Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-6874

Ericc-chCopilot-api5.3MEDIUM
DNS Rebinding Vulnerability in Ericc-ch Copilot-API up to Version 0...

A vulnerability exists in the Ericc-ch Copilot-API up to version 0.7.0, which affects the Header Handler component in the /token file. This issue allows an attacker to manipulate the Host argument, which may result in unintended reliance on reverse DNS resolution. Such an exploit can be executed ...

Discovered 4 hours ago

PoC for CVE-2026-40517

RadareorgRadare28.4HIGH
Command Injection in Radare2 PDB Parser Affecting Radare2 Software

Radare2 versions prior to 6.1.4 are susceptible to a command injection flaw within the PDB parser’s print_gvars() function. This vulnerability arises when an attacker crafts a malicious PDB file that incorporates newline characters within the symbol names. Through this manipulation, arbitrary com...

Discovered 5 hours ago

PoC for CVE-2017-0144

MicrosoftWindows Smb🟣 EPSS 94%8.8HIGH
Remote Code Execution Vulnerability in Microsoft Windows SMBv1

The SMBv1 protocol in various Microsoft Windows operating systems contains a vulnerability that enables remote attackers to execute arbitrary code by sending specially crafted packets to the server. This issue affects multiple versions of Windows, including desktop and server editions, allowing e...

Discovered 7 hours ago

PoC for CVE-2019-15107

WebminWebmin🟣 EPSS 94%9.8CRITICAL
Command Injection Vulnerability in Webmin by Guildford Software

Webmin versions up to 1.920 are susceptible to a command injection vulnerability through the 'old' parameter in the password_change.cgi script. An unauthenticated attacker can exploit this flaw to execute arbitrary commands on the server. This may lead to unauthorized access or further compromise...

Discovered 8 hours ago

PoC for CVE-2026-41469

BeghelliSicuroweb (sicuro24)5.1MEDIUM
Content Security Policy Bypass in Beghelli Sicuro24 SicuroWeb

The Beghelli Sicuro24 SicuroWeb application lacks a robust Content Security Policy (CSP), which exposes it to significant security risks. This failure allows attackers to load unauthorized external JavaScript resources, potentially leading to the execution of arbitrary remote payloads. When combi...

PoC for CVE-2026-41469

BeghelliSicuroweb (sicuro24)5.1MEDIUM
Content Security Policy Bypass in Beghelli Sicuro24 SicuroWeb

The Beghelli Sicuro24 SicuroWeb application lacks a robust Content Security Policy (CSP), which exposes it to significant security risks. This failure allows attackers to load unauthorized external JavaScript resources, potentially leading to the execution of arbitrary remote payloads. When combi...

Discovered 9 hours ago

PoC for CVE-2019-2215

GoogleAndroid🟣 EPSS 51%7.8HIGH
Use-After-Free Vulnerability in Android Binder Leading to Elevation...

A use-after-free vulnerability exists in the Android Binder service, which could allow attackers to elevate privileges from an application to the Linux Kernel. Exploitation of this vulnerability does not require any interaction from the user; however, it necessitates either the installation of a ...

Discovered 11 hours ago

PoC for CVE-2024-58344

94cbCarbon Forum5.1MEDIUM
Persistent Cross-Site Scripting in Carbon Forum 5.9.0 by Carbon Forum

Carbon Forum version 5.9.0 is susceptible to a persistent cross-site scripting vulnerability. This flaw enables authenticated administrators to insert malicious JavaScript code via the Forum Name field within the dashboard settings. When the malicious script is stored, it can be executed in the b...

PoC for CVE-2018-25272

ElbaElba59.3CRITICAL
Remote Code Execution Vulnerability in ELBA5 by ELBA

The ELBA5 version 5.8.0 contains a significant vulnerability that enables remote code execution through improper database access. Attackers can leverage default connector credentials to connect to the database, potentially retrieving sensitive information, such as database administrator passwords...

PoC for CVE-2018-25271

TextpadTextpad6.9MEDIUM
Denial of Service in TextPad 8.1.2 by Long Buffer Input

TextPad 8.1.2 contains a denial of service vulnerability that enables local attackers to crash the application by providing an overly long buffer string via the Run command interface. By submitting a 5000-byte payload into the Command field through Tools > Run, the application is susceptible to a...

PoC for CVE-2018-25270

ThinkPHPThinkPHP9.3CRITICAL
Remote Code Execution Vulnerability in ThinkPHP 5.0.23 by TopThink

ThinkPHP 5.0.23 has a vulnerability that allows unauthorized attackers to execute arbitrary PHP code remotely. This occurs through the manipulation of the routing parameters, where attackers can craft specific requests targeting the index.php endpoint. By supplying malicious function parameters, ...

PoC for CVE-2018-25269

IcewarpIcewarp Client5.1MEDIUM
Cross-Site Scripting Vulnerability in ICEWARP Email Client

ICEWARP version 11.0.0.0 is susceptible to a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious HTML content into emails. By utilizing base64-encoded payloads embedded in object and embed tags, attackers can craft emails containing data URIs that execute embedded s...

PoC for CVE-2018-25268

LizardsystemsLanspy8.6HIGH
Local Buffer Overflow in LanSpy 2.0.1.159 by Lizard Systems

LanSpy version 2.0.1.159 is susceptible to a local buffer overflow vulnerability. This issue arises when attackers provide oversized input to the scan field, allowing them to overwrite the instruction pointer. By crafting a specific payload composed of 688 bytes of padding followed by 4 bytes of ...

PoC for CVE-2018-25267

UltraisoUltraiso6.9MEDIUM
Local Buffer Overflow in UltraISO by UltraISO Development Team

UltraISO 9.7.1.3519 is prone to a local buffer overflow vulnerability within the Output FileName field of the Make CD/DVD Image dialog. This flaw can be exploited by attackers who craft a malicious filename string containing 304 bytes of data followed by specially constructed SEH record overwrite...

PoC for CVE-2018-25266

AngryipAngry Ip Scanner6.9MEDIUM
Buffer Overflow Vulnerability in Angry IP Scanner by Angry IP

Angry IP Scanner version 3.5.3 is susceptible to a buffer overflow vulnerability within its preferences dialog. This flaw enables local attackers to induce a denial of service by submitting an oversized string. The vulnerability can be exploited by creating a file filled with repeating characters...

PoC for CVE-2018-25265

LizardsystemsLanspy8.6HIGH
Local Buffer Overflow Vulnerability in LanSpy by Lizard Systems

LanSpy 2.0.1.159 has a local buffer overflow vulnerability in the scanning functionality that enables local attackers to execute arbitrary code. This is achieved through exploitation of the structured exception handling (SEH) mechanisms, allowing attackers to craft malicious payloads utilizing eg...

PoC for CVE-2018-25262

AngryipAngry Ip Scanner For L...6.9MEDIUM
Denial of Service Vulnerability in Angry IP Scanner for Linux

Angry IP Scanner for Linux version 3.5.3 has a denial of service vulnerability that can be exploited by local attackers. By inputting a specially crafted malicious string into the port selection field within the application, an attacker can trigger a buffer overflow, leading to an unexpected appl...

PoC for CVE-2018-25261

IperiusbackupIperius Backup8.6HIGH
Local Buffer Overflow in Iperius Backup by Iperius

Iperius Backup 5.8.1 features a local buffer overflow vulnerability in its structured exception handling (SEH) mechanism. This vulnerability allows local attackers to execute arbitrary code by providing a manipulated file path. By crafting a specific payload in the external file location field wh...

PoC for CVE-2018-25259

LizardsystemsTerminal Services Manager8.6HIGH
Stack-Based Buffer Overflow in Terminal Services Manager by LizardS...

Terminal Services Manager 3.1 has a stack-based buffer overflow vulnerability in the computer names field, which can be exploited by local attackers. By crafting a specially formatted input file containing shellcode and jump instructions, attackers can overwrite the structured exception handler (...

PoC for CVE-2018-25260

MagixMagix Music Editor8.6HIGH
Buffer Overflow Vulnerability in MAGIX Music Editor by MAGIX

MAGIX Music Editor 3.1 is susceptible to a buffer overflow vulnerability in its FreeDB Proxy Options dialog. This vulnerability allows local attackers to execute arbitrary code through misuse of structured exception handling. By crafting a malicious payload and entering it into the Server field v...

Discovered 16 hours ago

PoC for CVE-2026-25604

ApacheApache Airflow Provide...5.4MEDIUM
SAML Authentication Bypass in AWS Auth Manager by Apache

A vulnerability exists in AWS Auth Manager where the SAML authentication origin is utilized as provided by the client, without verification against the actual instance URL. This flaw potentially allows unauthorized access to different instances that may enforce diverse access controls, as attacke...

Discovered 19 hours ago

PoC for CVE-2026-39808

FortinetFortisandbox9.1CRITICAL
OS Command Injection Vulnerability in Fortinet FortiSandbox

An OS command injection vulnerability exists in Fortinet FortiSandbox versions 4.4.0 through 4.4.8. This flaw arises from improper neutralization of special elements used in operating system commands. An attacker can exploit this vulnerability to execute unauthorized commands, potentially comprom...

Discovered 1 day ago

PoC for CVE-2026-6799

ComfastCf-n1-s5.3MEDIUM
Command Injection Vulnerability in Comfast CF-N1-S Device

A security flaw has been identified in the Comfast CF-N1-S 2.6.0.1 involving the file /cgi-bin/mbox-config?method=SET&section=ping_config. This vulnerability allows an attacker to manipulate the argument 'destination', resulting in command injection. The exploit can be executed remotely, posing a...

PoC for CVE-2024-2997

BdtaskMulti-store Inventory ...5.4MEDIUM
Bdtask Multi-Store Inventory Management System Vulnerable to Cross-...

The first article discusses a vulnerability in the Bdtask Multi-Store Inventory Management System, which is susceptible to cross-site scripting. The vulnerability allows for remote attack through manipulation of certain arguments. The vendor has not responded to the disclosure, and the exploit ha...

PoC for CVE-2026-6745

BagistoBagisto5.1MEDIUM
Cross Site Scripting Vulnerability in Bagisto by Bagisto

A vulnerability exists in the Custom Scripts Handler component of Bagisto, affecting versions up to 2.3.15. This flaw allows for cross site scripting, enabling remote attackers to execute unauthorized scripts in the context of a user’s session. The issue has been publicly disclosed, and exploitat...

PoC for CVE-2026-41456

BluditBludit5.1MEDIUM
Reflected Cross-Site Scripting in Bludit CMS Search Plugin

A reflected cross-site scripting vulnerability exists in the search plugin of Bludit CMS prior to the commit 6732dde. This issue allows unauthenticated attackers to craft malicious search queries that inject arbitrary JavaScript. When users visit impacted URLs, these scripts can be executed in th...

PoC for CVE-2026-6744

BagistoBagisto5.3MEDIUM
Server-Side Request Forgery in Bagisto Downloadable Link Handler

A security issue has been identified in Bagisto, specifically affecting the Downloadable Link Handler component. This vulnerability allows an attacker to perform server-side request forgery (SSRF) attacks, which can be exploited remotely. The flaw allows malicious users to send crafted requests t...

PoC for CVE-2026-6743

WebsystemsWebtotum5.1MEDIUM
Cross Site Scripting Vulnerability in WebSystems WebTOTUM 2026 Cale...

A cross site scripting vulnerability was identified in the Calendar component of WebSystems WebTOTUM 2026. This issue allows attackers to execute malicious scripts in the context of the user's session, potentially leading to data theft or session hijacking. The attack can be initiated remotely, m...

PoC for CVE-2019-25714

Seeyon Internet S...A8-v5 Collaborative Ma...9.3CRITICAL
Unauthenticated Arbitrary File Write Vulnerability in Seeyon OA A8

Seeyon OA A8 is vulnerable to an unauthenticated arbitrary file write issue within the /seeyon/htmlofficeservlet endpoint. This vulnerability allows remote attackers to send specially crafted POST requests containing base64-encoded payloads, enabling them to write arbitrary files to the web appli...

PoC for CVE-2019-25714

Seeyon Internet S...A8-v5 Collaborative Ma...9.3CRITICAL
Unauthenticated Arbitrary File Write Vulnerability in Seeyon OA A8

Seeyon OA A8 is vulnerable to an unauthenticated arbitrary file write issue within the /seeyon/htmlofficeservlet endpoint. This vulnerability allows remote attackers to send specially crafted POST requests containing base64-encoded payloads, enabling them to write arbitrary files to the web appli...

Discovered 2 days ago

PoC for CVE-2026-2600

WordPressElementskit Elementor ...6.4MEDIUM
Stored Cross-Site Scripting in ElementsKit Elementor Addons for Wor...

The ElementsKit Elementor Addons and Templates plugin for WordPress is susceptible to a stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping on the 'ekit_tab_title' parameter within the Simple Tab widget. Authenticated users with contributor-level a...

PoC for CVE-2025-68999

WordPressHappy Addons For Eleme...8.5HIGH
SQL Injection Vulnerability in Happy Addons for Elementor by HappyM...

A significant SQL injection vulnerability exists in the Happy Addons for Elementor plugin developed by HappyMonster. This flaw enables attackers to potentially execute unauthorized SQL commands by exploiting improper neutralization of special elements in SQL queries. Affected versions include all...

PoC for CVE-2026-6662

Ericc-chCopilot-api6.9MEDIUM
Cross-Domain Policy Vulnerability in ericc-ch copilot-api by ericc-ch

A vulnerability in the ericc-ch copilot-api prior to version 0.7.0 affects the CORS function in the Token Endpoint, found in the src/server.ts file. This flaw allows for a permissive cross-domain policy that can be exploited by untrusted domains, enabling remote attacks. Attackers can manipulate ...

PoC for CVE-2025-32711

MicrosoftMicrosoft 365 Copilot9.3CRITICAL
Information Disclosure Vulnerability in Microsoft 365 Copilot

The M365 Copilot product from Microsoft is susceptible to an information disclosure vulnerability that permits unauthorized attackers to disclose sensitive information over a network. This defect stems from a command injection flaw within the AI functionalities of M365 Copilot, emphasizing the ne...

PoC for CVE-2026-6650

Z-BlogZ-blogPHP5.1MEDIUM
Unrestricted File Upload Vulnerability in Z-BlogPHP 1.7.5

A vulnerability has been identified in Z-BlogPHP version 1.7.5, specifically in the App::UnPack function within the app_upload.php file of the ZBA File Handler component. This flaw permits an attacker to upload files without any restriction, which can lead to serious security breaches. The vulner...

Discovered 3 days ago

PoC for CVE-2026-34429

GivanzVvveb5.1MEDIUM
Stored Cross-Site Scripting Vulnerability in Vvveb by Givanz

The Vvveb product prior to version 1.0.8.1 contains a stored cross-site scripting vulnerability. This issue allows authenticated users with media upload and rename permissions to exploit the application by executing arbitrary JavaScript. The vulnerability arises from the ability to bypass MIME ty...

PoC for CVE-2026-6649

QiboCms5.3MEDIUM
Server-Side Request Forgery Vulnerability in Qibo CMS by Guangzhou ...

A vulnerability exists in Qibo CMS 1.0 that enables an attacker to exploit the system through manipulated arguments to the /index/image/headers file. This can lead to server-side request forgery, allowing unauthorized remote access to internal services not intended for exposure. The vulnerability...

PoC for CVE-2026-6648

QiboCms5.1MEDIUM
Cross-Site Scripting Vulnerability in Qibo CMS from Guangzhou Qibo ...

A security vulnerability has been discovered in the Internal Message Module of Qibo CMS 1.0, which allows for potential cross-site scripting (XSS) attacks. This vulnerability enables remote attackers to execute arbitrary scripts in the context of a user's session. The exploit has been publicly di...

PoC for CVE-2026-6636

P2r3Convert5.3MEDIUM
Path Traversal Vulnerability in p2r3 Convert API by Vendor

A path traversal vulnerability has been identified in the p2r3 Convert API, specifically within the Bun.serve function of the buildCache.js file. This vulnerability is triggered by manipulating the pathname argument, allowing attackers to exploit the system remotely. The exploit has been made pub...

PoC for CVE-2026-6635

RowboatlabsRowboat6.9MEDIUM
Improper Authentication Vulnerability in Rowboat Labs Rowboat Tool

A vulnerability has been identified in Rowboat Labs' Rowboat, specifically in the tools_webhook component. The issue lies within the tool_call function in the apps/experimental/tools_webhook/app.py file, where manipulation of the X-Tools-JWE argument can lead to improper authentication. This coul...

PoC for CVE-2015-5254

RedhatOpenshift🟣 EPSS 80%9.8CRITICAL
Unsafe Deserialization in Apache ActiveMQ by The Apache Software Fo...

Apache ActiveMQ versions prior to 5.13.0 contain a vulnerability that permits remote attackers to execute arbitrary code. This occurs due to inadequate restrictions on the classes that may be serialized within the broker, specifically through a crafted serialized Java Message Service (JMS) Object...

PoC for CVE-2026-6634

UsememosMemos5.3MEDIUM
Improper Authorization in Usememos Memos by UseMemos

A vulnerability exists in Usememos Memos versions up to 0.22.1 due to improper authorization in the memos_access_token function located in the UpdateInstanceSetting component (src/App.tsx). This weakness allows attackers to manipulate arguments such as additionalStyle and additionalScript, enabli...

PoC for CVE-2026-6633

YifangCms5.1MEDIUM
Cross Site Scripting Vulnerability in Yifang CMS by Yifang

A security issue has been identified in Yifang CMS versions up to 2.0.5, specifically within the Extended Management Module. This vulnerability resides in the 'store' function found in 'plugins/yifang_backend_account/logic/admin/L_rbac_admin.php'. Attackers can exploit this flaw to execute cross-...

PoC for CVE-2026-6632

TendaF4518.7HIGH
Buffer Overflow Vulnerability in Tenda F451 by Tenda

A vulnerability exists in the Tenda F451 router affecting the SafeClientFilter functionality. Specifically, the fromSafeClientFilter function located in /goform/SafeClientFilter is susceptible to a buffer overflow due to improper handling of the 'menufacturer/Go' argument. This vulnerability perm...

PoC for CVE-2026-6631

TendaF4518.7HIGH
Buffer Overflow Vulnerability in Tenda F451 Router

A buffer overflow vulnerability exists in the Tenda F451 Router, specifically in the httpd component's fromwebExcptypemanFilter function. This vulnerability arises from improper handling of the 'page' argument, allowing attackers to manipulate it and potentially execute arbitrary code. The exploi...

PoC for CVE-2026-6630

TendaF4518.7HIGH
Buffer Overflow Vulnerability in Tenda F451 Router

A buffer overflow vulnerability exists in the Tenda F451 router due to improper handling of the 'dips' argument in the fromGstDhcpSetSer function within the httpd component. Attackers can exploit this vulnerability remotely, which may lead to unauthorized access and manipulation of the affected r...

PoC for CVE-2026-6629

Metasoft 美特软件Metacrm6.9MEDIUM
SQL Injection Vulnerability in Metasoft 美特软件 MetaCRM Interface Comp...

A SQL injection vulnerability exists in the Metasoft 美特软件 MetaCRM within the function Statement.executeUpdate in sql.jsp. This issue allows attackers to manipulate SQL commands through the application, potentially leading to unauthorized access to sensitive data. The flaw can be exploited remotel...

PoC for CVE-2026-6628

Phili67Ecclesia Crm5.3MEDIUM
SQL Injection Vulnerability in phili67 Ecclesia CRM by phili67

A security flaw exists in phili67 Ecclesia CRM versions up to 8.0.0, impacting the ValidateInput function located in the /v2/query/view/ path of the Query Viewer Component. By manipulating the 'custom' parameter, an attacker can exploit this vulnerability to execute SQL injection attacks. This ex...

PoC for CVE-2026-6626

Cockpit-hqCockpit5.3MEDIUM
Data Query Logic Injection Vulnerability in Cockpit-HQ Cockpit by C...

A significant vulnerability has been identified in Cockpit-HQ Cockpit versions up to 2.13.5, specifically within the Asset Handler and Aggregate Handler components. This flaw involves improper neutralization within data query logic, which could potentially be exploited by remote attackers. Despit...

PoC for CVE-2026-6625

Moxi624Mogu Blog V26.9MEDIUM
Server-Side Request Forgery in Mogu Blog from Moxi624

A vulnerability has been identified in Mogu Blog v2 up to version 5.2, specifically in the LocalFileServiceImpl.uploadPictureByUrl function. This flaw allows attackers to exploit the Picture Storage Service, potentially initiating a server-side request forgery (SSRF) attack remotely. The nature o...