Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-33057

Mesop-devMesop9.8CRITICAL
Unrestricted Remote Code Execution in Mesop Python Framework

The Mesop UI framework, used for building web applications, contains a significant vulnerability in its ai/testing module. This flaw permits the ingestion of untrusted Python code without any authentication measures, leading to Unrestricted Remote Code Execution. By exploiting the /exec-py endpoi...

PoC for CVE-2025-59528

FlowiseaiFlowise🟣 EPSS 87%10CRITICAL
Remote Code Execution Vulnerability in Flowise by FlowiseAI

Flowise, a user-friendly platform for creating customized large language model flows, has a significant vulnerability in version 3.0.5 that allows for remote code execution. The flaw lies within the CustomMCP node, where user input is inadequately sanitized. Specifically, the mcpServerConfig stri...

PoC for CVE-2025-10952

GeyangMl-logger6.9MEDIUM
Information Disclosure Vulnerability in Geyang ML-Logger

A security flaw exists in Geyang ML-Logger that affects the stream_handler function within the ml_logger/server.py file of the File Handler component. This vulnerability allows an attacker to exploit the application remotely through manipulation of the argument key, potentially leading to unautho...

Discovered 1 hour ago

PoC for CVE-2026-23751

Tungsten AutomationTungsten Capture (form...9.3CRITICAL
Unprotected .NET Remoting Channel in Kofax Capture by Tungsten Auto...

Kofax Capture exposes a deprecated .NET Remoting HTTP channel on port 2424, accessible without authentication. This vulnerability allows an unauthenticated remote attacker to utilize .NET Remoting techniques to manipulate various system objects. By leveraging these techniques, attackers may read ...

Discovered 2 hours ago

PoC for CVE-2023-27350

PapercutNg🟣 EPSS 100%9.8CRITICAL
Bypass Authentication Vulnerability in PaperCut NG 22.0.5

A vulnerability in PaperCut NG allows remote attackers to bypass authentication due to improper access control within the SetupCompleted class. This can lead to the execution of arbitrary code with SYSTEM privileges, posing significant security risks. Attackers do not need to authenticate to expl...

Discovered 5 hours ago

PoC for CVE-2026-70463

RsyncprojectRsync8.6HIGH
Authorization Bypass in rsync Affects User Authentication

In affected versions of rsync prior to 3.5.0, a vulnerability exists within the parsing of the 'auth users' directive, leading to an authorization bypass. The issue arises from how the parser tokenizes the user list. It incorrectly handles group names containing spaces, resulting in the group mem...

Discovered 7 hours ago

PoC for CVE-2026-82111

IswalleGetnote-mcp5.3MEDIUM
Path Traversal Vulnerability in iswalle Getnote-MCP Component

A path traversal vulnerability exists in the upload_image component of iswalle Getnote-MCP, affecting versions up to 1.5.0. This issue arises from improper handling of the argument image_path in the fs.readFileSync function found in src/index.ts. An attacker could exploit this vulnerability remot...

Discovered 12 hours ago

PoC for CVE-2025-57819

FreepbxEndpoint🟣 EPSS 88%10CRITICAL
Unauthenticated Access Vulnerability in FreePBX by Sangoma Technolo...

FreePBX, an open-source web-based GUI, suffers from a vulnerability that permits unauthenticated users to gain access to the FreePBX Administrator interface. This is primarily due to insufficient sanitization of user-provided data. The flaw can lead to unauthorized database manipulation and may a...

PoC for CVE-2026-79995

WordPressUser Registration & Me...4.3MEDIUM
User Registration & Membership WordPress Plugin Vulnerability Affec...

The User Registration & Membership plugin for WordPress, prior to version 5.2.5, has a significant flaw that allows authenticated users with Subscriber-level access and above to cancel pending email change requests belonging to any user. This weakness stems from the plugin's failure to verify whe...

PoC for CVE-2026-79615

WordPressQuiz And Survey Master...2.7LOW
Authorization Flaw in Quiz and Survey Master Plugin by WordPress

The Quiz and Survey Master plugin for WordPress prior to version 11.2.4 contains a security flaw where it fails to verify authorization when retrieving question bank entries via its REST API. This oversight allows users with minimal roles, such as Contributor, to access sensitive quiz information...

PoC for CVE-2026-79706

WordPressBreeze Cache5.3MEDIUM
File Path Manipulation Vulnerability in Breeze Cache WordPress Plugin

The Breeze Cache WordPress plugin fails to properly sanitize user input when constructing file paths for cached files. This flaw allows unauthenticated attackers to exploit the vulnerability, potentially leading to file creation at arbitrary locations on the server. As a result, sensitive data ex...

PoC for CVE-2026-79996

WordPressUser Registration & Me...7.2HIGH
Privilege Escalation Vulnerability in User Registration & Membershi...

The User Registration & Membership plugin for WordPress, prior to version 5.2.6, lacks essential capability checks during the save process for login settings. This oversight allows authenticated users, who possess specific management rights but not full administrator access, to manipulate site op...

PoC for CVE-2026-19084

WordPressShared-files-pro7.5HIGH
File Path Validation Issue in Shared-Files-Pro WordPress Plugin by ...

The Shared-Files-Pro WordPress plugin prior to version 1.7.70 is susceptible to a file path validation exploit. This vulnerability allows unauthenticated users to bypass security measures and access arbitrary files stored on the server. By leveraging this flaw during the creation of a featured im...

PoC for CVE-2026-19423

WordPressUltimate Member8.1HIGH
Unauthorized Role Assignment in Ultimate Member WordPress Plugin

The Ultimate Member WordPress plugin, prior to version 2.13.0, is susceptible to an improper input validation issue that allows unauthenticated users to manipulate role selections on their profile forms. Instead of validating the selected roles against a specific allow-list, the plugin incorrectl...

PoC for CVE-2026-77701

WordPressWcfm Marketplace5.3MEDIUM
Unauthorized Refund Request Vulnerability in WCFM Marketplace Plugi...

The WCFM Marketplace WordPress plugin prior to version 3.8.2 contains a vulnerability that fails to properly verify ownership of refund requests. As a result, this allows unauthenticated users to exploit the system by submitting refund requests for any guest checkout orders, potentially leading t...

PoC for CVE-2026-14567

WordPressUser Frontend5.3MEDIUM
Access Control Vulnerability in User Frontend Plugin for WordPress

The User Frontend plugin for WordPress versions prior to 4.3.10 suffers from an access control vulnerability, where the user directory search endpoint lacks proper authentication mechanisms. This oversight permits unauthorized attackers to indiscriminately access sensitive information, including ...

PoC for CVE-2026-14558

WordPressUser Frontend7.2HIGH
Remote Code Execution Vulnerability in User Frontend Plugin for Wor...

The User Frontend plugin for WordPress prior to version 4.3.10 fails to properly validate field type definitions, which permits deserialization of user-controlled post metadata during the rendering of submitted posts. This vulnerability can be exploited by users with Editor-level access or higher...

PoC for CVE-2026-12513

WordPressShared Files6.8MEDIUM
File Path Manipulation Vulnerability in Shared Files WordPress Plugin

The Shared Files WordPress plugin and its enhanced version, shared-files-pro, contain a significant vulnerability in their file handling mechanisms. Specifically, these plugins fail to appropriately sanitize file paths derived from frontend file submissions. This flaw allows unauthenticated users...

PoC for CVE-2026-12514

WordPressShared Files5.3MEDIUM
File Upload Flaw in Shared Files Plugin for WordPress

The Shared Files and shared-files-pro plugins for WordPress are susceptible to a file upload vulnerability due to the lack of proper capability checks in their file-upload handler. This handler is accessible to unauthenticated users and relies solely on a nonce shown on public pages for protectio...

Discovered 15 hours ago

PoC for CVE-2026-82090

GetpocketPocket9.2CRITICAL
XSS Vulnerability in Pocket by Read It Later, Inc.

The Pocket application, specifically in version 8.33.0.0, is susceptible to a Cross-Site Scripting vulnerability. This occurs due to the 'Save to Pocket' functionality which injects untrusted external HTML into the Document Object Model (DOM). This enables malicious JavaScript code to potentially...

Discovered 20 hours ago

PoC for CVE-2026-81847

Maa-aiMaamcp5.1MEDIUM
Path Traversal Vulnerability in MAA-AI MaaMCP Software

A vulnerability has been discovered in the MAA-AI MaaMCP software, specifically in the save_pipeline/load_pipeline functions within the pipeline_tools.py file. This flaw allows remote attackers to manipulate the system through path traversal, enabling unauthorized access to sensitive files. The a...

Discovered 21 hours ago

PoC for CVE-2020-14882

OracleWeblogic Server🟣 EPSS 100%9.8CRITICAL
Remote Code Execution Vulnerability in Oracle WebLogic Server by Or...

A vulnerability exists in Oracle WebLogic Server's Console component that allows for unauthorized remote code execution. An unauthenticated attacker with network access via HTTP can exploit this flaw, potentially leading to a complete takeover of the affected server instances. This issue affects ...

PoC for CVE-2026-81845

Arben-admMcp-sequential-thinking5.3MEDIUM
Path Traversal Vulnerability in arben-adm mcp-sequential-thinking

A path traversal vulnerability exists in the mcp-sequential-thinking component's import_session/export_session functionality. This issue is due to improper validation of the 'file_path' argument in server.py, allowing attackers to access unintended files on the server. This vulnerability can be e...

PoC for CVE-2021-27876

VeritasBackup Exec🟣 EPSS 14%8.1HIGH
Unauthorized Access Vulnerability in Veritas Backup Exec

A vulnerability has been identified in Veritas Backup Exec versions prior to 21.2 that compromises secure communication between clients and agents. This flaw arises from weaknesses in the SHA Authentication scheme, allowing an unauthorized attacker to bypass authentication. Once exploited, the at...

PoC for CVE-2026-81837

RoocodeincRoo-code5.3MEDIUM
Path Traversal Vulnerability in RooCodeInc Roo-Code Software

A security flaw within RooCodeInc's Roo-Code software allows for path traversal through the ApplyPatchTool component. Specifically, this issue affects the path.resolve function in the src/core/tools/ApplyPatchTool.ts file, enabling remote attackers to manipulate file paths. This vulnerability is ...

PoC for CVE-2026-81836

RoocodeincRoo-code6.3MEDIUM
Cleartext Transmission Vulnerability in Roo-Code OAuth Callback by ...

A security issue in RooCodeInc's Roo-Code software allows for the cleartext transmission of sensitive information through the OAuth Callback component. Specifically, the vulnerability is found in the file src/integrations/claude-code/oauth.ts, leading to potential exposure of critical data during...

Discovered 22 hours ago

PoC for CVE-2026-81835

RoocodeincRoo-code5.1MEDIUM
Code Injection Vulnerability in RooCodeInc Roo-Code Up to 3.51.1

A code injection vulnerability has been identified in the RooCodeInc Roo-Code application, specifically within the fetch_instructions function of the malicious_mcp_server.py file. This issue arises within the MCP Integration Trust Model and enables attackers to manipulate functions remotely, lead...

PoC for CVE-2026-81834

RoocodeincRoo-code5.3MEDIUM
Code Injection Vulnerability in Roo-Code by RooCodeInc

A code injection vulnerability exists in Roo-Code by RooCodeInc, specifically in the ExecaTerminalProcess function of the README File Handler component. This flaw allows an attacker to remotely execute malicious code by manipulating the affected feature. With the product no longer actively suppor...

Discovered 23 hours ago

PoC for CVE-2026-81833

RoocodeincRoo-code5.1MEDIUM
Code Injection Vulnerability in RooCodeInc Roo-Code Product

A security flaw has been found in RooCodeInc's Roo-Code product up to version 3.51.1. The vulnerability resides in the 'optimizeQuery' function of the 'src/utils/helpers.ts' file within the CodeIndexManager component. This weakness allows for code injection via manipulation, resulting in a potent...

PoC for CVE-2026-81934

RedisRedis9.2CRITICAL
Use-After-Free Vulnerability in Redis with TLS Support

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which processes incoming TLS data. When configured for TLS support, this vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands with the privileges of the Redis server. This cou...

PoC for CVE-2004-2687

SambaSamba🟣 EPSS 88%
Remote Command Execution Vulnerability in distcc for XCode and Others

distcc 2.x, often utilized in XCode 1.5 and other software, is prone to vulnerabilities when improperly configured. This flaw enables remote attackers to execute arbitrary commands through compilation jobs processed by the server without proper authorization checks. If access to the server port i...

Discovered 1 day ago

PoC for CVE-2026-76640

Unitree RoboticsG1 Edu7.7HIGH
Multiple Vulnerabilities in Unitree G1 EDU Firmware Impact BLE GATT...

The Unitree G1 EDU firmware exposes critical flaws through its BLE GATT server and WiFi provisioning stack, allowing proximity-based attackers to execute arbitrary code without authentication. By exploiting an unquoted heredoc variable in the WiFi provisioning script alongside a buffer overflow i...

PoC for CVE-2026-76640

Unitree RoboticsG1 Edu7.7HIGH
Multiple Vulnerabilities in Unitree G1 EDU Firmware Impact BLE GATT...

The Unitree G1 EDU firmware exposes critical flaws through its BLE GATT server and WiFi provisioning stack, allowing proximity-based attackers to execute arbitrary code without authentication. By exploiting an unquoted heredoc variable in the WiFi provisioning script alongside a buffer overflow i...

PoC for CVE-2015-3246

RedhatLibuser5.1MEDIUM
Local User Vulnerability Affecting Usermode Package in libuser

The vulnerability in the libuser library affects the userhelper program, allowing for a local user to directly modify the /etc/passwd file. If this modification fails, it may result in an inconsistent file state, leading to a denial of service. Additionally, this issue can potentially be exploite...

PoC for CVE-2015-5287

RedhatAutomatic Bug Reportin...7.8HIGH
Local Privilege Escalation Vulnerability in Automatic Bug Reporting...

The Automatic Bug Reporting Tool (ABRT) prior to version 2.7.1 is susceptible to a local privilege escalation vulnerability. This flaw allows local users with specific permissions to execute a symlink attack on files with predictable names, such as '/var/tmp/abrt/abrt-hax-coredump' or '/var/spool...

PoC for CVE-2026-19092

WordPressTutor Lms9.8CRITICAL
Remote Code Execution Vulnerability in Tutor LMS Plugin by WordPress

The Tutor LMS WordPress plugin, prior to version 4.0.6, contains a significant security flaw that permits unauthenticated users to manipulate request data, leading to the overwriting of internal variables during template rendering. This vulnerability enables attackers to invoke arbitrary zero-arg...

PoC for CVE-2026-72898

MetabaseMetabase🟣 EPSS 79%10CRITICAL
SQL Injection Vulnerability in Metabase by Metabase, Inc.

Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...

PoC for CVE-2026-38526

WebkulKrayin CRM9.9CRITICAL
Arbitrary File Upload Vulnerability in Webkul Krayin CRM

An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...

PoC for CVE-2026-19478

GitlabGitlab9.4CRITICAL
Remote Code Modification Vulnerability in GitLab CE/EE

A flaw in GitLab CE/EE allows unauthenticated users to exploit specific GraphQL directives, potentially resulting in unauthorized modification or deletion of public projects and user data. This vulnerability impacts various versions, necessitating immediate user awareness and prompt application o...

PoC for CVE-2026-20303

CiscoCisco Catalyst Sd-wan ...9.9CRITICAL
Improper Input Validation in Cisco Catalyst SD-WAN

Cisco's Catalyst SD-WAN product has been identified with vulnerabilities stemming from improper input validation, as revealed during an internal security review. These issues can potentially expose the system to various security risks, underscoring the importance of implementing software hardenin...

PoC for CVE-2026-77542

Ubiquiti IncUid Enterprise Agent9.1CRITICAL
Improper Input Validation in UID Enterprise Agent by Ubiquiti

A security flaw has been identified in the UID Enterprise Agent developed by Ubiquiti, where improper input validation can be exploited by malicious actors with network access and elevated privileges. This vulnerability enables the execution of command injection on the host device, potentially al...

PoC for CVE-2026-18431

WordPressAvada (fusion) Builder9.8CRITICAL
Avada Theme for WordPress Vulnerable to Arbitrary File Write

The Avada theme for WordPress presents a significant security risk due to an arbitrary file write vulnerability that affects all versions up to 7.16 when paired with an active Fusion Builder plugin (up to version 3.16). This flaw stems from a combination of authorization issues and inadequate inp...

PoC for CVE-2026-81562

AlexgladkovClaude-in-mobile4.8MEDIUM
OS Command Injection Vulnerability in AlexGladkov claude-in-mobile

A security flaw has been identified in AlexGladkov's claude-in-mobile, specifically affecting the execSync function in src/adb/client.ts. This vulnerability allows for OS command injection, requiring local access to the system for exploitation. An upgrade to version 3.10.3 is necessary to mitigat...

PoC for CVE-2026-8467

PhenixdigitalPhoenix Storybook9.5CRITICAL
Code Injection Vulnerability in Phoenix Storybook by Phenix Digital

A vulnerability exists in Phenix Digital's Phoenix Storybook that allows unauthenticated remote code execution due to unsanitized attribute value interpolation during HEEx template generation. The psb-assign WebSocket event handler permits arbitrary attribute names and values from unauthenticated...

PoC for CVE-2026-74233

ZbtlinkWe13269.3CRITICAL
Command Injection Vulnerability in Zbtlink Firmware Products

A security flaw in the Zbtlink firmware for multiple wireless devices allows remote attackers to exploit the infosrvd service via crafted UDP packets. This vulnerability bypasses authentication mechanisms, as it employs a hardcoded salt, enabling unprivileged users to execute arbitrary commands a...

PoC for CVE-2026-81560

BlackmsAistack6.9MEDIUM
Path Traversal in blackms aistack Affecting Static File Handler Fun...

A vulnerability exists in blackms aistack up to version 1.6.1, impacting the Static File Handler component located in src/web/server.ts. This flaw allows for path traversal due to improper handling of the req.url argument, which can be exploited remotely. The exploit code is publicly accessible, ...

Discovered 2 days ago

PoC for CVE-2026-78333

WordPress12 Step Meeting List8.8HIGH
Stored Cross-Site Scripting Vulnerability in 12 Step Meeting List P...

The 12 Step Meeting List WordPress plugin prior to version 3.19.17 allows unauthenticated users to submit unsanitized input, which is stored in the activity log. This input is later displayed back to users in the admin area without adequate escaping, making it possible for an attacker to execute ...

PoC for CVE-2026-78139

WordPressNotifima4.3MEDIUM
Authorization Bypass Vulnerability in Notifima WordPress Plugin

The Notifima WordPress plugin before version 3.1.4 lacks proper validation of subscription ownership on its REST endpoints. This oversight allows authenticated users with Subscriber-level access to manipulate subscription settings, specifically the ability to unsubscribe any customer from receivi...

PoC for CVE-2026-77017

WordPressWorkeera7.7HIGH
File Access Vulnerability in Workeera WordPress Plugin

The Workeera WordPress plugin versions prior to 1.0.6 allows users with minimal permissions, such as a subscriber, to submit any profile values without restrictions. This lack of input validation leads to unauthorized access where these users can read arbitrary files stored on the server. This in...

PoC for CVE-2026-78137

WordPressStoregrowth7.5HIGH
Price Manipulation Vulnerability in StoreGrowth Plugin for WordPress

The StoreGrowth WordPress plugin prior to version 2.1.2 is vulnerable due to insufficient validation of browser-supplied product prices on certain unauthenticated actions. This flaw permits attackers to specify arbitrary prices when adding products to the shopping cart, especially when the 'Buy O...