Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 52 minutes ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 2 hours ago
PoC for CVE-2026-90695
A vulnerability has been identified in the Vendor Management component of SourceCodester's Inventory Management System 1.0. This flaw exists within the file 'vendors_handler.php', allowing attackers to execute cross-site scripting (XSS) attacks. The exploit can be initiated remotely, posing a sig...
PoC for CVE-2026-90694
A vulnerability exists in the SourceCodester Inventory Management System version 1.0 that affects its Customer Management Module. Specifically, the issue arises from an insufficiently sanitized input in the /api/customers_handler.php file, where manipulation of the 'Customer_Name' argument could ...
Discovered 3 hours ago
PoC for CVE-2026-90691
A security issue has been identified in the 0x4m4 HexStrike AI application, specifically involving the FileOperationsManager function located in hexstrike_server.py. This vulnerability allows for path traversal attacks by manipulating the filename argument, potentially enabling unauthorized acces...
PoC for CVE-2026-90690
A vulnerability exists in the 0x4m4 HexStrike AI API Tools Endpoint due to improper handling of arguments within the subprocess.Popen function in hexstrike_server.py. Attackers can exploit this weakness to execute arbitrary OS commands remotely by manipulating various input parameters such as add...
PoC for CVE-2026-87492
An authorization flaw in Google Chrome allows remote attackers to potentially execute arbitrary code outside the sandbox by leveraging a specially crafted HTML page. This vulnerability highlights critical security implications for users and emphasizes the need for timely updates to ensure protect...
PoC for CVE-2024-51324
A security flaw in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 enables attackers to exploit the system through a Bring Your Own Vulnerable Driver (BYOVD) attack, allowing the execution of arbitrary code that can terminate any running process. This vulnerability compromises the integrity...
Discovered 4 hours ago
PoC for CVE-2026-90687
A vulnerability has been identified in GPAC's MP4Box component related to the gf_node_changed_internal function found in scenegraph/base_scenegraph.c. This flaw enables a use after free condition, allowing potential attackers to manipulate the application remotely. Affected versions are up to f12...
PoC for CVE-2026-90686
A memory corruption vulnerability exists in GPAC's MP4Box component due to improper handling in the gf_bt_report function located in scene_manager/loader_bt.c. This security flaw allows attackers to execute remote exploits that can manipulate memory, potentially leading to unauthorized access or ...
PoC for CVE-2026-90685
A vulnerability exists in GPAC’s MP4Box, specifically within the lsr_exec_command_list function located in the laser/lsr_dec.c file. This flaw allows local users to manipulate command execution leading to assertion failures. Given that the exploit has been publicly disclosed, users are advised to...
Discovered 5 hours ago
PoC for CVE-2026-90684
A vulnerability has been identified in GPAC's MP4Box component, specifically in the function gf_node_get_field_count within the file scenegraph/base_scenegraph.c. This flaw allows for local exploitation that can lead to a reachable assertion failure, potentially causing denial of service. Users a...
PoC for CVE-2026-90683
A vulnerability exists in the GPAC MP4Box component, specifically in the gf_node_unregister function within scenegraph/base_scenegraph.c. This issue can be exploited through local manipulation, leading to a reachable assertion failure. Attackers may utilize public exploits to trigger this vulnera...
PoC for CVE-2026-90682
A vulnerability has been discovered in the jhead component by Matthias-Wandel, specifically within the ProcessGpsInfo function located in gpsinfo.c. This flaw allows for the heap-based buffer overflow by manipulating GPS latitude and longitude tags. Such exploitation requires local access, but th...
PoC for CVE-2026-90681
A vulnerability has been discovered in the Matthias-Wandel jhead software, specifically in the Get16u function located in the exif.c file related to EXIF Parsing. This weakness allows for an out-of-bounds read condition, potentially leading to unauthorized access to sensitive information. The vul...
Discovered 6 hours ago
PoC for CVE-2026-42536
A Heap-based Buffer Overflow vulnerability exists in the Apache HTTP Server due to improper handling of untrusted content when utilizing mod_xml2enc. This vulnerability can be exploited by an attacker to execute arbitrary code or crash the server, leading to potential information disclosure or de...
PoC for CVE-2026-90623
A vulnerability has been discovered in the AndreasHappe Cochise project, specifically within the SSH Host Key Handler component. This issue arises in the asyncssh.connect function, located in src/cochise/ssh_connection.py, allowing for improper validation of SSH host keys. An attacker could explo...
PoC for CVE-2025-24071
The vulnerability in Microsoft Windows File Explorer poses a security risk by allowing unauthorized access to sensitive information. In an environment where it is present, attackers can exploit this flaw to spoof identities over a network, potentially compromising data integrity and confidentiali...
PoC for CVE-2026-90622
A security flaw in GNU libredwg 0.13.4 has been identified, primarily affecting the DWG_TABLE function within the Layer Encoding component. This vulnerability allows a local attacker to exploit a null pointer dereference, resulting in potential instability of the application. The issue is due to ...
PoC for CVE-2026-90621
A security flaw has been discovered in the ssh_run_command function of ipa-lab's HackingBuddyGPT, specifically within the src/hackingBuddyGPT/extensions/ssh_run_command.py file. This vulnerability allows attackers to execute arbitrary OS commands remotely, posing a significant security risk. The ...
Discovered 7 hours ago
PoC for CVE-2026-90620
A vulnerability has been identified in 0x4m4 HexStrike AI that exposes the API Command Endpoint's functionality due to missing authentication in the hexstrike_server.py file. This flaw allows unauthorized remote exploitation, potentially compromising the system. Users should be aware that the pro...
PoC for CVE-2026-90619
A vulnerability exists within the Execute Endpoint of 0x4m4 HexStrike AI due to improper handling of the 'code/script' argument in the hexstrike_server.py file. This can lead to OS command injection, enabling attackers to execute arbitrary commands remotely. The issue has been publicly disclosed,...
PoC for CVE-2026-90618
A security flaw has been identified in the GH05TCREW PentestAgent affecting the LocalRuntime component. The vulnerability is located in the function LocalRuntime.execute_command within the runtime.py file. This issue allows an attacker to execute arbitrary operating system commands through specia...
PoC for CVE-2026-90617
A vulnerability has been identified in the GH05TCREW PentestAgent, specifically in the MCP HTTP Server's run_task function located in interface/main.py. This vulnerability enables attackers to perform OS command injection remotely, which could compromise the integrity and security of the system. ...
Discovered 8 hours ago
PoC for CVE-2026-90615
A security vulnerability has been discovered in the SourceCodester Class and Exam Timetabling System, specifically within the file /subject1.php. This flaw allows an attacker to manipulate the input argument 'subject', leading to cross-site scripting (XSS). The attack can be executed remotely, wh...
PoC for CVE-2025-48384
A vulnerability exists in Git that affects how configuration values are read and written, particularly regarding trailing carriage returns. When a submodule path includes a trailing carriage return, it is altered when read back, which can cause the submodule to be checked out to an incorrect loca...
PoC for CVE-2026-90613
A security flaw exists in the MP4Box component of GPAC, specifically in the stbl_GetSampleInfos function located in the isomedia/stbl_read.c file. This vulnerability can lead to a reachable assertion when exploited from a local position. Attackers can trigger this flaw to disrupt normal operation...
PoC for CVE-2026-90612
A vulnerability exists in the GPAC MP4Box component related to an assertion failure within the gf_sm_dump_command_list function. This issue can only be exploited locally, and an attacker may use publicly available exploit code to trigger the flaw, resulting in a denial of service. Users are advis...
Discovered 9 hours ago
PoC for CVE-2026-90781
The alsa-lib library up to version 1.2.16.1 is vulnerable to a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function. This vulnerability arises when parsing 'name=' fields that contain 64 or more characters, allowing attackers to provide a long control-element identifier via saved...
PoC for CVE-2026-90611
A local execution vulnerability has been identified in the GPAC MP4Box, specifically within the xmt_parse_element function of scene_manager/loader_xmt.c. This flaw allows attackers to exploit a reachable assertion when manipulating the input, leading to potential denial of service. The issue has ...
PoC for CVE-2026-90610
A vulnerability exists in GPAC's MP4Box component within the gf_svg_attributes_copy function, located in the svg_attributes.c file. This vulnerability leads to a buffer over-read situation when manipulated. The exploit requires local access, making it critical for users to upgrade to version abi-...
Discovered 10 hours ago
PoC for CVE-2026-90606
A security weakness in the Totolink A3002MU router's ipv6 setup process allows for remote exploitation through a buffer overflow caused by improper handling of the 'static_ipv6' argument. The vulnerability resides in the file '/boafrm/formIpv6Setup' within its 'boa' component, enabling attackers ...
PoC for CVE-2026-90605
A vulnerability exists in the Totolink A3002MU that allows an unauthorized remote attacker to exploit the formFilter function in the boa component. This occurs via a malformed IP address input, specifically targeting the ip6addr argument. Successful exploitation can lead to a buffer overflow cond...
PoC for CVE-2026-85706
A vulnerability in GitLab CE/EE allows unauthenticated users to read arbitrary files due to inadequate path confinement and a lack of proper authentication checks in the repository commits API. This issue affects GitLab versions 18.7 prior to 19.1.8, 19.2 prior to 19.2.6, and 19.3 prior to 19.3.2...
PoC for CVE-2026-90604
A security flaw has been identified within the Totolink A3002MU Hh-B20211125.1046, specifically affecting the component known as the Anchor Tag Handler. This vulnerability enables attackers to manipulate inputs, leading to potential cross site scripting (XSS) attacks. The flaw allows remote explo...
Discovered 11 hours ago
PoC for CVE-2026-90600
A SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0. This flaw lies within an unknown function in the /pages/inv_edit1.php file, where manipulation of the ID argument allows an attacker to execute arbitrary SQL queries. This vulnerability c...
Discovered 12 hours ago
PoC for CVE-2026-90599
A vulnerability exists within the Rizwan17 inventory management system affecting the file includes/process.php. This flaw allows for the possibility of cross-site request forgery attacks, which can be initiated remotely. The exploit has already been reported and could potentially be utilized by m...
PoC for CVE-2026-21852
A vulnerability in Claude Code allowed malicious repositories to exfiltrate sensitive user data, including Anthropic API keys, before users could confirm trust. Attackers could leverage a compromised repository to adjust the configuration to point to their own server. Once the repository was open...
PoC for CVE-2026-90597
A security flaw has been identified in the itsourcecode Sales and Inventory System version 1.0, specifically within the /pages/sup_edit1.php file. This vulnerability allows an attacker to manipulate the argument ID, potentially leading to unauthorized SQL commands being executed. Such attacks can...
Discovered 13 hours ago
PoC for CVE-2026-90595
A security flaw in wxiaoqi's Spring-Cloud-Platform affects the OnlineController.getOnlineInfo function, leading to missing authorization for remote requests. Attackers can exploit this flaw to gain unauthorized access to sensitive operations. Though the issue was reported early to the project mai...
PoC for CVE-2026-90594
A vulnerability exists in wxiaoqi's Spring-Cloud-Platform versions 3.0.1 and 3.1.0, specifically within the Permission Service's checkUserPermission function. This oversight allows remote attackers to manipulate the system, leading to unauthorized access. While the issue was reported to the proje...
PoC for CVE-2026-90584
A vulnerability exists in the TooTallNate Java-WebSocket library where improper handling in the Fragmentation Handler's processFrameContinuousAndNonFin function allows remote attackers to exploit resource allocation issues. This weakness could be manipulated to exhaust resources, leading to servi...
Discovered 14 hours ago
PoC for CVE-2026-88802
Certain versions of the MDJM Event Management and Mobile Events Manager WordPress plugins are susceptible to an authorization bypass vulnerability. This flaw arises from a failure to validate user capabilities, nonces, or the specific type of record when executing delete requests for playlist ent...
PoC for CVE-2026-89050
The Quads Ads Manager for Google AdSense plugin prior to version 3.0.5 contains a security flaw that allows users to mark an ad-selling order as paid without verifying the completion of the payment through the configured payment gateway. This vulnerability poses a risk as it enables unauthorized ...
PoC for CVE-2026-88793
The YouTube Embed plugin for WordPress versions 10.0 to 10.3 is susceptible to an authorization bypass flaw, enabling unauthenticated attackers to execute arbitrary web scripts via an inadequately secured AJAX action. This vulnerability allows attackers to store malicious scripts, which can be ex...
PoC for CVE-2026-85129
The Hoo Companion plugin for WordPress version 1.0.2 contains a significant security flaw due to the absence of authorization and validation checks in one of its import features. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts, which are then executed for any u...
PoC for CVE-2026-81648
The CryptoPayment Gateway plugin for WordPress versions 1.2.1 and 1.2.2 contains a significant security flaw that fails to implement proper authorization checks on one of its AJAX endpoints. This vulnerability permits unauthorized users to execute administrative tasks without sufficient authentic...
PoC for CVE-2026-74933
The GenieWords WordPress plugin, from versions 1.5.27 to 1.5.34, is susceptible to authorization flaws, enabling unauthenticated users to exploit its REST API and AJAX actions. This vulnerability allows attackers to change the plugin's configuration and inject arbitrary web scripts, which can exe...
PoC for CVE-2026-90582
A vulnerability has been discovered in the evanchiu serverless-todo API, specifically within the saveTodos function located in the src/index.js file. This issue arises from improper handling of the event.body input, which can lead to excessive resource consumption when manipulated. The vulnerabil...
PoC for CVE-2026-90581
A vulnerability has been identified in the cym1102 nginxWebUI versions up to 4.4.2, specifically in the autoUpdate function of the MainController. This flaw permits manipulation of the argument url, leading to potential code injection. Remote attackers may exploit this vulnerability, presenting s...
PoC for CVE-2026-90580
A vulnerability exists in FlowiseAI Flowise up to version 3.0.2, specifically in the Evaluations Endpoint, where improper handling of the Host/X-Forwarded-Proto argument in the axios.post function may lead to server-side request forgery (SSRF). This flaw allows attackers to manipulate server requ...