Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 3 hours ago
PoC for CVE-2026-86272
A vulnerability has been identified in the U+Smart Enjoyment WebSite, specifically within the /Report/Upload/UploadFormImg.ashx file, where an unrestricted file upload is possible. By manipulating the 'File' argument, an attacker could upload potentially harmful files to the server, leading to se...
PoC for CVE-2026-86271
A security vulnerability was identified in FluentCMS versions up to 0.0.5, specifically within the GetAccessible function located in the PermissionManager.cs file. This flaw results in inadequate authorization checks, allowing unauthorized access when exploited. The vulnerability is particularly ...
PoC for CVE-2026-18963
A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...
PoC for CVE-2026-86270
A SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0, particularly in the settings_edit.php file. An attacker can exploit this vulnerability by manipulating the argument ID, allowing for unauthorized database queries and potential exposure of sensitive i...
PoC for CVE-2026-86269
A vulnerability has been identified in itsourcecode Sales and Inventory System 1.0, specifically within an undisclosed function located in the /pages/emp_edit1.php file. This flaw allows for SQL injection attacks due to improper handling of the argument ID, which can be exploited remotely. Attack...
Discovered 4 hours ago
PoC for CVE-2026-86268
A vulnerability affecting the itsourcecode School Management System 1.0 has been identified, where an unknown function in the User_Login.php file allows for SQL injection through the manipulation of the email argument. This flaw can be exploited remotely, raising concerns about unauthorized datab...
PoC for CVE-2026-86267
A security vulnerability has been identified in the itsourcecode Information System Society Membership System version 1.0, specifically in the file /society/check_student.php. This flaw allows an attacker to manipulate the student_id parameter, leading to potential SQL injection attacks. Such vul...
PoC for CVE-2026-86265
A remote code execution vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0. Specifically, the issue lies within an unknown functionality of the file /pages/us_transac.php, where inadequate sanitization of user input allows for SQL injection through manipu...
PoC for CVE-2026-86264
A cross site scripting vulnerability exists in the ssm_pro application from Sfturing due to an issue in the Order Endpoint functionality. Specifically, the flaw lies in the handling of input parameters such as hospitalName, officesName, and doctorName in the OrderController.java file. This weakne...
Discovered 5 hours ago
PoC for CVE-2026-86263
A significant vulnerability has been identified in the sfturing hosp_order application which affects the order cancellation functionality. The issue arises in the method orderRecordsService.cancelOrder located in the OrderController.java file. By manipulating the argument ID, an unauthorized acto...
PoC for CVE-2026-86262
A significant security flaw has been identified in Sfturing's Hosp_Order software, specifically within the Order Handler component. An attacker can exploit this vulnerability through remote manipulation of the userID/id argument in the updateOrderSta1/updateOrderdiseaseInfo function of OrderContr...
PoC for CVE-2026-86261
A vulnerability exists in the Sfturing Hosp_Order product that allows remote attackers to bypass authorization controls. This issue is linked to a mismanaged parameter within the Order Controller. Manipulating the userIdenf argument can enable unauthorized access to certain functionalities. The f...
PoC for CVE-2026-86260
A security flaw exists in the hosp_order's password recovery functionality, specifically within the modifyPassWord method of the CommonUserController.java file. This vulnerability enables an attacker to change user passwords without proper verification, potentially compromising user accounts. Sin...
Discovered 6 hours ago
PoC for CVE-2026-86245
A vulnerability has been identified in the itsourcecode Sales and Inventory System 1.0 related to a remote exploitable SQL injection through the '/pages/sup_transac.php' file. By manipulating the 'companyname' argument, attackers can execute arbitrary SQL queries on the database. This flaw poses ...
PoC for CVE-2026-86244
A security vulnerability exists in the FastAdmin User Controller, specifically in the register/login functionality within the User.php file. This flaw permits attackers to manipulate the URL argument, which can lead to cross site scripting (XSS). The vulnerability is remotely exploitable and pose...
PoC for CVE-2026-86241
A vulnerability has been discovered in liufee FeehiCMS versions up to 2.1.1 that affects the cookie validation component within the main-local.php configuration file. The flaw arises from the unsecure handling of the cookieValidationKey, which utilizes a hard-coded cryptographic key. This can be ...
PoC for CVE-2026-86240
A security flaw has been identified in Liufee FeehiCMS versions up to 2.1.1, specifically within the UEditor component's catchImage function located in backend/widgets/ueditor/Uploader.php. This vulnerability allows an attacker to manipulate the argument 'source[]', leading to server-side request...
Discovered 7 hours ago
PoC for CVE-2026-86239
A vulnerability has been discovered in the UEditor Widget component of FeehiCMS, specifically in the function UeditorAction::init within the file backend/widgets/ueditor/UeditorAction.php. This flaw allows for unrestricted file uploads, which could be exploited by remote attackers to upload malic...
Discovered 8 hours ago
PoC for CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...
PoC for CVE-2026-86235
A vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0, where improper validation in the /pages/pos_transac.php file can lead to SQL injection attacks. By manipulating the 'Customer' argument, an attacker can execute arbitrary SQL queries against the databa...
PoC for CVE-2026-86234
A SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0, specifically affecting the /pages/cust_transac.php endpoint with the action parameter set to add. By manipulating the firstname argument, attackers can execute arbitrary SQL commands. Thi...
PoC for CVE-2026-86233
A security vulnerability exists in the itsourcecode Sales and Inventory System version 1.0, specifically within the /pages/us_del.php?type=user file. This vulnerability arises from improper handling of user-supplied input, allowing attackers to manipulate the 'ID' argument. As a result, attackers...
PoC for CVE-2026-86232
A vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0, specifically within the functionality of the file /pages/sup_del.php?type=supplier. This flaw allows attackers to manipulate the ID argument, leading to SQL injection. The resulting exploit can be exec...
Discovered 9 hours ago
PoC for CVE-2026-86231
A vulnerability has been identified in mwiede jsch versions up to 2.28.5 related to the function getRevokedKeys found in the KnownHosts.java file. This flaw allows attackers to manipulate the argument known_hosts, resulting in an improper verification process for certificate revocation. The remot...
PoC for CVE-2026-86228
A security vulnerability has been identified in JeecgBoot versions prior to 3.9.4, specifically in the exportXls function of the AiragModelController.java file. This flaw allows for improper access control, enabling attackers to manipulate credentials and gain unauthorized access. The issue can b...
PoC for CVE-2026-86227
A weakness has been found in Valkey software, specifically within the kvstoreGetHashtable function of the src/kvstore.c file. This vulnerability allows an attacker to manipulate the 'didx' argument, leading to an out-of-bounds read, which could potentially reveal sensitive information. Remote exp...
PoC for CVE-2026-86226
A serious security flaw has been identified in the Projectwolds Online Attendance System version 1.0. The vulnerability exists in an unknown function within the profile.php file, where manipulating the 'email' argument leads to cross site scripting attacks. This flaw can be exploited remotely, po...
Discovered 10 hours ago
PoC for CVE-2026-86225
A security vulnerability has been discovered in the SourceCodester Class and Exam Timetabling System 1.0, specifically within the function 'mysqli_query' located in the file '/admin/modal_add_room.php'. This vulnerability can be exploited through the manipulation of the 'room_name' argument, allo...
PoC for CVE-2026-67276
MikroTik RouterOS contains a vulnerability in its SSH authentication mechanism, which fails to fully compare RSA public keys. While it checks the key type and modulus, the exponent is overlooked. An attacker with knowledge of an authorized RSA modulus can exploit this flaw by supplying a crafted ...
PoC for CVE-2026-86224
A security flaw exists in the SourceCodester Class and Exam Timetabling System version 1.0. This vulnerability arises in the `mysqli_query` function situated within the `admin/modal_add_product.php` file. Manipulating the argument `fname` can permit an unauthorized user to execute SQL injection a...
Discovered 12 hours ago
PoC for CVE-2026-86223
A SQL injection vulnerability exists in the SourceCodester Class and Exam Timetabling System version 1.0, specifically impacting the mysqli_query function in the /admin/modal_add_coursea.php file. This vulnerability allows malicious users to manipulate the 'course' argument, which can lead to una...
PoC for CVE-2026-86222
The SourceCodester Class and Exam Timetabling System version 1.0 contains a vulnerability in the /admin/modal_add_course2.php file, specifically within the mysqli_query function. This security flaw allows an attacker to manipulate the 'course' argument, potentially leading to SQL injection attack...
Discovered 13 hours ago
PoC for CVE-2026-86221
A vulnerability exists in SourceCodester's Class and Exam Timetabling System 1.0 due to improper handling of user input in the mysqli_query function within the file /admin/modal_add_course1.php. This flaw enables attackers to execute arbitrary SQL commands remotely, potentially compromising the u...
Discovered 14 hours ago
PoC for CVE-2026-86220
A SQL injection vulnerability exists in the SourceCodester Class and Exam Timetabling System version 1.0. This flaw is identified in the mysqli_query function located in the file /admin/modal_add_course.php. By manipulating the 'course' argument, an attacker may conduct a remote SQL injection att...
Discovered 17 hours ago
PoC for CVE-2026-86217
A vulnerability exists in the Hotel and Tourism Reservation system developed by Code-Projects, specifically within the Database Backup Handler component. An unknown function in the file '/ht/hotel_db%20(1).sql' can be exploited to disclose sensitive information. This vulnerability can be exploite...
Discovered 18 hours ago
PoC for CVE-2026-86216
A cross-site scripting vulnerability has been identified in the Hotel and Tourism Reservation system (PHP version 1.0) by Code-Projects. This security flaw exists within the /ht/details.php file, where improper handling of the 'room' parameter allows attackers to inject malicious scripts. The exp...
PoC for CVE-2026-86215
A flaw has been detected in the Logout Handler component of the Mstfakts College-Management-System, specifically within the function located in the server.php file. This vulnerability allows an attacker to manipulate the 'log_out' argument, resulting in premature session expiration. The attack ca...
PoC for CVE-2026-86214
A vulnerability exists in the Mstfakts College-Management-System, particularly within the login.php file, where the manipulation of the email argument can lead to improper authentication. This issue allows attackers to perform remote exploitation, potentially compromising user accounts. While the...
Discovered 19 hours ago
PoC for CVE-2026-86213
A SQL injection vulnerability exists in the Mstfakts College-Management-System, specifically in the Search Handler component found in the Front-end/university.php file. An attacker can exploit this vulnerability through the manipulated input parameters 'book_name' and 'book_author', allowing unau...
Discovered 20 hours ago
PoC for CVE-2026-86212
A vulnerability has been identified in Open5GS versions 2.7.7 and 2.8.0 that affects the AMF/MME component. This weakness allows for improper authorization, which can be exploited remotely by attackers. As a result, unauthorized actions may be executed, posing significant risks to application int...
Discovered 21 hours ago
PoC for CVE-2026-86211
A vulnerability exists in the login functionality of the rabindralamsal inventory-management-system version 1.0.0, specifically within the index.php file. This flaw allows for remote exploitation through SQL injection, where improper handling of the username and password inputs can enable attacke...
Discovered 22 hours ago
PoC for CVE-2026-86210
A vulnerability has been found in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the file /delete_user_account.php. This vulnerability allows for remote SQL injection through the manipulation of the argument ID. Attackers can leverage this exploit to execute...
PoC for CVE-2026-80437
The Ninja Forms plugin for WordPress, specifically versions prior to 3.15.2, contains a vulnerability where it fails to prevent shortcodes in request-derived values from executing. This flaw allows unauthenticated users to run any shortcode available on the site, potentially leading to unauthoriz...
PoC for CVE-2026-80439
The Contact Form 7 plugin for WordPress prior to version 3.2.11 is prone to a vulnerability that allows unauthenticated users to exploit form submissions. By injecting shortcodes into form fields, these users can execute any registered shortcode on the site, gaining access to its output. This cou...
PoC for CVE-2026-19859
The JetFormBuilder plugin for WordPress versions prior to 3.6.5.2 is susceptible to an arbitrary code execution vulnerability. This issue stems from the failure to properly sanitize a request parameter before it is utilized in rendering message content. Consequently, unauthenticated users may exp...
PoC for CVE-2026-19862
The JetFormBuilder plugin for WordPress, prior to version 3.6.5.2, contains a vulnerability allowing unauthenticated users to manipulate email headers through unvalidated address values sourced from form submissions. This flaw permits the injection of arbitrary email headers, facilitating hidden ...
PoC for CVE-2026-86209
A vulnerability has been detected in the SourceCodester Class and Exam Timetabling System 1.0. This issue involves an inadequately protected function within the /delete_user.php file, which can be exploited through remote SQL injection via manipulated argument IDs. Attackers can potentially execu...
PoC for CVE-2026-86208
A security vulnerability has been identified in the Class and Exam Timetabling System version 1.0 that allows remote attackers to manipulate the ID parameter within the /delete_teacher.php file, leading to SQL injection. This flaw can let unauthorized users execute arbitrary SQL commands, potenti...
PoC for CVE-2026-86183
A vulnerability exists in the Diem Project's dmWidget component, specifically within the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php. This flaw enables unauthorized users to bypass security measures by manipulating the 'widget_id' argument. As a result, remote attackers ...
Discovered 23 hours ago
PoC for CVE-2026-86182
A vulnerability has been identified in the dmConsole component of diem-project, specifically in the executeCommand function of actions.class.php. This issue allows an attacker to manipulate the dm_command argument, potentially leading to cross-site request forgery (CSRF). Given that the attack ca...