Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2024-40891
A post-authentication command injection vulnerability exists in the management commands of Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615. This flaw allows an authenticated attacker to execute arbitrary operating system commands via Telnet, potentially compromising the security and i...
Discovered 58 minutes ago
PoC for CVE-2026-19790
A vulnerability exists in the Tenda G0's Web Management Interface, specifically within the function formSetPortMirror located in the /goform/module file. This issue arises from improper handling of the argument portMirrorMirroredPorts, leading to a stack-based buffer overflow. The vulnerability c...
Discovered 1 hour ago
PoC for CVE-2026-19789
A security flaw exists in the Tenda AC1206 router's web management interface, specifically within the function set_wl_guest_iplist located in /goform/WifiGuestSet. This vulnerability allows for a stack-based buffer overflow due to improper handling of the shareSpeed argument. Successful exploitat...
PoC for CVE-2026-19788
A stack-based buffer overflow vulnerability exists in the Tenda AC1206 web management interface, specifically within the set_device_name function of the /goform/SetOnlineDevName endpoint. By manipulating the devName parameter, an attacker can exploit this vulnerability remotely, leading to potent...
Discovered 2 hours ago
PoC for CVE-2026-19787
A vulnerability exists in the SourceCodester Air Cargo Management System version 1.0 that allows for SQL injection through the manipulation of the ID parameter in the Master.php file, specifically within the save_cargo_type function. This vulnerability can be exploited remotely, enabling attacker...
PoC for CVE-2026-19784
A vulnerability has been identified in RosarioSIS versions prior to 12.9, specifically affecting the DBUpdate function within Discipline/Referrals.php. This flaw results in an authorization bypass that can be exploited remotely. The exploit is publicly available, posing substantial risks to users...
Discovered 3 hours ago
PoC for CVE-2026-19771
A vulnerability exists in the Baicells EG3661M due to improper handling of MaxHops, Timeout, and Size parameters in the LuCI Web Interface. This flaw allows an attacker to execute arbitrary commands on the operating system through remote exploitation. Without a timely vendor response to reported ...
PoC for CVE-2026-19770
A security vulnerability exists in Feedmob's FM-MCP-Servers version 0.0.3, specifically within the 'downloadReport' function located in the Download Endpoint module. This issue arises from the manipulation of the 'downloadUrl' argument, enabling an attacker to perform server-side request forgery ...
PoC for CVE-2026-19767
A vulnerability has been detected in the itsourcecode Hospital Management System 1.0, specifically in the file viewdoctortimings.php. This issue arises from improper handling of input parameters, primarily the 'delid' argument, which enables remote attackers to execute SQL injection attacks. Such...
PoC for CVE-2026-41940
The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...
PoC for CVE-2026-19765
A security flaw has been identified in eyaushev swagger-testcase-mcp, specifically impacting the loadSource function within the swagger-parser.ts file. This vulnerability allows remote attackers to manipulate requests and exploit the application for server-side request forgery. The issue was repo...
Discovered 4 hours ago
PoC for CVE-2026-19764
A SQL injection vulnerability has been discovered in the Raisecom Communication Command and Dispatch Management Platform, specifically affecting the /app/users/getpwd.php file in versions up to 7.6.5. This flaw allows attackers to manipulate the 'sip' argument, potentially leading to unauthorized...
Discovered 5 hours ago
PoC for CVE-2026-19758
A vulnerability has been identified in Dromara Lamp-Cloud versions up to 5.10.0, specifically within the FileChunkController.java component associated with the chunk-check endpoint. This flaw allows an attacker to manipulate the 'Name' argument, potentially leading to a path traversal attack. Suc...
PoC for CVE-2026-53413
A buffer overwrite vulnerability exists in the annotator function of Zoom Clients, enabling a malicious meeting participant to execute arbitrary code on another participant's device by exploiting this flaw via network access. This security concern underscores the importance of keeping Zoom Client...
PoC for CVE-2026-19757
A path traversal vulnerability exists in the File-Upload Controller (FileAnyoneController.java) of Dromara's lamp-cloud product versions up to 5.10.0. By manipulating the 'bucket' or 'bizType' parameters, an attacker can access restricted directories and potentially execute arbitrary code. Althou...
PoC for CVE-2026-33017
Langflow, a tool for constructing and deploying AI-driven agents and workflows, is susceptible to a vulnerability in the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint in versions before 1.9.0. This vulnerability enables an attacker to build public flows without authentication, leveraging ...
Discovered 6 hours ago
PoC for CVE-2026-25938
FUXA, a web-based Process Visualization software, is susceptible to an authentication bypass vulnerability when the Node-RED plugin is enabled. This flaw allows an unauthenticated remote attacker to execute arbitrary code on the server, posing a significant risk to system integrity. This issue ha...
PoC for CVE-2026-19756
A path traversal vulnerability has been identified in the Dromara Lamp-Cloud software's Code Generator component, specifically within the DefGenProjectController.java file. Attackers can exploit this vulnerability by manipulating the outputDir, parent, or projectPrefix arguments, enabling remote ...
PoC for CVE-2026-19753
A server-side request forgery vulnerability has been identified in MCP-RDF-Explorer version 1.0.0. This issue arises in the explore_url function within the server.py file of the MCP Server component. By manipulating the url argument, an attacker can execute unauthorized requests from the server, ...
PoC for CVE-2026-19752
The vulnerability found in the PDF Parsing function of EnzoVezzaro's mcp-dominican-layer allows attackers to exploit a flaw in argument manipulation, specifically with the pdfUrl parameter. This enables unauthorized server-side request forgery (SSRF) attacks, which can be executed remotely. Despi...
Discovered 7 hours ago
PoC for CVE-2026-19751
A vulnerability exists in the EnzoVezzaro mcp-dominican-layer related to the axios.get function in the parse-csv tool's src/index.ts file. This flaw can lead to server-side request forgery, enabling attackers to manipulate CSV URLs and potentially gain unauthorized access to sensitive server reso...
PoC for CVE-2026-19750
A security flaw has been identified in Tenda CH, CP, and TX3 product lines, specifically affecting the SSH component, which utilizes hard-coded passwords. This vulnerability can potentially allow unauthorized remote access to affected devices, enabling attackers to exploit the known credential we...
Discovered 8 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 10 hours ago
PoC for CVE-2026-73482
A CSRF vulnerability exists in phpList versions prior to 3.7.0-RC5, specifically affecting the lists/admin/admins.php file. This vulnerability allows an attacker to exploit the admin deletion functionality without needing authentication. Through maliciously crafted links, an attacker can trick a ...
PoC for CVE-2026-73481
The affected versions of phpList fail to adequately enforce CSRF token validation on the bounce rule deletion endpoint. Specifically, the vulnerability allows an attacker to delete arbitrary bounce rules from the database by tricking an authenticated administrator into triggering a crafted GET re...
PoC for CVE-2026-72777
Next AI Draw.io prior to version 0.4.16 is susceptible to a server-side request forgery vulnerability within its POST /api/parse-url endpoint. The flaw arises from insufficient hostname validation, which relies on pattern matching instead of DNS resolution. This vulnerability allows unauthenticat...
PoC for CVE-2026-73037
Next AI Draw.io versions 0.2.1 through 0.4.16 are susceptible to a reflected cross-site scripting (XSS) flaw stemming from the mcp query parameter not being properly sanitized. This allows attackers to construct malicious URLs that, when accessed, can execute arbitrary JavaScript code in the cont...
PoC for CVE-2026-72741
The Rainbond platform, through version 6.9.7, is susceptible to a broken access control vulnerability within its CheckToken function. This flaw permits authenticated attackers to exploit the system by modifying the tenant name within URL paths to access unauthorized enterprise resources. By lever...
Discovered 11 hours ago
PoC for CVE-2019-25765
ASP-CMS is vulnerable to SQL injection through the commentList.asp endpoint. Malicious actors can manipulate the 'id' parameter in GET requests, allowing them to inject arbitrary SQL code. This vulnerability enables attackers to bypass the application's keyword blocklist by embedding the string '...
PoC for CVE-2024-58374
The Hongjing e-HR application is exposed to an unauthenticated SQL injection vulnerability within the getSdutyTree servlet endpoint. By using a path traversal sequence in the request URI, malicious actors can bypass the oauthservlet authentication filter, allowing them to submit UNION-based SQL q...
Discovered 13 hours ago
PoC for CVE-2026-73515
PostGIS, a widely used geospatial database extender, has an out-of-bounds read vulnerability that occurs when a malformed FlatGeobuf buffer is processed. The vulnerability allows attackers to exploit the weakness in the property metadata decoder, which verifies the existence of a string length fi...
PoC for CVE-2026-19710
A remote SQL injection vulnerability has been identified in the Simple Student Information System developed by SourceCodester. This flaw resides in the 'view_department.php' file, where manipulation of the argument ID can lead to unauthorized access to sensitive database information. This exploit...
Discovered 18 hours ago
PoC for CVE-2026-66804
An improper access control vulnerability in the Windows Cross Device Service allows an attacker with authorized access to elevate their privileges locally. This can lead to unauthorized actions within the system, compromising the integrity and security of users' environments. Microsoft has releas...
PoC for CVE-2026-68820
A use after free vulnerability exists in the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to exploit the driver and potentially elevate privileges locally, threatening the integrity of the operating system. To mitigate risk, it is essential to apply the ...
Discovered 20 hours ago
PoC for CVE-2026-24031
An authentication bypass vulnerability exists in Dovecot SQL authentication, where an administrator can inadvertently disable the 'auth_username_chars' configuration. This misconfiguration allows attackers to bypass authentication checks, potentially enabling unauthorized access and user enumerat...
PoC for CVE-2026-15413
The Link Factory plugin for WordPress is compromised by a backdoor that enables unauthorized access via an operator-controlled REST API endpoint located at /wp-json/link-factory/v1/. This backdoor is authenticated using a detached Ed25519 signature, which is verified against a hardcoded public ke...
PoC for CVE-2026-14332
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress prior to version 7.0.9 is susceptible to an access control vulnerability. It lacks proper capability checks and nonce verification for specific store-management actions, potentially allowing any authenticated user, including sub...
Discovered 22 hours ago
PoC for CVE-2026-54984
A heap-based buffer overflow vulnerability exists in the Windows Imaging Component, which could allow an unauthorized attacker to execute arbitrary code locally. This flaw can be exploited by malicious actors to manipulate memory allocation and potentially gain unauthorized access to system resou...
PoC for CVE-2026-18945
The WP Helper Premium plugin for WordPress is susceptible to a vulnerability that allows unauthenticated users to access sensitive order details. Specifically, versions prior to 4.7.6 fail to verify order keys when rendering custom order confirmation pages or processing related AJAX actions. This...
PoC for CVE-2026-14213
A significant access control vulnerability exists in the Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.6. This flaw allows any authenticated employee to retrieve information about appointments without proper authorization, potentially exposing sensitive cu...
PoC for CVE-2026-19088
The ShopEngine Elementor WooCommerce Builder Addon for WordPress lacks adequate protection for its authentication endpoints, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. An attacker can exploit this vulnerability to trick a victim into authenticating to an attacker-controll...
PoC for CVE-2026-13610
The KiviCare WordPress plugin prior to version 4.5.2 is vulnerable due to a lack of restrictions on role assignments via its unauthenticated registration endpoint. This flaw enables attackers to create active, privileged accounts, such as clinic staff (doctors), granting them full access to sensi...
PoC for CVE-2026-14182
The Customer Email Verification for WooCommerce plugin prior to version 3.2.6 exhibits a vulnerability allowing unauthenticated users to bypass email verification mechanisms. This occurs due to inadequate validation of the email-verification activation code, which can be exploited by an attacker ...
PoC for CVE-2026-13328
The Food Menu plugin for WordPress prior to version 6.0.2 has a significant vulnerability that allows unauthenticated users to modify reservation statuses. This issue arises from the lack of proper capability and ownership checks in the reservation-status update action. The action is accessible t...
Discovered 1 day ago
PoC for CVE-2026-39987
Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...
PoC for CVE-2020-8597
The vulnerability in the PPP Daemon (pppd) versions 2.4.2 through 2.4.8 is a buffer overflow issue found in the eap_request and eap_response functions. This flaw can potentially allow an unauthorized attacker to exploit the overflow, leading to arbitrary code execution or causing the application ...
PoC for CVE-2026-68398
The vulnerability within the Linux kernel occurs in the pppol2tp_recv() function, which fails to properly manage memory deallocation in a multi-threaded environment. This oversight allows an unprivileged user to potentially exploit the system by dereferencing a channel that has already been freed...
PoC for CVE-2026-59827
Metabase, an open-source business intelligence and embedded analytics tool, suffers from a deserialization vulnerability in versions prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4. When configured with an H2 database connection, including the default sample database, this flaw permits authenti...
PoC for CVE-2026-28956
This vulnerability involves a memory corruption issue that arises when processing specially crafted media files, which can lead to unintended app termination or memory corruption in affected Apple devices. Apple has addressed this flaw with enhanced input validation in the latest versions of thei...
PoC for CVE-2026-23111
A vulnerability exists in the Linux kernel's netfilter module that affects the nft_map_catchall_activate() function. This function encounters an inverted element activity check, leading to a failure in appropriately handling catchall map elements during a failed transaction. The bug arises when t...