Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 5 hours ago
PoC for CVE-2026-85100
A vulnerability has been identified in the 2FastLabs Agent-Squad up to version 1.1.4, specifically within the AgentSquad.routeRequest function in the orchestrator.ts script. This flaw allows for potential remote exploitation, leading to undue resource consumption on affected systems. The issue be...
Discovered 6 hours ago
PoC for CVE-2025-9974
The ONT/Beacon device by Nokia features a critical input handling flaw in its unified WEBUI application. This vulnerability allows low-privileged authenticated users to exploit insufficient validation of user-supplied data, enabling them to execute arbitrary commands on the device's operating sys...
Discovered 8 hours ago
PoC for CVE-2026-63828
In the Linux kernel, a vulnerability exists within AppArmor that impacts the mediation of implicit connections when TCP Fast Open is enabled. The current implementation allows confined tasks to establish outbound TCP/MPTCP connections that would typically be blocked by the connect mediation. This...
Discovered 9 hours ago
PoC for CVE-2026-82329
JFrog Artifactory has a significant authentication weakness that could permit an attacker with network access to gain administrative privileges without authentication, particularly when the product is left in its default configuration. This vulnerability can expose sensitive resources and operati...
PoC for CVE-2026-65349
An out-of-bounds read vulnerability has been identified in Apple's iOS, iPadOS, and macOS products, which could allow an application to access unintended areas of memory. This may lead to unexpected application termination or unauthorized reading of kernel memory. Enhanced input validation measur...
PoC for CVE-2026-65343
A use after free vulnerability has been identified in Apple's iOS and macOS systems. This flaw arises from inadequate memory management that can lead to unexpected system terminations. An attacker capable of exploiting this vulnerability may impact the stability of affected devices. Apple has iss...
PoC for CVE-2026-65330
A memory handling vulnerability has been identified in Apple's iOS, iPadOS, and macOS products, which could allow a malicious application to initiate unexpected system terminations or potentially corrupt kernel memory. This issue has been addressed in the latest updates for affected operating sys...
PoC for CVE-2026-64788
A memory corruption issue has been identified in Apple’s iOS and macOS systems, resulting from the processing of maliciously crafted web content. This vulnerability allows attackers to exploit the weakness, potentially leading to system instability or unauthorized access. Apple has addressed this...
Discovered 12 hours ago
PoC for CVE-2026-85040
A security weakness has been detected in the CRMEB system from ZhongBangKeJi, specifically affecting versions prior to 6.0.0. This vulnerability arises from the handling of the eval function in the /adminapi/system/crontab/save file within the Custom Scheduled Task feature. By manipulating the cu...
Discovered 13 hours ago
PoC for CVE-2026-85030
A business logic error in HKUDS AI-Trader's selfRegister API Endpoint allows remote manipulation of the initial_balance argument in the routes_agent.py file. Attackers can exploit this flaw to cause significant inconsistencies in financial simulations. While the manipulation of initial_balance al...
Discovered 14 hours ago
PoC for CVE-2026-19490
The vulnerability in NetScaler ADC and NetScaler Gateway allows for unauthorized access and potential exploitation, impacting multiple versions of these products. This issue highlights the need for immediate action to secure affected systems to prevent unauthorized data access and maintain networ...
Discovered 17 hours ago
PoC for CVE-2026-24423
SmarterMail versions earlier than build 9511 are susceptible to an unauthenticated remote code execution vulnerability via the ConnectToHub API method. An attacker can exploit this weakness by directing the application to a malicious HTTP server that delivers harmful OS commands, which are then e...
PoC for CVE-2026-84888
A vulnerability has been identified in RightNow-AI OpenFang, specifically affecting the shell_exec function within the tool_runner.rs file. This flaw leads to uncontrolled memory allocation, enabling remote attackers to exploit the system. The vulnerability has been public since its disclosure, a...
PoC for CVE-2026-84887
A denial of service vulnerability exists in the simular-ai Agent-S, specifically linked to the file grounding.py within the Model-generated GUI Action Execution Workflow. This flaw can be exploited remotely, allowing attackers to disrupt service functionality. Publicly available exploit methods i...
Discovered 18 hours ago
PoC for CVE-2026-84886
A resource consumption vulnerability has been identified in simular-ai's Agent-S product, specifically in the OCR HTTP API's ImageData function within the gui_agents/s1/utils/ocr_server.py file. This vulnerability allows an attacker to manipulate the img_bytes argument, potentially leading to sig...
PoC for CVE-2026-84885
A security flaw has been identified in the Agent-S product, specifically located in the code_agent.py file of the CodeAgent component. Exploiting this vulnerability allows attackers to cause a denial of service, potentially disrupting the functionality of the affected system. This issue can be ex...
PoC for CVE-2026-84857
A significant flaw has been identified in the Sigoden Aichat API Endpoint, specifically within the src/serve.rs component. This vulnerability allows for uncontrolled memory allocation, which can be exploited remotely by attackers. The exploit has been publicly disclosed, posing a risk of a Denial...
Discovered 19 hours ago
PoC for CVE-2026-84856
A vulnerability has been identified in Rowboat Labs’ Rowboat, specifically in the Composio Webhook Endpoint. This issue arises from a flaw in the request handling function located in the code that can lead to denial of service. Attackers can exploit this vulnerability remotely, which could disrup...
PoC for CVE-2026-82524
UnoPim, prior to version 2.1.5, suffers from an authenticated file upload vulnerability that allows administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint. This weakness arises from inadequate validation of file extensions and MIME types. As a consequence, attacker...
PoC for CVE-2022-25765
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
PoC for CVE-2026-75134
The SEOWriting plugin for WordPress, up to version 1.12.5, contains a stored cross-site scripting vulnerability. Authenticated contributors can exploit this issue by injecting malicious JavaScript into post content. The vulnerability arises from an overly permissive KSES allowlist that allows the...
PoC for CVE-2026-84852
A vulnerability has been uncovered in the Reader Tools PDF Reader App version 98.8 for Android that allows local attackers to exploit the function ActSplashNew.handleDeeplink. By manipulating the argument _display_name, attackers can execute a path traversal attack, potentially allowing unauthori...
Discovered 20 hours ago
PoC for CVE-2026-84841
A security flaw exists in TSI Coop's TSI-DPDP-CMS software that enables client-side enforcement of server-side security protocols. This vulnerability can be exploited remotely, potentially leading to unauthorized access or manipulation of server-side functionalities. Users are strongly encouraged...
PoC for CVE-2026-84840
A vulnerability affecting TSI Coop's TSI DPDP CMS allows unauthorized access due to missing authentication in the Bootstrap Setup Endpoint component (specifically in the InterceptingFilter.java file). This flaw can be exploited remotely, potentially allowing attackers to manipulate the system wit...
PoC for CVE-2026-84839
A vulnerability exists in the TSI Coop TSI DPDP CMS Admin Console related to the web.xml file that may allow remote attackers to exploit missing authentication functionalities. This flaw could lead to unauthorized access and manipulation of sensitive information through the Admin Console and DPO ...
Discovered 21 hours ago
PoC for CVE-2026-7899
A vulnerability in the V8 JavaScript engine within Google Chrome allows remote attackers to execute arbitrary code within a sandbox environment. This is achieved through an out of bounds read and write technique facilitated by specially crafted HTML content, posing significant security risks to u...
PoC for CVE-2026-84833
A vulnerability exists in ntegrals OpenBrowser, specifically within the Browser Agent Message Construction component. This issue allows attackers to exploit specific functionalities within the agent.ts file, leading to excessive resource consumption. The exploit can be triggered remotely, potenti...
Discovered 22 hours ago
PoC for CVE-2026-9586
An unauthenticated SQL injection vulnerability has been identified in Sangoma Switchvox SMB Edition 8.3. The vulnerability resides in the /pa endpoint, which processes XML content starting with <PolycomIPPhone>. This endpoint improperly concatenates the user-controlled PhoneIP value into PostgreS...
PoC for CVE-2026-82329
JFrog Artifactory has a significant authentication weakness that could permit an attacker with network access to gain administrative privileges without authentication, particularly when the product is left in its default configuration. This vulnerability can expose sensitive resources and operati...
Discovered 1 day ago
PoC for CVE-2026-2811
The Ajaxify Comments WordPress plugin prior to version 3.2 is susceptible to HTTP Header Injection. This vulnerability arises from inadequate input sanitization and output escaping of data provided by users. As a result, unauthenticated attackers could potentially inject arbitrary HTTP headers, w...
PoC for CVE-2025-9314
The Developer Tools plugin for WordPress versions up to 1.1.3 is susceptible to an unauthenticated arbitrary file upload vulnerability due to a flaw in the bundled SWFUpload component. This security issue allows malicious actors to upload harmful files without proper authentication, which could p...
PoC for CVE-2025-15490
The Passster plugin for WordPress, prior to version 4.2.26, contains a security vulnerability related to inadequate global protection checks. This flaw permits unauthenticated users to bypass intended protection mechanisms through specially crafted URLs, potentially compromising site security and...
PoC for CVE-2025-8945
The Wp Edit Password Protected plugin for WordPress, prior to version 1.3.5, contains a security flaw that enables unauthorized users to bypass content protection measures implemented via the plugin. This vulnerability allows attackers to access restricted page content through the REST API, under...
PoC for CVE-2025-15489
The Passster WordPress plugin prior to version 4.2.24 has a significant input handling issue within its AJAX action operations. This flaw permits unauthenticated users to access and retrieve sensitive information from password-protected content, potentially exposing private data to unauthorized i...
PoC for CVE-2025-15481
The Notification Bar plugin for WordPress, up to version 1.1.8, has a serious vulnerability that exposes an unauthenticated CSV export script. This script can be exploited by unauthorized users to access and disclose all stored subscriber email addresses, leading to potential privacy breaches and...
PoC for CVE-2025-15485
The Auto x LINE plugin for WordPress, up to version 1.0.0, contains a critical vulnerability where several REST endpoints lack proper authorization checks. This oversight allows unauthenticated users to interact with the plugin's functionalities, including updating settings and clearing logs, whi...
PoC for CVE-2024-3773
The LiveJournal Shortcode plugin for WordPress versions up to 1.1.1 is susceptible to Stored Cross-Site Scripting attacks due to improper validation and escaping of shortcode attributes. This flaw enables users with contributor access and higher to inject malicious scripts, which can be executed ...
PoC for CVE-2023-3360
The Weaver Show Posts plugin for WordPress, prior to version 1.8.1, contains a vulnerability that allows for PHP object injection via improperly unserialised content from imported files. This vulnerability can be exploited when a user with elevated privileges imports a malicious file into the blo...
PoC for CVE-2026-83533
The WP Express Checkout plugin for WordPress versions prior to 2.4.9 is susceptible to a vulnerability that allows unauthorized users to artificially complete orders without making actual payments. This flaw arises due to the plugin's failure to validate whether a payment transaction was genuinel...
PoC for CVE-2026-83547
The Xpro Addons plugin for WordPress, prior to version 1.7.4, is susceptible to Stored Cross-Site Scripting attacks. This vulnerability arises from the plugin's failure to properly escape certain settings of its widgets before rendering them in HTML attributes. As a result, users with a Contribut...
PoC for CVE-2026-82884
The All in One SEO plugin for WordPress, prior to version 5.0.0.1, contains a vulnerability where it fails to properly sanitize and escape content stored within posts. This oversight allows users with contributor roles and above to conduct Stored Cross-Site Scripting attacks. The vulnerability is...
PoC for CVE-2026-8151
The Simple Membership MailChimp Integration plugin for WordPress prior to version 1.9.8 lacks essential CSRF checks on its settings page. This deficiency allows attackers to exploit the vulnerability by tricking a logged-in administrator into altering the third-party API key. If successful, the a...
PoC for CVE-2026-81571
The Brave WordPress plugin prior to version 0.8.8 contains a vulnerability that allows unauthenticated attackers to exploit URL parameters used to pre-fill form fields. This exploit enables malicious actors to execute arbitrary shortcodes server-side, posing a significant risk to the security and...
PoC for CVE-2026-78153
The Restrict User Access plugin for WordPress prior to version 2.8.1 is susceptible to an access control bypass vulnerability due to insufficient normalization of the REST API routes. This oversight permits unauthorized users to circumvent content protection measures, granting them the ability to...
PoC for CVE-2026-77794
The RegistrationMagic plugin for WordPress prior to version 6.0.9.9 contains a flaw in its payment processing system. Specifically, it fails to validate user-supplied quantity multipliers during registration, allowing unauthorized users to bypass payment requirements. This vulnerability enables u...
PoC for CVE-2026-77793
The RegistrationMagic WordPress plugin prior to version 6.0.9.9 is susceptible to a security flaw that permits unauthenticated users to exploit insufficient server-side validation of the total payment price. As a result, these users can finalize a paid registration without completing the payment,...
PoC for CVE-2026-77009
The WatchMan-Site7 WordPress plugin, prior to version 4.2.0, fails to adequately restrict access to its debugging console. This oversight permits any authenticated user, including those with minimal roles such as subscriber, to execute arbitrary PHP code on the server. Such vulnerabilities can le...
PoC for CVE-2026-4357
The Embed HTML5 Game WordPress plugin prior to version 1.3 is susceptible to a serious file upload vulnerability. This security flaw allows unauthorized users to upload arbitrary files, including PHP scripts, which can result in the injection of malicious backdoors on the server. The compromised ...
PoC for CVE-2026-2688
The HIPAA FORMS WordPress plugin before version 3.2.0 is vulnerable to an authentication bypass issue. This is achieved through a hardcoded parameter present in all AJAX requests which allows attackers to bypass nonce validation checks on the server. As a result, unauthenticated users can access ...
PoC for CVE-2026-19698
The GutenKit WordPress plugin has a vulnerability that allows users with Contributor roles and above to inject arbitrary CSS into posts. This vulnerability arises from the plugin's failure to validate or sanitize style settings before incorporating them into the CSS rendered on the front end. Whi...