Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 52 minutes ago
PoC for CVE-2026-84383
The vulnerability in libheif, versions prior to 1.23.2, arises from a failure to properly handle crafted HEIF, HEIC, or AVIF item graphs containing nested iden and auxl references. This flaw allows an attacker to trigger a heap out-of-bounds write by exploiting the improper handling of Alpha plan...
Discovered 2 hours ago
PoC for CVE-2026-102847
A cross site scripting vulnerability has been identified in the gedelumbung HospitalManagement software, specifically within the Guest Book component. This flaw is associated with the manipulation of the parameters 'nama', 'email', and 'pesan' in the 'kirim' function located in the file applicati...
PoC for CVE-2026-102846
A vulnerability has been identified in gedelumbung HospitalManagement that allows for improper authorization via the Configuration Handler. The issue lies within the function sistem.php::simpan, where manipulation of the arguments such as tipe, title, and content_setting can allow unauthorized ac...
PoC for CVE-2026-102261
A security flaw in Owen2345 Camaleon CMS versions up to 2.9.2 has been identified, specifically within the Media Crop Handler component. The issue arises from an improper manipulation of the saved_avatar argument in the crop function located in the media_controller.rb file. This vulnerability may...
PoC for CVE-2026-102845
An information disclosure vulnerability has been identified in the Gedelumbung HospitalManagement product, specifically affecting the error_reporting function in the index.php file related to HTTP Response management. This flaw potentially allows attackers to gain unauthorized access to sensitive...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-102844
A vulnerability in the gedelumbung HospitalManagement system's reporting module allows remote attackers to bypass authorization controls by manipulating the 'id_param' argument in the application/modules/admin/controllers/laporan_data_pasien.php file. This flaw can lead to unauthorized data acces...
Discovered 3 hours ago
PoC for CVE-2026-102843
A vulnerability has been identified in gedelumbung HospitalManagement that allows for path traversal through the manipulation of the argument 'gbr' in the hapus function located in application/modules/admin/controllers/data_galeri.php. This security issue can be exploited remotely, enabling an at...
PoC for CVE-2026-34990
OpenPrinting's CUPS, an open source printing system for Linux and other Unix-like operating systems, is susceptible to a local privilege escalation vulnerability. An unprivileged user can exploit this flaw to trick the cupsd service into authenticating with an attacker-controlled IPP service on l...
Discovered 4 hours ago
PoC for CVE-2026-102794
A command injection vulnerability has been identified in the Ziroom ZHOME A0101 product, specifically affecting version 1.0.1.0. The problem lies in the handling of the URL parameter within the file /api/ZRnetwork/ping, allowing an attacker to manipulate this argument. Such manipulation could lea...
PoC for CVE-2026-100381
The MediaWiki UploadWizard Extension by Wikimedia Foundation is vulnerable to Cross-Site Scripting (XSS) due to improper input neutralization during webpage generation. This can allow attackers to execute arbitrary scripts in the context of users’ browsers, potentially compromising user data and ...
PoC for CVE-2026-100380
The Mediawiki - Wikibase Extension has a Cross-Site Scripting (XSS) vulnerability due to improper handling of user input during web page generation. This can allow attackers to inject malicious scripts that may execute in the context of a user's browser, compromising user data. The issue is prese...
PoC for CVE-2026-96878
A vulnerability within the Mediawiki Cargo extension allows for improper neutralization of input during web page generation, leading to reflected cross-site scripting (XSS). This issue can potentially enable an attacker to execute arbitrary JavaScript code in the context of the affected user's se...
PoC for CVE-2026-96877
An improper neutralization of input during web page generation in the MediaWiki Cargo extension has been identified, leading to a reflected cross-site scripting (XSS) vulnerability. This flaw could allow attackers to inject malicious scripts into web pages viewed by users, potentially compromisin...
PoC for CVE-2026-96876
A cross-site scripting vulnerability exists in the Cargo extension for Mediawiki, enabling attackers to inject malicious scripts into webpages. Through an improper handling of input during page generation, this flaw can lead to reflected XSS attacks, posing significant risks to users' data and pr...
PoC for CVE-2026-96875
A cross-site scripting vulnerability has been identified in the Cargo extension of Mediawiki, allowing for stored XSS attacks. This vulnerability stems from improper handling of user input during the web page generation process, which may permit an attacker to execute arbitrary scripts in the con...
PoC for CVE-2026-96874
The Cargo extension of Mediawiki is affected by a vulnerability that allows for improper handling of input during web page generation, which may lead to stored cross-site scripting (XSS). This flaw can enable attackers to inject malicious scripts into web pages viewed by other users, potentially ...
PoC for CVE-2026-96873
An improper input neutralization vulnerability in the Mediawiki - CirrusSearch extension allows attackers to execute arbitrary JavaScript code in a user's browser. This reflected cross-site scripting (XSS) flaw primarily affects versions of CirrusSearch up to 1.46.0, enabling potential exploitati...
PoC for CVE-2026-96872
An improper handling of insufficient permissions vulnerability in the Mediawiki WikiLambda Extension allows users to access functionalities that are not adequately constrained by Access Control Lists (ACLs). This issue impacts users across various operating systems, including Linux, MacOS, and Wi...
PoC for CVE-2026-102793
A critical vulnerability in the Ziroom ZHOME A0101, specifically in the set_time_zone function located in /api/ZRFirmware/set_time_zone, enables attackers to execute arbitrary commands through manipulation of the hostname or zonename arguments. This flaw allows for remote exploitation, raising se...
Discovered 5 hours ago
PoC for CVE-2026-102792
A vulnerability has been identified in the Ziroom ZHOME A0101 version 1.0.1.0, specifically affecting the set_syslog function located in the /api/ZRnetwork/set_syslog endpoint. This vulnerability allows for command injection through improper handling of the conloglevel and log_size parameters. An...
Discovered 6 hours ago
PoC for CVE-2026-102771
A critical security vulnerability has been identified in the Naichen ThinkCMF version 8.0.7 and earlier. This issue resides in the MailController's templatePut function found in the MailController.php file of the Email Template component. The vulnerability arises from improper handling of special...
PoC for CVE-2025-32463
The Sudo software, prior to version 1.9.17p1, contains a vulnerability that enables local users to gain root access through improper handling of configuration files. Specifically, when the optional --chroot command is used, the software incorrectly processes the /etc/nsswitch.conf file from a use...
PoC for CVE-2026-102621
A vulnerability has been discovered in Freedesktop Poppler versions prior to 26.09.0, specifically in the function SplashClip::clipToPath. This issue can be exploited through local environment manipulation, leading to an integer overflow. Publicly available exploits exist, underscoring the need f...
Discovered 7 hours ago
PoC for CVE-2026-24088
This vulnerability arises from a cryptographic issue in Qualcomm's bootloader, specifically when processing a certain partition. The flaw enables unauthorized users to write access to the system, potentially allowing them to load a customized bootloader. This raises significant security risks as ...
PoC for CVE-2026-102620
A critical vulnerability has been identified in Freedesktop Poppler versions 26.06.0, 26.07.0, and 26.08.0, stemming from an integer overflow in the FoFiTrueType::cvtSfnts function located in fofi/FoFiTrueType.cc. This flaw enables local attackers to potentially execute malicious code. The vulner...
Discovered 8 hours ago
PoC for CVE-2026-80521
A memory management vulnerability exists in the Linux kernel that impacts garbage collection related to socket control blocks (SCCs). The issue arises during the handling of SCC entries when two SCCs are simultaneously processed. It can lead to a situation where a new edge is published without qu...
PoC for CVE-2026-31431
A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...
Discovered 9 hours ago
PoC for CVE-2026-102616
A vulnerability has been identified in the Risesoft Y9 WorkFlow-Engine, specifically in the function getByIdAndYear within the CustomHistoricProcessServiceImpl.java file of the OAuth2 Resource Filter. This flaw allows malicious actors to manipulate the year or processInstanceId arguments, resulti...
PoC for CVE-2026-82901
The Ultra Addons for Contact Form 7 plugin for WordPress contains a vulnerability that allows unauthorized file uploads due to inadequate validation of file types in the 'uacf7_wpcf7_mail_components' function. This weakness affects all versions up to and including 3.5.50. When exploited, particul...
Discovered 13 hours ago
PoC for CVE-2026-102491
A security flaw exists in Mahonelau Kykms, specifically within the 'doMultiFieldsOrder' function in the QueryGenerator.java file of the SqlInjectionUtil component. An attacker can exploit this vulnerability by manipulating the 'column' argument, potentially allowing for SQL injection attacks. As ...
PoC for CVE-2026-49869
Kestra is an open-source orchestration platform that allows users to manage event-driven workflows. An issue exists in its AuthenticationFilter, where the public configuration endpoint is improperly secured by being checked only for suffix matches. This oversight permits remote attackers to gain ...
PoC for CVE-2026-102570
ClipBucket versions 5 through 5.5.3-#197 are susceptible to a time-based blind SQL injection flaw due to improper handling of the language_id parameter in the language update function. This vulnerability allows an authenticated administrator with basic_settings permission to craft malicious SQL q...
Discovered 14 hours ago
PoC for CVE-2026-10817
A vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway due to insufficient input validation, particularly when TCP TimeStamp is enabled in the TCP Profile. This flaw can lead to a memory overread condition when associated with certain virtual server types such as Load Balancers (LB)...
Discovered 16 hours ago
PoC for CVE-2026-102507
The Sliver C2 Framework versions 1.7.7 and earlier contain a vulnerability in the operator gRPC handler that allows an attacker to crash the entire teamserver. By sending malformed or empty Download responses from a compromised implant, attackers can trigger an unhandled panic through the operato...
Discovered 17 hours ago
PoC for CVE-2026-59310
VMware vCenter features a directory traversal vulnerability in its Syslog server component. This flaw allows attackers with network access to exploit the vulnerability, potentially leading to unauthorized execution of arbitrary code. Proper safeguards and patching are essential to mitigate the ri...
Discovered 18 hours ago
PoC for CVE-2021-43718
An Authentication Bypass vulnerability exists in EPSON EH-TW5350, enabling remote access that may allow unauthorized users to execute commands or compromise the device. This could lead to a Denial of Service, affecting the functionality of the device when exploited with a specific sequence of HTT...
PoC for CVE-2021-43717
A vulnerability exists within the Epson iProjection application for the EH-TW5350 projector, allowing unauthorized access through hard-coded authentication credentials. This flaw enables potential malicious users to control the projector remotely without proper authorization, posing a security ri...
PoC for CVE-2021-43716
A verification bypass vulnerability has been identified in the EPSON EasyMP Network Updater, specifically in the version 1.20 of the product. This issue allows malicious actors to exploit weaknesses in the firmware update mechanism that utilizes encrypted firmware via USB. Attackers could potenti...
PoC for CVE-2026-100633
SiYuan, a self-hosted personal knowledge management system, has a vulnerability in versions 3.8.0 through 3.8.3 that affects the sensitive-path guard due to an incomplete fix. The MCP file tool allows an authenticated administrator to bypass the protected-workspace-file denylist during recursive ...
PoC for CVE-2026-101894
The decompress package for Node.js enables extraction of archives but contains a vulnerability in its default decompress(input, output) API. It fails to adequately check for symlink chains, allowing an attacker to craft malicious archives with chained symlink entries. This results in the potentia...
Discovered 20 hours ago
PoC for CVE-2020-13664
This vulnerability in Drupal Core allows for arbitrary PHP code execution under specific conditions. An attacker may deceive an administrator into visiting a malicious page, resulting in the creation of a specially named directory on the server's filesystem. This directory could potentially be ex...
Discovered 21 hours ago
PoC for CVE-2026-87902
An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...
Discovered 22 hours ago
PoC for CVE-2026-38526
An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...
PoC for CVE-2026-102293
A vulnerability exists in the realjerrytang tacomall application, specifically within the OrgStaffServiceImpl.add function in ApiMaApplication.java. This flaw stems from inadequate validation of the isAdmin/jobId parameters, allowing attackers to manipulate them and gain unauthorized access. The ...
Discovered 23 hours ago
PoC for CVE-2026-102292
A vulnerability exists in the coolbeans1212 MateisHomePage-Website that allows for cross-site scripting (XSS) through inadequate handling of input in the users.php file. Malicious actors can exploit this flaw remotely, allowing them to execute arbitrary scripts in the context of a victim's browse...
PoC for CVE-2026-102290
A cross-site scripting vulnerability has been identified in CodeCanyon's Rocket LMS, specifically affecting the Student Profile Image Upload feature in versions up to 2.2. This flaw allows attackers to execute remote scripts through manipulation of the upload function, potentially compromising us...
PoC for CVE-2026-5053
The NoMachine software contains a vulnerability that allows local attackers to delete arbitrary files by exploiting improper validation of environment variables. An attacker needs to execute low-privileged code on the target system to exploit this weakness. By supplying a malicious path, the atta...
PoC for CVE-2026-5054
This vulnerability in NoMachine involves improper validation of user-supplied file paths during command line operations. Local attackers can exploit this flaw by executing low-privileged code, leading to unauthorized privilege escalation and the potential execution of arbitrary code within a root...
Discovered 1 day ago
PoC for CVE-2026-102249
A significant security flaw has been identified in the REBUILD application, specifically in the `/commons/file-editor-save` functionality. This vulnerability arises from a missing authorization check in the processing of the `url/fileKey` argument, which may allow an unauthorized user to execute ...