Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 1 hour ago
PoC for CVE-2026-18963
A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...
Discovered 2 hours ago
PoC for CVE-2026-82669
A vulnerability has been identified in GitList 2.0.0, specifically within the XML Parsing component. The issue lies in the SimpleXMLElement function within the src/SCM/System/Git/CommandLine.php file. An attacker can manipulate this function, leading to a denial of service scenario. This vulnerab...
PoC for CVE-2026-82668
A vulnerability exists in GitList version 2.0.0 that allows for OS command injection through the 'getDefaultBranch' function found in the Git Command Line component. This issue can be exploited remotely, potentially leading to unauthorized system commands being executed. Users are strongly advise...
Discovered 3 hours ago
PoC for CVE-2026-82667
A vulnerability has been identified in yaojingang GEOFlow prior to version 2.1.1, located in the DistributionController.isValidHttpEndpoint function. This flaw can be exploited through manipulated input for the endpoint_url argument, potentially leading to server-side request forgery (SSRF). The ...
Discovered 4 hours ago
PoC for CVE-2026-82631
A security flaw has been identified in the Valkey product by valkey-io, specifically within the Blocked-on-keys Subsystem. The vulnerability arises from the function handleClientsBlockedOnKey located in the file src/blocked.c, leading to a use after free condition. This flaw allows attackers to e...
PoC for CVE-2026-82630
A security vulnerability has been detected in PowerJob, specifically within the Transport Endpoint component. The issue exists in the MuConnectionManager.getOrCreateConnection function of the TestController.java file. This flaw enables attackers to execute server-side request forgery (SSRF) attac...
PoC for CVE-2026-82629
An unrestricted file upload vulnerability exists in the Jeecgboot Jeewx-Boot component, specifically within the doUpload function of the MyJwWebJwid3Controller.java file. This flaw allows remote attackers to manipulate file upload arguments, potentially leading to malicious file uploads on the se...
Discovered 5 hours ago
PoC for CVE-2026-82625
A cross-site scripting vulnerability has been identified in the Simple Inventory System 1.0 that affects the /register.php file associated with user registration. By manipulating the 'last_name' parameter, an attacker could execute arbitrary JavaScript in a victim's browser. This exploit can be e...
PoC for CVE-2026-82624
A vulnerability has been identified in the Simple Inventory System version 1.0 that affects the database backup functionalities through the file 'inventorymanagement.sql'. This flaw could potentially allow an attacker to access sensitive information remotely, putting the security of the system at...
PoC for CVE-2026-82623
A vulnerability was identified in the open62541 library, specifically in the History Backend component. This issue arises from the UA_DataValue_backend_copyRange function located in the plugins/historydata/ua_history_data_backend_memory.c file. When exploited, it leads to a use after free conditi...
PoC for CVE-2026-77013
The Love Collection Data Collection and Publishing plugin for WordPress, version 1.0.0, has a security flaw that permits unauthenticated users to invoke handler methods without appropriate checks. This oversight allows attackers to create user accounts and taxonomy terms within WordPress, potenti...
PoC for CVE-2026-82622
A security vulnerability has been identified in the Employee Leave Managing System, specifically within the Employee Profile Update function located in editaction.php. This flaw allows remote attackers to exploit the application by manipulating the 'Name' argument, resulting in cross site scripti...
Discovered 6 hours ago
PoC for CVE-2026-82621
A vulnerability has been discovered in Soarkey StudentManagement and 学生信息管理系统 that could allow an attacker to bypass authorization controls. This weakness is present in the AdminDao.doGet function within the Administrative Servlet component. By manipulating the action argument, remote exploitatio...
PoC for CVE-2026-60004
A serious vulnerability exists in Gitea prior to version 1.27.1, allowing attackers to perform remote code execution via manipulation of the diffpatch API. Exploiting this vulnerability can enable unauthorized users to install malicious Git hooks. It is crucial for users of Gitea to update to ver...
PoC for CVE-2026-60004
A serious vulnerability exists in Gitea prior to version 1.27.1, allowing attackers to perform remote code execution via manipulation of the diffpatch API. Exploiting this vulnerability can enable unauthorized users to install malicious Git hooks. It is crucial for users of Gitea to update to ver...
PoC for CVE-2026-82620
A security flaw has been identified in Soarkey StudentManagement and 学生信息管理系统, specifically affecting the function CourseDao.course_ranking located in code/src/dao/CourseDao.java. This vulnerability allows an attacker to manipulate the argument 'cno', thereby executing SQL injection attacks remot...
PoC for CVE-2026-82619
A vulnerability exists in Systerel S2OPC prior to version 1.7.4, specifically in the function monitored_item_event_filter_treatment_bs__init_event_filter_ctx_and_result within the source file subscription_mgr.c. This issue arises from improper handling of the EventFilter argument, leading to a us...
Discovered 7 hours ago
PoC for CVE-2026-82616
A critical vulnerability has been identified in the TOTOLINK NR1800X router, specifically affecting the function setUploadSetting located in the file /cgi-bin/cstecgi.cgi. An exploitable stack-based buffer overflow occurs due to improper handling of the FileName argument, enabling an attacker to ...
PoC for CVE-2026-82615
A security flaw exists in the itsourcecode Online Medicine Delivery System version 1.0, specifically within the Password Recovery Interface. The issue arises in the function Customer::find_phone located in the /passwordrecover.php file. This vulnerability allows an attacker to manipulate the phon...
PoC for CVE-2026-82614
A SQL Injection vulnerability has been identified in the itsourcecode Online Medicine Delivery System, specifically within the Product Category Filter interface. This issue arises in the function loadResultList located in the /index.php?q=product file. An attacker can exploit this flaw by manipul...
PoC for CVE-2026-82613
The itsourcecode Online Medicine Delivery System 1.0 is impacted by a SQL injection vulnerability found in the Product Search Interface. Specifically, unauthorized manipulation of the search query parameter in the loadResultList function of the /index.php?q=product file allows attackers to execut...
Discovered 8 hours ago
PoC for CVE-2026-67363
The Balbooa Forms extension for Joomla is susceptible to a significant vulnerability where the stripeCharges and payAuthorize endpoints accept payment amounts from user-controlled parameters. This flaw allows unattended attackers to manipulate payment amounts, potentially allowing them to purchas...
PoC for CVE-2026-82612
A vulnerability exists in the itsourcecode Online Medicine Delivery System 1.0, specifically in the loadResultList function of the Product Detail Page located at /index.php?q=single-item. An attacker can manipulate the ID argument, leading to remote SQL injection. This manipulation allows unautho...
PoC for CVE-2026-82611
A vulnerability has been discovered in itsourcecode's Online Medicine Delivery System version 1.0. This weakness is located in the Customer Login Interface, specifically within the cusAuthentication function in the login.php file. The vulnerability allows for SQL injection through improper handli...
PoC for CVE-2026-82610
A security flaw has been identified in itsourcecode's Online Medicine Delivery System version 1.0. The issue resides in the employee authentication function within the login interface, specifically in the employee::employeeAuthentication method in the /rider/login.php file. This vulnerability all...
PoC for CVE-2026-82609
A SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0. This vulnerability affects the function located in the file /pages/inv_edit.php, specifically due to improper handling of the argument ID. Attackers can exploit this vulnerability remotel...
Discovered 9 hours ago
PoC for CVE-2026-82608
A vulnerability affecting Kamailio versions up to 5.5.0 and 6.0.7 has been reported where an out-of-bounds read can occur due to improper handling in the get_4bytes function of the AVP Handler component. This vulnerability allows attackers to exploit the flaw remotely, potentially leading to unau...
PoC for CVE-2026-82607
A vulnerability exists in the Cozmoslabs Profile Builder Plugin up to version 3.16.1 that allows for unrestricted file uploads through the function wppb_ajax_simple_avatar in the admin-ajax.php file. This flaw can be exploited remotely, enabling attackers to upload malicious files without proper ...
Discovered 10 hours ago
PoC for CVE-2026-82603
A path traversal vulnerability has been identified in SeaCMS versions up to 13.6, specifically within the member.php file when handling the del_pl action. This vulnerability allows attackers to manipulate the itype/vid argument, potentially enabling unauthorized access to sensitive files on the s...
PoC for CVE-2026-82602
A security vulnerability has been identified in SeaCMS versions up to 13.6, specifically in the unknown code located in the file /ass.php. This vulnerability allows attackers to bypass authorization controls, potentially giving them unauthorized access to certain functionalities. The flaw can be ...
PoC for CVE-2026-82601
A vulnerability has been discovered in SeaCMS versions up to 13.6 that may permit remote attackers to execute cross site scripting (XSS) attacks. The issue resides in the handling of specific input within the '/err.php' file, where manipulation of the 'errtxt' argument can lead to the execution o...
PoC for CVE-2026-82600
A vulnerability exists in SeaCMS up to version 13.6, allowing for SQL injection through manipulated parameters in the /zyapi.php?ac=videolist endpoint. This exploit can be executed remotely, posing significant risks to data integrity and application security. Attackers can leverage this flaw to e...
Discovered 11 hours ago
PoC for CVE-2026-82599
A path traversal vulnerability has been identified in SeaCMS, specifically within the Avatar Upload feature of the /member.php?action=chgpwdsubmit component. By manipulating the oldpic parameter, an attacker can navigate the file system, potentially accessing sensitive files and executing unautho...
PoC for CVE-2026-48611
The OAuth implementation in phpBB has a critical flaw where improper authentication checks can lead to account hijacking. This vulnerability is particularly concerning as it may allow unauthorized users to gain access to accounts even if OAuth is not configured or enabled. Default installations a...
PoC for CVE-2026-82598
A vulnerability exists in SeaCMS, specifically affecting the Template Engine's search.php file within the parseIf function. This flaw allows an attacker to manipulate the searchtype argument, potentially leading to code injection. The exploit can be executed remotely, and its details have been pu...
PoC for CVE-2026-82597
A remote command injection vulnerability exists in the TOTOLINK NR1800X that affects the setUssd function within the cgi-bin/cstecgi.cgi file. By manipulating the ussd argument, an attacker can execute unauthorized commands on the device, potentially compromising network security. As the exploit ...
Discovered 12 hours ago
PoC for CVE-2026-82595
A command injection vulnerability has been identified in the D-Link DIR-825M router firmware version 1.1.8. This flaw lies within the system command execution function, specifically in '/boafrm/formSysCmd', where improper validation of the 'sysCmd' argument allows attackers to inject malicious co...
PoC for CVE-2026-82594
A vulnerability has been identified within the LogNet grpc-spring-boot-starter framework, specifically in its Annotation Processing functionality. This issue allows for improper authorization, potentially enabling malicious actors to exploit the system via remote execution. The complexity of the ...
PoC for CVE-2026-82593
A vulnerability has been identified in the D-Link DIR-825M router, specifically within the LTE Module Firmware Upgrade functionality. The issue lies in the manipulation of the fota_url parameter in the formLtefotaUpgradeFibocom, which can lead to a stack-based buffer overflow. This flaw allows fo...
PoC for CVE-2026-82592
A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-825M router within the Disk Formatting Handler Endpoint. This issue arises from improper handling of the 'partition' argument, allowing for remote exploitation. Attackers can leverage this vulnerability to execute a...
Discovered 13 hours ago
PoC for CVE-2026-82589
A security vulnerability exists in Open5GS up to version 2.7.7, specifically in the N1-N2 Message Handler's function amf_namf_comm_handle_n1_n2_message_transfer. This flaw can be exploited remotely by manipulating the N1N2MessageTransferReqData.n2InfoContainer.smInfo.n2InfoContent.ngapIeType argu...
Discovered 14 hours ago
PoC for CVE-2026-76581
The WPMU DEV Dashboard plugin for WordPress is prone to an authentication bypass vulnerability due to inconsistent handling of HMAC message construction between the `wdpsso_step1` and `wdpsso_step2` AJAX actions. The first step improperly exposes a concatenation of sensitive tokens, while the sec...
PoC for CVE-2018-7600
Multiple versions of Drupal, including those prior to 7.58 and various 8.x releases, are susceptible to a vulnerability that permits remote attackers to execute arbitrary code. This exploit takes advantage of configuration flaws in several subsystems, particularly those using default or common mo...
PoC for CVE-2014-6271
GNU Bash versions up to 4.3 are vulnerable to a code injection flaw due to the mishandling of trailing strings after function definitions in environment variables. This vulnerability enables remote attackers to execute arbitrary code by crafting specific environment variables under various condit...
PoC for CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...
Discovered 16 hours ago
PoC for CVE-2026-18741
The Worksuite SaaS platform, in versions prior to 6.0.14, is affected by a stored cross-site scripting vulnerability within its Asset Management module. This allows authenticated administrators to submit malicious JavaScript payloads in the Location and Description fields when adding new assets. ...
PoC for CVE-2026-82587
A vulnerability has been identified in Open5GS versions up to 2.7.7, specifically within the AMF component. The issue arises from the amf_namf_comm_decode_ue_mm_context_list function, where improper handling of the ueContext.mmContextList[*].allowedNssai parameter may lead to memory corruption, a...
Discovered 18 hours ago
PoC for CVE-2026-82556
A vulnerability exists in the Repository Migration Handler of Forgejo, specifically in the function net.LookupIP located in the file services/migrations/allowlist/is_migrate_allowed.go. This issue can be exploited remotely, allowing attackers to perform server-side request forgery. The public dis...
PoC for CVE-2026-82555
A significant vulnerability exists within the TOTOLINK N600R Router, specifically in the loginAuth function of the Authentication Handler component. This flaw arises from the use of insufficiently random values, making the system susceptible to remote exploitation. Attackers could leverage this v...