Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered just now...
PoC for CVE-2026-0300
A buffer overflow vulnerability exists within the User-ID™ Authentication Portal of Palo Alto Networks PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by manipulating specially crafted packets. To miti...
PoC for CVE-2026-67598
Emlog Pro, as of version 2.6.23, is susceptible to a TLS certificate validation vulnerability that allows attackers in the same network vicinity to intercept HTTPS requests. This exploitation arises from the unconditional disabling of the CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST options ...
Discovered 54 minutes ago
PoC for CVE-2024-2961
The iconv() function in the GNU C Library (glibc) has a vulnerability that can cause a buffer overflow when converting strings to the ISO-2022-CN-EXT character set. This flaw occurs due to the function's failure to adequately check the size of the output buffer, allowing it to overflow by up to 4...
Discovered 1 hour ago
PoC for CVE-2026-25243
Redis, a widely used in-memory data structure store, is impacted by a vulnerability in its RESTORE command. This flaw allows authenticated attackers with permissions to execute the RESTORE command to manipulate serialized payloads, leading to potential memory access issues that can result in remo...
Discovered 2 hours ago
PoC for CVE-2026-15246
The RealHomes Memberships WordPress plugin prior to version 3.1.0 contains a flaw that permits authenticated users, such as Subscribers, to gain access to paid membership packages without completing the required payment. This is due to the absence of checks to verify the payment status, nonce val...
PoC for CVE-2026-70637
LightFTP version 2.4 is susceptible to multiple data race vulnerabilities that arise from concurrent execution paths in the control and worker threads. Specifically, when an anonymous attacker issues the LIST command followed by the ABOR command, the control thread may prematurely close data_sock...
Discovered 3 hours ago
PoC for CVE-2026-34990
OpenPrinting's CUPS, an open source printing system for Linux and other Unix-like operating systems, is susceptible to a local privilege escalation vulnerability. An unprivileged user can exploit this flaw to trick the cupsd service into authenticating with an attacker-controlled IPP service on l...
PoC for CVE-2026-34980
The OpenPrinting CUPS printing system is susceptible to a vulnerability that allows unauthorized clients to send print jobs to a shared PostScript queue without proper authentication. This issue arises in network-exposed instances of cupsd version 2.4.16 and earlier, where an attacker can manipul...
Discovered 4 hours ago
PoC for CVE-2026-19037
A weakness has been discovered in WonderTrader versions up to 0.9.9, specifically in the MatchEngine::update_lob function located in src/WtBtCore/MatchEngine.cpp. This vulnerability impacts the Internal Limit Order Book Cache Handler, potentially allowing attackers to manipulate enforcement of be...
Discovered 5 hours ago
PoC for CVE-2026-19036
A security flaw has been identified in Shibby Tomato 1.28.0000, specifically within the function sub_40F88C located in the file /tmp/ppp/wanoptions. This vulnerability arises from improper handling of the ppp_custom argument, which allows remote attackers to execute arbitrary OS commands. The exp...
PoC for CVE-2026-19035
A vulnerability in Shibby Tomato 1.28.0000 allows for OS command injection through improper handling of the new_qoslimit_enable argument in the new_qoslimit_start function within the file /etc/qoslimit. This flaw may be exploited remotely, enabling attackers to execute arbitrary commands on the s...
Discovered 6 hours ago
PoC for CVE-2026-19034
A significant vulnerability exists in Shibby Tomato 1.28.0000 within the function new_qoslimit_stop located in /tmp/qoslimittc_stop.sh. This flaw allows attackers to manipulate the wan_iface argument, potentially leading to unauthorized execution of operating system commands. An attacker can laun...
Discovered 8 hours ago
PoC for CVE-2026-18556
An authentication bypass vulnerability exists in N-able N-central, allowing attackers to exploit an alternate path or channel for unauthorized access. This critical security flaw can compromise the integrity and confidentiality of user data, posing significant risks to organizations utilizing the...
Discovered 9 hours ago
PoC for CVE-2026-19021
A security vulnerability has been identified in the SourceCodester Computer Repair Shop Management System version 1.0. This issue affects the file /classes/Master.php with the parameter f=delete_product, where an attacker can manipulate the argument ID to perform SQL injection. This vulnerability...
PoC for CVE-2026-19020
A vulnerability exists in the itsourcecode Hospital Management System 1.0, specifically in the /servicetype.php file. This vulnerability is attributed to a flaw in the argument handling of 'editid', which allows for SQL injection attacks. Attackers can exploit this weakness remotely, potentially ...
PoC for CVE-2026-19019
A significant security flaw has been identified in the poco-ai poco-agent, specifically within the WorkspaceManager._setup_session_persistence function of the Claude File Handler in executor/app/core/workspace.py. This vulnerability leads to incomplete cleanup of session data, potentially allowin...
PoC for CVE-2026-19019
A significant security flaw has been identified in the poco-ai poco-agent, specifically within the WorkspaceManager._setup_session_persistence function of the Claude File Handler in executor/app/core/workspace.py. This vulnerability leads to incomplete cleanup of session data, potentially allowin...
PoC for CVE-2026-19011
A vulnerability exists in TinyAGI version 0.0.20 within the function buildSystemPrompt located in the file packages/server/src/routes/agents.ts. This flaw allows for the potential manipulation of files, leading to unauthorized file inclusion. Attackers can exploit this vulnerability remotely, giv...
Discovered 10 hours ago
PoC for CVE-2026-19010
A vulnerability has been identified in TinyAGI version 0.0.20 within the processMessage function of the Message API Endpoint. This flaw permits unauthorized access, allowing attackers to manipulate the system remotely. Despite an early notification to the developers via an issue report, no respon...
PoC for CVE-2026-19009
A file inclusion vulnerability exists in version 0.0.20 of TinyAGI, specifically in the function collectFiles of the Message API Endpoint. This vulnerability allows for remote manipulation, which could be exploited to access sensitive files on the server. The issue was reported early to the devel...
PoC for CVE-2026-19008
A security loophole exists in the mf-yang openclaw-cn tool, specifically within the assertNoSymlinkEscape function of the sandbox-paths.ts file. This flaw permits link following, which can be exploited to manipulate the system remotely. The vulnerability, publicly known, has not yet been addresse...
PoC for CVE-2026-19007
A vulnerability has been identified in Openclaw-CN, specifically affecting versions up to 0.2.1. This issue arises within the isApprovedElevatedSender function located in the src/auto-reply/reply/reply-elevated.ts file. This vulnerability can lead to inadequate management of privileges, allowing ...
Discovered 11 hours ago
PoC for CVE-2025-8110
The vulnerability in the PutContents API of Gogs arises from improper handling of symbolic links, potentially allowing local execution of arbitrary code. This misconfiguration may expose sensitive data and facilitate unauthorized access to critical systems. Users and administrators are urged to u...
PoC for CVE-2026-13703
The SEO Redirection Plugin for WordPress, prior to version 9.19, contains a flaw that permits logged-in users, regardless of their privileges, to execute specific authenticated AJAX actions without proper capability checks. This vulnerability allows these users to gain access to sensitive configu...
PoC for CVE-2026-14204
The Google Authenticator WordPress plugin prior to version 0.56 is vulnerable to a Cross-Site Request Forgery (CSRF), which can be exploited to compromise two-factor authentication settings. Attackers can send a malicious request to a logged-in user, tricking them into changing their two-factor a...
PoC for CVE-2026-12713
The WPCargo Track & Trace WordPress plugin, prior to version 8.0.4, lacks adequate parameter sanitization and escaping practices within its SQL statements. This oversight creates a significant security risk, as it enables unauthenticated users to execute SQL injection attacks. Such vulnerabilitie...
PoC for CVE-2025-15678
The Nexter Blocks WordPress plugin, prior to version 5.0.2, permits users with file upload capabilities to upload SVG files without proper sanitization. This oversight allows these users to execute malicious JavaScript embedded within the SVG files, leading to stored cross-site scripting (XSS) vu...
PoC for CVE-2026-13154
The Gutenberg Essential Blocks plugin for WordPress before version 6.4.0 contains a significant access control vulnerability. It fails to properly verify whether an attacker-supplied post type is publicly viewable prior to executing queries in its public REST routes. This oversight allows unauthe...
PoC for CVE-2026-13153
The Gutenberg Essential Blocks plugin for WordPress prior to version 6.4.0 has a significant access control vulnerability, which allows unauthenticated users to retrieve sensitive sales metrics. Specifically, the plugin's public REST route permits an over-fetching of non-public WooCommerce inform...
PoC for CVE-2026-11588
The EONSR AEO Agent plugin for WordPress prior to version 3.7.9 is vulnerable due to inadequate authorization checks on specific REST API routes. This security flaw allows unauthenticated attackers to craft and publish posts with malicious web scripts. These scripts are stored on the server and e...
PoC for CVE-2026-19006
A significant vulnerability has been identified in the Ggateway Exec Approval Flow component of mf-yang's Openclaw-cn version 2026.2.5. This issue resides in the src/agents/bash-tools.exec.ts file, where improper authorization handling can lead to unauthorized access. Attackers may exploit this v...
PoC for CVE-2026-16065
The Welcart e-Commerce plugin for WordPress, prior to version 2.11.32, contains a vulnerability where it fails to adequately sanitize data imported from CSV files. This oversight allows users with Editor roles and above to potentially execute SQL injection attacks, manipulating the database and g...
PoC for CVE-2026-16537
The Slick Slider plugin for WordPress, before version 0.5.3, contains a vulnerability due to improper sanitization and escaping of a shortcode attribute value. This flaw allows users with Contributor privileges and above to conduct Stored Cross-Site Scripting attacks. When a user views the affect...
PoC for CVE-2026-14829
The Checkimate WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin fails to enforce adequate access controls for its license-management functions. This vulnerability is due to its reliance on a shared secret derived from publicly accessible information, which enables unau...
PoC for CVE-2026-18395
The Child Pages Card plugin for WordPress prior to version 1.09 is susceptible to stored Cross-Site Scripting (XSS) vulnerabilities. The plugin fails to properly sanitize and escape certain shortcode attributes upon outputting them in web pages. This oversight allows users with contributor privil...
PoC for CVE-2026-16734
The Stripe Payment Forms plugin by WP Full Pay prior to version 8.5.2 fails to validate ownership of payment intents for certain unauthenticated AJAX actions. This oversight allows malicious users to manipulate payment amounts by utilizing a nonce embedded in public pages. Although an ownership v...
PoC for CVE-2026-16954
The AI Engine WordPress plugin prior to version 3.6.4 contains a vulnerability that allows users with the Editor role to access sensitive configuration values, including third-party API keys and authentication tokens. These secrets, typically accessible only by administrators, are exposed in clea...
PoC for CVE-2026-18050
The Events Manager plugin for WordPress prior to version 7.4 lacks proper authorization checks on a REST route associated with file uploads. This flaw allows unauthenticated users to access another user's temporary file uploads if they possess knowledge of the temporary identifier, which is high-...
PoC for CVE-2026-16290
The ProfileGrid WordPress plugin versions prior to 6.0.0.0 suffer from a serious vulnerability that allows any unauthenticated visitor to access the member lists of various groups without proper authorization checks. This flaw exposes sensitive information, including member identifiers from priva...
PoC for CVE-2026-16268
The Newsletters WordPress plugin prior to version 4.16 is susceptible to a security vulnerability that fails to authenticate or validate bounce-processing requests. This oversight allows unauthenticated attackers to submit malicious user-supplied URLs, leading to arbitrary requests being executed...
PoC for CVE-2026-14240
The Tourmaster WordPress plugin prior to version 5.4.9 is susceptible to an insecure file exposure vulnerability. When administrators perform an export for orders or bookings, the exported data is saved in a fixed, predictable file location within a publicly accessible directory. This lack of pro...
PoC for CVE-2026-14547
The Estatik Real Estate Plugin for WordPress versions before 4.3.3 is susceptible to an improper input validation vulnerability that bypasses its anti-spam mechanisms. This flaw enables unauthenticated users to exploit the property request form by sending emails to any specified recipient, along ...
PoC for CVE-2026-16054
The Drag and Drop Multiple File Upload for WooCommerce plugin prior to version 1.1.8 exhibits a critical security flaw that permits unauthenticated users to exploit a valid nonce, which serves as the sole barrier to executing file deletion operations. This vulnerability allows malicious actors to...
PoC for CVE-2026-14314
The PeproDev WooCommerce Receipt Uploader plugin allows attackers to craft unauthorized access tokens that can be used to view image attachments uploaded by other users. This vulnerability occurs because the plugin does not properly validate the relationship between a requested attachment and the...
PoC for CVE-2026-14313
The PeproDev WooCommerce Receipt Uploader plugin for WordPress is impacted by a serious vulnerability that allows unauthenticated users to perform unauthorized write operations. This missing authorization flaw enables potential attackers to exploit the system, posing significant security risks, e...
PoC for CVE-2026-19005
A vulnerability has been identified in the nanocoai NanoClaw product, specifically in the Child-Agent Creation function. The issue is attributed to improper privilege management within the handleCreateAgent method located in the create-agent.ts file. This flaw permits remote attackers to exploit ...
PoC for CVE-2026-71211
MLflow's AI Gateway is vulnerable due to an insufficient validation mechanism for the auth_config.api_base value. When creating a gateway secret, the system allows the storage of this value without validating its scheme, host, or IP range. Consequently, the gateway proxy can process HTTP requests...
PoC for CVE-2026-19000
A server-side request forgery (SSRF) vulnerability has been detected in JeecgBoot versions prior to 3.9.2. This flaw involves an unknown function in the "Anonymous Chat Attachment Parser" component located in the file /airag/chat/send. Attackers can exploit this vulnerability remotely, allowing u...
Discovered 12 hours ago
PoC for CVE-2026-18998
A vulnerability exists in the Cosmicstack-Labs Mercury-Agent software that allows for improper authorization within the function SubAgent.run found in the delegate_task Tool. This issue affects versions up to 1.1.12 and can be exploited remotely. Details regarding this vulnerability were made pub...
PoC for CVE-2026-18997
A vulnerability exists in the cosmicstack-labs mercury-agent affecting versions up to 1.1.12. The issue arises in the function Agent.handleBgCommand located in the src/core/agent.ts file. This vulnerability enables attackers to exploit incorrect authorization mechanisms remotely, which could lead...