Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-77392

SourcecodesterDynamic Input Field Ge...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Dynamic Input Field G...

A vulnerability exists in the SourceCodester Dynamic Input Field Generator where the 'saveUser' function within the 'submit.php' file fails to properly validate input. Specifically, the manipulation of the 'Researcher' argument allows for SQL injection attacks, which can be executed remotely. Giv...

PoC for CVE-2026-77391

SourcecodesterDynamic Input Field Ge...5.3MEDIUM
Cross-Site Request Forgery Vulnerability in SourceCodester Dynamic ...

A security flaw has been identified in the SourceCodester Dynamic Input Field Generator, which utilizes HTML, CSS, and PHP. This vulnerability allows an attacker to manipulate a specific function, resulting in cross-site request forgery (CSRF) attacks that can be executed remotely. Exploiting thi...

Discovered 7 hours ago

PoC for CVE-2026-53804

Centuran ConsultingOtrs Community Edition8.6HIGH
OS Command Injection Vulnerability in OTRS Community Edition PGP En...

The OTRS Community Edition is affected by an OS command injection flaw within its PGP encryption module. This vulnerability allows administrators to execute arbitrary commands on the operating system by crafting specific values for the PGP binary path and command options. Because user-supplied co...

Discovered 10 hours ago

PoC for CVE-2026-77148

ComfastCf-n1-s9.4CRITICAL
Stack-based Buffer Overflow in Comfast CF-N1-S Web Management

A stack-based buffer overflow vulnerability exists in the Comfast CF-N1-S Web Management interface within the function sub_44B50C of the mbox-config component. This issue can be exploited remotely, allowing attackers to manipulate certain inputs to overflow the stack, potentially leading to arbit...

Discovered 11 hours ago

PoC for CVE-2026-77036

ElunezEladmin5.3MEDIUM
Improper Authorization in elunez eladmin by Elunez

A vulnerability exists in elunez eladmin versions up to 2.7, specifically within the EmailController, AliPayController, GeneratorController, and GenConfigController functions. This flaw allows for improper authorization that can be exploited remotely. The vulnerability was reported to the project...

PoC for CVE-2026-72844

LeanproverLean46.8MEDIUM
Type Checking Bypass in Lean 4 Kernel by Lean Prover

The Lean 4 kernel fails to verify the structure within a projection expression aligns with the projected value's type. Consequently, the function environment::add_inductive does not properly type check nested inductive applications. This oversight permits a metaprogram to construct an ill-typed n...

PoC for CVE-2026-72844

LeanproverLean46.8MEDIUM
Type Checking Bypass in Lean 4 Kernel by Lean Prover

The Lean 4 kernel fails to verify the structure within a projection expression aligns with the projected value's type. Consequently, the function environment::add_inductive does not properly type check nested inductive applications. This oversight permits a metaprogram to construct an ill-typed n...

PoC for CVE-2026-77031

TendaCh225.3MEDIUM
Command Injection Vulnerability in Tenda CH22 Router

A command injection vulnerability exists in the Tenda CH22 router, specifically within the function formcreateFileName of the file /goform/formcreateFileName. An attacker can manipulate the argument fileNameMit, enabling unauthorized execution of commands remotely. The potential for exploitation ...

Discovered 12 hours ago

PoC for CVE-2026-77025

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A SQL injection vulnerability exists in the itsourcecode Hospital Management System version 1.0, specifically within the /viewappointmentpending.php file. This flaw allows attackers to manipulate the 'delid' argument, enabling them to execute unauthorized SQL queries. The vulnerability may be exp...

PoC for CVE-2026-77022

ComfastCf-n1-s9.4CRITICAL
Stack-based Buffer Overflow Vulnerability in Comfast CF-N1-S by Com...

A security flaw has been identified in Comfast CF-N1-S version 2.6.0.1, specifically in the SSID Configuration component. This vulnerability resides in the function sub_44B438 within the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid. By manipulating the ssid argument, an attacker can tr...

PoC for CVE-2026-77020

CodeastroApartment Visitor Mana...6.9MEDIUM
SQL Injection Vulnerability in CodeAstro Apartment Visitor Manageme...

A SQL injection vulnerability exists in the CodeAstro Apartment Visitor Management System version 1.0, specifically in the password-recovery.php file. This security flaw allows an attacker to manipulate the 'email' parameter, potentially leading to unauthorized data access. The exploitation can b...

PoC for CVE-2026-77019

CodeastroApartment Visitor Mana...6.9MEDIUM
SQL Injection Vulnerability in CodeAstro Apartment Visitor Manageme...

A vulnerability exists in the CodeAstro Apartment Visitor Management System version 1.0, specifically within the file /apartment-visitor/forgotpw.php. An improperly handled argument 'secode' allows a SQL injection attack, enabling remote execution of unauthorized SQL commands. This vulnerability ...

Discovered 13 hours ago

PoC for CVE-2026-77004

ComfastCf-n1-s5.3MEDIUM
Command Injection Vulnerability in Comfast CF-N1-S Device

A command injection vulnerability exists in the Comfast CF-N1-S version 2.6.0.1, specifically within the sprintf function of the /cgi-bin/mbox-config?method=SET&section=ptest_sn endpoint. By manipulating the argument 'sn', an attacker can execute arbitrary commands remotely, leading to potential ...

PoC for CVE-2026-76998

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A security vulnerability has been identified in the SourceCodester Simple Online Food Ordering System version 1.0. An SQL injection flaw exists in the /admin/ajax.php file, specifically in the delete_category action. This vulnerability allows attackers to manipulate the ID argument, potentially l...

PoC for CVE-2026-76997

SourcecodesterSimple Online Food Ord...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A vulnerability exists in SourceCodester's Simple Online Food Ordering System version 1.0 that exposes the application to SQL injection attacks through the 'save_category' action in the 'ajax.php' file. This flaw allows a remote attacker to manipulate the 'ID' argument, facilitating unauthorized ...

Discovered 14 hours ago

PoC for CVE-2026-76996

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A significant security flaw has been identified in the SourceCodester Simple Online Food Ordering System version 1.0, specifically within the /fos/admin/view_order.php file. This vulnerability involves a manipulation of the 'ID' argument, which can lead to SQL injection attacks. Such exploitation...

PoC for CVE-2026-76995

SourcecodesterSimple Online Food Ord...5.1MEDIUM
Unrestricted File Upload Vulnerability in SourceCodester Simple Onl...

A vulnerability has been discovered in the SourceCodester Simple Online Food Ordering System that allows for unrestricted file uploads through manipulation of the img argument in the /admin/ajax.php?action=save_menu endpoint. This flaw can be exploited remotely, potentially allowing attackers to ...

PoC for CVE-2026-76993

GreydglPentestgpt2.3LOW
Web-Page Crawling Vulnerability in GreyDGL PentestGPT

A security vulnerability exists in GreyDGL's PentestGPT, specifically affecting the web-page crawling component. This flaw allows attackers to manipulate the Traceback argument, enabling remote code injection. Although the complexity of the exploit is considered high, its potential for exploitati...

PoC for CVE-2026-76991

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A serious SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0, specifically within the /viewappointmentapproved.php file. This flaw allows an attacker to manipulate the 'delid' argument, potentially leading to unauthorized access to the database. Remote explo...

Discovered 15 hours ago

PoC for CVE-2026-76990

Code-projectsSimple Inventory System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Simple Inventory System

A remote SQL injection vulnerability is present in the Code-Projects Simple Inventory System 1.0, specifically in the /delete.php file. By manipulating the argument ID, an attacker can execute unauthorized SQL commands against the database, potentially leading to unauthorized data exposure or mod...

Discovered 16 hours ago

PoC for CVE-2026-76989

Liftoff-srCipster6.9MEDIUM
Remote Out-of-Bounds Read in liftoff-sr CIPster TCP Encapsulation R...

A security vulnerability exists within the liftoff-sr CIPster product that affects the TCP Encapsulation Receive Path. Specifically, an unknown function in the source file source/src/enet_encap/encap.cc allows for out-of-bounds reading due to improper input validation. This flaw can be exploited ...

PoC for CVE-2026-76988

Liftoff-srCipster6.9MEDIUM
Out-of-Bounds Read Vulnerability in Liftoff-sr CIPster by Liftoff-sr

A vulnerability has been identified in the Liftoff-sr CIPster, specifically in the function CipConnMgrClass::forward_open located in cipconnectionmanager.cc. This can be exploited through manipulation of the product_code_ argument, leading to potential out-of-bounds read conditions. The vulnerabi...

PoC for CVE-2026-76987

Liftoff-srCipster6.9MEDIUM
Memory Corruption Vulnerability in Generic Attribute Logic of lifto...

A significant vulnerability has been identified in the liftoff-sr CIPster's Generic Attribute Logic, specifically in the CipAttribute::GetAttrData and CipAttribute::SetAttrData functions located in the ciptypes.h file. This flaw can lead to memory corruption through manipulation, enabling potenti...

Discovered 23 hours ago

PoC for CVE-2026-74992

WordPressKirki6.8MEDIUM
Arbitrary File Upload Vulnerability in Kirki WordPress Plugin by Ge...

The Kirki WordPress plugin, prior to version 6.2.3, features a vulnerability where file validation for user-uploaded archives is inadequate. Users with the Editor role can upload malicious files, as the plugin fails to securely handle these uploads by not correctly removing all unnecessary files ...

PoC for CVE-2026-75860

WordPressJson Options9.8CRITICAL
Unauthenticated Access Flaw in JSON Options WordPress Plugin

The JSON Options WordPress plugin prior to version 0.0.4 contains a significant security flaw that lacks proper capability checks and nonce verification. This oversight permits unauthenticated users to trigger actions that alter arbitrary WordPress options on every request. By exploiting this vul...

PoC for CVE-2026-19615

WordPressAdmin And Site Enhance...6.8MEDIUM
Improper File Handling in Admin and Site Enhancements Plugin for Wo...

The Admin and Site Enhancements (ASE) plugin for WordPress prior to version 9.0.1 presents a significant security risk due to inadequate sanitization of uploaded SVG files. This vulnerability allows users who have been granted upload permissions to store malicious files that can execute JavaScrip...

PoC for CVE-2026-19699

WordPressGutenkit2.7LOW
Improper Access Control in GutenKit Plugin for WordPress

The GutenKit plugin for WordPress, prior to version 2.5.0, lacks adequate capability verification on certain REST API endpoints. This oversight allows users with Contributor privileges and higher to access sensitive mailing-list audience metadata linked to the site's marketing account. Without pr...

PoC for CVE-2026-19697

WordPressGutenkit6.8MEDIUM
Stored Cross-Site Scripting Vulnerability in GutenKit WordPress Plugin

The GutenKit WordPress plugin prior to version 2.5.0 is vulnerable due to inadequate sanitization of uploaded SVG files, particularly on various upload paths. This flaw allows users with file upload permissions, such as Authors, to upload malicious SVG files. Consequently, these files can initiat...

PoC for CVE-2026-15049

WordPressDepicter — Popup & Sli...7.2HIGH
File Upload Vulnerability in Depicter Popup & Slider Builder by Wor...

The Depicter — Popup & Slider Builder WordPress plugin, prior to version 4.8.0, is susceptible to a file upload vulnerability. The plugin does not appropriately validate the type of files uploaded through its import feature, allowing users with editor-level access to upload malicious files, inclu...

PoC for CVE-2026-13405

WordPressRoyal Addons For Eleme...6.6MEDIUM
Arbitrary Code Execution Vulnerability in Royal Addons for Elemento...

The Royal Addons for Elementor plugin for WordPress prior to version 1.7.1066 contains a critical vulnerability that fails to properly sanitize custom widget markup when writing to a file. This oversight can be exploited by users with the manage_options capability, and in WordPress Multisite envi...

Discovered 1 day ago

PoC for CVE-2026-76800

DeDeCMSDedecms5.3MEDIUM
Unrestricted Upload Vulnerability in DeDeCMS 3 by DeDeCMS

A vulnerability exists in DeDeCMS 3 that allows an attacker to manipulate the 'uploadfile' argument within the /include/dialog/select_media_post.php file. This flaw can result in unrestricted file uploads, which can be exploited remotely. The availability of this exploit has been documented, rais...

PoC for CVE-2026-76799

Code-projectsLogin Registration System6.9MEDIUM
SQL Database Backup Handler Vulnerability in Code-Projects Login Re...

A vulnerability in the Login Registration System version 1.0 from Code-Projects has been identified, impacting the SQL Database Backup Handler. This issue allows unauthorized access to files or directories through manipulation of the /loginsystem/database/login_registration_system.sql file. The v...

PoC for CVE-2026-67919

Halo DevHalo9.8CRITICAL
Arbitrary Code Execution Vulnerability in Halo by Halo Dev

A vulnerability in Halo version 2.25.4 permits remote attackers to execute arbitrary code. This security flaw arises from the PluginEndpoint.java and installFromUri method, along with the DefaultPluginApplicationContextFactory components. Exploitation of this vulnerability could enable unauthoriz...

PoC for CVE-2026-76795

AeternalabshqPullmd6.9MEDIUM
Server-Side Request Forgery Vulnerability in AeternaLabsHQ PullMD R...

A critical vulnerability has been identified in the PullMD product from AeternaLabsHQ, specifically within the REST API Endpoint feature. The issue arises from the improper handling of the 'url' argument in the API, which can be exploited for server-side request forgery (SSRF). This allows attack...

PoC for CVE-2026-54121

MicrosoftWindows 10 Version 16078.8HIGH
Elevation of Privilege Vulnerability in Microsoft Active Directory ...

A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...

PoC for CVE-2026-76785

AmirsanniMini-inventory-and-sal...5.3MEDIUM
SQL Injection Vulnerability in amirsanni Mini-Inventory-and-Sales-M...

A security flaw in amirsanni's Mini-Inventory-and-Sales-Management-System version 0.1 has been identified, specifically in the function Transaction::getAll located in application/models/Transaction.php. This vulnerability arises from improper handling of the argument orderBy/orderFormat, allowing...

PoC for CVE-2026-76783

DeDeCMSDedecms6.9MEDIUM
SQL Injection Vulnerability in DeDeCMS by DeDeCMS

A security vulnerability has been identified in DeDeCMS version 53_1_UTF8, particularly in the advancedsearch.php file. This issue allows attackers to manipulate SQL queries through arguments, enabling unauthorized access to the database. The exploit can be executed remotely, putting systems at r...

PoC for CVE-2026-15748

WordPressForminator Forms – Con...9.8CRITICAL
Arbitrary File Upload Vulnerability in Forminator Forms Plugin by W...

The Forminator Forms plugin for WordPress is susceptible to an arbitrary file upload attack due to inadequate file type validation in the handle_file_upload function. Attackers can exploit this vulnerability by using specially crafted MIME types that bypass the system's dangerous-extension blockl...

PoC for CVE-2022-4996

mrubyMruby6.9MEDIUM
Floating Point Comparison Flaw in mruby by mruby

A vulnerability has been identified in version 3.1.0 of mruby, specifically within the udiv function found in bigint.c. This flaw allows for incorrect operator usage during floating point comparisons, creating potential opportunities for remote attacks. It's crucial for users to apply the necessa...

PoC for CVE-2026-61241

OracleOracle Internet Directory10CRITICAL
Unauthorized Access Vulnerability in Oracle Internet Directory by O...

An exploitable vulnerability exists in the Oracle Internet Directory component of Oracle Fusion Middleware. This issue permits an unauthenticated attacker with network access via LDAP to potentially compromise the Oracle Internet Directory, enabling them to take control over the system. Notably, ...

PoC for CVE-2026-76762

Code-projectsAssessment Management6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Assessment Management ...

A serious SQL injection vulnerability has been identified in the Code-Projects Assessment Management tool, specifically affecting version 1.0. The flaw exists in the unknown function located within the file /welcome.php, where improper handling of the 'userid' argument allows for remote exploitat...

PoC for CVE-2026-76761

Chenhg5Cc-connect6.9MEDIUM
OS Command Injection in chenhg5 cc-connect Management API

A security flaw has been found in the Management API of chenhg5 cc-connect, specifically in the shellExecCommand function located in core/engine.go. This vulnerability allows an attacker to manipulate the exec argument, leading to OS command injection. The exploit can be executed remotely, raisin...

PoC for CVE-2026-76760

Chenhg5Cc-connect6.9MEDIUM
Code Injection Flaw in chenhg5 cc-connect Product Suite

A code injection vulnerability exists in the chenhg5 cc-connect software up to version 1.4.1, specifically within the Authenticate function of core/webhook.go. This vulnerability allows attackers to manipulate the argument 'exec', potentially enabling remote code execution. The vulnerability has ...

PoC for CVE-2026-76591

TrendnetTew-755ap5.3MEDIUM
Command Injection Vulnerability in TRENDnet TEW-755AP Wireless Acce...

A security flaw has been identified in the TRENDnet TEW-755AP wireless access point, specifically impacting the 'log_email_server' functionality within the '/cgi-bin/email.cgi' component, identified as 'ssi'. This vulnerability allows attackers to execute arbitrary commands on the device remotely...

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 98%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-76590

TrendnetTew-755ap9.4CRITICAL
Stack-based Buffer Overflow in TRENDnet TEW-755AP

A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-755AP that affects the ssi component, specifically through the '/cgi-bin/wan.cgi' functionality. By manipulating the 'cameo.wan.wan_pppoe_password_00' argument, an attacker can exploit the vulnerability remotely. Publicly avai...

PoC for CVE-2026-76589

TrendnetTew-755ap9.4CRITICAL
Stack-based Buffer Overflow in TRENDnet TEW-755AP by TRENDnet

A vulnerability has been identified in the TRENDnet TEW-755AP that allows for a stack-based buffer overflow due to improper handling of the SSID argument in the /sbin/mycli file, specifically within the FUN_401000 function. This security flaw can potentially be exploited remotely, enabling attack...

PoC for CVE-2026-76584

TrendnetTv-ip751wic9.4CRITICAL
Stack-Based Buffer Overflow in TRENDnet TV-IP751WIC by TRENDnet

A vulnerability in the TRENDnet TV-IP751WIC webcam can be exploited through an insecure file index at /cgi-bin/admin/set_time.cgi, specifically within the alphapd component. The flaw allows an attacker to manipulate the 'Currenttime' argument, leading to a stack-based buffer overflow. This remote...

PoC for CVE-2026-76582

TrendnetTew-821dap5.3MEDIUM
Command Injection Vulnerability in TRENDnet TEW-821DAP

A command injection vulnerability exists in the TRENDnet TEW-821DAP due to improper handling of the 'ipaddr' argument in the /cgi-bin/ping.cgi script within the ssi component. This flaw allows attackers to execute arbitrary system commands remotely, posing a significant risk to users. As the expl...

PoC for CVE-2026-76576

YangzongzhuanRuoyi-vue5.3MEDIUM
Path Traversal Vulnerability in RuoYi-Vue by Yangzongzhuan

A path traversal vulnerability exists in the RuoYi-Vue framework affecting versions up to 3.9.2. This security flaw is located within the fileDownload/resourceDownload function of the Common Download Endpoint, specifically in CommonController.java. By manipulating the fileName/resource arguments,...