Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 2 hours ago
PoC for CVE-2026-18813
A command injection vulnerability exists in the H3C NX15 V100R017 product. The flaw is located in the delete function of the /api/esps endpoint, where unsanitized input from the esps.apcm.version argument can be manipulated to execute arbitrary commands. This vulnerability allows attackers to ini...
Discovered 3 hours ago
PoC for CVE-2026-18812
A vulnerability has been identified in the H3C NX15 Router, specifically within the esps.ipv6.wan function of the /api/esps file. This flaw allows an attacker to manipulate the workMode argument, which could lead to command injection. The vulnerability can be exploited remotely, increasing the ri...
PoC for CVE-2026-18811
A security flaw exists in the H3C NX15 V100R017, located in the Add function of the /api/esps file. By manipulating the argument esps.filter.url, an attacker can execute arbitrary commands on the target system. This vulnerability can be exploited remotely, allowing unauthorized access and control...
Discovered 6 hours ago
PoC for CVE-2026-18790
A vulnerability has been identified in Systerel S2OPC versions up to 1.7.3, specifically affecting the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse function within the DeleteMonitoredItemsRequest Handler. This flaw leads to out-of-bounds read conditions, potentially allowing an attacker t...
PoC for CVE-2026-45033
A security flaw exists in GitHub Copilot CLI that allows for arbitrary code execution through the exploitation of malicious bare git repositories. Prior to version 1.0.43, when users execute git operations, the CLI could inadvertently run commands specified by attackers via git's automatic bare r...
PoC for CVE-2026-18788
A vulnerability exists in Trippo ResponsiveFilemanager that allows attackers to upload files without proper authentication through an unknown function in filemanager/dialog.php. This security issue can be exploited remotely, leading to potential unauthorized access or system compromise. Notably, ...
PoC for CVE-2026-18788
A vulnerability exists in Trippo ResponsiveFilemanager that allows attackers to upload files without proper authentication through an unknown function in filemanager/dialog.php. This security issue can be exploited remotely, leading to potential unauthorized access or system compromise. Notably, ...
PoC for CVE-2026-18787
A command injection vulnerability has been identified in the GL.iNet AX1800 device, specifically within the function remove_rule in the file /usr/share/gl-ngx/oui-rpc.lua related to the RPC Endpoint component. This vulnerability allows remote attackers to manipulate the args.id argument, potentia...
PoC for CVE-2026-18785
A vulnerability has been identified in the open62541 project that impacts the UA_Client_getRemoteDataTypes function within the custom_datatype client types implementation. This flaw allows for potential exploitation via a use after free attack, posing a significant risk when executed on a local h...
PoC for CVE-2026-18577
An incomplete fix for prior vulnerabilities has left N-central susceptible to an authentication bypass, enabling potential account takeovers. This affects multiple versions of the software, which remain vulnerable until addressed with a proper patch.
Discovered 7 hours ago
PoC for CVE-2026-18784
A vulnerability exists in the o6 open62541 software that can lead to a heap-based buffer overflow through the UA_Client_readNodeClassAttribute function within the src/client/ua_client_highlevel.c file. This flaw necessitates local exploitation, allowing attackers to manipulate affected system beh...
PoC for CVE-2026-18775
A server-side request forgery vulnerability has been identified in the NousResearch hermes-agent up to version 0.16.0. This issue specifically affects the browser_snapshot function within the tools/browser_tool.py component, enabling an attacker to manipulate requests made by the server to intern...
PoC for CVE-2026-18774
A vulnerability exists in NousResearch's hermes-agent up to version 0.16.0, specifically within the save_url_image function in the xAI Image Generation Provider. This flaw allows for server-side request forgery (SSRF), potentially enabling attackers to initiate remote exploits. Despite early noti...
Discovered 8 hours ago
PoC for CVE-2026-69110
OpenCode Studio, prior to version 2.4.4, exhibits a missing authentication vulnerability. This flaw enables unauthorized remote attackers to access sensitive files within the temp and static/music directories by leveraging the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Addition...
PoC for CVE-2026-69100
The LAMP Rapid Development Platform, up to version 5.6.2, is susceptible to a remote code execution vulnerability in the GlueFactory module. This flaw allows attackers to execute unsandboxed Groovy scripts through database template fields without the need for compilation restrictions or whitelist...
PoC for CVE-2026-69098
Kotaemon versions up to 0.12.0 are susceptible to an insecure deserialization flaw in the check_connection endpoint. This vulnerability permits unauthenticated attackers to manipulate input—crafted YAML or JSON with a __type__ field—allowing them to instantiate arbitrary Python classes. By exploi...
PoC for CVE-2026-18773
A vulnerability exists in NousResearch's hermes-agent affecting versions up to 2026.6.5, particularly in the _check_slash_access function of the gateway/run.py file within the Quick Command Handler component. This flaw allows unauthorized access, enabling attackers to manipulate the system remote...
PoC for CVE-2023-31902
RPA Technology's Mobile Mouse version 3.6.0.4 has a vulnerability that allows attackers to execute arbitrary code remotely. This risk poses a serious concern for users of the application, potentially enabling unauthorized access and control over the affected system. It is crucial for users to upd...
Discovered 9 hours ago
PoC for CVE-2026-18766
A vulnerability exists in Chetans9 Core PHP Admin Panel, specifically in the processing of the 'filter_col' argument within the 'customers.php' file. This flaw can allow an attacker to execute SQL injection attacks remotely. The product utilizes a rolling release strategy, complicating version tr...
PoC for CVE-2026-67200
Perspective 5.0.0 is affected by a path traversal vulnerability that enables unauthenticated remote attackers to access arbitrary files on the server's filesystem. By exploiting this flaw, attackers can manipulate HTTP request URL paths, using ../ segments to escape the intended asset root direct...
PoC for CVE-2026-61514
The Puwell IP Camera firmware versions 2.x through 4.x is susceptible to an authentication bypass vulnerability. By exploiting this flaw, unauthorized attackers can send conforming packets to TCP port 23456, allowing them to access the device's functionalities without needing valid credentials. T...
PoC for CVE-2026-61515
The Puwell IP Camera firmware versions 2.x through 4.x is susceptible to an unauthenticated command injection vulnerability. This flaw enables remote attackers to execute arbitrary operating system commands by sending specially crafted JSON payloads to the DebugShell interface exposed on TCP port...
PoC for CVE-2026-23479
Redis, an in-memory data structure store, has a vulnerability in the unblock client flow within versions from 7.2.0 to 8.6.3. When re-executing a blocked command, the system fails to handle an error return, which may lead to a scenario where an authenticated attacker can exploit this flaw. If a b...
Discovered 11 hours ago
PoC for CVE-2026-58048
The vulnerability allows an attacker to execute arbitrary SQL commands in the root context due to insufficient handling of SQL mode settings during database renaming operations in cPanel. This could potentially lead to unauthorized access and manipulation of sensitive data within the database. Pr...
Discovered 15 hours ago
PoC for CVE-2026-18718
Ghidra features a flaw in its Swift demangler analyzer that enables attackers to execute arbitrary code. By creating a malicious Ghidra project with a crafted Swift tool directory path, an attacker can manipulate the context from which binaries are restored and executed. Upon opening the compromi...
Discovered 17 hours ago
PoC for CVE-2026-16547
The REST API Log plugin for WordPress, prior to version 1.7.1, has security weaknesses where the token intended to protect the log download feature does not adequately bind to the requested log entry. Furthermore, it fails to verify the requester's permissions. This oversight permits unauthentica...
PoC for CVE-2026-16548
The Chat Widget plugin for WordPress versions prior to 1.8.2 is susceptible to a file upload vulnerability. This flaw allows unauthenticated users to upload arbitrary files to the public response endpoint without proper validation of file type, extension, content, or size. Files are stored in the...
PoC for CVE-2026-16069
The Brizy WordPress plugin prior to version 2.8.19 is susceptible to a Cross-Site Scripting (XSS) vulnerability due to inadequate sanitization and escaping of focal-point coordinates for featured images. This weakness allows users with Contributor privileges or higher to inject malicious scripts ...
PoC for CVE-2026-16070
The Brizy WordPress plugin versions prior to 2.8.19 contains a significant authorization flaw. This vulnerability enables users with Contributor-level access and higher to improperly modify the template-type assignments of templates that they do not own. The plugin fails to accurately verify the ...
PoC for CVE-2026-16296
The Clearfy Cache plugin for WordPress prior to version 2.4.3 contains a vulnerability that arises from the lack of validation for the redirect target in its old-URL redirect handler, known as Cyrlitera. This deficiency permits unauthenticated attackers to manipulate the redirect mechanism, allow...
PoC for CVE-2026-16295
The Clearfy Cache Plugin for WordPress, prior to version 2.4.3, is susceptible to a vulnerability where it fails to implement adequate capability checks in its admin-page routing. This oversight enables any authenticated user, including those with minimal permissions like Subscribers, to access r...
PoC for CVE-2026-16293
The PowerPress Podcasting plugin by Blubrry fails to properly sanitize and escape several settings related to Podcast Episodes. This oversight allows attackers with low-level roles, such as Contributor, to craft malicious scripts that can be stored and executed within the applications of unsuspec...
PoC for CVE-2026-16546
The Wired Impact Volunteer Management plugin for WordPress, prior to version 2.8.2, contains an authorization flaw in one of its AJAX actions. This vulnerability allows authenticated users with minimal roles, such as Subscribers, to remove RSVPs associated with any volunteer opportunities regardl...
PoC for CVE-2026-16035
The miniOrange 2FA WordPress plugin, prior to version 6.2.7, contains a vulnerability that allows low-privileged users to send one-time passcode (OTP) emails to any arbitrary recipient. This oversight does not enforce restrictions on who may trigger the OTP configuration process, nor does it bind...
PoC for CVE-2026-15958
The Easy Integration for Dropbox plugin for WordPress prior to version 2.2.0 lacks proper authorization checks on its file-management AJAX actions. This oversight enables unauthenticated attackers to exploit the system, potentially allowing them to list, download, and upload arbitrary files acros...
PoC for CVE-2026-16068
The Brizy plugin for WordPress prior to version 2.8.19 exhibits poor access control, failing to restrict modifications to site-global design data effectively. This oversight allows authenticated users with Author-level permissions or higher to input arbitrary JavaScript code. The plugin does not ...
PoC for CVE-2026-16056
The Contest Gallery plugin for WordPress prior to version 30.0.7 lacks necessary capability and nonce validation in one of its handlers. This oversight permits any authenticated user, including those with minimal permissions such as Subscribers, to access the entire stored OpenAI prompt history o...
PoC for CVE-2026-15233
The Nested Pages plugin for WordPress prior to version 3.2.15 contains a vulnerability where post titles are not properly escaped before being rendered into HTML attributes. This oversight allows users with roles such as Editor, Contributor, or Author to inject arbitrary JavaScript into the admin...
PoC for CVE-2026-14848
The Paid Membership Subscriptions plugin for WordPress prior to version 3.0.8 allows authenticated users with Subscriber-level access or higher to modify another user's subscription. This vulnerability stems from the plugin's failure to verify subscription ownership during the change-subscription...
PoC for CVE-2026-14939
The Visualizer plugin for WordPress before version 4.0.6 is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This weakness occurs because the plugin does not adequately limit user-supplied URLs to safe ranges before fetching them on the server side. This oversight permits users ...
PoC for CVE-2026-14872
The Contact Form 7, WPforms, and Elementor Forms plugins for WordPress prior to version 1.5.5 contain a vulnerability due to improper sanitization and escaping of parameters in SQL statements. This flaw allows attackers, even with limited user permissions typically assigned to administrators, to ...
PoC for CVE-2026-14816
The GDPR Framework plugin for WordPress, developed by Data443, allows unauthenticated attackers to bypass authorization checks when recording cookie-consent choices and processing privacy requests. This vulnerability could lead to the forging of consent records associated with arbitrary email add...
PoC for CVE-2026-14824
The Quiz and Survey Master plugin for WordPress, prior to version 11.2.2, is susceptible to a cross-site scripting (XSS) vulnerability. This issue arises due to insufficient escaping of question settings before rendering them in unquoted HTML attributes. As a result, users with contributor-level ...
PoC for CVE-2026-10526
The EmbedPress plugin for WordPress, prior to version 4.6.1, suffers from a security flaw that leads to unvalidated user-supplied URLs being processed. This vulnerability enables unauthenticated attackers to exploit the system, causing the server to make unintended HTTP requests to internal servi...
PoC for CVE-2026-11366
The MonsterInsights plugin for WordPress before version 11.1.0 is vulnerable to a security flaw that allows unauthenticated attackers to bypass validation checks on an unauthenticated AJAX action. When the plugin is not connected to Google Analytics, the HMAC signing key is empty, which enables a...
PoC for CVE-2026-12698
The wpForo Forum WordPress plugin, prior to version 3.1.3, suffers from an authorization flaw that permits users with a subscriber role to modify restricted profile fields. This could lead to unauthorized changes, such as altering account status, reputation scores, and potentially reactivating ba...
PoC for CVE-2026-16536
The Simple Google Calendar Outlook Events Widget plugin for WordPress prior to version 3.1.0 is prone to a security vulnerability due to improper validation of user-supplied URLs. This oversight allows unauthenticated attackers to execute Server-Side Request Forgery (SSRF) attacks, which may enab...
PoC for CVE-2026-16623
The Create Block WordPress plugin prior to version 2.10.0 is susceptible to a PHP code injection vulnerability. Due to insufficient escaping of user-supplied text when creating a PHP pattern file, this flaw allows a multisite subsite administrator to inject and execute arbitrary PHP code on the s...
PoC for CVE-2026-16618
The Improve SEO WordPress plugin versions up to 2.0.11 has a critical issue where it fails to effectively validate uploaded files. The plugin only checks the content type of the file during the upload process. This insufficient validation allows untrusted users to upload files with malicious exte...
Discovered 20 hours ago
PoC for CVE-2026-18723
A serious security flaw in DWSurvey by diaowen, specifically in the Survey Status Handler's `/api/dwsurvey/app/survey/up-survey-status.do`, allows for improper authorization. This vulnerability can be exploited remotely, posing a risk for unauthorized access to sensitive survey data. Although the...