Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 2 hours ago

PoC for CVE-2026-108521

Studio-saelixSencho5.1MEDIUM
Server-Side Request Forgery Vulnerability in Studio-Saelix Sencho

A vulnerability exists in the Add Remote Node API Endpoint within Studio-Saelix Sencho versions up to 0.97.1. This weakness can be exploited through the isValidRemoteUrl function in the backend's validation utilities. By manipulating the API URL, an authenticated user with node-management permiss...

Discovered 3 hours ago

PoC for CVE-2026-108693

ImagemagickImagemagick7.3HIGH
Uncontrolled Search Path Vulnerability in ImageMagick by ImageMagick

ImageMagick versions on Windows prior to 7.1.2-33 and 6.9.13-58 are susceptible to an uncontrolled search path vulnerability within the NTGhostscriptEXE() function. This flaw allows attackers to execute arbitrary code with ImageMagick's privileges by placing a malicious version of gswin64c.exe in...

Discovered 4 hours ago

PoC for CVE-2026-108708

WukongopensourceWukong Hrm8.7HIGH
Missing Authorization Vulnerability in Wukong_HRM Affecting Data Se...

Wukong_HRM contains a significant missing authorization vulnerability due to a flaw in the EmployeeAspect component, which inadvertently assigns every authenticated user the HR administrator role. This allows low-privileged employees to access sensitive information, such as payslips and personal ...

PoC for CVE-2026-108707

WukongopensourceWukong Hrm9.3CRITICAL
Authentication Bypass Vulnerability in Wukong HRM by WuKong Open So...

Wukong HRM is susceptible to an authentication bypass vulnerability in its ParamAspect component, allowing unauthenticated malicious actors to access all HRM API endpoints by omitting the required AUTH-TOKEN header. This flaw can lead to unauthorized access to sensitive HR data, including employe...

PoC for CVE-2026-108706

ElunezEladmin5.3MEDIUM
Missing Authorization Vulnerability in eladmin S3 Storage Handler

The eladmin framework, through a specific commit, has a vulnerability in its S3 storage download handler that lacks proper authorization checks. As a result, any authenticated user can exploit this flaw to access stored object URLs, bypassing necessary permissions. By sequentially enumerating IDs...

PoC for CVE-2026-108707

WukongopensourceWukong Hrm9.3CRITICAL
Authentication Bypass Vulnerability in Wukong HRM by WuKong Open So...

Wukong HRM is susceptible to an authentication bypass vulnerability in its ParamAspect component, allowing unauthenticated malicious actors to access all HRM API endpoints by omitting the required AUTH-TOKEN header. This flaw can lead to unauthorized access to sensitive HR data, including employe...

PoC for CVE-2026-108705

1panel-devCordyscrm5.3MEDIUM
Missing Authorization Vulnerability in CordysCRM Product by 1Panel-dev

CordysCRM versions up to 1.9.3 are susceptible to a missing authorization vulnerability that affects the POST /custom-form/data/import endpoint. This flaw enables authenticated users, including those with low privileges, to exploit the customFormId parameter, thereby allowing unauthorized data im...

PoC for CVE-2026-108703

1panel-devCordyscrm5.3MEDIUM
Missing Authorization Vulnerability in CordysCRM by Cordys

CordysCRM versions up to 1.9.3 are susceptible to a missing authorization issue in the endpoint /approval-resource/push. This security flaw allows any authenticated user, regardless of their privilege level, to submit resource requests for approval without proper ownership validations. Attackers ...

PoC for CVE-2026-108704

1panel-devCordyscrm5.3MEDIUM
Authorization Bypass in CordysCRM Affects User Permissions

CordysCRM versions up to 1.9.3 are susceptible to an authorization bypass vulnerability, allowing authenticated users with low privileges to circumvent permission checks. By altering the owner field to their own user ID, attackers can exploit this flaw through various endpoints such as follow, re...

PoC for CVE-2026-108702

1panel-devCordyscrm5.3MEDIUM
Server-Side Request Forgery in 1Panel-dev CordysCRM Product

The CordysCRM application lacks a necessary permission check on the webhook endpoint, allowing authenticated users to send arbitrary requests to any URL. This vulnerability enables attackers to bypass the SSRF validation process and probe internal resources based on responses from GET requests. T...

PoC for CVE-2026-108701

1panel-devCordyscrm5.3MEDIUM
Missing Authorization Vulnerability in 1Panel-dev CordysCRM

The CordysCRM application prior to version 1.9.2 is susceptible to a missing authorization vulnerability within its ContractController sortModule handler. This flaw allows authenticated users without the appropriate contract update permissions to manipulate any contract by supplying unauthorized ...

PoC for CVE-2026-108700

1panel-devCordyscrm7.1HIGH
Missing Authorization in 1Panel-dev CordysCRM Allows Data Exposure ...

The 1Panel-dev CordysCRM product prior to version 1.9.2 has been found to possess a missing authorization vulnerability. Authenticated users can exploit this weakness to access business titles by sending a POST request to /field/source/business-title without appropriate permission checks. This fl...

PoC for CVE-2026-108691

Gz-yamiMall4j5.3MEDIUM
Improper Authorization Vulnerability in mall4j Affects User Cart Ma...

An improper authorization vulnerability exists in mall4j version 4.0 that allows authenticated storefront customers to manipulate other users' cart items. Exploiting an operator precedence error in the cleanExpiryProdList SQL query, attackers can issue a single DELETE request to the endpoint /p/s...

PoC for CVE-2026-108690

Gz-yamiMall4j5.3MEDIUM
Information Disclosure Vulnerability in mall4j by Yami

The mall4j version 4.0 contains an information disclosure vulnerability that permits authenticated users to access details from other customers' shopping carts. This flaw arises from an operator precedence issue within the getShopCartExpiryItems SQL filter, allowing attackers with a storefront ac...

PoC for CVE-2026-108689

WukongopensourceWukong Aicrm5.3MEDIUM
Authorization Bypass Vulnerability in Wukong AICRM by WuKong

Wukong AICRM, up to version 20260610, contains an authorization bypass vulnerability that permits authenticated users to gain unintended access to other users' AI chat sessions. This is achieved by manipulating the session ID in POST requests to /chat/send. Attackers can inject messages into anot...

PoC for CVE-2026-108688

ElunezEladmin5.3MEDIUM
Missing Authorization Flaw in Eladmin LocalStorageController

Eladmin versions up to 2.7 are affected by a vulnerability in the LocalStorageController's uploadPicture handler. This flaw allows authenticated users with low privileges to bypass required permissions for file uploads. By exploiting this weakness, attackers can issue POST requests with image-nam...

PoC for CVE-2026-84411

MikrotikRouteros9.3CRITICAL
Integer Underflow Vulnerability in RouterOS Web Management Service

The web management service of MikroTik's RouterOS is affected by an integer underflow issue that can be exploited by an unauthenticated attacker. This vulnerability allows for manipulation of HTTP request bodies, which could lead to arbitrary code execution with root privileges or cause a denial ...

PoC for CVE-2025-9548

LenovoPower Management Driver6.8MEDIUM
Null Pointer Dereference Vulnerability in Lenovo Power Management D...

A local authenticated user could exploit a null pointer dereference vulnerability present in the Lenovo Power Management Driver. This exploitation may lead to system instability, including a Windows blue screen error. It is crucial for users to apply the latest security updates to mitigate this r...

PoC for CVE-2026-69414

MicrosoftMicrosoft Malware Prot...7.8HIGH
Elevation of Privilege Vulnerability in Microsoft Malware Protectio...

A significant vulnerability has been identified within the Microsoft Malware Protection Engine used in Microsoft Defender, allowing for elevation of privilege. This may potentially enable attackers to gain elevated privileges on affected systems. Microsoft is actively working on a security update...

Discovered 7 hours ago

PoC for CVE-2026-108680

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot Allows Spoofing of Notifications...

JeecgBoot version 3.9.5 is susceptible to a missing authorization flaw that allows authenticated users to exploit the /sys/api/sendTemplateAnnouncement endpoint. This vulnerability can be leveraged by low-privileged attackers to fabricate sender and recipient parameters, modifying the title and t...

PoC for CVE-2026-108676

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot SysAnnouncementController Affect...

JeecgBoot version 3.9.5 features a vulnerability in the SysAnnouncementController that permits unauthorized file download access. Specifically, low-privileged authenticated users can manipulate the downLoadFiles handler to obtain ZIP files containing attachments from announcements. This exploitat...

PoC for CVE-2026-108675

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot by Jeecg

JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability in the SysAnnouncementController's editIzTop handler. This flaw enables low-privileged authenticated users to alter the pin status of announcements. Attackers can exploit this vulnerability by sending POST or ...

PoC for CVE-2026-108674

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot OpenApiController Affects User P...

The JeecgBoot platform, versions up to 3.9.5, is impacted by a missing authorization vulnerability located in the OpenApiController's queryById handler. This flaw permits low-privileged authenticated users to access OpenAPI definitions without the requisite permissions. Attackers can exploit this...

PoC for CVE-2026-108673

JeecgbootJeecgboot5.3MEDIUM
Authorization Flaw in JeecgBoot's AiragPromptsController Export Fea...

JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability in the AiragPromptsController's exportXls function. This flaw allows any authenticated user to export sensitive AI prompts from the system. Specifically, attackers with low privileges can access the /airag/pro...

PoC for CVE-2026-108671

JeecgbootJeecgboot7.1HIGH
Missing Authorization Vulnerability in JeecgBoot Affects Multiple V...

JeecgBoot version 3.9.5 is susceptible to a vulnerability that enables authenticated users to access MCP server configurations without proper permissions. Specifically, the lack of a functional permission check in the /airag/app/queryById endpoint allows attackers to exploit this flaw. By retriev...

PoC for CVE-2026-108672

JeecgbootJeecgboot5.3MEDIUM
Authorization Bypass in JeecgBoot allows Unauthorized Access to Use...

JeecgBoot versions up to 3.9.5 have a vulnerability in the getVideoRecords handler within the VideoGenerationController. This issue allows authenticated users to bypass authorization checks, enabling them to access the video generation history of other users. By manipulating the userId parameter,...

PoC for CVE-2026-108670

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot Product by Jeecg

JeecgBoot version 3.9.5 is affected by a missing authorization vulnerability in the promptExperiment handler of the AiragPromptsController. This flaw permits any authenticated user to execute AI prompt experiments, potentially allowing low-privileged attackers to specify other users' prompt templ...

PoC for CVE-2026-108668

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot's AiragPromptsCont...

The JeecgBoot version 3.9.5 software has a missing authorization vulnerability located in the AiragPromptsController's deleteRecycleBin handler. This flaw enables any authenticated user to exploit the system by sending DELETE requests with specific prompt template IDs. As a result, these users ca...

PoC for CVE-2026-108667

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Flaw in JeecgBoot Allows Low-Privileged User ...

JeecgBoot version 3.9.5 is affected by a missing authorization vulnerability that permits low-privileged authenticated users to exploit the revertRecycleBin endpoint. By sending crafted PUT requests to /airag/prompts/revertRecycleBin with specific template IDs, an attacker can bypass administrato...

PoC for CVE-2026-108666

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot's AiragPromptsController Allows ...

JeecgBoot versions up to 3.9.5 present a security issue in the AiragPromptsController due to a missing authorization check in the deleteBatch handler. This flaw enables authenticated users, including those with low privileges, to delete AI prompt templates created by other users or administrators...

PoC for CVE-2026-108663

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot SysTenantController Affects User...

JeecgBoot version 3.9.5 contains a vulnerability in the SysTenantController's deleteApply handler, allowing any authenticated user to compromise tenant administrator applications. This flaw enables low-privileged attackers to issue PUT requests with specific tenantId, packId, and userId values, e...

PoC for CVE-2026-108664

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot Affects User Data ...

JeecgBoot version 3.9.5 contains a vulnerability in the AiragPromptsController's queryById handler, which permits low-privileged authenticated users to access AI prompt templates improperly. By exploiting this vulnerability, attackers can enumerate IDs through the unsecured /airag/prompts/list en...

PoC for CVE-2026-108662

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot Enables User Removal by Low-Priv...

JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability that permits low-privileged authenticated users to remove other users from tenant product packs. By exploiting this flaw via the PUT request to /sys/tenant/deleteTenantPackUser, attackers can supply arbitrary ...

PoC for CVE-2026-108660

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot Affects User Account Management

JeecgBoot version 3.9.5 is susceptible to a missing authorization vulnerability, allowing authenticated users with low privileges to modify critical tenant settings. By exploiting this flaw, attackers can issue a PUT request to /sys/tenant/updateApplyStatus, altering the applyStatus field by subm...

PoC for CVE-2026-108661

JeecgbootJeecgboot7.1HIGH
Missing Authorization Vulnerability in JeecgBoot by Jeecg Technology

JeecgBoot versions up to 3.9.5 have a vulnerability that permits authenticated users to transfer tenant ownership without adequate authorization. The API endpoint /sys/tenant/changeOwenUserTenant can be exploited by low-privileged attackers who manipulate the userId and tenantId parameters. This ...

PoC for CVE-2026-108659

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot by Jeecg

JeecgBoot through version 3.9.5 has a missing authorization issue within the SysTenantController component. This vulnerability allows authenticated users, including those with low privileges, to exploit the listPackByTenantUserId endpoint. By manipulating the tenantId and userId parameters, attac...

PoC for CVE-2026-108658

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot Product by Jeecg

JeecgBoot up to version 3.9.5 is susceptible to a missing authorization vulnerability in the SysTenantController's queryTenantAuthInfo handler. This flaw permits any authenticated user to access and read the records of other tenants. Attackers with low privileges can potentially exploit this vuln...

PoC for CVE-2026-108655

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot Affects Job Record...

JeecgBoot version 3.9.5 has a vulnerability in the QuartzJobController's queryById handler, allowing authenticated users with low privileges to access sensitive scheduled job records. Attackers can exploit this flaw by sending a GET request to /sys/quartzJob/queryById with a specific job ID, ther...

PoC for CVE-2026-108652

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot Allows User Avatar...

JeecgBoot versions up to 3.9.5 have a security flaw in the SystemApiController's updateAvatar handler, allowing authenticated users with low privileges to change the avatars of other users, including administrators. By sending PUT requests with a target user ID and a malicious image URL, attacker...

PoC for CVE-2026-108651

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot by Jeecg

JeecgBoot versions up to 3.9.5 suffer from a missing authorization vulnerability in the getRolesByUserId handler within the SystemApiController. This flaw allows authenticated users with low privileges to exploit the endpoint /sys/api/getRolesByUserId by supplying arbitrary userId values. As a re...

PoC for CVE-2026-108650

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot by Jeecg

JeecgBoot, up to version 3.9.5, contains a vulnerability in the getUserPermissionSet handler of SystemApiController. This flaw allows authenticated users to access sensitive permission codes of other users by supplying an arbitrary userId in the request. Consequently, low-privileged attackers can...

PoC for CVE-2026-108649

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot Affects User Role Visibility

JeecgBoot versions up to 3.9.5 contain a vulnerability in the SystemApiController's queryUserRolesById function. This flaw allows authenticated users to access and enumerate user role assignments by sending a user ID to the /sys/api/queryUserRolesById endpoint. This could potentially enable low-p...

PoC for CVE-2026-108647

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot Affects Version 3.9.5

JeecgBoot version 3.9.5 contains a missing authorization vulnerability that exposes the SysCheckRuleController importExcel handler to low-privileged authenticated users. This flaw allows attackers to manipulate the system by uploading malicious Excel workbooks, bypassing critical access controls,...

PoC for CVE-2026-108646

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot Product by Jeecg

The JeecgBoot product up to version 3.9.5 is affected by a missing authorization vulnerability within the SysCategoryController's importExcel feature. This vulnerability permits any authenticated user, including those with low privileges, to import maliciously crafted Excel files. As a consequenc...

PoC for CVE-2026-108645

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Flaw in JeecgBoot Affects Category Management...

A vulnerability exists in JeecgBoot version 3.9.5, wherein authenticated users can exploit the SysCategoryController functionality. This flaw permits low-privileged attackers to execute POST or PUT requests to manipulate category dictionary nodes via the /sys/category/edit endpoint. Through this ...

PoC for CVE-2026-108644

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot by Jeecg

JeecgBoot version 3.9.5 is prone to a serious vulnerability in the SysCategoryController delete handler. This flaw allows any authenticated user to delete category dictionary nodes without proper authorization. Low-privileged attackers can exploit this vulnerability by retrieving node IDs from ex...

PoC for CVE-2026-108642

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot Product by Jeecg

The JeecgBoot application up to version 3.9.5 is susceptible to a missing authorization vulnerability in the SysAnnouncementSendController. This flaw enables authenticated users to manipulate the message delivery records of other users. By exploiting this issue, attackers can extract delivery IDs...

PoC for CVE-2026-108641

JeecgbootJeecgboot5.3MEDIUM
Insecure Direct Object Reference in JeecgBoot by Jeecg

JeecgBoot version 3.9.5 is vulnerable to an insecure direct object reference (IDOR) that enables authenticated users to access other users’ messages within the application. This vulnerability is exploited through the getOne handler of the SysAnnouncementSendController. Attackers can leverage the ...

PoC for CVE-2026-108639

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization Vulnerability in JeecgBoot by Jeecg

JeecgBoot version 3.9.5 is susceptible to a missing authorization vulnerability. This flaw permits any authenticated user to execute DELETE requests on the /sys/dict/deletePhysic/{id} endpoint. As a result, they can permanently eliminate data dictionaries and their associated items from the syste...

PoC for CVE-2026-108640

JeecgbootJeecgboot5.3MEDIUM
Missing Authorization in JeecgBoot Affects User Role Management

JeecgBoot, up to version 3.9.5, contains a vulnerability in the SysDepartRoleController specifically within the queryById handler. This issue arises due to the absence of necessary Shiro permission annotations, allowing low-privileged authenticated attackers to exploit the vulnerability. These at...