Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 2 hours ago
PoC for CVE-2026-94145
A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interface. The manipulation of the argument name/autho...
PoC for CVE-2026-94144
A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has bee...
PoC for CVE-2026-82187
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on...
Discovered 3 hours ago
PoC for CVE-2026-94143
A vulnerability in DrogonFramework's ORM Mapper component has been identified, specifically within the `Mapper::orderBy` function located in the Mapper.h library. This flaw allows for SQL injection through manipulation of the 'sort' argument, making it possible for attackers to execute remote exp...
Discovered 4 hours ago
PoC for CVE-2026-94139
A command injection vulnerability has been discovered in the cookie handler functionality of the Feiyu Star Router B-MB5E202-210322-r11656. Specifically, the issue arises when the session_id parameter within the /send_order.cgi endpoint is manipulated. This flaw allows attackers to execute arbitr...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-86552
The SmartLife app has a significant vulnerability where it dynamically generates authentication parameters at runtime. This flaw allows attackers to obtain valid authentication credentials, enabling them to complete account registrations with any arbitrary email address. Notably, the application ...
Discovered 5 hours ago
PoC for CVE-2026-94138
A command injection vulnerability exists in the Feiyu Star Router B-MB5E202-210322-r11656, specifically within the /send_order.cgi?parameter=del_expmac endpoint. By manipulating the 'mac' argument, attackers can execute arbitrary commands on the device remotely. This flaw could lead to significan...
Discovered 7 hours ago
PoC for CVE-2026-89274
The WP Recipe Maker plugin for WordPress is vulnerable due to a flaw that allows unauthorized execution of registered shortcodes on recipe pages. This arises from the method 'WPRM_Metadata::sanitize_metadata()' which processes every scalar field of the recipe's metadata, including 'reviewBody', w...
PoC for CVE-2026-94110
A vulnerability has been detected in QCMS versions up to 6.0.6, affecting the function self_Tmp in Lib/Config/Controllers.php. This vulnerability allows remote attackers to manipulate the argument ID, leading to SQL injection attacks. The exploit is facilitated by the router's handling of raw REQ...
PoC for CVE-2026-94103
A code injection vulnerability has been identified in RooCMS affecting versions up to 1.2.2, 1.3.4, and 1.4RC2. This issue resides in the eval function in the file roocms/site_pagePHP.php, which is part of the Frontend Rendering component. The vulnerability allows attackers to manipulate the cont...
PoC for CVE-2026-94102
A vulnerability exists in WuzhiCMS versions up to 4.1.0 within the Login component, specifically located at /index.php?m=member&v=Login. This flaw allows attackers to manipulate the 'forward' argument, potentially redirecting users to malicious sites. The vulnerability can be exploited remotely, ...
Discovered 8 hours ago
PoC for CVE-2026-94101
A buffer overflow vulnerability exists in the Netcore NBR200V2 router's vlan_load_form_uci function located in /usr/bin/routerd. Manipulation of the wan_num argument could allow an attacker to execute a remote exploit, potentially compromising system integrity. This issue has been publicly disclo...
Discovered 9 hours ago
PoC for CVE-2026-94097
A command injection vulnerability exists in the Netcore NBR200V2 router's CGI Diagnostic Endpoint. This flaw allows an attacker to manipulate the parameters, potentially executing unauthorized commands on the system remotely. The issue was found in the file located at /www/cgi-bin/network_tools, ...
PoC for CVE-2026-94096
A command injection vulnerability exists in the LAN IP Configuration Handler of the Netcore NBR200V2 product. This vulnerability can be exploited by manipulating the 'ipv4' argument within the /usr/bin/network_tools file. Attackers can launch remote exploits, potentially affecting network integri...
PoC for CVE-2026-94095
A security flaw exists in the Traceroute Diagnostic Feature of the Netcore NBR200V2 router, specifically within the /usr/bin/network_tools file. An attacker can exploit this vulnerability by manipulating the input argument, leading to unauthorized command execution on the device. This vulnerabili...
PoC for CVE-2026-94094
A significant flaw exists in OpenClaw's Canvas Host Route, specifically in the createCanvasHostHandler function. This weakness can be exploited through remote manipulation, leading to a denial of service. The root cause lies in the handling of file reading, where the system buffers the entire fil...
Discovered 10 hours ago
PoC for CVE-2026-71217
A vulnerability exists in iperf3 that allows remote attackers to exploit flawed input validation of control-channel JSON data. By submitting oversized numeric parameters such as 'parallel' and 'len', an attacker can provoke the server into creating excessive streams and threads, leading to large ...
PoC for CVE-2026-94092
A vulnerability in dmlc's DGL product versions up to 2.1.0 has been identified, particularly in the load_info/_read_torch_data function of the utils.py file. This flaw allows an attacker to manipulate the argument path, leading to potential remote code execution through deserialization. Despite p...
PoC for CVE-2026-94091
A vulnerability in piskvorky gensim versions up to 4.4.0 has been identified within the Model Loader component, specifically in the Load function of gensim/utils.py. This issue allows an attacker to manipulate the argument fname, leading to deserialization attacks. The exploit can be executed rem...
PoC for CVE-2026-93958
A vulnerability has been identified in the D-Link R95 BE9500 router, specifically in the file /bin/ssi associated with the DHMAPI component. This issue arises from improper handling of the NTPServer argument, allowing for OS command injection. Exploitation of this vulnerability can occur remotely...
Discovered 12 hours ago
PoC for CVE-2026-94089
A stack-based buffer overflow vulnerability exists in the authentication component of the D-Link DIR-868L firmware version 2.01b05. This security issue arises from improper handling of the 'strcpy' function within the '/webfa_authentication.cgi' file. By manipulating the 'id' or 'password' parame...
PoC for CVE-2026-94051
A vulnerability exists in the pdf-tools-mcp component of cowork_bench, specifically within the ControlFlowNode function of the server.py file. An attacker could manipulate the pdf_file_path argument to perform server-side request forgery, enabling remote execution of malicious commands. This vuln...
Discovered 13 hours ago
PoC for CVE-2026-94049
A vulnerability has been identified in the 06ketan Slideshot product, specifically within the render_slides function located in packages/cli/src/renderer.ts. This issue allows for path traversal via the manipulation of an argument called htmlPath, which can lead to unauthorized file access. The v...
PoC for CVE-2026-94048
A significant vulnerability has been identified in the CodeAstro QR Code Attendance Management System version 1.0, specifically within the Save function located in app/Controllers/UserController.php. The issue arises from improper handling of the argument role_id, which can lead to unauthorized p...
PoC for CVE-2026-94047
A security vulnerability has been identified in the samanhappy MCPHub affecting versions up to 1.0.32. The issue resides in the 'importTemplate' function located in 'src/services/templateService.ts', specifically within the Template Import Endpoint. This vulnerability allows for improper privileg...
PoC for CVE-2026-36213
A security vulnerability exists in the Microvirt MEmu Android Emulator 9.2.7.0 that enables a local attacker to escalate their privileges using the MemuService.exe component. This allows unauthorized access to system features and can potentially compromise the integrity of the host system.
Discovered 14 hours ago
PoC for CVE-2026-94046
A path traversal vulnerability has been identified in the ACE-MCP tool up to version 4.10.8. This weakness exists in the `get_file_snippet` function of the `getFileSnippet.ts` file, where improper handling of user-supplied input allows an attacker to manipulate file paths. Specifically, the argum...
PoC for CVE-2026-94045
A significant security flaw has been identified in the newbee-ltd newbee-mall application, specifically within the UploadController.java file responsible for handling goods data. This vulnerability allows for the manipulation of the 'goodsName' parameter, facilitating cross site scripting (XSS) a...
PoC for CVE-2026-94044
A vulnerability exists in the 03-lovepreetSingh MCP, specifically within the create_file function located in the app/api/mcp/route.ts file. This flaw allows an attacker to manipulate file paths through arguments, potentially leading to unauthorized access to system files via path traversal attack...
Discovered 15 hours ago
PoC for CVE-2026-94042
A significant SQL injection vulnerability exists in the AdithyaYelloju Restaurant Management System, specifically within the mysqli_query function of the admin/add_table.php file. This vulnerability can be exploited by manipulating the arguments of the table/members/price, allowing attackers to e...
PoC for CVE-2026-94041
A security vulnerability has been identified in the AdithyaYelloju Restaurant-Management-System located in the admin/add_menu.php file. This issue allows for remote SQL injection attacks through the manipulation of parameters such as item, price, image, and type. If exploited, this flaw could pot...
PoC for CVE-2026-94040
A security flaw exists in the vas3k TaxHacker application, specifically within the function testLLMProviderAction in the actions.ts file. This vulnerability allows an attacker to manipulate the argument values for provider, apiKey, model, or baseUrl, potentially leading to unauthorized server-sid...
Discovered 16 hours ago
PoC for CVE-2026-94039
A vulnerability in the Invoice PDF Renderer of vas3k TaxHacker, affecting versions up to 0.8.5, allows attackers to manipulate the `businessLogo` argument in the `generateInvoicePDF` function. This manipulation can lead to server-side request forgery, enabling malicious actors to send unauthorize...
PoC for CVE-2026-94038
A vulnerability has been identified in the NonceGeek dim-sum-app, specifically within the Deno Backend component. This issue arises in the textSearchV2Handler function located in the deno/main.tsx file, where manipulation of the argument 'supabase_url' can lead to a server-side request forgery (S...
PoC for CVE-2026-94037
A vulnerability has been identified in the 00Kisumi00 mcp-file-analyzer tool affecting the analyze_csv_data component. A flaw in the ControlFlowNode function within the main.py file allows for manipulation of the filename argument, leading to path traversal attacks. This vulnerability can be expl...
Discovered 17 hours ago
PoC for CVE-2026-94036
A security flaw has been identified in the D-Link DIR-X1860 and DIR-X1860Z routers, specifically within an undisclosed function related to the routerd component. The vulnerability arises from the manipulation of the 'passwd_set' argument, leading to improper access controls. An attacker within th...
PoC for CVE-2026-94035
A vulnerability has been identified in the SourceCodester Drug Recommendation System version 1.0, specifically affecting an unnamed function within the index.php file. By manipulating the 'full name' argument, an attacker can exploit this vulnerability to execute cross site scripting (XSS) attack...
PoC for CVE-2026-94034
A vulnerability has been identified in the SourceCodester Drug Recommendation System 1.0, specifically within the password change functionality. This issue arises from improper handling of input data in the '/drug_recommender/Admin/change_password' file, where an attacker can manipulate the argum...
Discovered 18 hours ago
PoC for CVE-2026-94033
The SourceCodester Drug Recommendation System version 1.0 has a critical security flaw in the User Management component. This vulnerability occurs in the file /drug_recommender/Admin/add_user, where improper handling of user-supplied input allows for cross-site scripting (XSS). Attackers can expl...
PoC for CVE-2026-94032
A vulnerability has been identified in itsourcecode Leave Management System version 1.0, specifically affecting the /module/department/index.php file. This flaw allows an attacker to manipulate the argument ID, enabling SQL injection attacks that can be executed remotely. The exploit has been mad...
PoC for CVE-2026-94031
A command injection vulnerability exists in the child_process.exec function of the src/auth/browser.ts file in the nexus_reauth component of the 0-Gaurav-0 nexus-mcp tool. This flaw allows an attacker to manipulate the argument URL to execute arbitrary commands remotely. Given that the product em...
Discovered 19 hours ago
PoC for CVE-2026-94030
A security vulnerability has been identified in the decode_bmp_pixel_data function of the BMPLoader component within SerenityOS's LibGfx library. This issue arises from an integer overflow caused by manipulation of the height argument during image processing. An attacker could exploit this vulner...
PoC for CVE-2026-94028
A vulnerability has been identified in the Mealie Recipes software in versions up to 3.25.1. This issue resides in the payload.model_dump function found in the controller_group_recipe_actions.py file. By manipulating the argument URL, an attacker can execute server-side request forgery attacks, w...
Discovered 20 hours ago
PoC for CVE-2026-94016
A security flaw has been identified in the SourceCodester Drug Recommendation System version 1.0, particularly affecting the /drug_recommender/Admin/add_symptom file. The vulnerability arises from improper handling of the 'txtname' argument, allowing attackers to inject malicious scripts, thereby...
PoC for CVE-2026-94015
A security flaw exists in the SourceCodester Drug Recommendation System 1.0 which allows an attacker to manipulate the argument ID in the /drug_recommender/Admin/edit_user.php file. This leads to SQL injection attacks that can be executed remotely. The availability of public exploits increases th...
Discovered 21 hours ago
PoC for CVE-2026-94003
A stack-based buffer overflow vulnerability has been identified in the Comfast CF-N1-S 2.6.0.1, specifically within the function get_css_path_from_uri located in the /cgi-bin/mbox-config file of its Web Management Interface. This vulnerability may allow attackers to execute remote exploits, poten...
PoC for CVE-2026-93997
A security flaw has been discovered in the SourceCodester Drug Recommendation System version 1.0, specifically in the file /Admin/edit_symptom.php. This vulnerability allows an attacker to manipulate the 'ID' argument, leading to SQL injection attacks. Such an exploit can be executed remotely, th...
PoC for CVE-2026-93980
A vulnerability in the Admin Login Form of the Internship Management System 1.0 allows unauthorized users to manipulate the Password argument in the /admin/login.php file. This manipulation can lead to SQL injection attacks, potentially exposing sensitive data or allowing an attacker to control t...
Discovered 22 hours ago
PoC for CVE-2026-93979
A security flaw has been identified in the Internship Management System version 1.0 developed by Code-Projects. This vulnerability resides in the login functionality located in the /employer/login.php file. By manipulating the Password parameter during login attempts, an attacker can execute SQL ...