Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2022-24355
This vulnerability exists in the TP-Link TL-WR940N router, allowing attackers in the network vicinity to execute arbitrary code due to insufficient validation of user-supplied data lengths when parsing file name extensions. This flaw can be exploited without authentication, enabling attackers to ...
PoC for CVE-2020-7882
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
PoC for CVE-2024-28000
The CVE-2024-28000 vulnerability is found in the widely-used LiteSpeed Cache Plugin for WordPress websites, allowing unauthenticated users to gain administrator-level access and create new user accounts with the administrator role. This critical privilege escalation vulnerability has a high CVSS ...
PoC for CVE-2026-16723
A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...
Discovered 5 hours ago
PoC for CVE-2026-10702
A JIT (Just-In-Time) miscompilation vulnerability has been identified in the JavaScript Engine of Firefox. This flaw could potentially allow attackers to exploit the JIT component, leading to unexpected behavior or execution of arbitrary code. This issue has been addressed in Firefox version 151....
Discovered 6 hours ago
PoC for CVE-2026-59726
The Ruflo Agent Meta-Harness prior to version 3.16.3 had a critical security flaw wherein its default Docker deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without any authentication. This oversight potentially allowed an unauthenticated attacker to execute commands, g...
Discovered 10 hours ago
PoC for CVE-2026-45746
The Termix Web Management Platform includes a vulnerability related to Broken Access Control, specifically in its File Manager feature. This issue stems from inadequate validation of the sessionId parameter, allowing attackers to exploit the backend's trust in a client-controlled identifier. As a...
PoC for CVE-2026-14310
The Tutor LMS WordPress plugin prior to version 4.0.0 features a significant flaw in its user access control mechanism. This vulnerability permits authenticated users, regardless of their role, to access Q&A threads not associated with courses they are enrolled in. Moreover, it enables such users...
PoC for CVE-2026-14305
The WP Delicious plugin for WordPress prior to version 1.10.2 is susceptible to an authorization bypass vulnerability. This flaw allows unauthenticated users to exploit AJAX actions without proper authorization. As a result, users can modify certain post metadata, specifically the like counter an...
PoC for CVE-2026-14239
The Tourmaster WordPress plugin prior to version 5.4.8 is vulnerable due to inadequate nonce checks when saving a custom-filter label from user input. This weakness allows unauthenticated attackers to exploit it and potentially inject malicious JavaScript. If a logged-in administrator is tricked ...
PoC for CVE-2026-13344
The Essential Addons for Elementor WordPress plugin prior to version 6.6.10 is susceptible to Stored Cross-Site Scripting due to inadequate validation of HTML tag names in the Pricing Table widget title. This vulnerability allows users with Contributor-level access and above to inject malicious J...
PoC for CVE-2026-13345
The Essential Addons for Elementor plugin for WordPress, prior to version 6.6.10, lacks necessary authorization checks in its product-comparison feature. This oversight allows unauthenticated users to access sensitive information, such as the titles, prices, and SKUs of draft, pending, and privat...
PoC for CVE-2026-13395
The Online Scheduling and Appointment Booking System plugin for WordPress prior to version 27.8 is vulnerable to SQL injection. This flaw arises from the plugin's failure to properly sanitize or cast user-supplied parameters in unauthenticated front-end booking requests. Attackers can exploit thi...
PoC for CVE-2026-13145
The WP Travel plugin for WordPress, prior to version 11.8.1, is susceptible to an information disclosure vulnerability. The flaw occurs because the plugin fails to verify the ownership of booking requests made through the customer account dashboard. Consequently, this allows any authenticated use...
PoC for CVE-2026-13330
The Animation Addons for Elementor plugin for WordPress allows users with the upload_files capability (Author and above) to upload SVG/SVGZ files without proper sanitization. This oversight enables the potential injection of malicious JavaScript into the application, resulting in stored cross-sit...
PoC for CVE-2026-13143
The WP Travel plugin for WordPress, prior to version 11.8.1, contains a vulnerability that allows unauthenticated attackers to manipulate payment statuses. This flaw stems from the plugin's failure to authenticate PayPal Instant Payment Notifications via the necessary post-back handshake. Consequ...
PoC for CVE-2026-13178
The Eventin WordPress plugin, prior to version 4.1.16, contains a vulnerability that allows unauthorized order creation. This occurs due to improper authorization checks, enabling attackers to modify order statuses without completing any payment process. As a result, unauthenticated users can cre...
PoC for CVE-2026-11881
The Fluent Forms WordPress plugin prior to version 6.2.6 contains a vulnerability that fails to properly sanitize and escape a specific form field configuration setting. When a form is rendered, this oversight enables users with low-level roles, such as Contributor with specific permissions, to p...
PoC for CVE-2026-11870
The WP Ghost (Hide My WP Ghost) WordPress plugin prior to version 7.0.05 fails to properly verify that the client IP address originates from a trusted proxy. This oversight allows attackers to manipulate HTTP headers to spoof their IP addresses. As a result, unauthenticated attackers can circumve...
PoC for CVE-2026-11867
The Frontend Admin plugin by DynamiApps, prior to version 3.29.7, contains a flaw that allows authenticated users with minimal privileges, like Subscribers, to perform unrestricted operations on taxonomy terms. This vulnerability permits these users to create, modify, and delete arbitrary taxonom...
PoC for CVE-2026-12500
The WP Travel Engine plugin for WordPress prior to version 6.8.2 is vulnerable due to insufficient access checks on AJAX actions. This flaw allows unauthenticated users to execute certain actions, specifically overwriting critical site-wide options, as the public nonce required for these actions ...
PoC for CVE-2026-15382
The Ultimate Addons for WPBakery Page Builder plugin allows for unauthorized deletion of a website's custom-uploaded icon font packs. Prior to version 3.21.4, the plugin fails to implement necessary capability and nonce checks, enabling unauthenticated attackers to issue a single request that can...
PoC for CVE-2026-11782
The Points and Rewards for WooCommerce plugin does not implement necessary authorization checks on wallet and points update actions, which are exposed to unauthenticated users. This vulnerability allows attackers to modify or corrupt the wallet balance and loyalty points of any user without verif...
PoC for CVE-2026-15255
The RegistrationMagic WordPress plugin prior to version 6.0.9.4 contains a security flaw that permits unauthenticated attackers to access sensitive user data. The issue arises from inadequate validation of one-time passwords stored in cookies, which enables unauthorized individuals to retrieve fr...
PoC for CVE-2026-15257
The RegistrationMagic WordPress plugin prior to version 6.0.9.4 allows unauthorized users to exploit the absence of proper authorization and nonce checks on front-end editing actions. This vulnerability enables attackers to overwrite the form submissions and associated profile fields of non-admin...
PoC for CVE-2026-15252
The Search Atlas SEO plugin for WordPress prior to version 2.6.12 is susceptible to an authentication bypass flaw due to insufficient validation in an AJAX handler. This vulnerability allows authenticated users, such as Subscribers, to interact with the site's Google Indexing API. Consequently, t...
PoC for CVE-2026-15240
The Customer Switching plugin for WordPress prior to version 2.1.3 has a security flaw that allows a user with lower privileges to exploit an active session. When an operator switches to another user account, the session is not securely bound, enabling the lower-privileged user to perform actions...
PoC for CVE-2026-14231
The LifterLMS WordPress plugin prior to version 10.0.10 has a vulnerability that fails to adequately verify user capabilities in one of its AJAX handlers. This oversight allows any authenticated user, even those with minimal subscriber-level permissions, to access sensitive titles of internal pos...
PoC for CVE-2026-14318
The GiveWP plugin for WordPress, specifically versions prior to 4.16.3, is vulnerable to a Cross-Site Scripting (XSS) issue. This vulnerability arises from a lack of proper escaping for donation-form template settings before they are displayed in HTML attributes. As a result, users with the 'Give...
PoC for CVE-2026-14207
The LifterLMS plugin for WordPress prior to version 10.0.10 is susceptible to a cross-site scripting vulnerability. This flaw arises from the plugin's failure to sanitize event-handler attributes within a course pricing field. As a result, users with editing privileges can inject malicious JavaSc...
PoC for CVE-2026-15250
The Appointment Booking Plugin for WordPress has a significant security flaw that permits unauthenticated users to manipulate certain booking fields through the public booking interface. This vulnerability enables unauthorized individuals to assign privileged values, such as the approval status, ...
PoC for CVE-2026-15153
The WP Hotel Booking plugin for WordPress prior to version 2.3.2 is susceptible to SQL injection due to improper sanitization and escaping of search parameters in administrative listings. Attackers with appropriate booking-management roles could exploit this vulnerability to execute unauthorized ...
PoC for CVE-2026-15235
The MotoPress Hotel Booking WordPress plugin prior to version 6.0.4 lacks sufficient capability checks in its AJAX functionalities. This oversight allows authenticated users with minimal privileges, such as Subscribers, to access sensitive customer information. Specifically, personal data includi...
PoC for CVE-2026-12687
The ProfileGrid WordPress plugin prior to version 5.9.9.8 contains a security flaw that allows anonymous users to bypass registration restrictions. As a result, these users can register into privileged groups without authentication, potentially being assigned roles with elevated permissions, incl...
PoC for CVE-2026-15054
The Bit Form plugin for WordPress has a security flaw that permits unauthenticated users to submit entries through public form submission handlers, even for forms that have been deactivated or unpublished. This oversight allows users to trigger configured workflows, such as email notifications, p...
PoC for CVE-2026-14592
The WP Real IP-based Access Control plugin prior to version 1.3.1 is susceptible to an access control vulnerability, allowing unauthenticated users to insert arbitrary JavaScript into a specific option value. This JavaScript becomes executable when an administrator accesses the plugin's settings ...
PoC for CVE-2026-14923
The Sync Post With Other Site plugin for WordPress prior to version 1.9.3 contains a serious flaw in its authorization mechanism on a REST route that manages post creation and updates. Due to an operator-precedence error, it fails to enforce proper page-editing capabilities, allowing authenticate...
PoC for CVE-2026-14602
The Remote API WordPress plugin versions up to 0.2 contains a serious security flaw in its handling of user-supplied input. This vulnerability allows unauthenticated attackers to inject malicious PHP objects through deserialization, which could lead to remote code execution if a suitable exploit ...
PoC for CVE-2026-14226
The Easy Appointments plugin for WordPress up to version 3.12.26 contains an access control vulnerability that permits users with minimal permissions to access sensitive appointment data through certain REST API endpoints. Specifically, the plugin only checks for a basic user capability that any ...
PoC for CVE-2026-14221
The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and t...
PoC for CVE-2026-14188
The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
PoC for CVE-2026-14223
The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
PoC for CVE-2026-14222
The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
Discovered 11 hours ago
PoC for CVE-2026-57827
The RSFiles Joomla extension presents a security vulnerability that allows for unauthenticated users to upload arbitrary files, potentially enabling the execution of malicious code remotely. This flaw can lead to significant security risks for affected Joomla installations as it opens pathways fo...
PoC for CVE-2024-36104
Apache OFBiz is affected by a Path Traversal vulnerability that allows attackers to gain unauthorized access to restricted directories. This issue can lead to sensitive data exposure and requires urgent remediation. Users are strongly encouraged to upgrade to version 18.12.14 or later to mitigate...
PoC for CVE-2026-43813
A vulnerability exists that stems from improper input validation, which has been resolved through enhanced input sanitization. This flaw allowed a maliciously crafted application to potentially bypass code signing enforcement mechanisms in various Apple operating systems. Users are encouraged to ...
Discovered 13 hours ago
PoC for CVE-2022-38181
The Arm Mali GPU kernel driver is vulnerable due to mishandled GPU memory operations, which allows unprivileged users to access freed memory. This issue affects multiple versions across the Bifrost, Valhall, and Midgard architectures, posing potential risks for system integrity and data security.
Discovered 14 hours ago
PoC for CVE-2026-2586
An authenticated Remote Code Execution vulnerability exists in the Administration Console of GlassFish. This flaw allows authorized users to send specially crafted requests, potentially resulting in the execution of arbitrary commands on the operating system with the privileges of the application...
Discovered 22 hours ago
PoC for CVE-2026-41939
The Care Everywhere Gateway version 14.3.10 contains a vulnerability due to hard-coded credentials in the embedded WildFly 8.2.0.Final management interface. This issue allows unauthenticated remote attackers to exploit default credentials, which are identical across all installations. By accessin...
Discovered 23 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...