Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 2 hours ago
PoC for CVE-2026-85402
A vulnerability in the Doctor Appointment System version 1.0 has been identified, specifically within the /patient/booking.php file. The flaw arises from improper handling of the doc_id parameter, which enables attackers to execute SQL injection attacks. This vulnerability can be exploited remote...
PoC for CVE-2026-85401
A vulnerability has been identified in the Dolibarr Legacy File Manager affecting versions up to 21.0.4, 22.0.5, and 23.0.3. The flaw exists in the configuration file located at htdocs/core/filemanagerdol/connectors/php/config.inc.php, where improper access controls can be exploited remotely. Thi...
PoC for CVE-2026-85399
A significant security flaw has been identified in the Hospital Information System 1.0 developed by code-projects, specifically within the function getSinglePresp located in includes/presp/PrespController.php. This vulnerability allows attackers to manipulate the argument ID, resulting in SQL inj...
PoC for CVE-2026-4813
A vulnerability in the Lutece Core XSL export management module allows authenticated administrators to execute arbitrary code remotely due to the absence of secure processing mode in XML/XSLT processing configuration. Attackers with administrator privileges can exploit this flaw by uploading a cr...
Discovered 3 hours ago
PoC for CVE-2026-85398
A flaw exists in the Hospital Information System 1.0, specifically within the viewReq function found in viewReq.php, which allows for SQL injection attacks. By manipulating the ID argument, attackers may execute arbitrary SQL queries against the database, leading to potential exposure of sensitiv...
PoC for CVE-2026-75604
Next.js, a popular framework for building web applications, contains a vulnerability that allows an attacker to exploit improper escaping of backslashes in route segments. When an application accepts crafted remote requests on Windows-hosted servers, it can unintentionally construct incremental-c...
PoC for CVE-2026-85397
A vulnerability exists in the Hospital Information System by Code-Projects that allows for SQL injection through the 'findBySearch' function in 'addReq.php'. This issue arises from improper handling of user input, which can be exploited remotely. As a result, an attacker could manipulate the sear...
PoC for CVE-2026-85383
A security flaw has been identified in the itsourcecode Sales and Inventory System version 1.0, specifically within the /pages/inv_del.php file. An attacker can exploit this vulnerability by manipulating the argument ID, potentially allowing for SQL injection attacks that can be executed remotely...
PoC for CVE-2026-85382
A vulnerability has been identified in the light0011 CMS specifically within the Chapter Content Output component. The issue lies in the function htmlspecialchars_decode located in the file App/Home/View/Default/Chapter/oneChapter.tpl. This flaw allows an attacker to manipulate the argument conte...
Discovered 4 hours ago
PoC for CVE-2026-85381
A security flaw has been identified in the Chapter Controller of Light0011 CMS due to improper processing of input arguments, which can result in authorization bypass. This vulnerability allows an attacker to manipulate content arguments remotely, potentially gaining unauthorized access to sensit...
PoC for CVE-2026-52810
Gogs, an open-source self-hosted Git service, is susceptible to an improper authorization vulnerability. Prior to version 0.14.3, the service's handling of Git smart HTTP requests permitted unauthorized users to perform push operations using the client-supplied service query string. This weakness...
PoC for CVE-2026-85380
A vulnerability has been discovered in the UEditor component of the light0011 CMS that allows for a server-side request forgery. An attacker can exploit this weakness by manipulating the arguments of the catchimage function within the Public/ueditor/php/controller.php file. This manipulation enab...
PoC for CVE-2026-64788
A memory corruption issue has been identified in Apple’s iOS and macOS systems, resulting from the processing of maliciously crafted web content. This vulnerability allows attackers to exploit the weakness, potentially leading to system instability or unauthorized access. Apple has addressed this...
Discovered 5 hours ago
PoC for CVE-2026-65343
A use after free vulnerability has been identified in Apple's iOS and macOS systems. This flaw arises from inadequate memory management that can lead to unexpected system terminations. An attacker capable of exploiting this vulnerability may impact the stability of affected devices. Apple has iss...
Discovered 6 hours ago
PoC for CVE-2026-85378
A significant vulnerability exists in the Chapter Controller of Light0011 CMS, where an authorization bypass can be exploited remotely through the _initialize function in ChapterController.class.php. This flaw potentially allows unauthorized access to sensitive functions and data within the appli...
Discovered 7 hours ago
PoC for CVE-2026-85225
The Doctor Appointment System 1.0 by Code-Projects has a SQL injection vulnerability located in the /patient_login.php file. This flaw can be exploited by manipulating the 'email' parameter, allowing attackers to execute arbitrary SQL queries. The attack can be initiated remotely, making it a sig...
PoC for CVE-2026-85224
A significant vulnerability exists in the D-Link DNS-320 ShareCenter, specifically within the file sharing component located at /cgi/file_sharing.cgi. The flaw allows a remote attacker to manipulate the argument 'fileurl', potentially leading to OS command injection. This vulnerability has been p...
Discovered 8 hours ago
PoC for CVE-2026-85223
A security flaw exists in the D-Link DNS-340L where an attacker can exploit the '/cgi-bin/dropbox.cgi' component. By manipulating the 'callback_url' and 'sync_interval' parameters, it is possible to execute arbitrary commands on the operating system. This vulnerability allows remote attackers to ...
PoC for CVE-2026-85222
A vulnerability exists in the D-Link DNS-340L device, specifically within the Add-On Center component at the '/cgi-bin/addon_center.cgi' endpoint. This security flaw permits remote attackers to execute arbitrary OS commands by manipulating the f_name, f_url, f_flag, and f_login_user parameters. G...
Discovered 9 hours ago
PoC for CVE-2026-85208
A security flaw has been identified in itsourcecode Online Medicine Delivery System 1.0, specifically within the 'doInsert' function of the Order Management Controller located at /rider/orders/controller.php?action=add. This vulnerability involves a manipulation of the 'image' argument, leading t...
PoC for CVE-2026-62735
A heap-based buffer overflow vulnerability exists in Windows HTTP.sys, which could allow an authorized attacker to elevate privileges on the local system. This attack potentially enables unauthorized access to sensitive resources or control over the affected system, making it critical for users t...
PoC for CVE-2026-82527
R2R version 3.6.6 has a SQL injection vulnerability that enables unauthorized users to inject malicious SQL predicates into the search query. By exploiting the manipulation of the filter key parameter in the retrieval search endpoint, attackers can execute both time-based and boolean-based attack...
Discovered 10 hours ago
PoC for CVE-2026-85207
A vulnerability has been detected in the Itsourcode Online Medicine Delivery System version 1.0, specifically within the /index.php?q=orderdetails file. This flaw allows attackers to manipulate the location argument, resulting in cross-site scripting (XSS) attacks. Such manipulations can be condu...
PoC for CVE-2026-78071
A vulnerability exists in DP Calendar, a Joomla extension developed by digital-peak.com, where an authenticated user with 'create' permissions can leverage stored XSS through the location title feature. This flaw occurs because the location title is rendered in a data attribute without proper esc...
PoC for CVE-2026-78070
The DP Calendar extension for Joomla exhibits a notable vulnerability that allows authenticated users with update permissions to execute blind SQL injection attacks. Specifically, when saving an article, the extension is susceptible to executing arbitrary SQL queries through its content plugin, w...
Discovered 11 hours ago
PoC for CVE-2026-19949
The All-in-One WP Migration and Backup plugin for WordPress contains a SQL injection vulnerability due to inadequate input escaping during the archive restore process. This flaw allows unauthenticated attackers to insert malicious SQL commands into existing queries. As a result, they can potentia...
PoC for CVE-2026-82526
The R2R product by SciPhi-AI up to version 3.6.6 harbors a significant vulnerability that allows an unauthenticated attacker to exploit a stacked SQL injection weakness. This vulnerability is triggered by manipulating the index name parameter during the index creation process. The absence of prop...
Discovered 12 hours ago
PoC for CVE-2026-85187
A security vulnerability has been identified in the itsourcecode Online Medicine Delivery System version 1.0, specifically within the Order Status Update function. The issue resides in the Order::pupdate method located in the /rider/orders/controller.php file. An attacker can manipulate the ID pa...
PoC for CVE-2026-85186
A vulnerability exists in the itsourcecode Online Medicine Delivery System 1.0 that allows attackers to exploit the doupdateimage function in the Customer Controller component. By manipulating the photo argument in the controller.php file, unauthorized users may upload arbitrary files remotely, p...
Discovered 13 hours ago
PoC for CVE-2026-85138
A vulnerability has been identified in the WeChat Module of SeaCMS versions up to 13.6, specifically within the addslashes function in weixin/index.php. By manipulating the Content argument, attackers can perform a SQL injection attack, potentially allowing them to access, modify, or delete datab...
Discovered 14 hours ago
PoC for CVE-2026-71963
Hermes Agent versions 0.18.2 through 0.21.0 contain a vulnerability that permits remote code execution via a manipulated git configuration file. An attacker can exploit this weakness by providing a crafted .git/config that specifies an arbitrary command through the core.fsmonitor setting. When a ...
PoC for CVE-2026-85137
A security flaw has been identified in the Locoy Collector component of SeaCMS versions up to 13.6, particularly affecting the 'parseIf' function within the 'seacms_locoy_news.php' file. This vulnerability allows an attacker to manipulate the 'pwd' argument, leading to potential code injection at...
PoC for CVE-2026-59822
LiteLLM, developed by BerriAI, is a proxy server that facilitates the usage of LLM APIs in OpenAI format. In versions prior to 1.84.0, a security flaw existed where an unauthenticated attacker could exploit a specially crafted Authorization header. This vulnerability enabled the attacker to bypas...
Discovered 15 hours ago
PoC for CVE-2026-85110
A buffer overflow vulnerability has been discovered in the Tenda HG10 device, specifically within the formWlanSetup function of the Boa Web Server. The issue arises from inadequate validation of the 'ssid' parameter, allowing an attacker to manipulate the argument and potentially trigger a buffer...
PoC for CVE-2026-85109
A vulnerability in the Tenda HG10 300001138 affects the Boa Web Server, specifically in the function formLogin located in /boaform/formLogin. An attacker can exploit this vulnerability by manipulating the Username argument, leading to a buffer overflow condition. This flaw can be exploited remote...
Discovered 19 hours ago
PoC for CVE-2026-85100
A vulnerability has been identified in the 2FastLabs Agent-Squad up to version 1.1.4, specifically within the AgentSquad.routeRequest function in the orchestrator.ts script. This flaw allows for potential remote exploitation, leading to undue resource consumption on affected systems. The issue be...
Discovered 20 hours ago
PoC for CVE-2025-9974
The ONT/Beacon device by Nokia features a critical input handling flaw in its unified WEBUI application. This vulnerability allows low-privileged authenticated users to exploit insufficient validation of user-supplied data, enabling them to execute arbitrary commands on the device's operating sys...
Discovered 22 hours ago
PoC for CVE-2026-63828
In the Linux kernel, a vulnerability exists within AppArmor that impacts the mediation of implicit connections when TCP Fast Open is enabled. The current implementation allows confined tasks to establish outbound TCP/MPTCP connections that would typically be blocked by the connect mediation. This...
Discovered 1 day ago
PoC for CVE-2026-82329
JFrog Artifactory has a significant authentication weakness that could permit an attacker with network access to gain administrative privileges without authentication, particularly when the product is left in its default configuration. This vulnerability can expose sensitive resources and operati...
PoC for CVE-2026-65349
An out-of-bounds read vulnerability has been identified in Apple's iOS, iPadOS, and macOS products, which could allow an application to access unintended areas of memory. This may lead to unexpected application termination or unauthorized reading of kernel memory. Enhanced input validation measur...
PoC for CVE-2026-65343
A use after free vulnerability has been identified in Apple's iOS and macOS systems. This flaw arises from inadequate memory management that can lead to unexpected system terminations. An attacker capable of exploiting this vulnerability may impact the stability of affected devices. Apple has iss...
PoC for CVE-2026-65330
A memory handling vulnerability has been identified in Apple's iOS, iPadOS, and macOS products, which could allow a malicious application to initiate unexpected system terminations or potentially corrupt kernel memory. This issue has been addressed in the latest updates for affected operating sys...
PoC for CVE-2026-64788
A memory corruption issue has been identified in Apple’s iOS and macOS systems, resulting from the processing of maliciously crafted web content. This vulnerability allows attackers to exploit the weakness, potentially leading to system instability or unauthorized access. Apple has addressed this...
PoC for CVE-2026-85040
A security weakness has been detected in the CRMEB system from ZhongBangKeJi, specifically affecting versions prior to 6.0.0. This vulnerability arises from the handling of the eval function in the /adminapi/system/crontab/save file within the Custom Scheduled Task feature. By manipulating the cu...
PoC for CVE-2026-85030
A business logic error in HKUDS AI-Trader's selfRegister API Endpoint allows remote manipulation of the initial_balance argument in the routes_agent.py file. Attackers can exploit this flaw to cause significant inconsistencies in financial simulations. While the manipulation of initial_balance al...
PoC for CVE-2026-85092
LiME versions up to 1.12.0 contain a vulnerability that allows unprivileged local users to exploit the disk acquisition output path. This issue arises due to inadequate validation of the output path and the failure to use O_NOFOLLOW when handling operator-supplied paths. An attacker controlling t...
PoC for CVE-2026-85091
The vulnerability in zlib versions 1.3.1.2 to 1.3.2 involves a heap buffer overflow in the gz_vacate() function, specifically when processing non-blocking gzwrite() operations with stale external buffer pointers. An attacker can exploit this flaw by invoking gzprintf() or gzvprintf() after a writ...
PoC for CVE-2026-85022
A vulnerability exists in the langgenius dify product, specifically in version 1.13.0, due to improper handling of the redirect_url parameter in the router.replace function found in the webapp-signin component. This flaw allows attackers to inject malicious scripts that execute in the context of ...
PoC for CVE-2026-19490
The vulnerability in NetScaler ADC and NetScaler Gateway allows for unauthorized access and potential exploitation, impacting multiple versions of these products. This issue highlights the need for immediate action to secure affected systems to prevent unauthorized data access and maintain networ...
PoC for CVE-2026-85021
A vulnerability exists in langgenius Dify 1.13.0 due to improper handling of the redirect_url parameter in the router.replace function within the splash.tsx file of the Splash Layout component. This flaw allows attackers to execute arbitrary JavaScript in the context of the user's session, leadin...