Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 1 hour ago

PoC for CVE-2026-100744

CoollabsioCoolify6.9MEDIUM
Authorization Flaw in Coolify by Coollabsio

A vulnerability exists in the Coolify application by Coollabsio, specifically related to an authorization issue in the Route-Level Middleware component. This flaw allows an attacker to execute a manipulation that can bypass crucial authorization checks, potentially leading to unauthorized access....

Discovered 2 hours ago

PoC for CVE-2026-61500

RejettoHfs9.3CRITICAL
Session Forgery Vulnerability in Rejetto HFS 3.0.0 to 3.2.0

The Rejetto HFS versions 3.0.0 to 3.2.0 contain a session forgery vulnerability due to the insecure generation of session-cookie signing keys, derived from the non-cryptographic Math.random() function. This design flaw allows unauthenticated attackers to intercept and analyze login responses. By ...

Discovered 5 hours ago

PoC for CVE-2026-100739

MathurvishalCloudclassroom-PHP-pro...6.9MEDIUM
SQL Injection Vulnerability in CloudClassroom-PHP-Project by mathur...

A SQL injection vulnerability was discovered in the viewresult.php file of the mathurvishal CloudClassroom-PHP-Project. By manipulating the 'seno' argument, an attacker can execute unauthorized SQL commands and potentially compromise the database. This vulnerability affects all versions up to com...

PoC for CVE-2026-93485

WordPressWordPress7.1HIGH
Cross-Site Scripting in Automattic WordPress Core

An improper neutralization of input during web page generation vulnerability in Automattic WordPress core can lead to a DOM-Based XSS attack. This issue arises from the default configuration of WordPress, which allows unauthenticated users to exploit cross-site scripting by bypassing comment mode...

Discovered 6 hours ago

PoC for CVE-2026-29053

TryghostGhost7.7HIGH
Arbitrary Code Execution Vulnerability in Ghost Node.js CMS

Ghost, a popular Node.js content management system, is vulnerable to an attack where specially crafted malicious themes can lead to arbitrary code execution on the server. This vulnerability affects versions 0.7.2 to 6.19.0 and has been addressed in version 6.19.1. Administrators are encouraged t...

Discovered 7 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 12 hours ago

PoC for CVE-2026-43682

AppleMac OS9.8CRITICAL
Memory Handling Vulnerability in Apple macOS Products

A vulnerability has been identified in Apple macOS products that relates to improper memory handling. This flaw allows a remote user to potentially exploit the issue, leading to unexpected system terminations and possible corruption of kernel memory. The flaw has been resolved in macOS Sequoia 15...

Discovered 14 hours ago

PoC for CVE-2026-67279

MikrotikRouteros6.9MEDIUM
Vulnerability in RouterOS SSH Allows Unauthorized Command Execution

The RouterOS SSH service is vulnerable due to improper authentication, enabling unauthenticated clients to establish a session channel after a rekey request. This flaw allows attackers to send execution requests without user credentials, leading to unauthorized command execution and potential alt...

Discovered 18 hours ago

PoC for CVE-2026-100312

MathurvishalCloudclassroom-PHP-pro...5.3MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom-PHP-Project

A security flaw has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically affecting the /updateguest.php file. An unknown function within this file is susceptible to SQL injection due to manipulation of the 'gname/editassid' argument. This vulnerability can be exploited rem...

Discovered 19 hours ago

PoC for CVE-2026-100311

MathurvishalCloudclassroom-PHP-pro...5.1MEDIUM
Cross-Site Scripting Vulnerability in mathurvishal CloudClassroom P...

A significant cross-site scripting vulnerability has been detected in the mathurvishal CloudClassroom PHP Project, specifically within the Faculty Video Management component. This vulnerability is caused by improper handling of parameters in the managevideos2.php file, allowing attackers to manip...

Discovered 21 hours ago

PoC for CVE-2026-96531

WordPressOptimole6.8MEDIUM
Cross-Site Scripting Vulnerability in Optimole WordPress Plugin

The Optimole WordPress plugin versions prior to 4.2.13 has a security flaw that allows users with the Author role or higher to insert unescaped event-handler attributes into the video-player block. This occurs because the plugin fails to properly sanitize these attributes prior to rendering. As a...

PoC for CVE-2026-96533

WordPressTestimonials Widget5.8MEDIUM
Improper Input Validation in Testimonials Widget Plugin by WordPress

The Testimonials Widget plugin for WordPress, up to version 4.0.4, fails to properly validate URLs supplied by users. This oversight allows unauthenticated individuals to manipulate the server into making requests to internal services and accessing the resulting data. As a result, sensitive infor...

PoC for CVE-2026-96532

WordPressTestimonials Widget7.5HIGH
Insufficient Input Validation in Testimonials Widget Plugin Affects...

The Testimonials Widget plugin for WordPress versions up to 4.0.4 is susceptible to an input validation vulnerability that permits unauthorized users to create and modify posts through the front-end testimonial submission form. This flaw arises from the absence of appropriate capability or owners...

PoC for CVE-2026-96526

WordPressMcp Server For WordPress2.7LOW
Unauthorized Disclosure Weakness in MCP Server for WordPress Plugin

The MCP Server for WordPress plugin prior to version 1.8.2 lacks a crucial object-level authorization check for its workflow REST routes. This deficiency enables users with the Contributor role to gain unauthorized access to sensitive information, disclosing titles and publication statuses of pos...

PoC for CVE-2026-92411

WordPressWP Delicious6.8MEDIUM
HTML Injection Vulnerability in Delicious Plugin for WordPress

The WP Delicious WordPress plugin prior to version 1.10.8 is vulnerable due to improper validation of user-supplied data in recipe blocks. This flaw permits users with Contributor role or higher to inject arbitrary HTML tags, including potentially malicious script tags. As a result, these scripts...

PoC for CVE-2026-96525

WordPressMcp Server For WordPress2.7LOW
Permission Bypass in WordPress Plugin MCP Server by OSWIT Technologies

The MCP Server plugin for WordPress is susceptible to a permissions bypass vulnerability that allows users with Contributor roles to execute unauthorized actions. Specifically, the plugin fails to properly validate user capabilities when handling REST API requests related to workflow management. ...

PoC for CVE-2026-96524

WordPressMcp Server For WordPress8.8HIGH
Vulnerability in MCP Server Plugin for WordPress Allows Unauthorize...

The MCP Server plugin for WordPress, prior to version 1.8.2, contains an issue where it fails to properly verify the nonce for REST API calls authenticated via cookies under certain conditions manipulated by an attacker. This flaw could potentially be exploited by unauthenticated adversaries who ...

PoC for CVE-2026-85081

WordPressFile Manager7.5HIGH
Cross-Site Scripting in File Manager and FileOrganizer WordPress Pl...

The File Manager and FileOrganizer plugins for WordPress feature a vulnerability that fails to validate the origin of window messages on their admin screens. This oversight permits unauthenticated attackers to execute arbitrary JavaScript within the context of a logged-in administrator's session,...

PoC for CVE-2026-84096

WordPressWP-review-slider-pro8HIGH
Stored Cross-Site Scripting Vulnerability in wp-review-slider-pro P...

The wp-review-slider-pro plugin for WordPress prior to version 12.7.12 contains a security flaw in its AJAX handler, which saves review submission forms. The vulnerability arises due to the lack of a proper capability check, enabling any authenticated user to manipulate live forms. This is furthe...

PoC for CVE-2026-84097

WordPressWP-review-slider-pro6.5MEDIUM
SQL Injection Vulnerability in wp-review-slider-pro Plugin by WordP...

The wp-review-slider-pro plugin for WordPress prior to version 12.7.12 fails to properly sanitize user-supplied data in an AJAX handler, which allows authenticated users to execute SQL injection attacks. This vulnerability exposes sensitive database information to unauthenticated visitors, posing...

PoC for CVE-2026-19708

WordPressFile Manager5.9MEDIUM
Unauthenticated File Access Vulnerability in File Manager Plugin fo...

The File Manager plugin for WordPress, versions prior to 8.0.5, is vulnerable due to its inability to restrict unauthenticated users from downloading sensitive database backup archives. This issue can lead to unauthorized access, potentially allowing malicious actors to download complete database...

PoC for CVE-2026-84095

WordPressWP-review-slider-pro8HIGH
Stored Cross-Site Scripting in wp-review-slider-pro Plugin by WordP...

The wp-review-slider-pro plugin for WordPress, in versions prior to 12.7.12, contains a vulnerability whereby an AJAX handler does not adequately check user capabilities. This oversight allows any authenticated user, such as a subscriber, to submit arbitrary review content that can later be displ...

PoC for CVE-2026-16591

WordPressWP Directory Kit7.2HIGH
Stored Cross-Site Scripting Vulnerability in WP Directory Kit Plugin

The WP Directory Kit plugin for WordPress, up to version 1.5.7, is subject to a vulnerability where it fails to properly sanitize and escape category and location fields. This oversight allows users with specific listing-management roles, who lack the unfiltered_html capability, to execute Stored...

PoC for CVE-2026-89237

WordPressBluff Post6.8MEDIUM
SQL Injection Vulnerability in Bluff Post WordPress Plugin

The Bluff Post WordPress plugin versions up to 1.1.1 is susceptible to SQL injection due to improper sanitization and escaping of parameters used in SQL queries. This vulnerability enables unauthenticated attackers to inject malicious SQL commands, potentially allowing them to access sensitive da...

PoC for CVE-2026-11871

WordPressTeam Members5.3MEDIUM
Authorization Flaw in Team Members Plugin by WordPress

The Team Members Plugin for WordPress, up to version 9.2, contains a significant vulnerability allowing unauthenticated users to access sensitive data through an AJAX action. This authorization flaw permits attackers to retrieve detailed information about team members, including email addresses a...

Discovered 23 hours ago

PoC for CVE-2024-3651

KjdKjd/idna7.5HIGH
Kjd/Idna Library Vulnerability Affects Version 3.6, Leading to Deni...

A vulnerability has been identified in the kjd/idna library, particularly affecting the functionality of the `idna.encode()` method in version 3.6. This problem stems from the method's inadequate handling of specially crafted input strings, which can lead to significant computational overhead. Wh...

Discovered 1 day ago

PoC for CVE-2026-59310

VmwareCloud Foundation9.8CRITICAL
Directory Traversal Vulnerability in VMware vCenter by VMware

VMware vCenter features a directory traversal vulnerability in its Syslog server component. This flaw allows attackers with network access to exploit the vulnerability, potentially leading to unauthorized execution of arbitrary code. Proper safeguards and patching are essential to mitigate the ri...

PoC for CVE-2026-86060

MikrotikRouteros9.2CRITICAL
Argument-handling Flaw in RouterOS by MikroTik

MikroTik's RouterOS is vulnerable due to an argument-handling flaw in the SSH login process, specifically affecting usernames that start with a prohibited character. This flaw allows an attacker to manipulate the trusted RouterOS policy mask, facilitating privilege escalation. The exploitation of...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-64560

LinuxLinux7.8HIGH
Use-After-Free Vulnerability in Linux Kernel Affecting Timer Manage...

A vulnerability in the Linux kernel related to posix CPU timers can lead to a use-after-free condition due to a race in non-leader exec() scenarios. When a timer associated with a process is deleted while concurrently executing an exec() command, it can cause access to freed memory. Specifically,...

PoC for CVE-2026-64560

LinuxLinux7.8HIGH
Use-After-Free Vulnerability in Linux Kernel Affecting Timer Manage...

A vulnerability in the Linux kernel related to posix CPU timers can lead to a use-after-free condition due to a race in non-leader exec() scenarios. When a timer associated with a process is deleted while concurrently executing an exec() command, it can cause access to freed memory. Specifically,...

PoC for CVE-2026-100372

MacwarriorClipbucket-v58.6HIGH
Path Traversal Vulnerability in ClipBucket Admin Template Editor by...

ClipBucket versions prior to 5.5.3-#197 contain a vulnerability in the admin template editor that allows authenticated administrators with manage_template_access permission to exploit directory traversal sequences. This flaw enables the modification of executable PHP files by traversing outside o...

PoC for CVE-2026-100373

Open-metadataOpenmetadata5.1MEDIUM
Server-Side Request Forgery in OpenMetadata by OpenMetadata

OpenMetadata versions up to 2.0.2 exhibit a server-side request forgery vulnerability in the URLValidator.validateURL function. This flaw arises from improper DNS hostname resolution and inadequate validation of internal addresses. Users with permissions to create or update EventSubscription can ...

PoC for CVE-2026-100310

GnuLibextractor7.3HIGH
Privilege Escalation Vulnerability in GNU libextractor by GNU

GNU libextractor prior to version 1.16 is susceptible to a privilege escalation vulnerability due to the improper handling of the LIBEXTRACTOR_PREFIX environment variable. This flaw allows a local attacker to exploit the system by loading plugins from an untrusted search path, potentially executi...

PoC for CVE-2026-100306

TduckcloudTduck-survey-form6.9MEDIUM
Write Password Bypass in TDuck Survey Form by TDuck Cloud

The TDuck Survey Form version 6.0 has a vulnerability that allows remote unauthenticated attackers to submit form entries without providing valid passwords. The application relies solely on client-side validation for write password enforcement, which can be bypassed through direct API access usin...

PoC for CVE-2026-100304

TduckcloudTduck-survey-form6MEDIUM
Information Disclosure Vulnerability in TDuck Survey Form by TDuckC...

The TDuck Survey Form 6.0 has a significant information disclosure issue wherein the FormAuthUtils.hasPermission method operates in a fail-open mode. This flaw allows authenticated users to access submissions from forms that are no longer valid. Specifically, when a user provides a dataId for a p...

PoC for CVE-2026-100303

TduckcloudTduck-survey-form5.3MEDIUM
Authorization Checks Bypass in TDuck Survey Form by TDuckCloud

The TDuck Survey Form, up to version 6.0, is susceptible to an authorization bypass vulnerability. Non-admin authenticated users can exploit the FormThemeController endpoints to manipulate global form themes and categories. This allows them to add, modify, or delete themes and theme categories, w...

PoC for CVE-2026-97896

KrayinLaravel-crm5.1MEDIUM
Cross Site Scripting Vulnerability in Krayin Laravel-CRM by Webkul

A cross site scripting vulnerability exists in Krayin Laravel-CRM versions up to 2.2.5, specifically in the Upload Functionality's ConfigurationForm::rules method. This issue can be exploited remotely, allowing attackers to inject scripts into web pages viewed by users. The vulnerability has been...

PoC for CVE-2026-97895

KrayinLaravel-crm5.3MEDIUM
Privilege Mismanagement in Krayin Laravel-CRM User Management

A vulnerability was identified in the Krayin Laravel-CRM framework affecting the User Management component. This issue arises from improper handling of the role_id argument in the UserController.php file, allowing unauthorized users to gain elevated privileges. The flaw can be exploited remotely,...

PoC for CVE-2026-97064

Yzcheng90X-springboot9.3CRITICAL
Authentication Bypass in X-SpringBoot Due to Hardcoded Static Maste...

X-SpringBoot versions up to 6.0 include a hardcoded static master login verification code (172839) that is enabled by default in the database seed. This vulnerability enables unauthenticated attackers to authenticate as any user by simply providing the public master code along with a known email ...

PoC for CVE-2026-97060

Yzcheng90X-springboot8.6HIGH
Object-Level Authorization Bypass in X-SpringBoot User Management

The X-SpringBoot framework through version 6.0 is susceptible to an object-level authorization bypass in its user management functionality. This vulnerability allows sub-administrators to manage users without proper ownership verification. Attackers with user-management permissions can exploit th...

PoC for CVE-2026-100192

Yzcheng90X-springboot6.9MEDIUM
Credential Exposure Vulnerability in X-SpringBoot by YZ Cheng

X-SpringBoot up to version 6.0 has a vulnerability in its application manager functionality that exposes sensitive appKey and appSecret credentials via an unauthenticated GET request. The flaw allows unauthorized attackers to access these credentials through the /application/manager/select endpoi...

PoC for CVE-2026-97886

MathurvishalCloudclassroom-PHP-pro...5.3MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom-PHP-Project

A SQL injection vulnerability has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically within the managevideos2.php file. This issue arises from the manipulation of the argument 'editassid', allowing remote attackers to execute unauthorized SQL commands. The software follo...

PoC for CVE-2026-97885

MathurvishalCloudclassroom-PHP-pro...6.9MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom Project

A vulnerability has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically in the updatefaculty.php file. This flaw arises from improper validation of the 'fid' argument, allowing for SQL injection attacks that can be executed remotely. As the project employs a rolling relea...

PoC for CVE-2026-97884

MathurvishalCloudclassroom-PHP-pro...5.3MEDIUM
SQL Injection Vulnerability in Student Update Functionality of math...

A vulnerability has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically in the Student Update Functionality located in the updatestudent.php file. This weakness, stemming from improper validation of user input, allows for SQL injection attacks through the manipulation of ...

PoC for CVE-2026-97883

MathurvishalCloudclassroom-PHP-pro...6.9MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom-PHP-Project

A security vulnerability exists in the mathurvishal CloudClassroom-PHP-Project prior to version 5dadec098bfbbf3300d60c3494db3fb95b66e7be, specifically in the 'updatequery.php' file. This issue allows an attacker to manipulate the 'gid' argument, resulting in SQL injection that can be initiated re...

PoC for CVE-2026-97882

MathurvishalCloudclassroom-PHP-pro...6.9MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom Faculty ...

A vulnerability exists in the mathurvishal CloudClassroom-PHP-Project that allows for SQL injection through the Faculty Authentication component. This vulnerability specifically resides in the 'loginlinkfaculty.php' file, where improper handling of user input in the form of arguments 'fid/pass' c...

PoC for CVE-2026-97879

ZhistareduStartraining6.9MEDIUM
Missing Authentication in zhistaredu StarTraining Component API-Doc...

A significant security flaw has been found in the zhistaredu StarTraining product, specifically within the API-Docs Endpoint at the SecurityConfig.java file. This vulnerability allows for missing authentication, enabling remote attackers to exploit the system. The vulnerability pertains to an unk...

PoC for CVE-2026-97878

ZhistareduStartraining6.9MEDIUM
Missing Authentication Vulnerability in zhistaredu StarTraining Dru...

A significant vulnerability has been identified in the zhistaredu StarTraining product affecting the Druid Console component. The flaw exists in the 'anonymous' function located in the '/druid/index.html' file, where inadequate authentication controls can be exploited. Attackers may leverage this...

PoC for CVE-2026-97877

ZhistareduStartraining6.9MEDIUM
JWT Token Handler Vulnerability in zhistaredu StarTraining Software

A vulnerability has been identified in the zhistaredu StarTraining software, specifically in the JWT Token Handler component. The issue arises from the UserLoginService.createToken function in application.yml, which leads to the use of hard-coded passwords due to improper handling of user_id and ...