Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-20079
A security flaw in the Cisco Secure Firewall Management Center's web interface may enable unauthenticated remote attackers to bypass authentication mechanisms. This enables the execution of arbitrary script files, potentially granting root access to the device’s operating system. The issue arises...
PoC for CVE-2026-6765
This vulnerability involves an information disclosure flaw in the Form Autofill component of Firefox and Firefox ESR. When exploited, it can reveal sensitive user data. Mozilla has addressed this issue in versions 150 of Firefox and 140.10 of Firefox ESR, emphasizing the importance of updating to...
PoC for CVE-2025-21479
This vulnerability allows unauthorized command execution in the GPU micronode, leading to potential memory corruption when a specific sequence of commands is executed. Attackers could exploit this weakness to disrupt system functionality or gain access to sensitive areas of memory, posing risks t...
Discovered 38 minutes ago
PoC for CVE-2026-56852
A vulnerability exists in the Go language's norm.Iter component where it fails to properly handle input containing invalid UTF-8 byte sequences. This oversight allows an attacker to exploit the input handling mechanism, potentially causing the system to enter an infinite loop. Such behavior can l...
Discovered 2 hours ago
PoC for CVE-2026-41042
A vulnerability in Apache Gravitino allows unauthenticated users to provide a malicious H2 JDBC URL via the testConnection API. This can lead to the execution of arbitrary Java code on the server due to improper handling of the INIT parameter in H2. This issue predominantly affects environments w...
PoC for CVE-2026-75014
A SQL injection vulnerability has been identified in the SourceCodester Pet Grooming Management Software (version 1.0). The flaw resides within the /admin/get_barcode_data.php file, where manipulations of the input argument 'barcode' can allow unauthorized remote attackers to execute arbitrary SQ...
Discovered 3 hours ago
PoC for CVE-2026-75013
A vulnerability in the TOTOLINK EX1200L router, specifically in the function setWizardCfg of the cstecgi.cgi file, allows for a null pointer dereference. This security flaw can be exploited remotely, leading to potential system instability or unauthorized access. Given that exploit code is public...
PoC for CVE-2026-75012
A vulnerability exists in the Password Configuration Handler of the TOTOLINK EX1200L router, specifically in the setPasswordCfg function of the cgi-bin/cstecgi.cgi file. This issue leads to a null pointer dereference, allowing remote attackers to exploit the vulnerability. Public disclosure of th...
Discovered 4 hours ago
PoC for CVE-2026-75011
A command injection vulnerability exists in the kylecui NetForensicMCP version 2.1.0, specifically within the execAsync function located in index.js. By manipulating the argument for the interface/protocol, an attacker can execute arbitrary commands remotely. This significant security flaw has be...
Discovered 5 hours ago
PoC for CVE-2026-59310
VMware vCenter features a directory traversal vulnerability in its Syslog server component. This flaw allows attackers with network access to exploit the vulnerability, potentially leading to unauthorized execution of arbitrary code. Proper safeguards and patching are essential to mitigate the ri...
PoC for CVE-2026-68138
A vulnerability exists in the Linux kernel's networking subsystem that allows for a race condition involving qdisc_rtab_list. This occurs when multiple CPU cores attempt to access and modify the same singly linked list of rate tables concurrently. The lack of proper synchronization mechanisms can...
Discovered 11 hours ago
PoC for CVE-2026-74251
The Phoca Cart extension for Joomla contains a vulnerability that allows unauthenticated attackers to exploit specific GET parameters ('a[]' and 's[]') on the public shop items page. By manipulating these parameters, attackers can create unfiltered SQL queries, leading to unauthorized access to s...
PoC for CVE-2026-74843
A security vulnerability exists in Wavlink network devices WN531P3 and WN535M1 due to improper handling of the HTTP_COOKIE argument within the export_pingortrace.cgi script. This flaw can be exploited remotely, leading to a stack-based buffer overflow, thereby allowing an attacker to potentially ...
Discovered 12 hours ago
PoC for CVE-2026-74842
A vulnerability exists in Kira-Pgr's PromptShopMCP Image-Toolkit-MCP-Server related to the function download_image in server.py. By manipulating the image_url parameter, an attacker can perform a server-side request forgery, enabling remote exploitation. The vulnerability has been publicized, yet...
Discovered 14 hours ago
PoC for CVE-2026-20000
An SQL injection vulnerability has been identified in the itsourcecode Hospital Management System version 1.0. The flaw arises from an unspecified function in the file /viewprescriptionrecord.php, where manipulation of the argument 'delid' allows attackers to execute arbitrary SQL queries. This v...
Discovered 15 hours ago
PoC for CVE-2026-19999
A security vulnerability in Open Asset Import Library Assimp's Bone Transformation Key Parser allows for buffer overflow due to improper handling of the transmatrix_count/pcBoneTransforms argument in the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7. This flaw can be exploited remote...
PoC for CVE-2026-19998
A vulnerability has been discovered in the Code-Projects Online Shopping System, specifically within the 'offersmail.php' file. This issue arises from improper handling of user input in the email argument, which makes it susceptible to cross-site scripting attacks. Remote attackers could exploit ...
PoC for CVE-2026-19997
A security flaw has been identified in Webkul Bagisto that impacts versions up to 2.4.4. This vulnerability arises from improper handling of the /admin/sales/rma/requests endpoint within the Backend Sales RMA component, enabling remote attackers to bypass authorization controls. Although the vend...
PoC for CVE-2026-19996
A vulnerability exists in Webkul Bagisto, specifically impacting versions up to 2.4.4. This flaw is located in the Backend Customer Behavior Data Endpoint, where manipulation of the argument ID can result in improper privilege management. This allows an attacker to potentially exploit the system ...
Discovered 16 hours ago
PoC for CVE-2026-19995
A cross-site scripting vulnerability exists in Webkul Bagisto versions up to 2.4.4 in the RMA Message Handler component. This weakness can be exploited by manipulating the 'Message' argument in the /customer/account/rma/send-message file, potentially allowing attackers to execute arbitrary script...
PoC for CVE-2026-19994
A vulnerability exists in Webkul Bagisto versions up to 2.4.4, specifically affecting the configuration management functionality located at /admin/configuration/cache-management/execute. By manipulating the 'action' argument, an unauthorized party could bypass expected permissions. This flaw enab...
PoC for CVE-2026-13700
The WooMS WordPress plugin, up to version 9.14, is susceptible to a vulnerability that allows an attacker to craft a malicious URL. This exploitation occurs due to improper validation of user-supplied URLs before executing them in server-side requests. Consequently, stored third-party integration...
PoC for CVE-2026-14832
The ShopSmart Loyalty for WooCommerce plugin version 1.0.0 lacks essential authorization checks for phone number lookups. This oversight permits unauthenticated users to access sensitive customer profiles by simply knowing a customer's phone number. Once accessed, an unauthorized individual can v...
PoC for CVE-2026-19993
A vulnerability exists in Webkul Bagisto prior to version 2.4.4 in the RMA State Validation component, specifically concerning the file /customer/account/rma/update-status. This issue enables a potential attacker to enforce behavioral workflows through unauthorized manipulation. The attack can be...
PoC for CVE-2026-19992
A vulnerability has been identified in the Orange View Limited DualSafe Password Manager & Digital Vault Extension for Chrome, specifically within the postMessage-based bridge function. This flaw allows attackers to potentially manipulate the component, leading to unauthorized information disclos...
Discovered 17 hours ago
PoC for CVE-2026-19988
Alaev SEO Tools Extension for Chrome versions up to 1.0.10 has a vulnerability in its Popup UI component, specifically in the addDiv function within src/popup.html. This vulnerability allows remote attackers to execute scripts in the context of the user’s browser, leading to potential unauthorize...
PoC for CVE-2026-19986
A vulnerability has been detected in the Adblock for Youtube Extension version 7.2.1 for Chrome, originating from a flaw in the updateDynamicRules function within contentscript.js. This vulnerability allows attackers to exploit the argument yt-anti-adblock-detected, which can lead to improper aut...
PoC for CVE-2026-19984
A security flaw in the jkawamoto mcp-florence2 plugin, specifically in the get_images function of src/mcp_florence2/__init__.py, allows for server-side request forgery. This vulnerability enables an attacker to manipulate input arguments and potentially exploit server weaknesses from remote locat...
Discovered 19 hours ago
PoC for CVE-2026-19978
A flaw exists in the jiantao88 Android MCP Server, specifically in the Command Execution function located in build/index.js. This vulnerability allows for OS command injection by manipulating parameters such as deviceId, packageName, permission, and extras[].key or extras[].value. The exploit is ...
PoC for CVE-2026-19977
A vulnerability has been identified in the EFM ipTIME A3004T router, specifically within the httpcon_check_session_url function associated with session validation. This flaw enables improper authentication, which could allow attackers to exploit the system remotely. The vulnerability has been mad...
PoC for CVE-2026-19976
A command injection vulnerability exists in the COMFAST CF-N1-S version 2.6.0.1. The flaw lies in the unvalidated handling of the 'macaddress' parameter in the sub_44A968 function within the /cgi-bin/mbox-config path. An attacker can exploit this to execute arbitrary commands on the device remote...
Discovered 20 hours ago
PoC for CVE-2026-19974
A security flaw has been identified in the TreeFrog Framework affecting the Session Cookie Handler component. This vulnerability arises from an issue in the std::strncmp function located in the src/tsessioncookiestore.cpp file, which may lead to improper authentication. Attackers can exploit this...
PoC for CVE-2026-19973
A security flaw has been identified in the itsourcecode Hospital Management System version 1.0, specifically within the /viewpaymentreport.php file. This vulnerability allows attackers to manipulate the 'delid' argument, leading to SQL injection attacks. The issue can be exploited remotely, makin...
PoC for CVE-2026-19972
A vulnerability exists in the itsourcecode Hospital Management System version 1.0 due to improper handling of inputs in the remote file /viewpatient.php. This weakness allows attackers to manipulate the 'delid' argument, resulting in SQL injection. Successful exploitation could enable unauthorize...
Discovered 21 hours ago
PoC for CVE-2026-19970
A vulnerability was identified within the Open Asset Import Library Assimp, specifically in the function Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 located in the MDLLoader.cpp file. This vulnerability arises from improper handling of the argument bones_num, leading to a potential heap-ba...
PoC for CVE-2026-8508
An improper authentication flaw exists in the 'social_login.cgi' CGI program within Zyxel WAX650S firmware, allowing attackers connected to the WLAN to bypass captive portal authentication protocols. This vulnerability could enable unauthorized access to network resources, posing a significant ri...
PoC for CVE-2026-6837
A post-authentication command injection vulnerability exists in the 'export-cgi' CGI program of Zyxel WAX650S firmware, allowing authenticated users with administrator privileges to execute arbitrary operating system commands on the device. This vulnerability poses significant risks as it could b...
PoC for CVE-2026-19969
A security vulnerability identified in the Open Asset Import Library Assimp version 17c12da affects the function Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 within the MDLLoader.cpp file. This vulnerability allows for a buffer overflow due to improper handling of input data, which could p...
PoC for CVE-2026-19968
A weakness exists within the Open Asset Import Library Assimp specifically related to the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7. This vulnerability can potentially lead to a heap-based buffer overflow, allowing attackers to execute malicious code. The exploit can be initiated remotely...
Discovered 22 hours ago
PoC for CVE-2026-19967
A security flaw has been identified in the Open Asset Import Library Assimp, specifically within the Assimp::Compression::decompressBlock function in the Common/Compression.cpp file. This vulnerability may allow an attacker to exploit a heap-based buffer overflow through manipulation of the input...
PoC for CVE-2026-19966
A vulnerability has been discovered in the CodeCanyon TimeCamp Integration for CRM plugin, affecting versions up to 2.8. This issue occurs during the processing of the 'save_contact' file in the Contact Information Update component, specifically through manipulation of the 'contact_id' argument. ...
PoC for CVE-2025-55182
A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...
PoC for CVE-2026-19964
A code injection vulnerability exists in the Jij-Inc Jij-MCP-Server 0.1.0, specifically in the PythonREPL.run function within the file jij_mcp/python_repr.py. This issue allows for remote code execution due to improper handling of input arguments, enabling attackers to manipulate the 'code' argum...
Discovered 23 hours ago
PoC for CVE-2026-19963
A command injection vulnerability has been identified in the Edimax EW-7478APC at version 1.04. The flaw resides in the 'stainfo' function located in the /goform/stainfo file, where improper handling of the 'interface' argument allows for remote code execution. This vulnerability poses significan...
PoC for CVE-2026-19962
A command injection vulnerability exists in the Edimax EW-7478APC network device due to improper validation of user input in the setWAN function located at /goform/setWAN. By manipulating the parameters pppUserName, pptpUserName, or L2TPUserName, an attacker can execute arbitrary commands on the ...
PoC for CVE-2026-19961
A buffer overflow vulnerability has been identified in the Edimax EW-7478APC's formWlSiteSurvey function, specifically in the /goform/formWlSiteSurvey file. Manipulating the 'selSSID' argument could allow remote attackers to execute arbitrary code. This vulnerability is particularly concerning as...
PoC for CVE-2026-19960
A serious command injection vulnerability has been identified in the Edimax EW-7478APC, specifically within the formWlbasic function of the /goform/formWlbasic file. This vulnerability arises from improper handling of the rootAPmac parameter, allowing an attacker to execute arbitrary commands rem...
Discovered 1 day ago
PoC for CVE-2026-19959
A buffer overflow vulnerability has been identified in the Edimax EW-7478APC routing device, specifically within the function formWanTcpipSetup located at /goform/formWanTcpipSetup. The issue arises from improper handling of the pppUserName argument, allowing for stack-based buffer overflow condi...
PoC for CVE-2026-19958
A vulnerability has been identified in the iatsiuk pptr-mcp execute Tool, specifically within the executeCode function located in the src/vm-executor.ts file. This flaw allows for remote code injection, opening a path for attackers to execute malicious scripts remotely. Despite the discovery of t...
PoC for CVE-2026-19957
A vulnerability has been discovered in version 1.0.1 of the Graphlit MCP Server, specifically within the fetch function in the src/tools.ts file associated with the ssrf-test endpoint. This vulnerability allows for potential server-side request forgery, enabling attackers to manipulate URL parame...