Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2022-22965

VmwareSpring Framework🟣 EPSS 100%9.8CRITICAL
Remote Code Execution Vulnerability in Spring Framework Products by...

A vulnerability in the Spring Framework could allow unauthorized remote code execution (RCE) when an application is running on JDK 9+ with Spring MVC or Spring WebFlux deployed as a WAR on a Tomcat server. If the application is executed as a Spring Boot executable JAR, it is not susceptible to th...

PoC for CVE-2026-3891

WordPressPix For WooCommerce9.8CRITICAL
Arbitrary File Upload Vulnerability in Pix for WooCommerce Plugin b...

The Pix for WooCommerce plugin for WordPress is susceptible to arbitrary file uploads due to a lack of capability checks and insufficient file type validation within the 'lkn_pix_for_woocommerce_c6_save_settings' function. This vulnerability exists across all versions through 1.5.0. An unauthenti...

PoC for CVE-2026-15409

SonicwallSma1000🟣 EPSS 78%10CRITICAL
Server-Side Request Forgery in SonicWall SMA1000 Appliance Work Pla...

A Server-side Request Forgery (SSRF) vulnerability has been identified within the Work Place interface of the SMA1000 Appliance. This security flaw allows a remote attacker, without authentication, to exploit the appliance, enabling it to make requests to unintended and potentially malicious loca...

PoC for CVE-2026-26114

MicrosoftMicrosoft Sharepoint E...8.8HIGH
Remote Code Execution Vulnerability in Microsoft Office SharePoint

In Microsoft Office SharePoint, a vulnerability exists that enables an authorized attacker to manipulate untrusted data, leading to potential remote code execution. This flaw allows the attacker to send serialized data that can be improperly processed by the SharePoint server. If successfully exp...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2023-30547

PatriksimekVm2🟣 EPSS 72%9.8CRITICAL
Sandbox Escape in vm2

The vm2 sandbox environment, designed for executing untrusted Node.js code, contains a vulnerability in its exception handling mechanism. Versions up to 3.9.16 are susceptible to an attack that allows an unsanitized host exception to be raised within the `handleException()` function. This flaw ca...

Discovered 14 minutes ago

PoC for CVE-2023-36874

MicrosoftWindows 10 Version 1809🟣 EPSS 43%7.8HIGH
Windows Error Reporting Service Elevation of Privilege Vulnerability

The Windows Error Reporting Service contains a vulnerability that can allow attackers to elevate their privileges. This weakness may enable an unauthorized user to take control of affected systems, potentially leading to further exploits. It is essential for users to apply security updates and pa...

Discovered 28 minutes ago

PoC for CVE-2026-9848

WordPressCustomer Support Ticke...7.5HIGH
SQL Injection Vulnerability in WP Ticket Plugin for WordPress

The WP Ticket plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit SQL Injection through the search query parameter. This occurs when the plugin processes search requests without properly sanitizing inputs, leading to potential exposure of sensitive informatio...

Discovered 55 minutes ago

PoC for CVE-2026-43637

PreferredaiCornac8.8HIGH
Path Traversal Vulnerability in Cornac Library by PreferredAI

The Cornac library prior to version 2.6.0 is susceptible to a path traversal vulnerability, enabling malicious actors to exploit file writing practices. By delivering a specially crafted TAR archive that includes '../' sequences or absolute path definitions, attackers can manipulate the _extract_...

Discovered 2 hours ago

PoC for CVE-2026-63720

KoxudaxiDatamodel-code-generator7.5HIGH
Code Injection Vulnerability in datamodel-code-generator by koxudaxi

The datamodel-code-generator prior to version 0.70.0 is susceptible to a code injection issue that enables attackers with control over input schemas to execute arbitrary Python code. By providing a malicious customBasePath value—which includes embedded newlines and a dot-free Python expression—an...

PoC for CVE-2026-65321

Laughingman7743Pyathena9.3CRITICAL
SQL Injection Vulnerability in PyAthena Product by LaughingMan

PyAthena prior to version 3.35.4 is susceptible to SQL injection due to improper quote-escaping in the DefaultParameterFormatter.format() function. This flaw enables unauthenticated attackers to inject arbitrary SQL commands, particularly through DELETE and CTAS SQL statements. An exploit can occ...

Discovered 3 hours ago

PoC for CVE-2026-18616

Gl-inetGl-mt30009.3CRITICAL
Command Injection Vulnerability in GL-iNet GL-MT3000 Products

A command injection vulnerability has been discovered in the GL-iNet GL-MT3000, specifically affecting versions up to 4.4.5. The issue arises from improper handling of the 'public_key' argument in the 'server.set_peer' function of the '/cgi-bin/glc' file within the 'wg-server.so' native plugin. T...

PoC for CVE-2026-18615

Gl-inetGl-mt30009.3CRITICAL
Command Injection Vulnerability in GL-iNet GL-MT3000 by GL-iNet

A command injection vulnerability exists in the GL-iNet GL-MT3000 device, specifically within the wg-server.generate_publickey function found in the /cgi-bin/glc path of the wg-server.so Native Plugin. By manipulating the private_key argument, an attacker could execute arbitrary commands on the s...

PoC for CVE-2026-18614

Gl-inetGl-mt30009.3CRITICAL
Command Injection in GL-iNet GL-MT3000's Native Plugin

A command injection vulnerability exists in the GL-iNet GL-MT3000's s2s.so Native Plugin, specifically in the s2s.enable_echo_server function. This vulnerability allows attackers to manipulate the 'port' argument, enabling remote code execution through crafted input. The risk is heightened as the...

PoC for CVE-2026-18613

Gl-inetGl-mt30009.3CRITICAL
Injection Vulnerability in GL-iNet GL-MT3000 Plugins

A security issue has been identified in GL-iNet's GL-MT3000 router affecting versions up to 4.4.5, specifically within the 'plugins.set_config' function located in the '/cgi-bin/glc' file of the 'plugins.so' native plugin. This vulnerability enables attackers to perform remote injection by manipu...

Discovered 4 hours ago

PoC for CVE-2026-18612

Gl-inetGl-mt30009.3CRITICAL
Command Injection Vulnerability in GL-iNet GL-MT3000

A vulnerability in the GL-iNet GL-MT3000 router has been identified that allows for command injection through the plugins.so Native Plugin. The flaw resides in the manipulation of the functions 'plugins.remove_package' and 'plugins.install_package' within the /cgi-bin/glc file. This issue can be ...

PoC for CVE-2026-18607

WavlinkWn5728.7HIGH
Stack-based Buffer Overflow in Wavlink Routers

A security vulnerability has been identified in several Wavlink routers where a stack-based buffer overflow occurs in the upload.cgi file due to improper handling of the HTTP_COOKIE argument in the strcpy function. This flaw allows an attacker to remotely execute an exploit, which could lead to u...

Discovered 5 hours ago

PoC for CVE-2026-18606

RazerRzupdateservice8.5HIGH
Privilege Escalation in Razer RzUpdateService Version 1.10.14.0

A vulnerability in Razer's RzUpdateService version 1.10.14.0 was discovered that affects the Named Pipe Handler component. This security issue involves manipulations of the lpThreadParameter argument, which can lead to improper privilege management. Attackers with local access could exploit this ...

PoC for CVE-2026-67612

OpenemrOpenemr4.8MEDIUM
Stored Cross-Site Scripting Vulnerability in OpenEMR Patient Portal...

OpenEMR versions up to 8.2.0 are susceptible to a stored cross-site scripting (XSS) vulnerability found in the patient portal template system. Authenticated administrators can inadvertently introduce malicious HTML and JavaScript payloads through the template save mode, which inadequately filters...

PoC for CVE-2026-67611

OpenemrOpenemr8.6HIGH
Authentication Bypass in OpenEMR by OpenEMR Inc.

OpenEMR versions until 8.2.0 exhibit a vulnerability that allows attackers with valid user credentials to bypass multi-factor authentication. This is accomplished by exploiting an unauthenticated client registration endpoint as part of the OAuth2 password grant flow. By registering an OAuth2 clie...

PoC for CVE-2026-67610

OpenemrOpenemr8.6HIGH
Improper Authentication in OpenEMR OAuth2 Client Registration by Op...

OpenEMR versions up to 8.2.0 are susceptible to an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint. This flaw allows unauthenticated attackers to register a malicious client by submitting a self-generated RSA keypair through the jwks field. Once an adminis...

PoC for CVE-2026-18605

CheckmalAppcheck Pro7.3HIGH
Uncontrolled Search Path Issue in CheckMAL AppCheck Pro Software

A security flaw has been identified in CheckMAL AppCheck Pro version 3.1.43.10, stemming from an unknown function within the AppCheckD.sys library, which is part of the Kernel Mini-Filter Driver. This vulnerability allows for an uncontrolled search path that could be exploited through local manip...

PoC for CVE-2026-39932

OpenemrOpenemr9.4CRITICAL
Remote Code Execution Vulnerability in OpenEMR by OpenEMR

OpenEMR versions prior to 8.2.0 are susceptible to a remote code execution vulnerability involving the document category tree component. Authenticated administrators can exploit this flaw by injecting malicious PHP payloads into the categories database table. Attackers may manipulate the id colum...

PoC for CVE-2026-39931

OpenemrOpenemr8.6HIGH
SQL Injection Vulnerability in OpenEMR by OpenEMR Inc.

OpenEMR versions up to 8.2.0 contain a critical SQL injection vulnerability in the backup configuration import feature. This vulnerability enables attackers with administrative privileges to upload maliciously crafted SQL files, leading to unauthorized execution of arbitrary Data Definition Langu...

PoC for CVE-2026-41453

KrayinLaravel-crm8.7HIGH
Blind SQL Injection Vulnerability in Krayin CRM by Krayin

Krayin CRM versions prior to 2.2.4 are susceptible to a blind SQL injection vulnerability found in the leads DataGrid. This issue arises when authenticated users manipulate the 'rotten_lead[in]' query parameter, allowing them to inject arbitrary SQL into a HAVING clause. The vulnerability stems f...

PoC for CVE-2026-18604

TextplusText Message And Call App4.8MEDIUM
Improper Export of Android Application Components in textPlus App b...

A vulnerability found in the textPlus Text Message and Call App on Android, specifically impacting version 8.3.5, allows for improper export of application components through the DialerActivity. This security flaw necessitates local access to exploit and can lead to unauthorized access to sensiti...

PoC for CVE-2026-41452

KrayinLaravel-crm9.3CRITICAL
Missing Authentication Vulnerability in Krayin CRM by Krayin

Krayin CRM version 2.2.4 is susceptible to a vulnerability in its installer middleware that enables unauthorized remote attackers to compromise the primary administrator account. By crafting a specific HTTP POST request with an X-Requested-With: XMLHttpRequest header, attackers can circumvent the...

Discovered 6 hours ago

PoC for CVE-2026-39987

Marimo-teamMarimo🟣 EPSS 97%9.3CRITICAL
Pre-Authentication Remote Code Execution in Marimo Python Notebook

Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...

PoC for CVE-2026-18602

Gl.inetGl-mt30009.3CRITICAL
Command Injection Vulnerability in GL.iNet GL-MT3000 Router

A command injection vulnerability exists in the GL.iNet GL-MT3000 router's ovpn-client native plugin. This vulnerability is triggered when an attacker manipulates the Hostname argument within the ovpn-client.get_recommend_config function. The flaw allows for remote exploitation, enabling unauthor...

PoC for CVE-2026-33937

Handlebars-langHandlebars.js9.8CRITICAL
Remote Code Execution Vulnerability in Handlebars by Handlebars.js

In Handlebars versions 4.0.0 through 4.7.8, a vulnerability exists where `Handlebars.compile()` can accept a pre-parsed AST object directly. This leads to the potential injection of arbitrary JavaScript into the generated code because the `value` field of a `NumberLiteral` AST node is emitted dir...

PoC for CVE-2025-29927

VercelNext.js🟣 EPSS 99%9.1CRITICAL
Authorization Bypass in Next.js Framework by Vercel

A security flaw exists in the Next.js framework that allows an attacker to bypass authorization checks if such checks are implemented in middleware. This vulnerability arises in versions prior to 14.2.25 and 15.2.3. To mitigate risk, it is recommended to restrict incoming requests that include th...

Discovered 8 hours ago

PoC for CVE-2026-67609

Telenia SoftwareTvox8.5HIGH
Privilege Escalation Vulnerability in Telenia Software TVox Products

An insecure sudoers configuration in Telenia Software TVox versions 26.5.3 and earlier (including 24.9.21 and prior) allows privileged elevation by users with access to the apache account. This loophole enables attackers to execute arbitrary commands as root without a password due to the NOPASSWD...

PoC for CVE-2026-67608

Telenia SoftwareTvox8.6HIGH
OS Command Injection Vulnerability in Telenia Software TVox

The TVox versions 26.5.3 and earlier, as well as 24.9.21 and prior, contain a significant OS command injection flaw located in the action_audio.php file. This vulnerability allows authenticated attackers to execute arbitrary operating system commands by manipulating the unsanitized 'pid' paramete...

PoC for CVE-2026-64827

Telenia SoftwareTvox9.3CRITICAL
Authentication Bypass Vulnerability in Telenia Software TVox

An authentication bypass vulnerability exists in Telenia Software TVox versions 26.5.3 and earlier, as well as 24.9.21 and prior. The flaw is located in the set_env.php file, specifically within the redirectToLoginAdminIRequestHaveAccessToken() function. This function improperly derives the curre...

PoC for CVE-2026-18601

Gl.inetGl-mt30009.3CRITICAL
Command Injection Vulnerability in GL.iNet GL-MT3000 Router

A command injection vulnerability has been identified in the GL.iNet GL-MT3000 router, specifically affecting the ovpn-client.check_config function within the /cgi-bin/glc of the ovpn-client.so Native Plugin. By manipulating the argument 'filename', an attacker can exploit this vulnerability to e...

PoC for CVE-2026-18600

Gl.inetGl-mt30008.7HIGH
Command Injection Vulnerability in GL.iNet GL-MT3000 Network Component

A vulnerability has been identified in the GL.iNet GL-MT3000 device, specifically within the Network Lua RPC Plugin. The flaw lies in the handling of the 'switch' argument in the network.switch_info and network.switch_status functions. This weakness may allow an attacker to execute arbitrary comm...

PoC for CVE-2026-52887

NocobaseNocobase10CRITICAL
SQL Injection Vulnerability in NocoBase AI-Powered Platform

NocoBase, an AI-powered no-code/low-code platform, has a vulnerability in versions prior to 2.0.61 due to an improper handling of input parameters in the notification API. The GET request to /api/myInAppChannels:list allows authenticated users to inject unvalidated input into SQL commands. This o...

Discovered 9 hours ago

PoC for CVE-2026-63223

Codeigniter4Codeigniter49.8CRITICAL
File Upload Vulnerability in CodeIgniter PHP Framework

CodeIgniter, a popular PHP web framework, has a vulnerability that arises from inadequate validation of uploaded files. Before version 4.7.4, the upload validation rules, specifically 'is_image' and 'mime_in', fail to enforce safe client filename extensions independently. This oversight allows re...

PoC for CVE-2026-12940

IBMLangflow Oss9.8CRITICAL
Remote Code Execution Vulnerability in IBM Langflow

IBM Langflow OSS versions 1.0.0 through 1.10.1 are exposed to a remote code execution vulnerability due to improper handling of environment variables in the MCP (Model Context Protocol) stdio launcher. Specifically, the vulnerability lies in the failure of the software to include critical variabl...

PoC for CVE-2026-18599

Gl.inetGl-mt30008.6HIGH
Command Injection Vulnerability in GL.iNet GL-MT3000 Router

A command injection vulnerability has been identified in the GL.iNet GL-MT3000 router, specifically affecting version 4.4.5. This flaw resides within the Logread Lua RPC Plugin, particularly in the logread.set_config function. An attacker can manipulate the record_size argument in a way that allo...

Discovered 10 hours ago

PoC for CVE-2026-18598

Gl.inetGl-mt30008.7HIGH
Command Injection Vulnerability in GL.iNet GL-MT3000 Router

A command injection vulnerability exists in the Logread Lua RPC plugin of GL.iNet GL-MT3000 routers, specifically in the logread.get_system_log function. This flaw allows remote attackers to manipulate parameters, leading to unauthorized command execution on the device. The exploit is publicly av...

Discovered 12 hours ago

PoC for CVE-2026-1337

Neo4jEnterprise Edition1.1LOW
Cross-Site Scripting Vulnerability in Neo4j Enterprise and Communit...

A cross-site scripting (XSS) vulnerability exists in the query log handling of Neo4j Enterprise and Community Editions prior to version 2026.01. Due to insufficient escaping of Unicode characters, users may inadvertently expose themselves to XSS attacks when logs are opened in tools that render t...

Discovered 13 hours ago

PoC for CVE-2026-18593

VxcontrolPentagi6.3MEDIUM
Tool Management Protocol Handler Vulnerability in vxcontrol PentAGI

A vulnerability has been identified in the vxcontrol PentAGI product up to version 2.1.0, specifically affecting the Tool Management Protocol Handler. This vulnerability resides within the file backend/pkg/templates/prompts/pentester.tmpl and can potentially allow for remote exploitation leading ...

Discovered 14 hours ago

PoC for CVE-2026-18592

osCommerceOscommerce5.1MEDIUM
SQL Injection Vulnerability in osCommerce Email Template Configuration

A security vulnerability has been identified in osCommerce version 4.14.63493, specifically within the EmailController function located in app/lib/backend/controllers/EmailController.php. This flaw allows an attacker to exploit the email_templates_key argument, leading to SQL injection. The attac...

PoC for CVE-2026-18591

MeeshoOnline Shopping App2.4LOW
Cleartext Storage Vulnerability in Meesho Online Shopping App on An...

A vulnerability in the Meesho Online Shopping App for Android, specifically in the com.meesho.supply component, allows for the unsafe handling of sensitive user data. This weakness results in the cleartext storage of personal information such as user ID, phone number, email address, and name, whi...

Discovered 15 hours ago

PoC for CVE-2026-16565

WordPressDokan: Ai Powered WooC...4.3MEDIUM
Product Ownership Verification Flaw in Dokan WooCommerce Multivendo...

The Dokan WooCommerce Multivendor Marketplace Solution plugin prior to version 5.0.9 is susceptible to an authorization bypass vulnerability. This flaw occurs due to the plugin's failure to verify product ownership on its product-attribute REST write endpoints. As a result, users with Dokan vendo...

PoC for CVE-2026-16539

WordPressSm Page Duplicator8.1HIGH
SQL Injection Vulnerability in Page Duplicator Plugin for WordPress

The Page Duplicator plugin for WordPress, up to version 1.0.0, contains an SQL injection vulnerability due to insufficient sanitization and escaping of user inputs during the page duplication process. This flaw allows users with the Editor role and higher to execute malicious SQL queries, potenti...

PoC for CVE-2026-16564

WordPressDokan: Ai Powered WooC...4.3MEDIUM
Order Status Modification Vulnerability in Dokan by WeDevs

The Dokan plugin for WordPress prior to version 5.0.9 contains a significant access control vulnerability. This flaw does not verify the ownership of orders on a REST endpoint responsible for bulk order-status changes, which can permit users holding a Dokan vendor account to alter the status of a...

PoC for CVE-2026-16563

WordPressAcademy Lms6.5MEDIUM
Insecure API Access in Academy LMS Plugin for WordPress

The Academy LMS WordPress plugin versions before 3.8.3 contains a vulnerability where the REST API does not properly verify course enrollment or status of lesson publication. This oversight allows users with a Subscriber-level account to access the content of lessons they are not enrolled in. Thi...

PoC for CVE-2026-16572

WordPressLogmytrip8.6HIGH
SQL Injection Vulnerability in LogMyTrip WordPress Plugin

The LogMyTrip plugin for WordPress, up to version 1.9, is susceptible to SQL injection attacks due to its failure to properly sanitize and escape user input taken from cookies before incorporating it into SQL queries. This vulnerability permits unauthenticated users to manipulate the database thr...