Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 2 hours ago
PoC for CVE-2026-52910
A vulnerability exists in the Linux kernel's handling of UDP reuse ports which may lead to buffer overflow issues. When a cBPF program is replaced while another thread is sending a UDP packet to the reuse port group, improper resource management can occur. Specifically, the reuseport program is f...
Discovered 8 hours ago
PoC for CVE-2026-62183
An improper privilege management vulnerability in Apache Syncope allows users to misuse defined Roles through a compromised REST API call. When the all-Java or Flowable user workflow adapters are incorrectly configured, users may escalate their privileges by granting themselves roles without prop...
Discovered 10 hours ago
PoC for CVE-2026-8082
The bpost-shipping-platform WordPress plugin, prior to version 3.2.3, is susceptible to a SQL injection vulnerability due to improper parameter sanitization during WooCommerce order processing. This flaw permits unauthenticated attackers to execute time-based blind SQL injection attacks, potentia...
PoC for CVE-2026-14185
The WPBot plugin for WordPress has a security vulnerability where it fails to perform necessary capability and nonce checks in its settings handlers. This oversight allows authenticated users with subscriber-level access to modify configurations within the WPBot plugin prior to version 8.2.0. Suc...
PoC for CVE-2026-11767
The Free Builder for Elementor plugin for WordPress prior to version 1.6.7 is vulnerable to a stored cross-site scripting (XSS) flaw. This vulnerability arises because the plugin does not sanitize user input from contact form fields, allowing unauthenticated attackers to craft malicious payloads....
PoC for CVE-2026-14184
The Academy LMS plugin for WordPress prior to version 3.8.1 contains a significant security flaw in its lesson AJAX handlers. The vulnerability arises from the failure to verify the ownership of user-supplied identifiers, allowing authenticated users with minimal permissions, such as subscribers,...
PoC for CVE-2026-14183
The Classified Listing plugin for WordPress, prior to version 5.3.9, suffers from inadequate access control in its payment-receipt handling functionality. This flaw allows authenticated users with subscriber-level permissions to access and view payment receipt details belonging to other users' or...
PoC for CVE-2026-13694
The Bit Form WordPress plugin prior to version 3.1.0 is prone to a security issue where it fails to properly validate its workflow-trigger token after the associated transient expires. As a result, unauthenticated attackers can exploit this weakness to re-trigger form actions, including sending n...
PoC for CVE-2026-13693
The Bit Form WordPress plugin, prior to version 3.1.0, is vulnerable due to its failure to secure file-field values from user input. This oversight enables unauthenticated attackers to exploit the plugin, leading to unauthorized access of sensitive server files, including the WordPress configurat...
Discovered 11 hours ago
PoC for CVE-2026-12191
A deserialization vulnerability was identified in Comma AI Openpilot 0.11, specifically in the function pickle.load/pickle.loads located in selfdrive/modeld/modeld.py. This vulnerability allows an attacker with local access to exploit the Pickle Module, potentially manipulating the application's ...
Discovered 12 hours ago
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-45585
A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...
Discovered 14 hours ago
PoC for CVE-2026-16334
A SQL injection vulnerability exists in the itsourcecode Hospital Management System version 1.0, specifically within the `prescriptionorder.php` file. This flaw allows unauthenticated attackers to manipulate the `editid` parameter, potentially leading to unauthorized access to the database. Explo...
PoC for CVE-2026-49098
The Apache Camel Kafka Component is susceptible to an input validation flaw that enables an attacker to manipulate the target Kafka topic at runtime. Specifically, the kafka.OVERRIDE_TOPIC header can be exploited to publish messages to arbitrary, potentially sensitive topics, bypassing predefined...
PoC for CVE-2026-16332
A vulnerability found in the D-Link DNS-320 version 1.0.2 allows remote attackers to exploit the multi_uploadify.php functionality. By manipulating the 'Filedata[]' parameter, unauthorized users can perform unrestricted file uploads to the device. This can lead to potential security breaches, as ...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
Discovered 15 hours ago
PoC for CVE-2026-16331
A security flaw has been identified in the D-Link DNS-320 that allows attackers to perform unrestricted file uploads via the save_ajax.php script, potentially leading to unauthorized execution of files on the server. By manipulating the 'Malicious Handler' parameter, remote attackers can exploit ...
PoC for CVE-2026-16330
A vulnerability has been discovered in D-Link DNS-320 version 1.0.2, specifically in the '/web/jquery/uploader/uploadify.php' file. This flaw allows for unrestricted file uploads via a manipulated request to a specific resource. As a result, attackers can exploit this weak point remotely, enablin...
PoC for CVE-2026-16329
A vulnerability has been discovered in the D-Link DNS-320 version 1.0.2, specifically in the file 'uploadify.php'. This security flaw allows for the manipulation of a malicious handler that could lead to unrestricted file uploads. Such an exploit can be triggered remotely, exposing the system to ...
Discovered 16 hours ago
PoC for CVE-2026-41940
The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...
Discovered 17 hours ago
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-49097
The Apache Camel IRC component is vulnerable due to improper input validation that allows an attacker to manipulate the destination of IRC messages. This occurs when an HTTP route passes headers from an inbound request without proper filtering, allowing any client to redirect messages meant for a...
PoC for CVE-2021-42013
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default ...
Discovered 18 hours ago
PoC for CVE-2026-16324
A vulnerability has been discovered in the MetaCRM software from Metasoft, affecting versions up to 6.4.0 Beta06. This flaw resides in the file /business/qnaire/upload.jsp, where an unknown function allows for unrestricted file uploads. This capability could enable attackers to upload malicious f...
PoC for CVE-2026-49086
A vulnerability exists in Apache Camel's DAPR component, specifically in the Dapr Pub/Sub consumer. This flaw arises from improper input validation, allowing an attacker with publishing rights to manipulate CloudEvent headers, namely the pub/sub component name and topic. By doing so, they can red...
Discovered 20 hours ago
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-63767
The ktransformers library, versions up to 0.6.3, is vulnerable to an unauthenticated pickle deserialization flaw. This vulnerability allows remote attackers to execute arbitrary commands by sending specially crafted pickle payloads to the SchedulerServer's ZMQ ROUTER socket. By exploiting malicio...
PoC for CVE-2026-63768
The cal.diy application, from Calcom, is susceptible to an open redirect vulnerability located in the conferencing OAuth callback endpoint. This flaw allows attackers to craft malicious state parameters that can redirect unsuspecting users from a legitimate domain to arbitrary URLs controlled by ...
PoC for CVE-2026-63769
Huginn versions up to and including 2022.08.18 are susceptible to a server-side request forgery (SSRF) vulnerability found in the fetch_url method of ScenarioImport. Authenticated users can exploit this flaw to submit specially crafted URLs that allow them to perform arbitrary HTTP requests. This...
Discovered 21 hours ago
PoC for CVE-2026-63770
The Glance application version 0.8.5 is impacted by an IP address spoofing vulnerability within its authentication handler. This flaw allows unauthenticated attackers to evade brute-force lockout protections. By manipulating the X-Forwarded-For request header, attackers can present arbitrary valu...
PoC for CVE-2026-63771
The vulnerability in Adminer, found in versions prior to 5.4.3, arises from the improper handling of cookie attributes via the unsanitized X-Forwarded-Prefix HTTP header. This flaw enables attackers to manipulate the Set-Cookie path attributes, thereby downgrading SameSite protections. When a rev...
PoC for CVE-2026-63731
The vulnerability in HyperDX prior to version 2.31.0 allows authenticated team members to exploit the server using a controlled host parameter to access arbitrary internal destinations. This is done via the ClickHouse proxy test endpoint, which lacks proper URL validation and allowlist enforcemen...
PoC for CVE-2026-63108
Roo Code versions prior to 3.54.0 are susceptible to a command injection vulnerability that exploits the auto-approve feature. This flaw allows attackers to bypass predefined allowlist and denylist checks by nesting command substitutions within parameter expansions. The issue arises from the comm...
PoC for CVE-2026-63107
LimeSurvey versions 6.17.10 and 7.0.4 are vulnerable to server-side request forgery (SSRF) through their REST API. This vulnerability allows authenticated users to manipulate the Host header, enabling the server to execute arbitrary HTTP requests. Exploiting this flaw could permit attackers to ac...
Discovered 22 hours ago
PoC for CVE-2026-60121
Vitec Flamingo version 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint. This flaw enables remote attackers to execute arbitrary commands by taking advantage of a double-evaluation issue in how shell arguments are handled. The endpoint uses...
PoC for CVE-2026-49042
An improper input validation vulnerability exists in Apache Camel, affecting multiple versions. This flaw could potentially allow malicious actors to exploit the application by sending crafted requests, resulting in unintended behavior or security breaches. Users are strongly advised to upgrade t...
Discovered 23 hours ago
PoC for CVE-2026-42533
A vulnerability in NGINX Plus and NGINX Open Source arises when a map directive improperly utilizes regex matching in conjunction with string expressions referencing the map’s regex capture variables before the map output variable, or when non-cacheable variables are used under specific condition...
PoC for CVE-2026-48206
The Apache Camel JIRA component is susceptible to an improper input validation and authorization bypass vulnerability. This occurs due to the way it processes operation parameters from Exchange message headers without adequate filtering. The headers, such as `IssueKey`, `ProjectKey`, and `IssueTr...
Discovered 1 day ago
PoC for CVE-2026-4858
Mattermost versions up to 11.6.0, 11.5.3, 11.4.4, and 10.11.14 exhibit a path traversal vulnerability due to insufficient validation of integration URLs. This flaw enables a malicious authenticated user, possessing a system admin Mattermost auth token, to exploit arbitrary API calls, potentially ...
PoC for CVE-2026-16252
A security vulnerability has been identified in the Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System version 8.2.2. The flaw resides within an unknown function located at /admin/system/structure/updateStructure/deflate/Insecure/Staffshinel Ds.jsp, where the manipul...
PoC for CVE-2026-16248
A stack-based buffer overflow vulnerability has been identified in the Tenda AC10 router's /goform/AdvSetLanip component, specifically within the fromAdvSetLanip function. This flaw arises due to improper handling of the GetValue/SetValue arguments, allowing an attacker to exploit the vulnerabili...
PoC for CVE-2026-16244
A security flaw has been identified in the itsourcecode Hospital Management System version 1.0. This vulnerability resides in the /prescriptionorderreport.php file, where insufficient input validation allows an attacker to manipulate the 'delid' argument. By exploiting this weakness, a malicious ...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-9833
The Tag Groups plugin for WordPress versions prior to 2.2.0 is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper escaping of AJAX parameters. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any logged-in user with Editor level a...
PoC for CVE-2026-13432
The ThumbPress WordPress plugin prior to version 6.2.2 is susceptible to a security flaw where it fails to verify user capabilities on specific AJAX actions. This omission allows authenticated users with subscriber permissions or higher to deactivate the plugin. Consequently, this can lead to con...
PoC for CVE-2026-8825
The Elementor Website Builder plugin for WordPress prior to version 4.1.4 contains a flaw that allows authenticated users with Contributor-level access or higher to improperly access private post data through its REST endpoints. This vulnerability permits these users to retrieve sensitive informa...
PoC for CVE-2026-12973
The PayPlus Payment Gateway plugin for WordPress has a security flaw that allows unauthenticated users to exploit AJAX actions, leading to unauthorized access to sensitive WooCommerce order information. By bypassing necessary authorization and order-ownership checks, attackers could potentially r...
PoC for CVE-2026-13142
The Social Login, Passkeys, Magic Link & Email OTP plugin for WordPress versions prior to 1.4.1 is vulnerable due to a lack of rate limiting and absence of lockout mechanisms for its passwordless email one-time-password verification. This oversight allows attackers to exploit the security weaknes...
PoC for CVE-2026-13147
The Kirki WordPress plugin prior to version 6.0.12 is susceptible to a sever-side request forgery (SSRF) vulnerability. This issue arises because the plugin does not adequately validate URLs provided by users, potentially allowing unauthenticated attackers to initiate HTTP requests to arbitrary s...
PoC for CVE-2026-13156
The MailerSend WordPress plugin prior to version 1.0.8 lacks a necessary nonce check for its configuration-delete action. While it verifies the manage_options capability, it fails to validate the nonce, allowing an attacker to potentially trick a logged-in administrator into visiting a maliciousl...