Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-55200

Libssh2Libssh29.2CRITICAL
Out-of-Bounds Write Vulnerability in libssh2 Affects Remote Code Ex...

libssh2 contains an out-of-bounds write vulnerability in the ssh2_transport_read() function that fails to impose proper limits on the packet_length field. This flaw allows remote attackers to exploit the vulnerability by sending specially crafted SSH packets with excessively large packet_length v...

PoC for CVE-2026-22226

Tp-link Systems Inc.Archer Be230 V1.28.5HIGH
Command Injection Vulnerability in TP-Link Archer BE230 Router

A command injection vulnerability exists in the VPN server configuration module of the TP-Link Archer BE230 v1.2, which can be exploited after administrative authentication. This flaw allows an attacker to execute arbitrary commands, potentially granting full administrative control over the route...

Discovered 59 minutes ago

PoC for CVE-2026-48907

Joomlacontentedit...Joomla Content Editor ...🟣 EPSS 80%10CRITICAL
JCE Editor Extension for Joomla Vulnerability Allows Unauthenticate...

A flaw in the JCE editor extension for Joomla permits unauthorized users to create new editor profiles. This malicious capability exposes the site to risks, including the ability to upload PHP code and execute it, potentially leading to a full compromise of the website security. Site administrato...

Discovered 3 hours ago

PoC for CVE-2026-13579

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability has been detected in the itsourcecode Hospital Management System version 1.0, specifically in the functionality associated with the file /patientchangepassword.php. This issue arises from improper handling of the input parameter newpassword, making it susceptible to SQL injection ...

PoC for CVE-2026-13578

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A security flaw has been identified in the itsourcecode Hospital Management System version 1.0, specifically in the /patientdetail.php file. This vulnerability arises from an exploitable argument manipulation of 'editid', which allows for SQL injection attacks. Attackers can execute this attack r...

PoC for CVE-2026-13574

LlvmLlvm-project4.8MEDIUM
Heap-Based Buffer Overflow in LLVM Project's Bitcode File Handler

A vulnerability exists in the LLVM llvm-project affecting the Bitcode File Handler, specifically within the GCRelocateInst::getBasePtr function. This issue allows for heap-based buffer overflow, potentially enabling local attackers to exploit the flaw. Despite early reports of the issue to the pr...

PoC for CVE-2026-13573

LlvmLlvm-project4.8MEDIUM
Stack-Based Buffer Overflow in LLVM Project's ValueSymbolTable Module

A vulnerability has been identified in the LLVM project's ValueSymbolTable module, specifically within the llvm::StringMap::insert function in /lib/IR/ValueSymbolTable.cpp. This vulnerability allows for a stack-based buffer overflow, which may lead to exploit scenarios if an attacker can execute ...

Discovered 4 hours ago

PoC for CVE-2026-13572

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability exists in version 1.0 of the itsourcecode Hospital Management System related to an unknown function within the /insertbillingrecord.php file. This flaw allows an attacker to manipulate the patientid parameter, leading to SQL injection attacks. The vulnerability is remotely exploit...

PoC for CVE-2026-13571

SourcecodesterSimple Food Ordering S...6.9MEDIUM
Business Logic Errors in SourceCodester Simple Food Ordering System

A vulnerability exists within the SourceCodester Simple Food Ordering System 1.0, specifically in the /cart.php file. A flaw in an undocumented function allows attackers to manipulate the argument item_price, potentially leading to significant business logic errors. This vulnerability can be expl...

PoC for CVE-2026-13569

Weng-xianhuEyoucms5.1MEDIUM
SQL Injection Vulnerability in weng-xianhu EyouCMS by Weng-Xianhu

A security flaw has been identified in the weng-xianhu EyouCMS, specifically in versions up to 1.7.1. The vulnerability resides in the /index.php file associated with the API component, where improper handling of the 'click_like' argument can lead to SQL injection attacks. This vulnerability allo...

Discovered 5 hours ago

PoC for CVE-2026-40521

FrontaccountingFrontaccounting8.7HIGH
Path Traversal Vulnerability in FrontAccounting by FrontAccounting

FrontAccounting versions before 2.4.20 are susceptible to a path traversal vulnerability present in the attachment upload handler. This vulnerability enables authenticated attackers to manipulate the unique_name parameter, allowing the inclusion of malicious path traversal sequences like '../../....

PoC for CVE-2026-13567

Code-projectsOnline Music Site5.3MEDIUM
Cross Site Scripting Vulnerability in Code-Projects Online Music Si...

A security vulnerability has been identified in code-projects Online Music Site version 1.0, specifically within the POST Request Handler located in the /Frontend/Feedback.php file. This flaw allows for cross-site scripting (XSS) through manipulated arguments such as fname, femail, faddress, and ...

PoC for CVE-2026-40522

FrontaccountingFrontaccounting7.1HIGH
SQL Injection Vulnerability in FrontAccounting Product by FrontAcco...

An SQL injection vulnerability exists in FrontAccounting, specifically in versions prior to 2.4.20, affecting the Bank Statement report handler. This vulnerability allows authenticated attackers to exploit the PARAM_0 POST parameter by injecting malicious SQL commands. By leveraging this flaw, at...

PoC for CVE-2026-40523

FrontaccountingFrontaccounting7.2HIGH
SQL Injection Vulnerability in FrontAccounting by FrontAccounting

A notable SQL injection issue exists in FrontAccounting prior to version 2.4.20, specifically within the Audit Trail report handler. This vulnerability can be exploited by authenticated users holding the SA_GLANALYTIC permission. By injecting malicious SQL queries through the PARAM_2 and PARAM_3 ...

PoC for CVE-2026-40524

FrontaccountingFrontaccounting7.2HIGH
SQL Injection Vulnerability in FrontAccounting Software by EASYPAY

FrontAccounting prior to version 2.4.20 contains an SQL injection vulnerability in the get_gl_transactions() function. This issue arises because the filter_type parameter is concatenated directly into a SQL IN() clause without proper parameterization. Malicious actors with SA_GLANALYTIC permissio...

PoC for CVE-2026-13566

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A vulnerability in the SourceCodester Class and Exam Timetabling System version 1.0 permits SQL injection through the /preview3.php file. The issue arises when the argument 'course_year_section' is manipulated by attackers, allowing the potential for unauthorized database access. This exploit can...

PoC for CVE-2026-13565

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A vulnerability exists in the SourceCodester Class and Exam Timetabling System, specifically within the /edit_class1.php file. This vulnerability arises from improper handling of user-supplied input related to the argument ID. Attackers can exploit this weakness to execute arbitrary SQL commands,...

Discovered 6 hours ago

PoC for CVE-2026-13564

EdimaxEw-7478apc8.7HIGH
Stack-Based Buffer Overflow in Edimax EW-7478APC Due to POST Reques...

A stack-based buffer overflow vulnerability exists in the Edimax EW-7478APC version 1.04, specifically within the formPPPoESetup function of the POST Request Handler. This vulnerability can be triggered remotely by manipulating the pppUserName parameter. If exploited, it can lead to unauthorized ...

PoC for CVE-2026-13563

EdimaxEw-7478apc8.7HIGH
Stack-based Buffer Overflow in Edimax EW-7478APC Product

A vulnerability affecting the Edimax EW-7478APC version 1.04 has been identified in the POST Request Handler, specifically within the formL2TPSetup function. This flaw allows for a stack-based buffer overflow when the L2TPUserName parameter is improperly manipulated. Attackers can exploit this vu...

PoC for CVE-2026-13562

EdimaxEw-7478apc8.7HIGH
Buffer Overflow Vulnerability in Edimax EW-7478APC Wireless Range E...

A vulnerability in the Edimax EW-7478APC wireless range extender has been identified, specifically in the function handling POST requests for site surveys. The incident involves improper processing of the 'selSSID' parameter, leading to a buffer overflow situation. This weakness can be exploited ...

PoC for CVE-2026-13561

EdimaxEw-7478apc5.3MEDIUM
OS Command Injection Vulnerability in Edimax EW-7478APC by Edimax

An OS command injection vulnerability exists in Edimax EW-7478APC version 1.04. This flaw is found in the POST Request Handler within the function formiNICbasic, specifically when manipulating the rootAPmac argument. Successful exploitation allows remote attackers to execute arbitrary OS commands...

Discovered 7 hours ago

PoC for CVE-2026-13560

EdimaxEw-7478apc5.3MEDIUM
OS Command Injection Vulnerability in Edimax EW-7478APC by Edimax

A security vulnerability has been identified in the Edimax EW-7478APC version 1.04, specifically within the formAccept function of the POST Request Handler. This flaw allows remote attackers to manipulate the submit-url parameter, leading to potential OS command injection. This vulnerability has ...

PoC for CVE-2026-13559

Code-projectsReal State Services6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Real State Services by...

A vulnerability has been detected in the Code-Projects Real State Services, specifically in the function within the file /single-list_sale.php when the action parameter is set to 'add'. By manipulating the argument ID, an attacker can execute an SQL injection, potentially exposing sensitive data....

PoC for CVE-2026-13558

CodeastroComplaint Management S...5.1MEDIUM
Cross Site Scripting Vulnerability in CodeAstro Complaint Managemen...

A security vulnerability has been identified in the CodeAstro Complaint Management System version 1.0, specifically within the Report Handler component. The flaw is triggered by improper handling of the 'Report Title' argument in the /report/addreport file. This oversight allows attackers to inje...

PoC for CVE-2026-13557

ItsourcecodeOnline Hotel Managemen...5.3MEDIUM
Cross-Site Scripting Vulnerability in itsourcecode Online Hotel Man...

A cross-site scripting (XSS) vulnerability was discovered in the itsourcecode Online Hotel Management System version 1.0, specifically in the POST Request Handler component located in the file /admin/mod_room/controller.php. This vulnerability allows an attacker to manipulate the argument 'Name',...

Discovered 8 hours ago

PoC for CVE-2026-13556

ItsourcecodeOnline Hotel Managemen...5.3MEDIUM
Cross Site Scripting Vulnerability in itsourcecode Online Hotel Man...

A cross site scripting vulnerability exists within itsourcecode Online Hotel Management System version 1.0, specifically affecting the POST Request Handler component. The vulnerability arises from improper handling of user input in the file /admin/mod_users/controller.php when the 'edit' action i...

PoC for CVE-2026-13555

ItsourcecodeOnline Hotel Managemen...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Hotel Management...

A security flaw has been identified in the itsourcecode Online Hotel Management System 1.0, where the file /admin/mod_users/controller.php allows remote attackers to execute SQL injection attacks. By manipulating the 'Name' argument, unauthorized users could potentially access or alter sensitive ...

PoC for CVE-2026-13554

ItsourcecodeOnline Hotel Managemen...5.3MEDIUM
Cross Site Scripting in Online Hotel Management System by itsourcecode

A vulnerability exists in the Online Hotel Management System (version 1.0) due to improper handling of POST requests in the controller file. Specifically, the 'add' action in /admin/mod_amenities/controller.php is susceptible to cross site scripting (XSS) attacks. By manipulating the 'Name' argum...

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 100%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

PoC for CVE-2026-13553

ItsourcecodeOnline Hotel Managemen...6.9MEDIUM
Unrestricted File Upload Vulnerability in itsourcecode Online Hotel...

A security flaw has been identified in the itsourcecode Online Hotel Management System version 1.0, specifically in the /admin/mod_amenities/controller.php file. This vulnerability is associated with an unprotected function that processes image uploads, allowing an attacker to manipulate argument...

PoC for CVE-2026-48908

Joomshaper.netSp Page Builder Extens...10CRITICAL
Arbitrary File Upload in SP Page Builder for Joomla

A vulnerability in the SP Page Builder for Joomla permits unauthenticated users to upload arbitrary files. This weakness can lead to the execution of PHP code, presenting significant security risks for Joomla websites using this extension.

Discovered 9 hours ago

PoC for CVE-2026-13552

ItsourcecodeOnline Hotel Managemen...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Hotel Management...

A SQL injection vulnerability exists in the itsourcecode Online Hotel Management System version 1.0, specifically impacting the /admin/mod_amenities/controller.php?action=edit endpoint. This vulnerability allows attackers to manipulate the 'amen_id' parameter, leading to unauthorized database acc...

PoC for CVE-2025-66680

WiseCleanerWise Force Deleter7.1HIGH
Arbitrary File Deletion Vulnerability in WiseCleaner Wise Force Del...

A vulnerability exists in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter versions 7.3.2 and earlier, which allows attackers to execute crafted requests that can lead to unauthorized deletion of arbitrary files from the system. This issue poses a significant risk as it can compr...

PoC for CVE-2026-13551

ItsourcecodeBaptism Information Ma...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Baptism Information Man...

A security concern has been identified in itsourcecode's Baptism Information Management System 1.0. A flaw exists in the /editBaptism.php file, where manipulation of the parameter 'ID' can allow an attacker to execute SQL injection attacks. This vulnerability can be exploited remotely, posing a s...

PoC for CVE-2026-13550

ItsourcecodeBaptism Information Ma...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Baptism Information Man...

A security weakness has been discovered in the itsourcecode Baptism Information Management System, specifically affecting the /delbaptism.php file. The vulnerability arises from improper handling of the argument ID, allowing for SQL injection attacks. This flaw can be exploited remotely, leading ...

PoC for CVE-2026-13549

CodeastroComplaint Management S...5.3MEDIUM
Authorization Bypass in CodeAstro Complaint Management System

A security vulnerability has been identified in the CodeAstro Complaint Management System version 1.0, specifically in the deletereport function located in application/controllers/Report.php of the Report Endpoint component. This flaw allows attackers to bypass authorization measures, enabling po...

Discovered 10 hours ago

PoC for CVE-2026-13548

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A significant SQL injection vulnerability has been identified in the itsourcecode Hospital Management System version 1.0, specifically within the file /doctortimings.php. This vulnerability allows for the manipulation of the 'editid' argument, which can enable unauthorized access and manipulation...

PoC for CVE-2026-13547

HanwangE-face General Managem...6.9MEDIUM
Remote Code Execution Vulnerability in Hanwang e-Face General Manag...

A vulnerability exists in the Hanwang e-Face General Management Platform 6.3.5.4 that allows for unrestricted file uploads through the manipulation of the /manage/resourceUpload/upload.do endpoint. This security flaw could be exploited remotely, enabling attackers to upload malicious files onto t...

PoC for CVE-2026-13546

FeehiCms6.9MEDIUM
Authentication Vulnerability in Feehi CMS REST API Endpoint

A vulnerability exists in Feehi CMS versions up to 2.1.1 affecting the REST API Endpoint used for handling articles. This issue results from missing authentication mechanisms in the /api/articles file, allowing unauthorized remote access. Attackers can exploit this vulnerability to manipulate req...

PoC for CVE-2026-13545

D-linkDcs-935l8.7HIGH
OS Command Injection Vulnerability in D-Link DCS-935L Camera

A vulnerability has been identified in the D-Link DCS-935L HD Wi-Fi Camera, specifically in version 1.10.01. This issue occurs within the POST Parameter Handler, particularly in the function sub_400E40 of the setconf.cgi file. An attacker can manipulate the UID argument to execute arbitrary OS co...

PoC for CVE-2026-24418

Devcode-itOpenstamanager8.7HIGH
SQL Injection Vulnerability in OpenSTAManager by Devcode IT

OpenSTAManager, an open source tool for managing technical support and invoicing, contains a vulnerability in its Payment Schedule module. The application improperly validates array entries used in SQL queries, enabling attackers to execute malicious SQL commands. This could lead to unauthorized ...

Discovered 11 hours ago

PoC for CVE-2026-13544

FeehiCms5.3MEDIUM
Access Control Vulnerability in Feehi CMS by Liufee

A flaw exists in Feehi CMS versions prior to 2.1.1, specifically within the API component at /api/users. This vulnerability allows for improper access controls, enabling attackers to potentially exploit functionality that should be restricted. The issue can be triggered remotely, posing a signifi...

PoC for CVE-2026-13543

DocumensoDocumenso6.3MEDIUM
Improper Authentication in Documenso's Google OAuth Login Component

A vulnerability discovered in Documenso versions up to 2.11.0 pertains to a flaw in the Google OAuth Login component. This issue resides in the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts, where improper authentication functionality can be exploited. The vulnerability allows ...

PoC for CVE-2026-13542

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A security vulnerability has been identified in the itsourcecode Hospital Management System version 1.0, specifically within the /doctorprofile.php file. This issue is caused by the improper handling of the 'doctorname' parameter, which allows attackers to execute SQL injection attacks remotely. ...

PoC for CVE-2026-13541

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management Sys...

A vulnerability has been identified in the itsourcecode Hospital Management System 1.0, specifically affecting the /doctorchangepassword.php file. An attacker can exploit this weakness by manipulating the 'newpassword' parameter, leading to SQL injection attacks. This type of attack allows unauth...

PoC for CVE-2026-10083

WordPressApcu Manager7.5HIGH
Stored Cross-Site Scripting Vulnerability in APCu Manager Plugin fo...

The APCu Manager plugin for WordPress, prior to version 4.5.0, can lead to a Stored Cross-Site Scripting vulnerability due to the improper handling of APCu object-cache keys. When persistent object caching is enabled, cache keys derived from unsanitized user input can be rendered unescaped on adm...

PoC for CVE-2026-9676

WordPressF4 Post Tree4.3MEDIUM
Unauthorized Modification Vulnerability in F4 Post Tree WordPress P...

The F4 Post Tree WordPress plugin prior to version 2.0.5 exposes a serious security flaw where it fails to conduct proper capability checks and lacks CSRF/nonce verification on specific AJAX actions. This oversight allows authenticated users with Subscriber-level access and above to alter the par...

PoC for CVE-2026-23918

ApacheApache Http Server🟣 EPSS 43%8.8HIGH
Double Free and Remote Code Execution Vulnerability in Apache HTTP ...

A double free vulnerability has been identified in Apache HTTP Server that may lead to remote code execution, particularly concerning the HTTP/2 protocol. This issue affects version 2.4.66, and it is crucial for users to upgrade to version 2.4.67 to mitigate any potential security risks associate...

Discovered 12 hours ago

PoC for CVE-2026-13540

GitBucketGitbucket5.3MEDIUM
Server-Side Request Forgery Vulnerability in GitBucket by GitBucket

A security flaw has been identified in GitBucket versions up to 4.46.1, specifically affecting the Git.cloneRepository.setURI function within the RepositoryCreationService.scala file. This vulnerability allows attackers to perform server-side request forgery (SSRF) by manipulating the URL argumen...

PoC for CVE-2026-13539

WavlinkWl-nu516u1-a8.7HIGH
Stack-Based Buffer Overflow in Wavlink WL-NU516U1-A Vulnerable Comp...

A stack-based buffer overflow vulnerability was discovered in the Wavlink WL-NU516U1-A device's POST parameter handler, specifically within the function sub_407504 of the /cgi-bin/wireless.cgi file. Attackers can exploit this vulnerability remotely by manipulating the Guest_ssid argument, leading...