Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2024-40891

ZyxelVmg4325-b10a Firmware🟣 EPSS 22%8.8HIGH
Command Injection Vulnerability in Zyxel DSL CPE Firmware

A post-authentication command injection vulnerability exists in the management commands of Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615. This flaw allows an authenticated attacker to execute arbitrary operating system commands via Telnet, potentially compromising the security and i...

Discovered 58 minutes ago

PoC for CVE-2026-19790

TendaG08.7HIGH
Stack-Based Buffer Overflow in Tenda G0 Web Management Interface

A vulnerability exists in the Tenda G0's Web Management Interface, specifically within the function formSetPortMirror located in the /goform/module file. This issue arises from improper handling of the argument portMirrorMirroredPorts, leading to a stack-based buffer overflow. The vulnerability c...

Discovered 1 hour ago

PoC for CVE-2026-19789

TendaAc12068.7HIGH
Buffer Overflow Vulnerability in Tenda AC1206 Router's Web Manageme...

A security flaw exists in the Tenda AC1206 router's web management interface, specifically within the function set_wl_guest_iplist located in /goform/WifiGuestSet. This vulnerability allows for a stack-based buffer overflow due to improper handling of the shareSpeed argument. Successful exploitat...

PoC for CVE-2026-19788

TendaAc12068.7HIGH
Stack-Based Buffer Overflow in Tenda AC1206 Web Management Interface

A stack-based buffer overflow vulnerability exists in the Tenda AC1206 web management interface, specifically within the set_device_name function of the /goform/SetOnlineDevName endpoint. By manipulating the devName parameter, an attacker can exploit this vulnerability remotely, leading to potent...

Discovered 2 hours ago

PoC for CVE-2026-19787

SourcecodesterAir Cargo Management S...5.1MEDIUM
SQL Injection Vulnerability in SourceCodester Air Cargo Management ...

A vulnerability exists in the SourceCodester Air Cargo Management System version 1.0 that allows for SQL injection through the manipulation of the ID parameter in the Master.php file, specifically within the save_cargo_type function. This vulnerability can be exploited remotely, enabling attacker...

PoC for CVE-2026-19784

FrancoisjacquetRosariOSis5.3MEDIUM
Authorization Bypass in RosarioSIS by Francoiscjacquet

A vulnerability has been identified in RosarioSIS versions prior to 12.9, specifically affecting the DBUpdate function within Discipline/Referrals.php. This flaw results in an authorization bypass that can be exploited remotely. The exploit is publicly available, posing substantial risks to users...

Discovered 3 hours ago

PoC for CVE-2026-19771

BaicellsEg3661m8.6HIGH
OS Command Injection Vulnerability in Baicells EG3661M LuCI Web Int...

A vulnerability exists in the Baicells EG3661M due to improper handling of MaxHops, Timeout, and Size parameters in the LuCI Web Interface. This flaw allows an attacker to execute arbitrary commands on the operating system through remote exploitation. Without a timely vendor response to reported ...

PoC for CVE-2026-19770

FeedmobFm-mcp-servers4.8MEDIUM
Server-Side Request Forgery Vulnerability in Feedmob FM-MCP-Servers

A security vulnerability exists in Feedmob's FM-MCP-Servers version 0.0.3, specifically within the 'downloadReport' function located in the Download Endpoint module. This issue arises from the manipulation of the 'downloadUrl' argument, enabling an attacker to perform server-side request forgery ...

PoC for CVE-2026-19767

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability has been detected in the itsourcecode Hospital Management System 1.0, specifically in the file viewdoctortimings.php. This issue arises from improper handling of input parameters, primarily the 'delid' argument, which enables remote attackers to execute SQL injection attacks. Such...

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 98%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-19765

EyaushevSwagger-testcase-mcp5.3MEDIUM
Server-Side Request Forgery Vulnerability in eyaushev swagger-testc...

A security flaw has been identified in eyaushev swagger-testcase-mcp, specifically impacting the loadSource function within the swagger-parser.ts file. This vulnerability allows remote attackers to manipulate requests and exploit the application for server-side request forgery. The issue was repo...

Discovered 4 hours ago

PoC for CVE-2026-19764

RaisecomCommunication Command ...6.9MEDIUM
SQL Injection Vulnerability in Raisecom Communication Command and D...

A SQL injection vulnerability has been discovered in the Raisecom Communication Command and Dispatch Management Platform, specifically affecting the /app/users/getpwd.php file in versions up to 7.6.5. This flaw allows attackers to manipulate the 'sip' argument, potentially leading to unauthorized...

Discovered 5 hours ago

PoC for CVE-2026-19758

DromaraLamp-cloud6.9MEDIUM
Path Traversal Vulnerability in Dromara Lamp-Cloud by Dromara

A vulnerability has been identified in Dromara Lamp-Cloud versions up to 5.10.0, specifically within the FileChunkController.java component associated with the chunk-check endpoint. This flaw allows an attacker to manipulate the 'Name' argument, potentially leading to a path traversal attack. Suc...

PoC for CVE-2026-53413

Zoom CommunicationsZoom Clients8.3HIGH
Buffer Overwrite Vulnerability in Zoom Clients by Zoom

A buffer overwrite vulnerability exists in the annotator function of Zoom Clients, enabling a malicious meeting participant to execute arbitrary code on another participant's device by exploiting this flaw via network access. This security concern underscores the importance of keeping Zoom Client...

PoC for CVE-2026-19757

DromaraLamp-cloud6.9MEDIUM
Path Traversal Vulnerability in Dromara Lamp-Cloud Product

A path traversal vulnerability exists in the File-Upload Controller (FileAnyoneController.java) of Dromara's lamp-cloud product versions up to 5.10.0. By manipulating the 'bucket' or 'bizType' parameters, an attacker can access restricted directories and potentially execute arbitrary code. Althou...

PoC for CVE-2026-33017

Langflow-aiLangflow🟣 EPSS 96%9.3CRITICAL
Authentication Bypass in Langflow Tool for AI-Powered Workflows

Langflow, a tool for constructing and deploying AI-driven agents and workflows, is susceptible to a vulnerability in the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint in versions before 1.9.0. This vulnerability enables an attacker to build public flows without authentication, leveraging ...

Discovered 6 hours ago

PoC for CVE-2026-25938

FrangoteamFuxa9.5CRITICAL
Authentication Bypass in FUXA Web-Based Process Visualization Software

FUXA, a web-based Process Visualization software, is susceptible to an authentication bypass vulnerability when the Node-RED plugin is enabled. This flaw allows an unauthenticated remote attacker to execute arbitrary code on the server, posing a significant risk to system integrity. This issue ha...

PoC for CVE-2026-19756

DromaraLamp-cloud5.3MEDIUM
Path Traversal Vulnerability in Dromara Lamp-Cloud Software

A path traversal vulnerability has been identified in the Dromara Lamp-Cloud software's Code Generator component, specifically within the DefGenProjectController.java file. Attackers can exploit this vulnerability by manipulating the outputDir, parent, or projectPrefix arguments, enabling remote ...

PoC for CVE-2026-19753

Model Context Pro...Mcp-rdf-explorer6.9MEDIUM
Server-Side Request Forgery Vulnerability in MCP-RDF-Explorer by Em...

A server-side request forgery vulnerability has been identified in MCP-RDF-Explorer version 1.0.0. This issue arises in the explore_url function within the server.py file of the MCP Server component. By manipulating the url argument, an attacker can execute unauthorized requests from the server, ...

PoC for CVE-2026-19752

EnzovezzaroMcp-dominican-layer5.3MEDIUM
Server-Side Request Forgery in PDF Parsing Component of EnzoVezzaro...

The vulnerability found in the PDF Parsing function of EnzoVezzaro's mcp-dominican-layer allows attackers to exploit a flaw in argument manipulation, specifically with the pdfUrl parameter. This enables unauthorized server-side request forgery (SSRF) attacks, which can be executed remotely. Despi...

Discovered 7 hours ago

PoC for CVE-2026-19751

EnzovezzaroMcp-dominican-layer5.3MEDIUM
Server-Side Request Forgery in EnzoVezzaro mcp-dominican-layer Tool

A vulnerability exists in the EnzoVezzaro mcp-dominican-layer related to the axios.get function in the parse-csv tool's src/index.ts file. This flaw can lead to server-side request forgery, enabling attackers to manipulate CSV URLs and potentially gain unauthorized access to sensitive server reso...

PoC for CVE-2026-19750

TendaCh9.2CRITICAL
SSH Vulnerability in Tenda CH, CP, and TX3 Products

A security flaw has been identified in Tenda CH, CP, and TX3 product lines, specifically affecting the SSH component, which utilizes hard-coded passwords. This vulnerability can potentially allow unauthorized remote access to affected devices, enabling attackers to exploit the known credential we...

Discovered 8 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 10 hours ago

PoC for CVE-2026-73482

PHPlistPHPlist37.2HIGH
Cross-Site Request Forgery Vulnerability in phpList

A CSRF vulnerability exists in phpList versions prior to 3.7.0-RC5, specifically affecting the lists/admin/admins.php file. This vulnerability allows an attacker to exploit the admin deletion functionality without needing authentication. Through maliciously crafted links, an attacker can trick a ...

PoC for CVE-2026-73481

PHPlistPHPlist35.3MEDIUM
CSRF Vulnerability in phpList Product by phpList

The affected versions of phpList fail to adequately enforce CSRF token validation on the bounce rule deletion endpoint. Specifically, the vulnerability allows an attacker to delete arbitrary bounce rules from the database by tricking an authenticated administrator into triggering a crafted GET re...

PoC for CVE-2026-72777

DayuanjiangNext-ai-draw-io7.7HIGH
Server-Side Request Forgery in Next AI Draw.io by DayuanJiang

Next AI Draw.io prior to version 0.4.16 is susceptible to a server-side request forgery vulnerability within its POST /api/parse-url endpoint. The flaw arises from insufficient hostname validation, which relies on pattern matching instead of DNS resolution. This vulnerability allows unauthenticat...

PoC for CVE-2026-73037

DayuanjiangNext-ai-draw-io5.1MEDIUM
Reflected Cross-Site Scripting in Next AI Draw.io by DayuanJiang

Next AI Draw.io versions 0.2.1 through 0.4.16 are susceptible to a reflected cross-site scripting (XSS) flaw stemming from the mcp query parameter not being properly sanitized. This allows attackers to construct malicious URLs that, when accessed, can execute arbitrary JavaScript code in the cont...

PoC for CVE-2026-72741

GoodrainRainbond8.6HIGH
Access Control Vulnerability in Rainbond by Goodrain

The Rainbond platform, through version 6.9.7, is susceptible to a broken access control vulnerability within its CheckToken function. This flaw permits authenticated attackers to exploit the system by modifying the tenant name within URL paths to access unauthorized enterprise resources. By lever...

Discovered 11 hours ago

PoC for CVE-2019-25765

Asp-cms ProjectAsp-cms8.7HIGH
SQL Injection Vulnerability in ASP-CMS by Lou Dong Ji He

ASP-CMS is vulnerable to SQL injection through the commentList.asp endpoint. Malicious actors can manipulate the 'id' parameter in GET requests, allowing them to inject arbitrary SQL code. This vulnerability enables attackers to bypass the application's keyword blocklist by embedding the string '...

PoC for CVE-2024-58374

Hongjing CenturyE-hr8.7HIGH
Unauthenticated SQL Injection Vulnerability in Hongjing e-HR

The Hongjing e-HR application is exposed to an unauthenticated SQL injection vulnerability within the getSdutyTree servlet endpoint. By using a path traversal sequence in the request URI, malicious actors can bypass the oauthservlet authentication filter, allowing them to submit UNION-based SQL q...

Discovered 13 hours ago

PoC for CVE-2026-73515

PostgisPostgis7.2HIGH
Out-of-Bounds Read Vulnerability in PostGIS by OSGeo

PostGIS, a widely used geospatial database extender, has an out-of-bounds read vulnerability that occurs when a malformed FlatGeobuf buffer is processed. The vulnerability allows attackers to exploit the weakness in the property metadata decoder, which verifies the existence of a string length fi...

PoC for CVE-2026-19710

SourcecodesterSimple Student Informa...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Student Inform...

A remote SQL injection vulnerability has been identified in the Simple Student Information System developed by SourceCodester. This flaw resides in the 'view_department.php' file, where manipulation of the argument ID can lead to unauthorized access to sensitive database information. This exploit...

Discovered 18 hours ago

PoC for CVE-2026-66804

MicrosoftWindows 10 Version 22h27.8HIGH
Windows Cross Device Service Elevation of Privilege Vulnerability i...

An improper access control vulnerability in the Windows Cross Device Service allows an attacker with authorized access to elevate their privileges locally. This can lead to unauthorized actions within the system, compromising the integrity and security of users' environments. Microsoft has releas...

PoC for CVE-2026-68820

MicrosoftWindows 10 Version 16077HIGH
Privilege Elevation Vulnerability in Windows Ancillary Function Dri...

A use after free vulnerability exists in the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to exploit the driver and potentially elevate privileges locally, threatening the integrity of the operating system. To mitigate risk, it is essential to apply the ...

Discovered 20 hours ago

PoC for CVE-2026-24031

Open-xchange GmbhOx Dovecot Pro7.7HIGH
Authentication Bypass Vulnerability in Dovecot by Open-Xchange

An authentication bypass vulnerability exists in Dovecot SQL authentication, where an administrator can inadvertently disable the 'auth_username_chars' configuration. This misconfiguration allows attackers to bypass authentication checks, potentially enabling unauthorized access and user enumerat...

PoC for CVE-2026-15413

WordPressLink Factory10CRITICAL
Backdoor in Link Factory WordPress Plugin Exposes REST API

The Link Factory plugin for WordPress is compromised by a backdoor that enables unauthorized access via an operator-controlled REST API endpoint located at /wp-json/link-factory/v1/. This backdoor is authenticated using a detached Ed25519 signature, which is verified against a hardcoded public ke...

PoC for CVE-2026-14332

WordPressEcwid By Lightspeed Ec...5.4MEDIUM
Store Management Vulnerability in Ecwid by Lightspeed Ecommerce Sho...

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress prior to version 7.0.9 is susceptible to an access control vulnerability. It lacks proper capability checks and nonce verification for specific store-management actions, potentially allowing any authenticated user, including sub...

Discovered 22 hours ago

PoC for CVE-2026-54984

MicrosoftWindows 10 Version 16077.8HIGH
Heap-based Buffer Overflow in Windows Imaging Component by Microsoft

A heap-based buffer overflow vulnerability exists in the Windows Imaging Component, which could allow an unauthorized attacker to execute arbitrary code locally. This flaw can be exploited by malicious actors to manipulate memory allocation and potentially gain unauthorized access to system resou...

PoC for CVE-2026-18945

WordPressWP Helper Premium8.2HIGH
Order Information Exposure in WP Helper Premium WordPress Plugin

The WP Helper Premium plugin for WordPress is susceptible to a vulnerability that allows unauthenticated users to access sensitive order details. Specifically, versions prior to 4.7.6 fail to verify order keys when rendering custom order confirmation pages or processing related AJAX actions. This...

PoC for CVE-2026-14213

WordPressBooking For Appointmen...3.7LOW
Unauthorized Access in Booking for Appointments and Events Calendar...

A significant access control vulnerability exists in the Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.6. This flaw allows any authenticated employee to retrieve information about appointments without proper authorization, potentially exposing sensitive cu...

PoC for CVE-2026-19088

WordPressShopengine Elementor W...5.4MEDIUM
CSRF Vulnerability in ShopEngine Elementor WooCommerce Builder Addo...

The ShopEngine Elementor WooCommerce Builder Addon for WordPress lacks adequate protection for its authentication endpoints, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. An attacker can exploit this vulnerability to trick a victim into authenticating to an attacker-controll...

PoC for CVE-2026-13610

WordPressKivicare
Authentication Bypass in KiviCare WordPress Plugin Allows Unauthori...

The KiviCare WordPress plugin prior to version 4.5.2 is vulnerable due to a lack of restrictions on role assignments via its unauthenticated registration endpoint. This flaw enables attackers to create active, privileged accounts, such as clinic staff (doctors), granting them full access to sensi...

PoC for CVE-2026-14182

WordPressCustomer Email Verific...9.8CRITICAL
Authentication Bypass in Customer Email Verification for WooCommerc...

The Customer Email Verification for WooCommerce plugin prior to version 3.2.6 exhibits a vulnerability allowing unauthenticated users to bypass email verification mechanisms. This occurs due to inadequate validation of the email-verification activation code, which can be exploited by an attacker ...

PoC for CVE-2026-13328

WordPressFood Menu
Authorization Flaw in Food Menu Plugin Exposes Reservation Status t...

The Food Menu plugin for WordPress prior to version 6.0.2 has a significant vulnerability that allows unauthenticated users to modify reservation statuses. This issue arises from the lack of proper capability and ownership checks in the reservation-status update action. The action is accessible t...

Discovered 1 day ago

PoC for CVE-2026-39987

Marimo-teamMarimo🟣 EPSS 97%9.3CRITICAL
Pre-Authentication Remote Code Execution in Marimo Python Notebook

Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...

PoC for CVE-2020-8597

Point-to-point Pr...Point-to-point Protocol🟣 EPSS 20%9.8CRITICAL
Buffer Overflow in PPP Daemon Affects Multiple Platforms

The vulnerability in the PPP Daemon (pppd) versions 2.4.2 through 2.4.8 is a buffer overflow issue found in the eap_request and eap_response functions. This flaw can potentially allow an unauthorized attacker to exploit the overflow, leading to arbitrary code execution or causing the application ...

PoC for CVE-2026-68398

LinuxLinux7.8HIGH
Use-After-Free in Linux Kernel Pppol2tp Functionality

The vulnerability within the Linux kernel occurs in the pppol2tp_recv() function, which fails to properly manage memory deallocation in a multi-threaded environment. This oversight allows an unprivileged user to potentially exploit the system by dereferencing a channel that has already been freed...

PoC for CVE-2026-59827

MetabaseMetabase9.9CRITICAL
Deserialization Flaw in Metabase's H2 Database Connection

Metabase, an open-source business intelligence and embedded analytics tool, suffers from a deserialization vulnerability in versions prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4. When configured with an H2 database connection, including the default sample database, this flaw permits authenti...

PoC for CVE-2026-28956

AppleiOS And iPad OS6.5MEDIUM
Memory Corruption Issue in Apple Products due to Malicious Media Files

This vulnerability involves a memory corruption issue that arises when processing specially crafted media files, which can lead to unintended app termination or memory corruption in affected Apple devices. Apple has addressed this flaw with enhanced input validation in the latest versions of thei...

PoC for CVE-2026-23111

LinuxLinux7.8HIGH
Local Privilege Escalation Vulnerability in Linux Kernel Utilizing ...

A vulnerability exists in the Linux kernel's netfilter module that affects the nft_map_catchall_activate() function. This function encounters an inverted element activity check, leading to a failure in appropriately handling catchall map elements during a failed transaction. The bug arises when t...