenticated attackers to execute time-based blind SQL injection attacks, potentia...
PoC for CVE-2026-14185
The WPBot plugin for WordPress has a security vulnerability where it fails to perform necessary capability and nonce checks in its settings handlers. This oversight allows authenticated users with subscriber-level access to modify configurations within the WPBot plugin prior to version 8.2.0. Suc...
PoC for CVE-2026-11767
The Free Builder for Elementor plugin for WordPress prior to version 1.6.7 is vulnerable to a stored cross-site scripting (XSS) flaw. This vulnerability arises because the plugin does not sanitize user input from contact form fields, allowing unauthenticated attackers to craft malicious payloads....
PoC for CVE-2026-14184
The Academy LMS plugin for WordPress prior to version 3.8.1 contains a significant security flaw in its lesson AJAX handlers. The vulnerability arises from the failure to verify the ownership of user-supplied identifiers, allowing authenticated users with minimal permissions, such as subscribers,...
PoC for CVE-2026-13694
The Bit Form WordPress plugin prior to version 3.1.0 is prone to a security issue where it fails to properly validate its workflow-trigger token after the associated transient expires. As a result, unauthenticated attackers can exploit this weakness to re-trigger form actions, including sending n...