Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 14 minutes ago
PoC for CVE-2022-38694
The vulnerability occurring in UNISOC's BootRom allows a possible unchecked write address, enabling local escalation of privilege without requiring additional execution privileges. This flaw poses a significant security risk, as it can be exploited by malicious actors to gain unauthorized access ...
Discovered 22 minutes ago
PoC for CVE-2026-5430
The vulnerability in WSO2 products relates to the JWT authentication mechanism, which improperly validates tokens signed with algorithms not explicitly configured or supported. This flaw enables an attacker to create a JSON Web Token (JWT) using an unsupported signing algorithm. If an attacker su...
Discovered 1 hour ago
PoC for CVE-2014-0160
The vulnerability in the TLS and DTLS implementations of OpenSSL versions prior to 1.0.1g allows remote attackers to exploit crafted Heartbeat Extension packets. This exploitation results in a buffer over-read, potentially revealing sensitive information from the memory of the affected process. A...
Discovered 2 hours ago
PoC for CVE-2026-92364
A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit ha...
PoC for CVE-2026-92469
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifiers via GET /files and delete arbitrary users' files and meta...
PoC for CVE-2026-92468
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path...
PoC for CVE-2026-92468
zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path...
PoC for CVE-2026-92467
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request bod...
PoC for CVE-2026-92466
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including use...
PoC for CVE-2026-92466
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including use...
PoC for CVE-2026-92466
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including use...
PoC for CVE-2026-92466
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including use...
PoC for CVE-2026-92466
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including use...
PoC for CVE-2026-65374
A memory corruption vulnerability has been identified in macOS products, which can be exploited when connecting to a malicious WebDAV server. This flaw allows the potential for arbitrary code execution, posing significant risks to users. Apple has addressed this issue in the latest updates, inclu...
Discovered 4 hours ago
PoC for CVE-2026-92463
A vulnerability exists in yshop-crm version 2.1.3 due to an authorization failure in the GET /admin-api/system/user/page endpoint. The @PreAuthorize annotation is commented out, which permits authenticated back-office users lacking the necessary permissions to enumerate all users. Attackers with ...
PoC for CVE-2026-92462
The yshop-crm application, up to version 2.1.3, contains a flaw that permits authenticated back-office users to invoke the DELETE /admin-api/crm/flow/delete-step endpoint without proper authorization. This oversight allows users to remove critical approval workflow steps necessary for managing co...
PoC for CVE-2026-92461
yshop-crm versions up to 2.1.3 contain a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint. This flaw allows any authenticated back-office user to access sensitive approval workflow data, including the approval chain topology, ordering, and identifiers for app...
PoC for CVE-2026-92460
The yshop-crm product up to version 2.1.3 lacks proper authorization checks on the GET /admin-api/crm/operatelog/page endpoint. This oversight permits any authenticated back-office user to access sensitive information contained in the installation-wide audit trail. Through this vulnerability, use...
PoC for CVE-2026-92458
In yshop-crm version 2.1.3, a flaw exists in the StoreProductController where the onSale handler does not enforce proper authorization checks. This vulnerability allows authenticated back-office users to alter the sale status of products by accessing the /admin-api/product/store-product/sale endp...
PoC for CVE-2026-92459
The yshop-crm application through version 2.1.3 is susceptible to a missing authorization vulnerability that affects the 'receiveCustomer' endpoint within the CrmCluesController. This flaw enables authenticated back-office users to reassign sales leads without adequate permission checks, allowing...
PoC for CVE-2026-92457
A security issue in the yshop-crm platform allows authenticated back-office users to manipulate invoice issuance through the CrmInvoiceController's issueInvoice endpoint. This vulnerability permits users lacking the necessary permissions to issue invoices, modify contract values, and send invoice...
PoC for CVE-2026-92455
The yshop-crm application version 2.1.3 contains a vulnerability that fails to enforce proper authorization controls on the sendSms and sendMail API endpoints within the CrmCustomerController. This oversight allows any authenticated back-office user to send SMS and email communications to arbitra...
PoC for CVE-2026-92455
The yshop-crm application version 2.1.3 contains a vulnerability that fails to enforce proper authorization controls on the sendSms and sendMail API endpoints within the CrmCustomerController. This oversight allows any authenticated back-office user to send SMS and email communications to arbitra...
PoC for CVE-2026-92456
The yshop-crm product version 2.1.3 contains an authorization vulnerability that permits any authenticated back-office user to access and alter critical settings through the saveRedisSet and getRedisSet endpoints in the CrmCustomerController. This flaw allows users to manipulate shared Redis keys...
Discovered 9 hours ago
PoC for CVE-2026-86475
The Appointment Hour Booking WordPress plugin versions before 1.5.95 contains a vulnerability that fails to validate the booking capacity for appointments. As a result, unauthenticated users can exploit this flaw to reserve appointment slots that are already at full capacity, potentially leading ...
PoC for CVE-2026-84906
The Eventin plugin for WordPress, prior to version 4.1.24, has an authorization flaw that allows unauthenticated visitors to falsely mark unpaid orders as paid. This issue arises because the plugin solely relies on successful transaction reports from the payment gateway, without validating the tr...
PoC for CVE-2026-19857
The Formidable Forms WordPress plugin, prior to version 6.35, is susceptible to a security vulnerability that allows unauthenticated users to manipulate a request-derived value. This flaw enables malicious visitors to execute arbitrary shortcodes with attacker-defined attributes. When these short...
PoC for CVE-2026-13407
The Royal Elementor Addons WordPress plugin prior to version 1.7.1067 has a flaw that allows unauthenticated users to exploit the form widget by submitting values that are not properly sanitized or escaped. This vulnerability enables attackers to inject arbitrary HTML into the body of notificatio...
PoC for CVE-2026-87896
The Rox Appointment Booking plugin for WordPress, prior to version 1.2.8, is vulnerable due to a lack of authorization checks on its endpoints. This allows unauthenticated attackers to access sensitive information related to booking agents, including email addresses, phone numbers, internal notes...
PoC for CVE-2026-87959
A flaw in the WPBot WordPress plugin versions prior to 8.7.6 allows users with only subscriber-level access to bypass authorization checks on an AJAX action. This vulnerability enables them to alter critical settings, including the API key utilized for outgoing requests by the WPBot's AI features...
PoC for CVE-2026-87907
The Rox Appointment Booking plugin for WordPress prior to version 1.2.8 contains a significant vulnerability that permits unauthorized users to access confidential internal notes associated with various booking services and categories. The plugin's endpoints for retrieving these records lack nece...
PoC for CVE-2026-88910
The kboard WordPress plugin is susceptible to a vulnerability that permits unauthenticated attackers to delete uploaded media files without appropriate verification of ownership or context. This issue stems from the inability of the plugin to validate user permissions, allowing malicious users to...
PoC for CVE-2026-89328
The FluentBoards WordPress plugin prior to version 2.0.15 is susceptible to privilege escalation due to improper verification of user permissions. Specifically, it fails to ensure that users possess the necessary board-manager privileges before allowing them to execute critical board-management t...
PoC for CVE-2026-89327
The FluentBoards WordPress plugin prior to version 2.0.15 contains a vulnerability that allows board members to submit comments on behalf of other users. This lack of proper verification can lead to unauthorized comment postings under the names of different users, including admin accounts, compro...
PoC for CVE-2026-87860
The Subscriptions for WooCommerce plugin prior to version 2.0.3 is vulnerable due to inadequate verification of security tokens in subscription cancellation requests. This flaw can be exploited by malicious actors, who may trick logged-in customers into making crafted requests that inadvertently ...
PoC for CVE-2026-86823
The Newsletter WordPress plugin prior to version 9.3.7 has a security flaw due to insufficient validation of redirect destinations following public subscription actions. This vulnerability enables unauthenticated attackers to manipulate redirects, potentially leading users to malicious external s...
PoC for CVE-2026-87828
The Seraphinite Accelerator plugin for WordPress fails to adequately validate permissions during state-update AJAX actions. This oversight allows authenticated users, including those with minimal privileges such as subscribers, to inject malformed data. Such actions can trigger unhandled errors o...
PoC for CVE-2026-86784
The Visualizer WordPress plugin prior to version 4.0.8 is susceptible to a cross-site scripting vulnerability due to improper sanitization and escaping of JSON data source configurations in the chart editor. This flaw enables users with Contributor roles or higher to inject malicious JavaScript, ...
PoC for CVE-2026-87854
The Subscriptions for WooCommerce plugin, prior to version 2.0.3, contains a vulnerability that fails to properly validate the shared secret for one of its REST endpoints. This security oversight allows unauthenticated users to access a complete list of the store's subscriptions. The exposed data...
PoC for CVE-2026-86447
The LearnPress plugin for WordPress, prior to version 4.4.7, is susceptible to an information disclosure vulnerability. This flaw allows unauthenticated attackers to access sensitive data, including the display names and user identifiers of all enrolled students in various courses. Additionally, ...
PoC for CVE-2026-86449
The LearnPress WordPress plugin prior to version 4.4.7 contains a significant flaw in its REST API functionality. The plugin fails to adequately verify user permissions before applying a filter based on user-supplied post statuses. This oversight enables unauthenticated attackers to exploit the R...
PoC for CVE-2026-86448
The LearnPress WordPress plugin, prior to version 4.4.7, contains a significant vulnerability that allows attackers to access sensitive data without proper authentication. An unauthenticated user can exploit this flaw to download order export files, which include customer names, purchase details,...
PoC for CVE-2026-86445
The LearnPress plugin for WordPress, prior to version 4.4.7, features a serious flaw in its administrative template handlers, failing to properly validate user capabilities. This vulnerability empowers unauthenticated attackers to access and extract sensitive information, including quiz questions...
PoC for CVE-2026-85572
The Tutor LMS WordPress plugin, prior to version 4.0.8, contains a vulnerability that allows authenticated users to access lesson discussion content from courses they are not enrolled in. This loophole enables users, including those with subscriber-level access, to read comments—including those a...
PoC for CVE-2026-85569
The Tutor LMS plugin for WordPress prior to version 4.0.8 contains a vulnerability that compromises its REST API access control. It fails to adequately verify the source of incoming requests, allowing users with a read-only key to execute actions typically reserved for administrator accounts. Thi...
PoC for CVE-2026-85641
The Formidable Forms plugin for WordPress prior to version 6.35 fails to properly restrict user permissions when setting the identifier for form entries. This lack of access control permits unauthenticated users to manipulate the identifier, which is used to determine HTML stripping in stored ent...
PoC for CVE-2026-86444
The LearnPress plugin for WordPress, prior to version 4.4.7, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This occurs due to the failure to properly escape user-supplied data before embedding it in HTML attributes on public pages. An attacker can exploit this flaw by crafting a m...
PoC for CVE-2026-85530
The GiveWP WordPress plugin prior to version 4.16.8.1 contains a vulnerability that mishandles the normalization of donor email addresses. This inconsistency allows unauthorized users to be misidentified as legitimate donors, potentially granting them the ability to alter the WordPress password o...
PoC for CVE-2026-85349
The FluentBoards plugin for WordPress prior to version 2.0.15 contains an authorization flaw that fails to properly verify user permissions when retrieving a list of boards a user is associated with. This vulnerability could enable any authenticated user, including those with minimal access right...
PoC for CVE-2026-84905
The Eventin WordPress plugin prior to version 4.1.24 contains a significant security flaw that fails to verify user permissions properly. This oversight allows users with contributor-level access and higher to create new WordPress user accounts with elevated privileges. Consequently, these accoun...