Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 18 minutes ago

PoC for CVE-2025-43537

AppleiOS And iPad OS3.5LOW
Path Handling Issue in Apple iOS and iPadOS Products

A path handling flaw in Apple's iOS and iPadOS products may allow attackers to manipulate and modify protected system files by restoring a maliciously crafted backup file. This vulnerability has been addressed through enhanced validation measures in the updated versions of iOS and iPadOS. Users a...

Discovered 22 minutes ago

PoC for CVE-2025-57819

FreepbxEndpoint🟣 EPSS 77%10CRITICAL
Unauthenticated Access Vulnerability in FreePBX by Sangoma Technolo...

FreePBX, an open-source web-based GUI, suffers from a vulnerability that permits unauthenticated users to gain access to the FreePBX Administrator interface. This is primarily due to insufficient sanitization of user-provided data. The flaw can lead to unauthorized database manipulation and may a...

Discovered 2 hours ago

PoC for CVE-2026-11556

TendaF4518.7HIGH
Tenda F451 Web Management WriteFacMac formWriteFacMac os command in...

A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. Remote exploitation of the attack i...

PoC for CVE-2026-11555

D-linkDgs-1100-08pd6.3MEDIUM
D-Link DGS-1100-08PD Web boa.conf least privilege violation

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of comp...

PoC for CVE-2026-11554

TotolinkCp4505.3MEDIUM
TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation

A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be ...

PoC for CVE-2026-11553

TendaHg7hg98.7HIGH
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow

A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public a...

Discovered 3 hours ago

PoC for CVE-2026-39908

OpenbulletOpenbullet27.1HIGH
OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source

OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application...

PoC for CVE-2026-11534

Imvks786Student Management System5.1MEDIUM
imvks786 student_management_system add.php cross site scripting

A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of the argument name/address/fname results in cross site scripting. It is possible to laun...

PoC for CVE-2026-11533

Imvks786Student Management System5.3MEDIUM
imvks786 student_management_system Student Deletion Endpoint see.ph...

A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deletion Endpoint. The manipulation of the argument del leads t...

PoC for CVE-2026-11532

Imvks786Student Management System5.3MEDIUM
imvks786 student_management_system Student Record add.php access co...

A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record Handler. Executing a manipulation can lead to improper access controls. The attack may be perfo...

Discovered 4 hours ago

PoC for CVE-2026-11531

Imvks786Student Management System6.9MEDIUM
imvks786 student_management_system Administrator Login Endpoint adm...

A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the component Administrator Login Endpoint. Performing a manipulation of the argument a_usr/a_pwd results...

PoC for CVE-2026-11530

Imvks786Student Management System6.9MEDIUM
imvks786 student_management_system Login index.ph sql injection

A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely...

PoC for CVE-2026-11529

DesigncomputerMysql-mcp-server5.3MEDIUM
designcomputer mysql-mcp-server mysql URI server.py read_resource s...

A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of t...

PoC for CVE-2026-11528

TendaAc188.7HIGH
Tenda AC18 Web Management getRebootStatus sub_45304 stack-based ove...

A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. The manipulation of the argument callback results in stack-based buffer overflow. The attack may be launched remotely....

Discovered 5 hours ago

PoC for CVE-2026-11524

TendaW20e8.7HIGH
Tenda W20E Web Management modifyWifiFilterRules stack-based overflow

A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The manipulation of the argument wifiFilterListRemark leads to stack-based buffer overflow. The attack may be...

PoC for CVE-2026-11523

TendaW20e8.7HIGH
Tenda W20E Web Management PortalAuth formPortalAuth stack-based ove...

A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. Th...

PoC for CVE-2026-11522

TendaW20e8.7HIGH
Tenda W20E setPortMirror formSetPortMirror stack-based overflow

A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts results in stack-based buffer overflow. The attack can be initiated remotely. The ex...

PoC for CVE-2026-11521

Mohammed-eid35Bank-management-system...5.3MEDIUM
Mohammed-eid35 bank-management-system-springboot Transaction Endpoi...

A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controller/TransactionController.java of the component Transaction...

Discovered 6 hours ago

PoC for CVE-2026-25558

QloappsQloapps4.8MEDIUM
QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded throu...

PoC for CVE-2026-11518

SourcecodesterInventory System5.3MEDIUM
SourceCodester Inventory System User Management users.php cross sit...

A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The manipulation of the argument fullname/username leads to cross site scripting. The attack is possible to be carried out remotely....

PoC for CVE-2026-11517

UttHiper 2610g8.7HIGH
UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow

A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /goform/formConfigDnsFilterGlobal. Executing a manipulation of the argument GroupName can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly ...

Discovered 7 hours ago

PoC for CVE-2026-11516

UttHiper 2610g5.1MEDIUM
UTT HiPER 2610G formNatStaticMap strcpy buffer overflow

A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBinds results in buffer overflow. The exploit has been made public and could be used.

PoC for CVE-2026-11514

ItsourcecodeHospital Management Sy...5.3MEDIUM
itsourcecode Hospital Management System addpatient.php sql injection

A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

PoC for CVE-2026-11513

ItsourcecodeHospital Management Sy...5.3MEDIUM
itsourcecode Hospital Management System adminaccount.php sql injection

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.

Discovered 8 hours ago

PoC for CVE-2026-11512

ItsourcecodeHospital Management Sy...5.3MEDIUM
itsourcecode Hospital Management System billing.php cross site scri...

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disc...

PoC for CVE-2026-11510

CodeastroLeave Management System5.3MEDIUM
CodeAstro Leave Management System add_leave.php sql injection

A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of the argument type_of_leave results in sql injection. It is possible to initiate the attack remotely. The exploit has been relea...

Discovered 9 hours ago

PoC for CVE-2026-11508

CodeastroLeave Management System5.3MEDIUM
CodeAstro Leave Management System search_staff_to_assign_pc.php sql...

A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The...

PoC for CVE-2026-11507

CodeastroLeave Management System5.3MEDIUM
CodeAstro Leave Management System delete_leave_type.php sql injection

A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/delete_leave_type.php. The manipulation of the argument leave_type results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

PoC for CVE-2026-11506

CodeastroLeave Management System5.3MEDIUM
CodeAstro Leave Management System search_staff_for_deletion.php sql...

A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed t...

Discovered 10 hours ago

PoC for CVE-2026-11504

TendaCx12l8.7HIGH
Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi set...

A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration Endpoint. Performing a manipulation of the argument schedStartTime/schedEndTime results in stack-based buffer ...

PoC for CVE-2026-11503

TendaCx12l8.7HIGH
Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form...

A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set of the component Wi-Fi Configuration Endpoint. Such manipulation of the argument ssid leads to stack-based buffer overfl...

PoC for CVE-2026-11502

Jeecgboot2.3LOW
JeecgBoot Third-Party Login ThirdLoginController.java HttpServletRe...

A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login. This manipulation of ...

PoC for CVE-2026-11501

SourcecodesterHospitals Patient Reco...6.9MEDIUM
SourceCodester Hospitals Patient Records Management System Master.p...

A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=save_patient. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remot...

Discovered 11 hours ago

PoC for CVE-2026-11500

Weaviate2.3LOW
Weaviate Static API Key client.go validateConfig authorization

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argument StaticApiKey leads to authorization bypass. It is pos...

Discovered 13 hours ago

PoC for CVE-2026-11497

D-linkDcs-56156.9MEDIUM
D-Link DCS-5615 Boa Webserver boa.conf least privilege violation

A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has bee...

PoC for CVE-2026-11495

CodeastroIngredients Stock Mana...5.3MEDIUM
CodeAstro Ingredients Stock Management System add_stock.php sql inj...

A vulnerability was detected in CodeAstro Ingredients Stock Management System 1.0. This impacts an unknown function of the file /Ingredients-Stock/add_stock.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be...

Discovered 14 hours ago

PoC for CVE-2026-11494

TotolinkAc1200 T85.3MEDIUM
TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation

A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly ...

PoC for CVE-2026-11493

TendaAc152.3LOW
Tenda AC15 Samba smb.conf weak password

A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements. The attack is only possible within the local network. A high complexity level...

PoC for CVE-2026-11492

D-linkDir-823g5.3MEDIUM
D-Link DIR-823G vsftpd vsftpd.conf least privilege violation

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to...

PoC for CVE-2026-11491

CodeastroHuman Resource Managem...4.8MEDIUM
CodeAstro Human Resource Management System Notice Board Management ...

A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function of the file /notice/All_notice of the component Notice Board Management. Such manipulation of the argument Notice Title with the input <svg onload="alert('Stored XSS Triggered by Ashi...

Discovered 15 hours ago

PoC for CVE-2026-11490

Code-projectsOnline Music Site6.9MEDIUM
code-projects Online Music Site Search.php sql injection

A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclo...

PoC for CVE-2026-11489

Code-projectsOnline Music Site6.9MEDIUM
code-projects Online Music Site AdminDeleteAlbum.php sql injection

A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public an...

PoC for CVE-2026-11488

Code-projectsSimple Flight Ticket B...6.9MEDIUM
code-projects Simple Flight Ticket Booking System POST Parameter ch...

A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remot...

PoC for CVE-2026-11487

Neovim4.8MEDIUM
Neovim View Branch secure.lua M.read command injection

A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The ...

Discovered 16 hours ago

PoC for CVE-2026-11486

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SourceCodester Class and Exam Timetabling System archive1.php sql i...

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /archive1.php. Performing a manipulation of the argument sy results in sql injection. Remote exploitation of the attack is possible. The exp...

PoC for CVE-2026-11485

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SourceCodester Class and Exam Timetabling System archive2.php sql i...

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive2.php. Such manipulation of the argument sy leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly ...

PoC for CVE-2026-11484

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SourceCodester Class and Exam Timetabling System archive3.php sql i...

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /archive3.php. This manipulation of the argument sy causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public an...

PoC for CVE-2026-11483

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SourceCodester Class and Exam Timetabling System archive4.php sql i...

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /archive4.php. The manipulation of the argument sy results in sql injection. The attack can be launched remotely. The exploit has been released to the public a...

Discovered 17 hours ago

PoC for CVE-2026-11482

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SourceCodester Class and Exam Timetabling System archive5.php sql i...

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /archive5.php. The manipulation of the argument sy leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and mi...

PoC for CVE-2026-11481

YoanbernabeuGrepai2LOW
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresSto...

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. ...