Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-19500

SureformsSureforms7.5HIGH
Server Resource Exhaustion in Brainstorm Force SureForms

The Entries component in Brainstorm Force SureForms versions prior to 2.1.3 lacks sufficient validation on user-controlled form fields. This vulnerability permits remote attackers to exploit the system by crafting malicious form submissions that can deplete server resources. Such an attack may im...

PoC for CVE-2026-19501

SureformsSureforms
CSV Export Vulnerability in Brainstorm Force SureForms Product

The SureForms product by Brainstorm Force contains a vulnerability in its CSV export functionality, present in versions 2.1.1 and earlier. The flaw arises from the failure to sanitize user-controlled form field names, which can include spreadsheet formula characters. This oversight allows a remot...

Discovered 23 minutes ago

PoC for CVE-2026-44578

VercelNext.js🟣 EPSS 39%8.6HIGH
Server-Side Request Forgery Vulnerability in Next.js Framework by V...

The Next.js framework, utilized for building web applications, is exposed to a server-side request forgery vulnerability when using versions from 13.4.13 up to but not including 15.5.16 and 16.2.5. This flaw arises when self-hosted applications that employ the built-in Node.js server allow attack...

Discovered 2 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 3 hours ago

PoC for CVE-2015-1805

GoogleAndroid
Linux Kernel I/O Vector Vulnerability in Pipe Implementations by Re...

The Linux kernel prior to version 3.16 contains vulnerabilities within the pipe_read and pipe_write functions that improperly handle failures in memory copy operations. This oversight may result in a denial of service by causing system crashes or may potentially allow attackers to exploit the vul...

Discovered 4 hours ago

PoC for CVE-2026-75877

TrendnetTv-ip751wic9.4CRITICAL
Stack-Based Buffer Overflow in TRENDnet TV-IP751WIC by TRENDnet

A serious flaw has been identified in the TRENDnet TV-IP751WIC surveillance camera, specifically within its alphapd component. The vulnerability allows for stack-based buffer overflows via functions such as SystemNetworkChanged, SystemDDNSChanged, SystemEmailChanged, SystemFTPChanged, websCheckRe...

Discovered 5 hours ago

PoC for CVE-2026-75876

XianrendzwEasyreport5.3MEDIUM
SQL Injection Vulnerability in xianrendzw EasyReport Software

A security flaw has been identified in xianrendzw EasyReport, specifically within the Move Operations component in the ModuleController.java file. This vulnerability allows attackers to manipulate the sourcePath argument, making the application susceptible to SQL injection attacks. Exploits can b...

Discovered 6 hours ago

PoC for CVE-2026-75130

UptashContext76.4MEDIUM
Prompt Injection Vulnerability in Context7 by Noma Security

The vulnerability in Context7, specifically version 2.1.2, allows attackers to perform prompt injection through the Custom AI Instructions feature. By injecting unsanitized content via the MCP server, adversaries can manipulate AI coding agents to execute harmful instructions. This exploitation e...

Discovered 8 hours ago

PoC for CVE-2026-19478

GitlabGitlab9.4CRITICAL
Remote Code Modification Vulnerability in GitLab CE/EE

A flaw in GitLab CE/EE allows unauthenticated users to exploit specific GraphQL directives, potentially resulting in unauthorized modification or deletion of public projects and user data. This vulnerability impacts various versions, necessitating immediate user awareness and prompt application o...

PoC for CVE-2026-69414

MicrosoftMicrosoft Malware Prot...7.8HIGH
Elevation of Privilege Vulnerability in Microsoft Malware Protectio...

A significant vulnerability has been identified within the Microsoft Malware Protection Engine used in Microsoft Defender, allowing for elevation of privilege. This may potentially enable attackers to gain elevated privileges on affected systems. Microsoft is actively working on a security update...

Discovered 9 hours ago

PoC for CVE-2022-38694

Unisoc (shanghai)...Sc9863a//t310/t610/t618/7.8HIGH
Uncontrolled Write Vulnerability in UNISOC BootRom Product

The vulnerability occurring in UNISOC's BootRom allows a possible unchecked write address, enabling local escalation of privilege without requiring additional execution privileges. This flaw poses a significant security risk, as it can be exploited by malicious actors to gain unauthorized access ...

Discovered 10 hours ago

PoC for CVE-2026-75784

TrendnetTew-wlc10010CRITICAL
Stack-Based Buffer Overflow in TRENDnet TEW-WLC100 HTTP Header Func...

A significant vulnerability was identified in the TRENDnet TEW-WLC100, specifically in the HTTP Header Handler component. The issue arises from the improper handling of the 'Server' argument within the FUN_0040da4c function located at /usr/nginx/sbin/nginx, leading to a stack-based buffer overflo...

Discovered 11 hours ago

PoC for CVE-2026-75783

TrendnetTew-wlc100p9.4CRITICAL
Buffer Overflow Vulnerability in TRENDnet TEW-WLC100P Router

A security vulnerability has been identified in the TRENDnet TEW-WLC100P router, specifically within the DHCP blobmsg handler associated with the netifd file. This issue can lead to a stack-based buffer overflow, requiring the attacker to be present on the local network to execute the exploit. Pu...

Discovered 12 hours ago

PoC for CVE-2026-75778

Code-projectsTask Management System6.9MEDIUM
SQL Injection Vulnerability in code-projects Task Management System...

A security flaw has been discovered in the code-projects Task Management System 1.0. The vulnerability resides in the Operation::select_with_multiple_condition function located in the /index.php file of the Login Form component. By manipulating the email argument, an attacker can exploit this fla...

Discovered 13 hours ago

PoC for CVE-2026-75774

Karakeep-appKarakeep6.3MEDIUM
Improper Authentication Vulnerability in karakeep App by karakeep

The karakeep app, specifically its OAuth Sign-In component, is affected by a vulnerability that allows for improper authentication. This flaw resides in an unspecified function within the 'apps/web/server/auth.ts' file and permits remote attacks. While executing this exploit may require a higher ...

PoC for CVE-2026-75773

Karakeep-appKarakeep6.3MEDIUM
Excessive Authentication Attempts Vulnerability in Karakeep-App by ...

A vulnerability exists in the Login Endpoint of the Karakeep application that allows for improper restriction of excessive authentication attempts. This flaw arises from the function 'authorize' in the auth.ts file, which could potentially be exploited remotely. Although the exploitation is chara...

PoC for CVE-2026-65400

AppleMac OS9.8CRITICAL
Authentication Vulnerability in macOS Products by Apple

An authentication flaw has been identified in macOS products, potentially allowing an attacker on the same network to gain unauthorized access to Screen Sharing services without presenting valid credentials. This vulnerability impacts versions such as macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, an...

Discovered 14 hours ago

PoC for CVE-2024-14046

OpenBoxesOpenboxes5.3MEDIUM
Unrestricted Upload Vulnerability in OpenBoxes Document Upload Cont...

A security vulnerability has been identified in OpenBoxes, affecting versions up to 0.9.1, specifically in the Document Upload Controller component. This flaw allows for unrestricted file uploads, which can be exploited remotely. An attacker may leverage this weakness to upload malicious files to...

Discovered 15 hours ago

PoC for CVE-2024-14045

OpenBoxesOpenboxes5.3MEDIUM
Improper Authorization Vulnerability in OpenBoxes Product Supplier ...

A vulnerability has been discovered in OpenBoxes prior to version 0.9.3, specifically within the Product Supplier Edit Controller's RoleInterceptor.groovy file. This issue can result in improper authorization, allowing unauthorized access or manipulation from remote attackers. The exploit has bee...

PoC for CVE-2026-19650

GitlabGitlab7.1HIGH
Unauthorized Access Vulnerability in GitLab Products

A vulnerability in GitLab CE/EE versions prior to specific patch releases allows unauthorized users to execute mutations through GET requests due to flawed request validation mechanisms within the GraphQL multiplex query handling process. This could potentially lead to unauthorized data manipulat...

Discovered 16 hours ago

PoC for CVE-2026-15826

WordPressUser Profile Builder –...9.8CRITICAL
Authentication Bypass Vulnerability in User Profile Builder Plugin ...

The User Profile Builder plugin for WordPress faces a significant vulnerability allowing unauthorized users to gain access to site administration. The flaw arises from the plugin's improper handling of user registration submissions with usernames that are 61–70 characters long. Specifically, the ...

Discovered 17 hours ago

PoC for CVE-2026-20217

CiscoCisco Secure Endpoint7.5HIGH
Memory Corruption Vulnerability in ClamAV's PESpin File Format Parser

A vulnerability exists within the PESpin file format parser of ClamAV, allowing an unauthenticated remote attacker to potentially cause a denial of service (DoS) condition. This issue arises from inadequate boundary checks for PESpin file content during the scanning process, which can lead to out...

PoC for CVE-2026-71518

TypemillTypemill8.7HIGH
Authorization Bypass in Typemill Media File Download Route by Typemill

An authorization bypass vulnerability exists in Typemill versions prior to 2.26.0, specifically affecting the media file download route. This flaw allows unauthorized users to access restricted files by submitting cleverly crafted path-equivalent URL variants. Attackers can exploit normalized pat...

Discovered 20 hours ago

PoC for CVE-2026-20079

CiscoCisco Secure Firewall ...🟣 EPSS 38%10CRITICAL
Authentication Bypass in Cisco Secure Firewall Management Center

A security flaw in the Cisco Secure Firewall Management Center's web interface may enable unauthenticated remote attackers to bypass authentication mechanisms. This enables the execution of arbitrary script files, potentially granting root access to the device’s operating system. The issue arises...

Discovered 22 hours ago

PoC for CVE-2026-6765

MozillaFirefox5.3MEDIUM
Information Disclosure in Firefox and Firefox ESR Products by Mozilla

This vulnerability involves an information disclosure flaw in the Form Autofill component of Firefox and Firefox ESR. When exploited, it can reveal sensitive user data. Mozilla has addressed this issue in versions 150 of Firefox and 140.10 of Firefox ESR, emphasizing the importance of updating to...

PoC for CVE-2026-74970

MozillaFirefox5.4MEDIUM
Site Isolation Flaw in Firefox Graphics Component

A site isolation vulnerability exists in the Graphics component of Mozilla Firefox, which could allow attackers to execute unauthorized actions across different sites. This issue has been addressed in Firefox version 154 and Firefox Extended Support Release (ESR) version 153.1, enhancing user sec...

PoC for CVE-2026-74945

MozillaFirefox
Information Disclosure in Firefox's Graphics: Text Component

A vulnerability within the Graphics: Text component of Firefox allows for unintended information disclosure. This issue could potentially expose sensitive data that should remain protected. Mozilla has addressed this vulnerability in various versions, ensuring enhanced security and privacy for us...

PoC for CVE-2026-74943

MozillaFirefox
Use-After-Free Vulnerability in Firefox ImageLib Component

A use-after-free vulnerability has been discovered in the Graphics: ImageLib component of Firefox. This issue may allow an attacker to cause a crash or potentially execute arbitrary code on the affected system. Mozilla has released updates addressing this vulnerability in Firefox version 154, and...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-75094

ComfastCf-n1-s9.4CRITICAL
OS Command Injection Flaw in COMFAST CF-N1-S 2.6.0.1

A security flaw exists in the COMFAST CF-N1-S 2.6.0.1 related to the CGI interface, specifically within the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid. This vulnerability allows an attacker to manipulate the 'ssid' argument, potentially leading to remote co...

Discovered 23 hours ago

PoC for CVE-2026-75093

SonosTract5.3MEDIUM
Buffer Size Calculation Vulnerability in Sonos Tract by Sonos

A vulnerability has been identified in Sonos Tract versions up to 0.23.4, specifically within the Tensor::from_raw_dt_align function in the ONNX Initializer Loader. This flaw allows for remote exploitation through manipulation resulting in incorrect buffer size calculations. The vulnerability has...

PoC for CVE-2026-75090

EriclbuehlerMistral.rs5.3MEDIUM
Out-of-Bounds Read Vulnerability in EricLBuehler Mistral.rs GGUF To...

A vulnerability in the GGUF Tokenizer component of EricLBuehler Mistral.rs, specifically in the convert_gguf_to_hf_tokenizer function, exposes systems to out-of-bounds reads due to improper handling of parameters like eos_token_id, bos_token_id, and unknown_token_id. This issue, impacting version...

PoC for CVE-2026-75089

PHPgurukulComplaint Management S...6.9MEDIUM
SQL Injection Vulnerability in PHPGurukul Complaint Management Syst...

A vulnerability exists in the PHPGurukul Complaint Management System 1.0, specifically within the user/check_availability.php file. This weakness enables an attacker to manipulate the email argument, leading to SQL injection attacks. Such remote exploitation is possible and poses a significant ri...

PoC for CVE-2026-75088

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability found in the itsourcecode Hospital Management System version 1.0 affects the handling of the delid argument in the /viewbilling.php file. This flaw allows for remote SQL injection, which can potentially lead to unauthorized access to the database, manipulation of data, or exposure...

Discovered 1 day ago

PoC for CVE-2026-75087

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability has been identified in the itsourcecode Hospital Management System version 1.0, specifically within the file /viewdepartment.php. This issue allows an attacker to manipulate the 'delid' parameter, resulting in SQL injection, which could enable remote exploitation. As the details o...

PoC for CVE-2026-75086

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A SQL Injection vulnerability exists in the itsourcecode Hospital Management System version 1.0, specifically within an unknown function in the /viewroom.php file. This weakness allows attackers to manipulate input parameters, leading to unauthorized access to the database. Given that the exploit...

PoC for CVE-2026-75082

WebkulBagisto5.3MEDIUM
Cross-Site Scripting Vulnerability in Webkul Bagisto Customer Regis...

A security flaw has been identified in Webkul Bagisto affecting versions up to 2.4.4. The vulnerability resides in the customer registration notification email component, particularly due to improper handling of input parameters 'first_name' and 'last_name'. This oversight enables attackers to ex...

PoC for CVE-2026-75081

WebkulBagisto5.3MEDIUM
Improper Input Validation in Webkul Bagisto Affects User Account Ma...

A vulnerability has been discovered in Webkul Bagisto that allows remote manipulation of specific arguments within the /customer/account/rma/store endpoint. This issue may lead to the enforcement of unintended behavioral workflows. The vendor has acknowledged that these problems were previously i...

PoC for CVE-2025-21479

QualcommSnapdragon8.6HIGH
Memory Corruption Vulnerability in Qualcomm GPU Micronode

This vulnerability allows unauthorized command execution in the GPU micronode, leading to potential memory corruption when a specific sequence of commands is executed. Attackers could exploit this weakness to disrupt system functionality or gain access to sensitive areas of memory, posing risks t...

PoC for CVE-2026-75080

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A security vulnerability exists in the SourceCodester Class and Exam Timetabling System 1.0, specifically affecting the /edit_subject1.php file. An attacker can exploit this vulnerability by manipulating the ID parameter, leading to unauthorized SQL command execution. This remote attack vector ca...

PoC for CVE-2026-75079

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A vulnerability exists in the SourceCodester Class and Exam Timetabling System version 1.0, specifically in the /edit_subject2.php file. This weakness allows for SQL injection attacks through manipulation of the 'ID' argument. The exploit can be executed remotely, exposing users to potential unau...

PoC for CVE-2026-75078

SourcecodesterClass And Exam Timetab...5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Class and Exam...

A security flaw has been identified in the SourceCodester Class and Exam Timetabling System version 1.0 located in the /BSHRM1.php file. This vulnerability allows for cross-site scripting (XSS) via manipulation of the course argument, which can lead to remote exploitation by attackers. The detail...

PoC for CVE-2026-56852

Golang.org/x/textGolang.org/x/text/unic...7.5HIGH
Infinite Loop Vulnerability in Go Language's norm.Iter Handling Inv...

A vulnerability exists in the Go language's norm.Iter component where it fails to properly handle input containing invalid UTF-8 byte sequences. This oversight allows an attacker to exploit the input handling mechanism, potentially causing the system to enter an infinite loop. Such behavior can l...

PoC for CVE-2026-75077

SourcecodesterClass And Exam Timetab...5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Class and Exam...

A vulnerability exists in the SourceCodester Class and Exam Timetabling System 1.0 that allows attackers to execute cross-site scripting (XSS) via manipulation of parameters in the file /BSCE2.php. This security flaw may be exploited remotely, allowing an attacker to inject malicious scripts into...

PoC for CVE-2026-41042

ApacheApache Gravitino9.1CRITICAL
Code Execution Vulnerability in Apache Gravitino Affecting H2 JDBC ...

A vulnerability in Apache Gravitino allows unauthenticated users to provide a malicious H2 JDBC URL via the testConnection API. This can lead to the execution of arbitrary Java code on the server due to improper handling of the INIT parameter in H2. This issue predominantly affects environments w...

PoC for CVE-2026-75014

SourcecodesterPet Grooming Managemen...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pet Grooming Manageme...

A SQL injection vulnerability has been identified in the SourceCodester Pet Grooming Management Software (version 1.0). The flaw resides within the /admin/get_barcode_data.php file, where manipulations of the input argument 'barcode' can allow unauthorized remote attackers to execute arbitrary SQ...

PoC for CVE-2026-75013

TotolinkEx1200l7.1HIGH
Remote Null Pointer Dereference in TOTOLINK EX1200L Router

A vulnerability in the TOTOLINK EX1200L router, specifically in the function setWizardCfg of the cstecgi.cgi file, allows for a null pointer dereference. This security flaw can be exploited remotely, leading to potential system instability or unauthorized access. Given that exploit code is public...

PoC for CVE-2026-75012

TotolinkEx1200l7.1HIGH
Remote Null Pointer Dereference in TOTOLINK EX1200L

A vulnerability exists in the Password Configuration Handler of the TOTOLINK EX1200L router, specifically in the setPasswordCfg function of the cgi-bin/cstecgi.cgi file. This issue leads to a null pointer dereference, allowing remote attackers to exploit the vulnerability. Public disclosure of th...

PoC for CVE-2026-75011

KylecuiNetforensicmcp5.3MEDIUM
Command Injection Vulnerability in kylecui NetForensicMCP Product

A command injection vulnerability exists in the kylecui NetForensicMCP version 2.1.0, specifically within the execAsync function located in index.js. By manipulating the argument for the interface/protocol, an attacker can execute arbitrary commands remotely. This significant security flaw has be...

PoC for CVE-2026-59310

VmwareCloud Foundation9.8CRITICAL
Directory Traversal Vulnerability in VMware vCenter by VMware

VMware vCenter features a directory traversal vulnerability in its Syslog server component. This flaw allows attackers with network access to exploit the vulnerability, potentially leading to unauthorized execution of arbitrary code. Proper safeguards and patching are essential to mitigate the ri...