Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-82329

JfrogArtifactory9.8CRITICAL
Authentication Weakness in JFrog Artifactory Affects Unauthenticate...

JFrog Artifactory has a significant authentication weakness that could permit an attacker with network access to gain administrative privileges without authentication, particularly when the product is left in its default configuration. This vulnerability can expose sensitive resources and operati...

Discovered 24 minutes ago

PoC for CVE-2021-3493

UbuntuLinux🟣 EPSS 49%8.8HIGH
Local Privilege Escalation in Linux Kernel OverlayFS Implementation...

The OverlayFS implementation in the Linux kernel failed to adequately validate user namespaces when setting file capabilities on underlying file systems. This weakness, combined with specific patches in the Ubuntu kernel that permit unprivileged overlay mounts, enables attackers to exploit the si...

Discovered 5 hours ago

PoC for CVE-2026-13611

WordPressKivicare5.3MEDIUM
Authorization Flaw in KiviCare Plugin Enables Information Disclosure

The KiviCare WordPress plugin prior to version 4.5.5 contains a significant security vulnerability that fails to enforce authorization checks on certain REST API endpoints. This oversight allows unauthenticated attackers to gain access to sensitive information, including the patient roster and, i...

PoC for CVE-2026-78363

WordPressMw WP Form4.8MEDIUM
Remote Code Execution in MW WP Form for WordPress Plugin

The MW WP Form WordPress plugin allows shortcodes from user-submitted values to be executed within messages. This occurs when the plugin merges these values into a message, leading to potential exploitation by unauthenticated users to run any registered shortcode on the site. To exploit this vuln...

PoC for CVE-2026-74916

WordPressWP Fastest Cache6.5MEDIUM
Caching Vulnerability in WP Fastest Cache Plugin Affects WordPress ...

The WP Fastest Cache plugin for WordPress exhibits a vulnerability that permits unauthenticated attackers to exploit the caching mechanism. Specifically, the plugin fails to incorporate a set of query parameters related to tracking within its cache key. As a result, pages cached under these condi...

Discovered 6 hours ago

PoC for CVE-2023-49792

NextcloudSecurity-advisories5.3MEDIUM
Bruteforce protection can be bypassed with misconfigured proxy

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when a (reverse) proxy is configured as trus...

Discovered 7 hours ago

PoC for CVE-2026-83772

CobhamSatcom Vsat7090 Mariti...9.4CRITICAL
Command Injection Vulnerability in Cobham SATCOM VSAT7090 Maritime ...

A command injection vulnerability has been identified in the Cobham SATCOM VSAT7090 Maritime Satellite Router affecting the mail-report.sh component. This issue arises from improper handling in the c_set_reports_decode function, which allows manipulation of the sender/recipients argument. Attacke...

PoC for CVE-2026-83744

InvoiceninjaInvoice Ninja5.3MEDIUM
Server-Side Request Forgery Vulnerability in Invoice Ninja by Invoi...

A security vulnerability exists in the Invoice Ninja application up to version 5.13.26, specifically in the Purify::isHostSafe function located in the app/Services/Pdf/Purify.php file. This flaw allows an attacker to manipulate the 'notes' argument, potentially leading to remote server-side reque...

Discovered 8 hours ago

PoC for CVE-2026-83743

InvoiceninjaInvoice Ninja5.3MEDIUM
Authorization Bypass in Invoice Ninja Vendor Portal Profile Update ...

A significant security flaw exists in Invoice Ninja's Vendor Portal Profile Update functionality, specifically affecting version 5.13.26. This vulnerability arises from inadequate authorization checks that allow attackers to manipulate the 'vendor_contact' parameter. As a result, a remote attacke...

Discovered 14 hours ago

PoC for CVE-2026-83524

RedportOptimizer Wxa-2039.4CRITICAL
Command Injection Vulnerability in RedPort Optimizer Versions

A security vulnerability has been discovered in the RedPort Optimizer, affecting versions wXa-203, wXa-213, and wXa-223. This flaw resides in the System Clock component, specifically within the exec function found in the datetime.php file. The vulnerability allows for command injection, which cou...

PoC for CVE-2026-82971

QvidiumOpera1110CRITICAL
Command Injection Vulnerability in QVidium Opera11 CGI Script

A command injection vulnerability exists in the CGI script located at /cgi-bin/net_tr.cgi in QVidium Opera11 version 3.3.2a26-Ax4x-opera11. This vulnerability can be exploited by manipulating the 'ipaddr' argument, allowing attackers to execute arbitrary commands on the server. Given that QVidium...

Discovered 15 hours ago

PoC for CVE-2026-82922

ShopexEcshop6.9MEDIUM
SQL Injection Vulnerability in ShopEx ECShop by ShopEx Software Co....

A security vulnerability exists in ShopEx ECShop affecting the flow_update_cart function in the /flow.php file. The flaw allows manipulation of the rec_id argument, leading to SQL injection attacks that can be executed remotely. This vulnerability has been publicly disclosed, posing a risk to unp...

PoC for CVE-2026-82921

ShopexEcshop6.9MEDIUM
Unrestricted File Upload in ShopEx ECShop Affects Remote Operations

A vulnerability exists within ShopEx ECShop versions up to 2.5.1 in the check_img_type functionality located in admin/pack.php. Specifically, this weakness allows an attacker to manipulate the pack_img argument, resulting in unrestricted file uploads. This flaw exposes affected systems to potenti...

Discovered 16 hours ago

PoC for CVE-2026-82914

Kishan0725Hospital-management-sy...6.9MEDIUM
SQL Injection Vulnerability in kishan0725 Hospital Management Syste...

A security flaw has been identified in version 1.0 of the kishan0725 Hospital Management System, specifically affecting the /search.php file. This vulnerability arises from inadequate input validation in the 'Contact' argument, allowing an attacker to execute SQL injection attacks remotely. The p...

PoC for CVE-2026-82909

QuantumnousNew-api5.3MEDIUM
Session Expiration Vulnerability in QuantumNous new-api API Token H...

The new-api component of QuantumNous contains a vulnerability in its Revoked API Token Handler, allowing attackers to manipulate the system and cause session expiration. This issue arises from an unspecified functionality within the API usage token file, which can be exploited remotely. Affected ...

PoC for CVE-2026-82908

MsiDragon Center9.3CRITICAL
Integer Overflow Vulnerability in MSI Dragon Center's NTIOLib_X64.s...

A vulnerability exists in MSI Dragon Center, found in the MmioWritePath function of the NTIOLib_X64.sys library. This issue arises from improper handling of argument counts and element sizes, leading to integer overflow. The exploit requires local access to the affected system, and while the vuln...

PoC for CVE-2026-82906

SdcbChats6.3MEDIUM
Authenticated Access Vulnerability in sdcb chats by sdcb

A significant security flaw has been identified in sdcb chats versions up to 1.12.0. This vulnerability affects the DownloadPublic function within the Signed File Download Endpoint, specifically in the FileController.cs file. The issue arises due to inadequate authentication checks, allowing unau...

Discovered 17 hours ago

PoC for CVE-2026-82905

SdcbChats5.3MEDIUM
Server-Side Request Forgery in SDCB Chats by SDCB

A vulnerability has been identified in SDCB Chats, specifically in versions up to 1.12.0. The issue resides within the McpController function of the fetch-tools Endpoint, compromising the system's security by allowing unauthorized server-side request forgery. This flaw can be exploited remotely, ...

PoC for CVE-2026-82835

CaoqianmingDjango-vue-admin5.3MEDIUM
Improper Access Control in Django-Vue-Admin by Caoqianming

A vulnerability has been discovered in Django-Vue-Admin version 1.0, where an improper access control issue exists in the '/api/file/' endpoint. The flaw allows remote attackers to manipulate the 'file_id' argument, potentially leading to unauthorized access to sensitive files and data. This vuln...

PoC for CVE-2026-82834

DoccanoOpen Source Annotation...5.3MEDIUM
Improper Access Control in Doccano Open Source Annotation Tools

A security issue has been identified in the Doccano Open Source Annotation Tools, particularly within the Bulk-Delete Endpoint for the LabelList function. This vulnerability allows for improper access control, potentially enabling remote exploitation. The issue affects versions of Doccano up to a...

PoC for CVE-2026-82833

DoccanoOpen Source Annotation...5.3MEDIUM
Improper Access Control in Doccano Open Source Annotation Tools for...

A vulnerability exists in Doccano Open Source Annotation Tools that affects the Project Example Detail Endpoint in versions up to 1.8.5. This flaw allows unauthorized access due to improper access controls in the ExampleDetail function of the endpoint located at /v1/projects/1/examples/. Given th...

Discovered 18 hours ago

PoC for CVE-2026-82821

FLVMetaFlvmeta5.3MEDIUM
Null Pointer Dereference in FLVMeta AMF Object Parsing

A vulnerability exists in FLVMeta, affecting versions up to 1.2.2, specifically within the AMF Object Parsing component. This deficiency enables an attacker to exploit the function amf_object_get located in the src/amf.c file, causing a null pointer dereference. Although the attack can be initiat...

PoC for CVE-2026-82820

NoirotMFlvmeta5.3MEDIUM
Heap-Based Buffer Overflow in FLVMeta by NoirotM

A heap-based buffer overflow vulnerability exists in the AMF string processing function `amf_string_new` of FLVMeta up to version 1.2.2. This flaw arises from improper handling of argument length, allowing attackers to potentially exploit the vulnerability remotely. Although the project maintaine...

PoC for CVE-2026-82818

Dibo-softwareDiboot5.3MEDIUM
Access Control Flaw in dibo-software diboot Affects Tenant Resource...

A significant access control vulnerability exists in dibo-software's diboot version 3.8.0, specifically affecting the Tenant Resource Assignment Handler found in the file /api/iam/tenant/resource. The vulnerability arises from improper validation of the tenantId argument, which could allow attack...

PoC for CVE-2026-82817

Dibo-softwareDiboot5.3MEDIUM
Access Control Vulnerability in dibo-software diboot 3.8.0

A vulnerability exists in dibo-software diboot version 3.8.0, related to the Tenant Administrator Management API. Unauthorized manipulation of the 'tenantId' argument leads to improper access controls, potentially enabling remote attackers to exploit the API without proper authorization. Despite ...

Discovered 19 hours ago

PoC for CVE-2026-82816

Dibo-softwareDiboot5.3MEDIUM
Authorization Bypass Vulnerability in Dibo-Software Diboot 3.8.0

A vulnerability exists in Dibo-Software's Diboot version 3.8.0 involving the AI Session Endpoint located at /api/ai-session/. This issue allows for an authorization bypass, which can be exploited remotely. The nature of this vulnerability could expose sensitive functionalities of the application ...

PoC for CVE-2026-82815

MegaeaseEaseprobe6.9MEDIUM
Access Control Vulnerability in MegaEase EaseProbe Middleware

A vulnerability has been identified in MegaEase EaseProbe up to version 2.3.0 that affects the realIP function in the Middleware component. The flaw involves the improper handling of the X-Forwarded-For/X-Real-IP/True-Client-IP headers, which can lead to unauthorized access. This vulnerability al...

PoC for CVE-2026-82813

Ben GroupTubebuddy For Youtube ...5.3MEDIUM
Data Authenticity Issue in BEN Group TubeBuddy for YouTube Extensio...

A significant vulnerability has been identified in the TubeBuddy for YouTube Extension by BEN Group, affecting versions up to 5.8.4 on Chrome browsers. The flaw resides in the TBGlobal.GetToken function within the tubebuddymaster1.js file, which fails to adequately verify the authenticity of data...

PoC for CVE-2026-82811

Toggl OüToggl Track Extension5.3MEDIUM
Origin Validation Error in Toggl Track Extension by Toggl OÜ

A security vulnerability has been identified in the Toggl Track Extension version 4.11.16 that allows remote attackers to exploit an origin validation error through the postMessage handler. This vulnerability could enable an attacker to manipulate messages coming from unauthorized origins. The ve...

Discovered 20 hours ago

PoC for CVE-2026-76569

Phoca.czPhoca Download Extensi...5.3MEDIUM
Reflected XSS Vulnerability in Phoca Download by Phoca.cz

A reflected XSS vulnerability has been identified in the Phoca Download extension used for Joomla. Malicious actors can exploit this flaw through the search GET parameter, potentially executing arbitrary JavaScript in the context of the user's browser, leading to unauthorized access and data expo...

PoC for CVE-2026-82810

Extension.vn2fa Authenticator Exte...4.8MEDIUM
Information Disclosure in extension.vn 2FA Authenticator Extension ...

A vulnerability has been discovered in the extension.vn 2FA Authenticator Extension version 1.0.0.2, specifically within the Background Service Worker component. The flaw resides in the function chrome.runtime.onMessageExternal.addListener, which fails to properly manage the sender.id argument. T...

PoC for CVE-2026-82809

VidiqVision For Youtube Ext...5.3MEDIUM
Information Disclosure Vulnerability in vidIQ Vision for YouTube Ex...

An information disclosure vulnerability has been identified in the vidIQ Vision for YouTube Extension (version 3.199.0) for Chrome. The flaw resides in the window.addEventListener method utilized by the postMessage handler, allowing an attacker to manipulate the argument 'vidiqEvent' and extract ...

PoC for CVE-2026-82808

Inbox FoundryActiveinbox Extension6.9MEDIUM
Hard-Coded Credentials Vulnerability in Inbox Foundry ActiveInbox E...

A vulnerability has been detected in the Inbox Foundry ActiveInbox Extension for Chrome, which affects versions up to 7.10.24. It involves the improper handling of Google OAuth Client Secret within the file dist/service-worker.production-esm.js. This flaw allows an attacker to manipulate hard-cod...

PoC for CVE-2026-82807

IeungsoftUltra Ramdisk Pro9.3CRITICAL
Local Privilege Escalation Vulnerability in ieungSoft Ultra RAMDisk...

A local privilege escalation vulnerability exists in the ieungSoft Ultra RAMDisk Pro 1.82. The issue is located in the URDSCSI.sys library within the Kernel Driver component, where inadequate privilege management can be exploited. The attack requires local access to the system, and details of the...

Discovered 21 hours ago

PoC for CVE-2026-82805

TyporaTypora5.3MEDIUM
Cross-Site Scripting Vulnerability in Typora's Mermaid Rendering Co...

A cross-site scripting vulnerability exists in Typora versions up to 1.13.8 and 1.14.6, affecting the Mermaid Rendering Engine. This flaw allows for the manipulation of the classDef/style argument, which can be exploited remotely. The vulnerability has been publicly disclosed, and users are advis...

PoC for CVE-2026-82803

ArminkStruct2json6.9MEDIUM
Null Pointer Dereference in Armink Struct2json JSON Deserialization...

A vulnerability exists in the Armink Struct2json library in version 1.0, specifically in the function S2J_STRUCT_GET_string_ELEMENT located in the header file `s2jdef.h`, which is responsible for JSON deserialization. This flaw arises from the manipulation of the argument `valuestring`, leading t...

PoC for CVE-2026-82802

NasaEarthdata-search6.9MEDIUM
Server-Side Request Forgery in NASA Earthdata-Search by NASA

A vulnerability has been identified in NASA's Earthdata-Search version 1.0.0 related to the OpenSearchGranuleSearchLambda function, located in the handler.js file. This flaw allows an attacker to manipulate the openSearchOsdd argument, potentially leading to a server-side request forgery (SSRF). ...

PoC for CVE-2026-82801

NasaEarthdata-search6.9MEDIUM
Server-Side Request Forgery in NASA Earthdata-Search

A vulnerability exists in the scaleImage function within the serverless/src/scaleImage/handler.js file of NASA's Earthdata-Search product version 1.0.0. This flaw allows a remote attacker to exploit the scale Endpoint, potentially leading to unauthorized server-side request forgery (SSRF). The ex...

Discovered 22 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-82703

EdimaxBr-6214k5.1MEDIUM
OS Command Injection Vulnerability in Edimax BR-6214K Router

A security vulnerability has been identified in the Edimax BR-6214K router, specifically affecting the asp_setPing endpoint within the file www/ping.asp. This flaw allows an attacker to manipulate the pingstr argument, enabling remote OS command injection. The exploitation of this vulnerability p...

PoC for CVE-2026-82702

EdimaxBr-6214k5.1MEDIUM
OS Command Injection Vulnerability in Edimax BR-6214K Router

A significant OS command injection vulnerability exists in the Edimax BR-6214K Router, specifically within the www/wlanMP.asp file of the asp_WlanMP Endpoint. By manipulating the eatFunc argument, an attacker can exploit this flaw remotely, potentially allowing unauthorized access to execute syst...

PoC for CVE-2026-82701

Code-projectsOnline Shopping System6.9MEDIUM
SQL Injection Vulnerability in Online Shopping System by Code-Projects

A vulnerability exists in the Online Shopping System version 1.0, specifically within the Search Functionality component. An attacker can manipulate the 'keyword' parameter in the /action.php file, leading to a SQL injection exploit. This vulnerability can be triggered remotely, making it crucial...

PoC for CVE-2026-82700

Code-projectsOnline Shopping System5.3MEDIUM
Cross-Site Scripting Vulnerability in Online Shopping System by Cod...

A cross-site scripting vulnerability has been identified in the Online Shopping System 1.0 developed by Code-Projects, specifically within the Newsletter Subscription feature accessed via the /offersmail.php file. An attacker can exploit this vulnerability by manipulating the 'email' argument, po...

Discovered 23 hours ago

PoC for CVE-2026-82699

SambitrajStudent Management System5.1MEDIUM
Cleartext Storage Vulnerability in sambitraj Student Management System

A vulnerability exists within the sambitraj Student Management System, specifically in the Password Handler component of the aca.sql file. This flaw allows for the manipulation of the Password argument, resulting in the potential cleartext storage of sensitive user information. The vulnerability ...

PoC for CVE-2026-82698

SambitrajStudent-management-system6.9MEDIUM
Default Password Vulnerability in Student-Management-System by Samb...

The sambitraj Student-Management-System is affected by a vulnerability that allows attackers to exploit a default password found in the aca.sql file. This security flaw enables unauthorized remote access to the system. As the exploit is now publicly available, it presents a significant risk to us...

PoC for CVE-2026-82697

SambitrajStudent-management-system6.3MEDIUM
Session Cookie Vulnerability in sambitraj Student-Management-System

A vulnerability has been identified in the sambitraj Student-Management-System that affects the session management functionality. Specifically, the 'session_start' function does not enforce the 'HttpOnly' flag on session cookies, exposing users to potential session hijacking. This vulnerability c...

PoC for CVE-2026-82696

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A security vulnerability exists within version 1.0 of the itsourcecode Sales and Inventory System, specifically in the /pages/inv_searchfrm.php file. This flaw allows attackers to manipulate input arguments, leading to potential SQL injection attacks. These attacks can be executed remotely, makin...

Discovered 1 day ago

PoC for CVE-2026-82695

TendaAc1810CRITICAL
Telnet Handler Vulnerability in Tenda AC18 Routers

A security flaw has been identified in Tenda AC18 routers where the Telnet handler is susceptible to missing authentication. This vulnerability allows attackers to access critical functions of the router remotely, making it possible to exploit the device without authentication. The exploit has be...

PoC for CVE-2026-82694

TendaAc120610CRITICAL
Missing Authentication in Tenda AC1206 Web UI

A security vulnerability has been detected in the Tenda AC1206 device, specifically within the Web User Interface (UI) where the R7WebsSecurityHandler function lacks proper authentication checks. This flaw enables remote attackers to gain unauthorized access, potentially leading to exploitation o...

PoC for CVE-2026-82693

TendaAc120610CRITICAL
Missing Authentication in Tenda AC1206 Web UI Telnet Functionality

A significant security vulnerability has been identified in the Tenda AC1206's Web UI, specifically affecting the Telnet function. This flaw allows unauthorized remote access to the system through the /goform/telnet interface due to inadequate authentication measures. As a result, attackers can e...