Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2022-3218
Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.
PoC for CVE-2025-64512
Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...
PoC for CVE-2026-71362
Adobe Commerce has a vulnerability related to incorrect authorization mechanisms, which may allow an attacker to escalate their privileges and access sensitive resources without any user interaction. This security issue emphasizes the importance of robust authorization checks in e-commerce enviro...
PoC for CVE-2017-7494
Samba versions 3.5.0 up to 4.6.4, along with specific earlier releases, contain a serious vulnerability where a malicious client can upload a shared library to a writable share. This exploit allows the server to load and execute the uploaded file, leading to unauthorized control and potential dam...
PoC for CVE-2026-72898
Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...
Discovered 1 minute ago
PoC for CVE-2026-8794
PaperCut NG/MF features an undisclosed flaw within its authentication mechanism that allows unauthenticated remote attackers to exploit timing discrepancies. By analyzing the response times of login attempts, attackers can conduct username enumeration. The system engages in password hash comparis...
Discovered 31 minutes ago
PoC for CVE-2026-8793
The PaperCut NG/MF software experiences a vulnerability in its login component that inadequately restricts excessive authentication attempts. This weakness can be exploited by unauthenticated remote attackers to launch brute-force or credential-stuffing attacks. In specific configurations, attack...
Discovered 1 hour ago
PoC for CVE-2026-72898
Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...
PoC for CVE-2026-68820
A use after free vulnerability exists in the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to exploit the driver and potentially elevate privileges locally, threatening the integrity of the operating system. To mitigate risk, it is essential to apply the ...
Discovered 2 hours ago
PoC for CVE-2026-19905
A vulnerability in Jinher OA 1.0 has been discovered, allowing unauthorized SQL injection through an unprotected function located in the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This weakness enables remote attackers to manipulate the argument 'httpOID' for malicious purpose...
Discovered 3 hours ago
PoC for CVE-2026-72898
Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...
Discovered 4 hours ago
PoC for CVE-2026-19901
A security flaw has been identified in the LB-LINK X-PRO version 1.0.22-20231206 that impacts an unspecified function within the /etc/config/easycwmp file. The vulnerability enables the presence of hard-coded credentials, which could be exploited remotely. Although the complexity of the attack is...
PoC for CVE-2026-19900
A significant security vulnerability has been discovered in the LB-LINK X-PRO router, specifically in version 1.0.22-20231206. This issue pertains to an unknown function within the /etc/shadow file that exposes hard-coded credentials. Attackers can exploit this vulnerability remotely, allowing ac...
PoC for CVE-2026-19899
A SQL injection vulnerability has been identified in the SourceCodester Class and Exam Timetabling System, specifically in the 'edit_teacher.php' file. This issue arises from improper handling of the argument ID, enabling attackers to execute malicious SQL code remotely. The exploit has been publ...
Discovered 5 hours ago
PoC for CVE-2026-19898
A vulnerability exists in the VMAuth Authentication Endpoint of VictoriaMetrics, specifically within the requestHandler function in app/vmauth/main.go. This flaw allows attackers to perform excessive authentication attempts, potentially leading to unauthorized access. The vulnerability can be exp...
PoC for CVE-2026-19897
A security flaw exists within the D-Tale product developed by Man Group, specifically in the Login function found in the dtale/auth.py file. This vulnerability allows attackers to manipulate the Login Endpoint to bypass restrictions on excessive authentication attempts. As a result, it poses a ri...
Discovered 6 hours ago
PoC for CVE-2024-56426
A vulnerability exists in Samsung's Exynos mobile and wearable processors due to improper validation on incoming USB packets. This lack of length checks can potentially lead to out-of-bounds writes, allowing attackers to modify memory contents and execute arbitrary code. The affected processors i...
Discovered 7 hours ago
PoC for CVE-2026-19896
A vulnerability in the Man-Group dtale product affects the function responsible for generating cryptographic keys, specifically within the Flask Session Cookie implementation. This flaw leads to insufficiently random values, which could be exploited remotely, making the system susceptible to vari...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-19895
A security flaw has been identified in Open Source Point of Sale versions up to 3.4.2, impacting the Login Endpoint. Specifically, the vulnerability lies within the `Login::index` function in the `app/Config/Filters.php` file, allowing an attacker to exploit improper restrictions on excessive aut...
Discovered 8 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 9 hours ago
PoC for CVE-2026-19894
A vulnerability has been identified in the itsourcecode Hospital Management System version 1.0, specifically in the /viewmedicine.php file. The issue arises from improper handling of the 'delid' argument, allowing for SQL injection attacks to be executed remotely. Exploitation of this vulnerabili...
Discovered 15 hours ago
PoC for CVE-2026-18807
The ECS WordPress plugin prior to version 4.3.8 lacks adequate capability and ownership verification for its dynamic repeater actions. This inadequate validation enables users with contributor-level access and above to read, modify, and delete post configurations they do not own, Furthermore, it ...
PoC for CVE-2026-16541
The Simply Schedule Appointments WordPress plugin prior to version 1.6.12.17 suffers from improper access control. This flaw allows users with low privilege, such as those in staff roles, to access user records from REST endpoints without adequate restrictions. Consequently, this vulnerability en...
PoC for CVE-2026-16611
The Product Feed PRO plugin for WooCommerce prior to version 13.5.7 is susceptible to an authorization bypass due to a lack of proper checks on one of its REST read routes. This flaw permits unauthenticated users to access and disclose sensitive store feed configurations, including rules, filters...
PoC for CVE-2026-18216
The Backup Migration plugin for WordPress, prior to version 2.1.7, contains a security flaw whereby it fails to adequately restrict the automatic login feature following a restoration of backups. This oversight permits a user with administrative privileges on one site within a multisite network t...
PoC for CVE-2026-14230
The ECS WordPress plugin prior to version 4.3.8 lacks adequate capability and object-ownership checks for its Dynamic Repeater AJAX handlers. This flaw allows a Contributor level user to inject their own data-source bindings into any post, including those authored by admins. The injected values c...
PoC for CVE-2026-14229
The ECS WordPress plugin prior to version 4.3.8 has a critical vulnerability that permits unauthenticated users to access unpublished documents. This flaw occurs due to inadequate checks on post status or user capabilities when rendering Elementor documents through AJAX actions. As a result, atta...
Discovered 16 hours ago
PoC for CVE-2026-16007
The Qcuiknote feature of AppFlowy is susceptible to SQL injection attacks. This vulnerability allows authenticated users to manipulate SQL queries, potentially enabling them to exfiltrate sensitive data from the underlying SQL database. It highlights the importance of securing applications agains...
PoC for CVE-2026-31816
Budibase, a low code platform for creating internal tools, exhibits a significant vulnerability in its server's authorization mechanism. In versions 3.31.4 and earlier, the 'authorized()' middleware designed to protect server-side API endpoints can be bypassed entirely by appending a specific web...
Discovered 17 hours ago
PoC for CVE-2026-52715
An unauthenticated SQL injection vulnerability exists in the GEO my WordPress plugin prior to version 4.5.5. This vulnerability can be exploited by sending crafted requests that manipulate SQL queries, potentially allowing an attacker to retrieve sensitive data from the database. It is crucial fo...
Discovered 20 hours ago
PoC for CVE-2021-41773
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default config...
Discovered 21 hours ago
PoC for CVE-2026-53365
A vulnerability exists in the Linux kernel's vsock/virtio implementation regarding zerocopy completion for multi-segment sends. If a large message is fragmented into multiple skbs, only the last skb has the zerocopy user argument (uarg) allocated, leaving non-final skbs with pinned user pages tha...
PoC for CVE-2026-8452
A memory overflow vulnerability has been identified in Citrix's NetScaler ADC and NetScaler Gateway, which may lead to unpredictable behavior and potential denial of service if configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. This vulnerability can compromise s...
Discovered 23 hours ago
PoC for CVE-2026-54433
A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail prior to version 1.6.17 and in the 1.7.x series before 1.7.2. An attacker can exploit this vulnerability by sending a specially crafted plain-text email message. Upon the victim opening or previewing the email, the atta...
Discovered 1 day ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-19847
A security flaw has been identified in the TOTOLINK A800R router, specifically in the setWiFiWpsConfig function within the /cgi-bin/cstecgi.cgi file of the wps.so component. By manipulating the argument pin, an attacker can trigger a stack-based buffer overflow, allowing for potential remote expl...
PoC for CVE-2026-19846
A stack-based buffer overflow vulnerability exists in the setUrlFilterRules function of the firewall component in the TOTOLINK A800R router. This vulnerability can be exploited remotely by manipulating the url parameter in the /cgi-bin/cstecgi.cgi file. If successfully executed, it may lead to un...
PoC for CVE-2026-19845
A vulnerability exists in the TOTOLINK A800R router's setStaticDhcpConfig function, located in the /cgi-bin/cstecgi.cgi file within the lan.so component. An attacker can exploit this vulnerability by manipulating the Comment argument, which can lead to a stack-based buffer overflow. This vulnerab...
PoC for CVE-2026-19844
A stack-based buffer overflow vulnerability exists in the TOTOLINK A800R router firmware version 4.1.2cu.5137_B20200730, specifically within the setRadvdCfg function located in /cgi-bin/cstecgi.cgi of the ipv6.so component. An attacker can exploit this vulnerability by manipulating the radvdinter...
PoC for CVE-2026-19839
The Simple Doctors Appointment System version 1.0 by SourceCodester contains a vulnerability in the save_doctor function located in /save_file.php. This flaw allows attackers to remotely upload files without proper restrictions, posing significant security risks to the system. The exploit method ...
PoC for CVE-2026-19838
A significant security issue has been identified in the Webkul Bagisto platform, specifically within the Backend Reporting Endpoint located at /admin/reporting/sales/. This vulnerability allows unauthorized users to bypass access controls, potentially leading to unauthorized data exposure and man...
PoC for CVE-2026-72550
An SQL injection vulnerability exists in Friendica through the 2026.08-dev branch. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. As this parameter is concatenated without proper escaping into a SHOW COLUMNS query through ...
PoC for CVE-2026-19837
A vulnerability has been discovered in the Webkul Bagisto eCommerce platform, specifically affecting versions up to 2.4.4 in the Customer Search component. This weakness allows attackers to manipulate the 'Query' argument in the /admin/customers/search file, potentially leading to information exp...
PoC for CVE-2026-19836
A security vulnerability has been identified in Webkul Bagisto, specifically within the Backend Customer Detail Feature. The issue resides in the file /admin/customers/view, where manipulating the argument ID can lead to unauthorized access. This flaw allows attackers to remotely exploit the syst...
PoC for CVE-2026-19835
A security flaw has been detected in Webkul's Bagisto platform up to version 2.4.4, specifically related to the Customer Item Deletion Endpoint. This flaw allows attackers to bypass normal access controls, leading to unauthorized manipulation of customer data. The vulnerability can be exploited r...
PoC for CVE-2026-19834
A vulnerability exists in the Admin Customer Impersonation feature of Webkul Bagisto versions up to 2.4.4. This flaw allows unauthorized access due to the manipulation of the argument ID within the login-as-customer function. The exploitation of this vulnerability can be initiated remotely, posin...
PoC for CVE-2026-19829
A vulnerability has been identified in the 648540858 wvp-GB28181-pro product version 2.7.4-20260107, specifically within the Log File Download Endpoint in the LogController.java file. This flaw allows an attacker to manipulate the fileName argument, potentially leading to path traversal attacks. ...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-19828
A path traversal vulnerability was identified in the 648540858 wvp-GB28181-pro version 2.7.4-20260107. The issue resides in the PlayController.java file, specifically concerning the Snapshot Endpoint. An attacker can manipulate the deviceId or channelId arguments, allowing unauthorized access to ...