Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2025-43529
A significant use-after-free vulnerability has been identified in Apple’s iOS and macOS products, impacting versions prior to the latest updates. This flaw arises due to improper memory management, allowing maliciously crafted web content to trigger arbitrary code execution. Apple has acknowledge...
Discovered 3 hours ago
PoC for CVE-2026-1457
The TP-Link VIGI C385 Web API has a significant buffer handling flaw due to insufficient input sanitization, which could lead to memory corruption. This vulnerability allows authenticated attackers to exploit the buffer overflow, potentially enabling them to execute arbitrary code with elevated p...
Discovered 5 hours ago
PoC for CVE-2026-24858
Fortinet products, including FortiAnalyzer and FortiManager, are susceptible to a vulnerability that allows an attacker with a FortiCloud account to bypass authentication, granting unauthorized access to devices linked with different accounts. This issue can be exploited if FortiCloud SSO authent...
PoC for CVE-2026-24858
Fortinet products, including FortiAnalyzer and FortiManager, are susceptible to a vulnerability that allows an attacker with a FortiCloud account to bypass authentication, granting unauthorized access to devices linked with different accounts. This issue can be exploited if FortiCloud SSO authent...
Discovered 17 hours ago
PoC for CVE-2022-38694
The vulnerability occurring in UNISOC's BootRom allows a possible unchecked write address, enabling local escalation of privilege without requiring additional execution privileges. This flaw poses a significant security risk, as it can be exploited by malicious actors to gain unauthorized access ...
PoC for CVE-2020-11107
A privilege escalation vulnerability is present in XAMPP versions prior to 7.2.29, 7.3.16, and 7.4.4 on Windows systems. An unprivileged user has the capability to modify the xampp-control.ini configuration file, potentially allowing unauthorized access to all users, including administrators. Thi...
Discovered 18 hours ago
PoC for CVE-2026-1638
A significant security vulnerability has been identified in the Tenda AC21 router, specifically within the mDMZSetCfg function located in the /goform/mDMZSetCfg file. This vulnerability allows an attacker to manipulate the dmzIp argument, leading to potential command injection that can be execute...
PoC for CVE-2019-11707
A type confusion vulnerability exists in Mozilla Firefox and Thunderbird, stemming from improper handling of JavaScript objects in the Array.pop function. This flaw can facilitate an exploitable crash, potentially compromising the stability and security of affected applications. Recent attacks in...
Discovered 19 hours ago
PoC for CVE-2026-1637
A stack-based buffer overflow vulnerability affects the Tenda AC21 router, specifically within the fromAdvSetMacMtuWan function located in the /goform/AdvSetMacMtuWan file. This flaw enables an attacker to potentially execute arbitrary code remotely. Given that exploits for this vulnerability are...
Discovered 20 hours ago
PoC for CVE-2009-3999
A stack-based buffer overflow exists in the goform/formExportDataLogs function within HP Power Manager, prior to version 4.2.10. This flaw enables remote attackers to execute arbitrary code by exploiting the vulnerability through a specially crafted long 'fileName' parameter. The issue poses a si...
PoC for CVE-2026-24423
SmarterMail versions earlier than build 9511 are susceptible to an unauthenticated remote code execution vulnerability via the ConnectToHub API method. An attacker can exploit this weakness by directing the application to a malicious HTTP server that delivers harmful OS commands, which are then e...
Discovered 21 hours ago
PoC for CVE-2026-1623
A command injection vulnerability has been identified in the Totolink A7000R router, specifically affecting the setUpgradeFW function within the /cgi-bin/cstecgi.cgi file. This weakness allows an attacker to manipulate the FileName parameter, enabling remote execution of arbitrary commands. Given...
PoC for CVE-2026-1623
A command injection vulnerability has been identified in the Totolink A7000R router, specifically affecting the setUpgradeFW function within the /cgi-bin/cstecgi.cgi file. This weakness allows an attacker to manipulate the FileName parameter, enabling remote execution of arbitrary commands. Given...
Discovered 23 hours ago
PoC for CVE-2026-1601
A security weakness has been found in the Totolink A7000R router, specifically within the setUploadUserData function located in the /cgi-bin/cstecgi.cgi file. By manipulating the FileName argument, attackers can execute arbitrary commands on the device, which poses a serious threat as the exploit...
PoC for CVE-2026-1601
A security weakness has been found in the Totolink A7000R router, specifically within the setUploadUserData function located in the /cgi-bin/cstecgi.cgi file. By manipulating the FileName argument, attackers can execute arbitrary commands on the device, which poses a serious threat as the exploit...
Discovered 1 day ago
PoC for CVE-2026-1600
A recently identified security flaw in the Bdtask Bhojon All-In-One Restaurant Management System affects the Add-to-Cart submission endpoint. The vulnerability resides in an unspecified function of the file /hungry/addtocart, where improper manipulation of the parameters price or allprice can lea...
PoC for CVE-2026-1600
A recently identified security flaw in the Bdtask Bhojon All-In-One Restaurant Management System affects the Add-to-Cart submission endpoint. The vulnerability resides in an unspecified function of the file /hungry/addtocart, where improper manipulation of the parameters price or allprice can lea...
PoC for CVE-2026-1599
A vulnerability exists in the Bdtask Bhojon All-In-One Restaurant Management System's checkout functionality, specifically in the handling of parameters during the order process. An attacker may exploit this flaw by manipulating the arguments related to the calculation of total amounts, including...
PoC for CVE-2026-1599
A vulnerability exists in the Bdtask Bhojon All-In-One Restaurant Management System's checkout functionality, specifically in the handling of parameters during the order process. An attacker may exploit this flaw by manipulating the arguments related to the calculation of total amounts, including...
PoC for CVE-2026-1598
A cross-site scripting vulnerability exists in the User Information Module within the Bdtask Bhojon All-In-One Restaurant Management System, specifically in the '/dashboard/home/profile' file. By manipulating the 'fullname' argument, attackers can execute arbitrary code remotely, potentially comp...
PoC for CVE-2026-1597
A vulnerability has been identified in Bdtask SalesERP versions up to 20260116 that affects the Administrative Endpoint. This flaw allows an attacker to manipulate the 'ci_session' argument, leading to improper authorization. Exploitation can be performed remotely, posing a significant risk to us...
PoC for CVE-2026-1597
A vulnerability has been identified in Bdtask SalesERP versions up to 20260116 that affects the Administrative Endpoint. This flaw allows an attacker to manipulate the 'ci_session' argument, leading to improper authorization. Exploitation can be performed remotely, posing a significant risk to us...
PoC for CVE-2025-5419
A security vulnerability exists in Google Chrome versions before 137.0.7151.68, which allows remote attackers to exploit out-of-bounds read and write conditions in the V8 JavaScript engine. By crafting a specific HTML page, an attacker may manipulate heap memory, potentially leading to unauthoriz...
PoC for CVE-2026-1595
A security vulnerability exists in itsourcecode Society Management System version 1.0, specifically affecting the /admin/edit_student_query.php file. This vulnerability allows an attacker to manipulate the 'student_id' parameter, leading to SQL injection. The exploitation of this vulnerability ca...
PoC for CVE-2026-1594
A security vulnerability in the itsourcecode Society Management System version 1.0 allows for SQL injection through manipulation of the argument 'detail' in the /admin/add_expenses.php file. This flaw could enable remote attackers to execute unauthorized SQL commands, potentially compromising the...
PoC for CVE-2026-1593
A vulnerability has been discovered in itsourcecode's Society Management System version 1.0, specifically related to an inadequate security measure in the file /admin/edit_expenses_query.php. This issue allows an attacker to manipulate the 'detail' argument, potentially leading to SQL injection a...
PoC for CVE-2020-37021
The 10-Strike Bandwidth Monitor version 3.9 is susceptible to an unquoted service path vulnerability in various services. This flaw enables local attackers to exploit the service startup process by placing a malicious executable in specific directory paths. Successful exploitation allows attacker...
PoC for CVE-2020-37018
GOautodial 4.0 is affected by a persistent cross-site scripting vulnerability, enabling authenticated agents to inject malicious scripts through message subjects. Attackers can exploit this trust to craft messages containing JavaScript that execute upon being viewed by an administrator. This can ...
PoC for CVE-2020-37017
CodeMeter 6.60 features an unquoted service path vulnerability that permits local users to potentially execute arbitrary code with elevated system privileges. Exploiting this flaw involves manipulating the unquoted binary path utilized by the CodeMeter Runtime Server service, enabling attackers t...
PoC for CVE-2020-37020
SonarQube version 8.3.1 contains an unquoted service path vulnerability, which poses a significant risk for local attackers. By exploiting this flaw, malicious users can manipulate the service executable path to replace the legitimate 'wrapper.exe' with a malicious executable. This can lead to co...
PoC for CVE-2020-37015
The Ruijie Networks Switch eWeb S29_RGOS 11.4 is susceptible to a directory traversal vulnerability that enables unauthorized users to exploit the /download.do endpoint. By leveraging specially crafted file path parameters containing '../' sequences, attackers can gain access to sensitive system ...
PoC for CVE-2020-37016
BarcodeOCR version 19.3.6 has a vulnerability related to an unquoted service path, which can be exploited by local attackers. This flaw enables the injection of malicious executables that execute with elevated privileges during system startup. By exploiting this vulnerability, attackers can execu...
PoC for CVE-2020-37013
Audio Playback Recorder version 3.2.2 contains a local buffer overflow vulnerability that arises from improper handling of the eject and registration parameters. This flaw allows attackers to exploit the application by crafting malicious inputs that can overwrite the Structured Exception Handler ...
PoC for CVE-2020-37012
Tea LaTex 1.0 is susceptible to a remote code execution vulnerability that permits unauthenticated attackers to execute arbitrary shell commands. This vulnerability arises when a specially crafted malicious LaTeX payload is processed via the /api.php endpoint, notably during the execution of the ...
PoC for CVE-2020-37011
Gnome Fonts Viewer version 3.34.0 contains a heap corruption flaw that could be exploited by attackers to perform out-of-bounds writes. By crafting a malicious TTF font file with an oversized pattern, attackers can induce an infinite malloc() loop, potentially leading to the crash of the gnome-fo...
PoC for CVE-2020-37013
Audio Playback Recorder version 3.2.2 contains a local buffer overflow vulnerability that arises from improper handling of the eject and registration parameters. This flaw allows attackers to exploit the application by crafting malicious inputs that can overwrite the Structured Exception Handler ...
PoC for CVE-2020-37008
EasyPMS 1.0.0 is affected by an authentication bypass vulnerability, enabling unprivileged users to manipulate SQL queries through JSON requests. By exploiting inadequate input validation, attackers can inject single quotes into ID parameters, allowing them to gain unauthorized access to admin us...
PoC for CVE-2020-37009
MedDream PACS Server 6.8.3.751 is susceptible to an authenticated remote code execution vulnerability. This flaw permits authorized users to upload malicious PHP files through the uploadImage.php endpoint, enabling potential attackers to execute arbitrary system commands with elevated privileges....
PoC for CVE-2020-37010
BearShare Lite 5.2.5 has a vulnerability that enables buffer overflow through the Advanced Search keywords input. This flaw allows attackers to submit a specially crafted payload via the search input, leading to potential arbitrary code execution by overwriting the EIP register and running shellc...
PoC for CVE-2020-37006
berliCRM version 1.0.24 is vulnerable to a SQL injection flaw in the 'src_record' parameter. This vulnerability permits remote attackers to submit crafted POST requests to the index.php endpoint, potentially allowing them to execute unintended SQL commands. As a result, attackers could extract se...
PoC for CVE-2020-37007
Liman 0.7 contains a vulnerability that allows attackers to exploit cross-site request forgery (CSRF) weaknesses. By crafting malicious HTML forms, attackers can deceive logged-in users into submitting unauthorized requests, which may lead to the manipulation of their account settings, including ...
PoC for CVE-2020-37005
TimeClock Software 1.01 is susceptible to an authenticated time-based SQL injection vulnerability that enables attackers to enumerate valid usernames. By manipulating the 'notes' parameter in the add_entry.php endpoint, adversaries can inject conditional time delays. This allows them to ascertain...
PoC for CVE-2020-37004
The Ultimate Project Manager CRM PRO 2.0.5 is susceptible to a blind SQL injection vulnerability. This flaw can be exploited through the /frontend/get_article_suggestion/ endpoint, allowing malicious users to craft specially designed search parameters. By utilizing boolean-based inference techniq...
PoC for CVE-2020-37002
Ajenti version 2.1.36 is vulnerable to an authentication bypass that enables remote attackers to execute arbitrary commands post-login. By exploiting the /api/terminal/create API endpoint, attackers can send a netcat reverse shell payload to a designated IP address and port, potentially compromis...
PoC for CVE-2020-36999
Elaniin CMS version 1.0 contains a vulnerability that allows attackers to bypass authentication and gain unauthorized access to the admin dashboard. This exploitation is performed by manipulating login parameters, particularly by utilizing SQL injection techniques through crafted email and passwo...
PoC for CVE-2020-37001
Frigate Professional version 3.36.0.9 contains a local buffer overflow vulnerability within the Pack File feature. This vulnerability allows attackers to craft a malicious payload that exploits the 'Archive To' input field, potentially leading to arbitrary code execution. By overflowing this fiel...
PoC for CVE-2020-37000
Free MP3 CD Ripper 2.8 is affected by a stack buffer overflow vulnerability that permits remote attackers to execute arbitrary code. By crafting a malicious WAV file with an oversized payload, attackers can leverage this vulnerability to gain control over vulnerable Windows systems. This exploit ...
PoC for CVE-2020-36997
BacklinkSpeed 2.4 is vulnerable to a buffer overflow issue that can lead to corruption of the Structured Exception Handler (SEH) chain. By importing a specially crafted malicious file, attackers could overwrite SEH addresses, potentially allowing them to execute arbitrary code and take control of...
PoC for CVE-2020-36995
Mocha Telnet Lite for iOS version 4.2 is susceptible to a denial of service vulnerability due to improper handling of user input in the configuration settings. An attacker can exploit this weakness by entering an excessive amount of data, specifically 350 bytes of repeated characters in the 'User...
PoC for CVE-2020-36994
The QlikView application version 12.50.20000.0 contains a vulnerability in its FTP server address input field. This issue allows local attackers to crash the application by submitting a specially crafted request with a 300-character buffer. Exploiting this vulnerability compromises the applicatio...