Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 2 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 6 hours ago
PoC for CVE-2026-54121
A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...
Discovered 8 hours ago
PoC for CVE-2026-66031
Ekushey Project Manager CRM versions up to 5.0 are susceptible to a stored cross-site scripting vulnerability. This flaw enables authenticated users to insert arbitrary HTML and JavaScript into the Reply Ticket field. Attackers can exploit this vulnerability by crafting malicious scripts that are...
PoC for CVE-2026-66030
Ekushey Project Manager CRM up to version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to input malicious HTML and JavaScript code via the Ticket Title field on the Create New Ticket page. This could lead to attackers being able to store and exec...
PoC for CVE-2026-66029
The Ekushey Project Manager CRM, up to version 5.0, is vulnerable to a stored cross-site scripting issue. This vulnerability allows authenticated users to enter malicious HTML and JavaScript code into the client Name field within the Edit Profile page without proper input sanitization. As a resul...
PoC for CVE-2026-66028
Ekushey Project Manager CRM version 5.0 has a vulnerability due to a missing uniqueness constraint that permits authenticated administrators to create multiple client accounts with the same email address. This flaw allows for conflicting account states where different passwords can be associated ...
Discovered 9 hours ago
PoC for CVE-2026-42533
A vulnerability in NGINX Plus and NGINX Open Source arises when a map directive improperly utilizes regex matching in conjunction with string expressions referencing the map’s regex capture variables before the map output variable, or when non-cacheable variables are used under specific condition...
PoC for CVE-2026-66731
facil.io versions 0.7.5 and 0.7.6 contain a vulnerability in the HTTP/1.1 chunked transfer encoding parser. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted POST request with a negative chunk size value in the 'Transfer-Encoding: chunked' header. This manipu...
PoC for CVE-2026-66730
The facil.io framework versions 0.6.0 to 0.7.6 contain a vulnerability in the multipart body parser that can lead to a denial-of-service condition. An unauthenticated remote attacker can exploit this flaw by sending specially crafted multipart/form-data requests with a partial closing boundary. T...
PoC for CVE-2026-66729
The facil.io product through version 0.7.6 is susceptible to an integer underflow vulnerability within its multipart MIME body parser. This flaw allows unauthenticated remote attackers to exploit the server by sending a specially crafted Content-Disposition header with an empty field name. Such a...
Discovered 10 hours ago
PoC for CVE-2026-17531
A vulnerability has been identified in the Unitedbyai Droidclaw up to version 0.5.3, specifically in the Unsigned Scheduled Callback feature within the file server/src/routes/goals.ts. This issue allows for authorization bypass, enabling unauthorized access to functionalities. The complexity of e...
PoC for CVE-2023-52076
Atril Document Viewer, the default document reader for the MATE desktop environment in Linux, is affected by a path traversal and arbitrary file write vulnerability in versions prior to 1.26.2. Attackers can exploit this flaw to write arbitrary files anywhere on the filesystem that the user has a...
PoC for CVE-2026-17530
A significant security flaw has been identified in the AstrBot application developed by AstrBotDevs. This vulnerability affects the _build_handoff_toolset function in the astr_agent_tool_exec.py file, which is part of the Subagent component. The exploit allows attackers to manipulate the authoriz...
Discovered 11 hours ago
PoC for CVE-2026-17529
A vulnerability has been discovered in AstrBot by AstrBotDevs, specifically impacting versions up to 4.25.5. The flaw resides in an unidentified function within the file astrbot/core/astr_main_agent.py, leading to improper authorization due to the manipulation of the argument req.func_tool. This ...
Discovered 12 hours ago
PoC for CVE-2026-66050
NitroShare Desktop versions up to 0.3.4 are vulnerable to a path traversal flaw within its LAN file transfer server. This vulnerability allows unauthenticated attackers on the same network to exploit the file transfer feature. By sending a specially crafted filename that contains directory traver...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
Discovered 13 hours ago
PoC for CVE-2026-17514
A path traversal vulnerability has been identified in the ZJONSSON node-unzipper library, specifically in the Extract function of lib/extract.js. This flaw allows attackers with local access to manipulate file paths during extraction processes, potentially leading to unauthorized file access. Alt...
PoC for CVE-2026-41179
The Rclone tool, designed for file synchronization with various cloud storage systems, has a vulnerability stemming from the unsecured RC endpoint `operations/fsinfo`. In versions 1.48.0 through 1.73.4, this endpoint allows unauthenticated attackers to send controlled `fs` input, which can instan...
PoC for CVE-2026-61511
The vBulletin platform, including versions 5.x up to 5.7.5 and 6.x up to 6.2.1, is susceptible to an eval injection vulnerability found in the vB5_Template_Runtime::runMaths() method. This issue can be leveraged by unauthenticated attackers who submit specially crafted inputs through the pagenav[...
PoC for CVE-2026-61511
The vBulletin platform, including versions 5.x up to 5.7.5 and 6.x up to 6.2.1, is susceptible to an eval injection vulnerability found in the vB5_Template_Runtime::runMaths() method. This issue can be leveraged by unauthenticated attackers who submit specially crafted inputs through the pagenav[...
Discovered 15 hours ago
PoC for CVE-2026-4861
A vulnerability has been discovered in the Wavlink WL-NU516U1 device, specifically affecting the function ftext located in the /cgi-bin/nas.cgi file. This issue arises due to improper handling of the Content-Length argument, leading to a stack-based buffer overflow. Attackers can exploit this vul...
Discovered 20 hours ago
PoC for CVE-2026-9830
The BookingPress Appointment Booking Pro plugin for WordPress prior to version 5.7.3 contains a vulnerability that fails to properly enforce REST API authentication. As a result, this oversight allows unauthenticated attackers to gain access to sensitive customer booking data and make unauthorize...
PoC for CVE-2026-14827
The Calendar Plugin for WordPress prior to version 1.3.18 is susceptible to Cross-Site Scripting (XSS) attacks due to inadequate escaping of user inputs. Specifically, the plugin fails to properly escape event fields submitted by users, which are then displayed in HTML attributes without sufficie...
PoC for CVE-2026-14820
The Quiz and Survey Master plugin for WordPress, prior to version 11.1.3, suffers from a vulnerability that allows unauthenticated attackers to perform username enumeration and brute-force attacks. The plugin lacks appropriate rate limiting and fails to log unsuccessful login attempts effectively...
PoC for CVE-2026-14568
The User Frontend plugin for WordPress prior to version 4.3.8 contains a flaw that allows unauthorized users to delete attachments without proper verification of ownership. This flaw can be exploited by unauthenticated attackers, enabling them to permanently remove media uploaded by users without...
PoC for CVE-2026-14236
The Contact Form 7 plugin for WordPress prior to version 2.5 fails to properly validate the host of user-provided return URLs. This oversight allows an attacker to craft malicious links that redirect users to arbitrary external sites during the success or cancel phase of a Stripe checkout process...
PoC for CVE-2026-14289
The FacturaONE plugin for WooCommerce prior to version 5.37 holds a critical security flaw that lacks proper authentication mechanisms for one of its request handlers. This oversight stems from a default empty cryptographic key, exposing the plugin to unauthenticated attackers. Such attackers can...
PoC for CVE-2026-14190
The Sina Extension for Elementor, a WordPress plugin, has a Cross-Site Scripting (XSS) vulnerability due to improper escaping of values reconstructed from user input in its unauthenticated AJAX handlers. This flaw allows unauthenticated attackers to inject and execute arbitrary JavaScript code in...
PoC for CVE-2026-14189
The WPBot WordPress plugin, prior to version 8.5.2, is susceptible to SQL injection due to the failure to validate administrator-configured field identifiers before their use in SQL queries. This allows administrators, if compromised, to craft queries that can be executed when a visitor makes a s...
PoC for CVE-2026-13726
The MPG WordPress plugin prior to version 4.1.8 is susceptible to a reflected cross-site scripting vulnerability. Due to improper sanitization and escaping of a specific parameter, unauthenticated attackers can exploit this flaw by crafting a malicious request. When a victim interacts with this r...
PoC for CVE-2026-14203
The Smart Manager plugin for WordPress versions prior to 8.92.0 contains a cross-site scripting vulnerability due to improper encoding of a post field before rendering it into an HTML attribute. This flaw allows users with the Contributor role or higher to inject malicious JavaScript code. When a...
PoC for CVE-2026-14235
The Download Manager plugin for WordPress, prior to version 3.3.62, contains a flaw that allows generated download tokens to remain valid across multiple sessions without proper expiration. This oversight permits an unauthorized user to exploit a leaked download token and access role- or password...
PoC for CVE-2026-13597
The 微信二维码登陆 plugin for WordPress versions up to 1.3 contains a security flaw that permits unauthorized access through weak validation of webhook requests. The plugin's signature verification fails, allowing an attacker to simulate a login event for any existing user by intercepting the webhook re...
PoC for CVE-2026-13400
The Simply Schedule Appointments WordPress plugin contains a vulnerability that allows unauthenticated attackers to inject malicious scripts into the notification content field. This is due to a failure in proper sanitization, where a double-encoded payload bypasses filters and is executed when t...
PoC for CVE-2026-13714
The Realtyna Organic IDX and WPL Real Estate WordPress plugins before version 5.3.0 allow unauthenticated users to upload arbitrary files through a file upload feature that lacks proper validation. This functionality is controlled by an API with hardcoded credentials enabled by default, exposing ...
PoC for CVE-2026-12982
The Document Gallery plugin for WordPress prior to version 5.1.1 is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This flaw arises due to inadequate sanitization and escaping of user input during an unauthenticated AJAX action, allowing attackers to inject malicious scripts...
PoC for CVE-2026-13332
The Masteriyo LMS plugin for WordPress prior to version 2.3.1 contains a vulnerability that permits unauthenticated attackers to exploit an AJAX action related to user session management. This flawed implementation allows unauthorized users to clear active sessions for any registered user, includ...
PoC for CVE-2026-13390
The Events Calendar plugin for WordPress prior to version 6.16.5.1 features a security flaw that allows attackers to bypass authorization checks on specific Event Aggregator import REST API routes. This vulnerability can be exploited by unauthenticated users to mark existing import records as fai...
PoC for CVE-2026-12493
The Clover Payment Gateway for WooCommerce by Zaytech prior to version 1.3.6 contains a significant oversight in its payment verification process. It fails to ensure that an external payment record legitimately corresponds to a WooCommerce order being processed. This flaw allows unauthorized user...
PoC for CVE-2026-13152
The Custom Fields Account Registration for Woocommerce plugin prior to version 1.4 contains a vulnerability that permits an unauthenticated user to exploit custom registration fields. By setting up a corresponding field name that maps to the user capabilities meta key, an attacker can grant thems...
PoC for CVE-2025-15662
The Printcart Web to Print Product Designer plugin for WooCommerce prior to version 2.5.3 lacks proper validation of user-supplied URLs, which enables attackers to exploit this flaw and execute arbitrary server-side requests. This vulnerability allows unauthorized users to access sensitive local ...
PoC for CVE-2026-10082
The Advanced Ads plugin for WordPress prior to version 2.0.23 contains a security flaw where a shortcode parameter is not properly sanitized and escaped before being output on the page. This vulnerability allows users with a Contributor role or higher to inject arbitrary web scripts. Such scripts...
PoC for CVE-2026-12255
The MainWP Child plugin for WordPress prior to version 6.1.2 contains a significant flaw that fails to verify the identity of the requester during site-registration requests. When password authentication is disabled for the targeted account, this vulnerability enables an unauthenticated attacker ...
PoC for CVE-2026-12394
The MemberGlut WordPress plugin prior to version 1.1.5 contains a vulnerability where the selected role during front-end registration is not properly validated. This flaw permits unauthenticated users to create accounts with arbitrary roles, including that of an administrator. Exploiting this vul...
Discovered 23 hours ago
PoC for CVE-2026-54121
A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...
Discovered 1 day ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-60137
A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...
Discovered 2 days ago
PoC for CVE-2026-17459
A vulnerability identified in the SparkJava framework up to version 2.9.4 relates to the `staticFiles.externalLocation` function. This issue allows an attacker to exploit the symlink following behavior within the `ExternalResourceHandler` component. The flaw can be exploited remotely, posing a si...
PoC for CVE-2026-17458
A vulnerability exists in the mf-yang Openclaw-CN application, specifically within the Browser Control HTTP API. The flaw, located in the clickViaPlaywright function of the agent.act.ts file, allows attackers to carry out server-side request forgery (SSRF) attacks. This means that by manipulating...