Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 7 hours ago

PoC for CVE-2026-29000

Pac4jPac4j-jwt9.3CRITICAL
Authentication Bypass in JwtAuthenticator of pac4j-jwt by pac4j

The pac4j-jwt library's JwtAuthenticator prior to versions 4.5.9, 5.7.9, and 6.3.3 is susceptible to an authentication bypass that could allow remote adversaries to create forged authentication tokens. By leveraging the server's RSA public key, attackers are able to craft a JWE-wrapped PlainJWT w...

Discovered 15 hours ago

PoC for CVE-2026-21509

MicrosoftMicrosoft 365 Apps For...7.8HIGH
Security Feature Bypass in Microsoft Office

A vulnerability exists in Microsoft Office that allows attackers to manipulate untrusted inputs, enabling them to bypass critical security measures locally. This flaw can expose systems to unauthorized actions, compromising the integrity of sensitive data. It is crucial for users to apply the lat...

Discovered 21 hours ago

PoC for CVE-2026-31816

BudibaseBudibase9.1CRITICAL
Unauthorized API Access Vulnerability in Budibase Low Code Platform

Budibase, a low code platform for creating internal tools, exhibits a significant vulnerability in its server's authorization mechanism. In versions 3.31.4 and earlier, the 'authorized()' middleware designed to protect server-side API endpoints can be bypassed entirely by appending a specific web...

Discovered 1 day ago

PoC for CVE-2018-7600

DrupalDrupal Before 7.58, 8....🟣 EPSS 94%9.8CRITICAL
Remote Code Execution Vulnerability in Drupal by Acquia

Multiple versions of Drupal, including those prior to 7.58 and various 8.x releases, are susceptible to a vulnerability that permits remote attackers to execute arbitrary code. This exploit takes advantage of configuration flaws in several subsystems, particularly those using default or common mo...

PoC for CVE-2026-4045

ProjectSendProjectsend6.3MEDIUM
Remote Code Execution Vulnerability in ProjectSend Auth Component

A security vulnerability exists in ProjectSend affecting versions up to r1945, specifically in the Auth.php file. This flaw allows for the manipulation of the ldap_email argument, which can cause discrepancies in the application's responses. An attacker may exploit this issue remotely, although t...

PoC for CVE-2019-25543

NetartmediaNetartmedia Real Estat...8.8HIGH
SQL Injection Vulnerability in Netartmedia Real Estate Portal Product

The Netartmedia Real Estate Portal 5.0 has an SQL injection vulnerability that can be exploited by attackers to manipulate database queries. By sending specially crafted POST requests to index.php with malicious SQL in the page parameter, unauthorized users can bypass security measures, extract s...

PoC for CVE-2019-25541

NetartmediaNetartmedia PHP Mall8.8HIGH
SQL Injection Vulnerabilities in Netartmedia PHP Mall by Netartmedia

Netartmedia PHP Mall 4.1 has been found to contain multiple SQL injection vulnerabilities that enable unauthenticated attackers to manipulate database queries. By exploiting unvalidated parameters, such as 'id' in index.php and 'Email' in loginaction.php, threat actors can execute time-based blin...

PoC for CVE-2019-25539

Sourceforge202cms8.8HIGH
Blind SQL Injection in 202CMS v10 Beta by sourceforge

202CMS v10 beta is vulnerable to a blind SQL injection flaw, which allows attackers to exploit the log_user parameter. Through carefully crafted POST requests to index.php, attackers can implement time-based blind injection techniques to execute arbitrary SQL commands. This vulnerability can lead...

PoC for CVE-2019-25537

NetartmediaNetartmedia Event Portal8.8HIGH
SQL Injection Vulnerability in Netartmedia Event Portal

Netartmedia Event Portal 2.0 is vulnerable to a time-based blind SQL injection, enabling unauthenticated attackers to insert SQL commands through the Email parameter. By sending manipulated POST requests to loginaction.php, attackers can extract sensitive data from the database, posing severe ris...

PoC for CVE-2019-25536

NetartmediaNetartmedia PHP Real E...8.8HIGH
SQL Injection Vulnerability in Netartmedia PHP Real Estate Agency S...

The Netartmedia PHP Real Estate Agency 4.0 software contains a serious SQL injection vulnerability that allows unauthenticated attackers to craft malicious POST requests. By exploiting the features[] parameter in the index.php file, attackers can execute arbitrary SQL queries that may lead to una...

PoC for CVE-2019-25535

NetartmediaNetartmedia PHP Dating...8.8HIGH
SQL Injection Vulnerability in Netartmedia PHP Dating Site

The Netartmedia PHP Dating Site is vulnerable to SQL injection attacks via the Email parameter in the loginaction.php file. This allows unauthenticated attackers to inject malicious SQL code, potentially enabling them to extract sensitive data from the database. By sending specially crafted POST ...

PoC for CVE-2019-25534

NetartmediaNetartmedia PHP Car De...8.8HIGH
SQL Injection Vulnerability in Netartmedia PHP Car Dealer

The Netartmedia PHP Car Dealer contains a significant SQL injection vulnerability that enables attackers, without authentication, to execute arbitrary SQL queries. This flaw is exploited through the features[] parameter in POST requests to index.php, allowing malicious users to inject SQL payload...

PoC for CVE-2019-25533

PHPbusinessdirectoryNetartmedia PHP Busine...8.8HIGH
SQL Injection Vulnerability in Netartmedia PHP Business Directory

Netartmedia's PHP Business Directory version 4.2 is susceptible to an SQL injection flaw that can be exploited by unauthenticated users. This vulnerability allows attackers to inject malicious SQL statements through the Email parameter when sending POST requests to the loginaction.php endpoint. S...

PoC for CVE-2019-25532

NetartmediaNetartmedia Jobs Portal8.8HIGH
SQL Injection Vulnerability in Netartmedia Jobs Portal 6.1

The Netartmedia Jobs Portal 6.1 is susceptible to an SQL injection vulnerability, which enables unauthenticated attackers to manipulate database queries. By sending carefully crafted POST requests to the loginaction.php file with malicious SQL code injected through the Email parameter, attackers ...

PoC for CVE-2019-25531

NetartmediaNetartmedia Deals Portal8.8HIGH
SQL Injection Vulnerability in Netartmedia Deals Portal

The Netartmedia Deals Portal is susceptible to an SQL injection vulnerability through the Email parameter in loginaction.php. This flaw enables unauthenticated attackers to execute crafted SQL queries via POST requests, providing them the capability to manipulate database operations. As a result,...

PoC for CVE-2019-25530

Hotel-booking-scriptUhotelbooking System8.8HIGH
SQL Injection Vulnerability in uHotelBooking System by uZer

The uHotelBooking System is susceptible to an SQL injection vulnerability, which enables unauthenticated attackers to manipulate database queries. By exploiting the 'system_page' GET parameter, malicious users can inject SQL commands via crafted requests to index.php. This misuse can lead to the ...

PoC for CVE-2019-25529

SourceforgePlaceto Cms7.1HIGH
SQL Injection Vulnerability in Placeto CMS Alpha by Placeto

Placeto CMS Alpha version 4 contains a vulnerability that enables authenticated attackers to exploit SQL injection through the 'page' parameter. By manipulating the parameter, attackers can craft GET requests to the admin/edit.php endpoint, leveraging techniques such as boolean-based blind, time-...

PoC for CVE-2019-25528

InoutscriptsInout Easyrooms Ultima...8.8HIGH
SQL Injection Vulnerability in Inout EasyRooms Ultimate Edition by ...

Inout EasyRooms Ultimate Edition v1.0 contains a security flaw that allows unauthorized users to execute SQL commands through the property1 parameter. By crafting specific POST requests to the search/searchdetailed endpoint, attackers can inject harmful SQL queries, potentially exposing sensitive...

PoC for CVE-2019-25524

XooscriptsXoogallery8.8HIGH
SQL Injection Vulnerability in XooGallery by XooTheme

XooGallery, a product by XooTheme, has a vulnerability that enables unauthorized individuals to execute SQL injection attacks through the 'p' parameter in a GET request to results.php. This means that attackers can pass crafted SQL code, compromising the integrity of the database. Such exploits c...

PoC for CVE-2019-25520

JettwebHazir Haber Sitesi Scr...8.8HIGH
Authentication Bypass Vulnerability in Jettweb PHP Script by Jettweb

The Jettweb PHP Hazir Haber Sitesi Scripti V1 is susceptible to an authentication bypass vulnerability that allows attackers to circumvent authentication protections in the administration panel. Through improper SQL query validation, malicious users can inject SQL payloads into the username and p...

PoC for CVE-2019-25515

JettwebHazir Haber Sitesi Scr...8.7HIGH
Authentication Bypass in Jettweb PHP Hazir Haber Sitesi Scripti V3

The Jettweb PHP Hazir Haber Sitesi Scripti V3 contains a significant security flaw that enables unauthenticated users to gain administrative access to the system. By exploiting the vulnerability present in the login.php administration panel, attackers can craft specific SQL syntax and manipulate ...

PoC for CVE-2019-25510

JettwebHazir Haber Sitesi Scr...8.8HIGH
Authentication Bypass Vulnerability in Jettweb PHP Hazir Haber Site...

The Jettweb PHP Hazir Haber Sitesi Scripti V2 is susceptible to an authentication bypass vulnerability due to improper validation of SQL queries in the administration panel. This flaw allows unauthenticated attackers to exploit SQL injection payloads using the login form at admingiris.php, potent...

PoC for CVE-2019-25509

XooscriptsXoodigital8.8HIGH
SQL Injection Vulnerability in XooDigital Latest Product

The XooDigital Latest product is susceptible to an SQL injection vulnerability via the 'p' parameter in the results.php file. This flaw enables unauthenticated attackers to craft GET requests with malicious 'p' values, allowing them to manipulate database queries and potentially extract sensitive...

PoC for CVE-2019-25508

JettwebHazir Ilan Sitesi Scripti8.8HIGH
SQL Injection Vulnerability in Jettweb PHP Hazir Ilan Sitesi Script...

The Jettweb PHP Hazir Ilan Sitesi Script V2 contains a significant SQL injection vulnerability that permits unauthenticated attackers to manipulate database queries through the 'kat' parameter. By sending specially crafted GET requests to the katgetir.php endpoint with malicious 'kat' values, att...

PoC for CVE-2019-25488

JettwebRent A Car Scripti8.8HIGH
SQL Injection Vulnerability in Jettweb Hazir Rent A Car Script by J...

The Jettweb Hazir Rent A Car Script V4 is plagued by multiple SQL injection vulnerabilities within its admin panel. These flaws allow unauthenticated attackers to execute arbitrary SQL commands by manipulating GET parameters such as 'tur', 'id', and 'ozellikdil' in the admin/index.php endpoint. S...

PoC for CVE-2019-25482

JettwebHazir Rent A Car Sites...8.8HIGH
SQL Injection Vulnerability in Jettweb PHP Hazir Rent A Car Sitesi ...

The Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 is susceptible to an SQL injection flaw that allows attackers to exploit the 'arac_kategori_id' parameter. By crafting POST requests with malicious SQL code, unauthenticated users can manipulate database queries, potentially exposing sensitive in...

PoC for CVE-2019-25479

InoutscriptsInout Realestate8.8HIGH
SQL Injection Vulnerability in Inout RealEstate by Inout

Inout RealEstate is susceptible to SQL injection, primarily affecting the agents/agentlistdetails endpoint. This vulnerability allows unauthenticated attackers to manipulate database queries by injecting malicious SQL code through the city parameter. By sending crafted POST requests, attackers ca...

PoC for CVE-2019-25481

IscriptsIscripts Reservelogic8.8HIGH
SQL Injection in iScripts ReserveLogic

iScripts ReserveLogic is affected by an SQL injection vulnerability that enables unauthenticated attackers to exploit the jqSearchDestination parameter. By sending specially crafted POST requests to the search endpoint, attackers can inject malicious SQL code, allowing them to manipulate database...

PoC for CVE-2019-25473

SoftwebinternationalClinic Pro7.1HIGH
SQL Injection Vulnerability in Clinic Pro by Clinic Pro Vendor

Clinic Pro is exposed to a SQL injection vulnerability due to improper handling of user-supplied input through the month parameter. This flaw allows authenticated attackers to craft malicious POST requests targeting the monthly_expense_overview endpoint. By utilizing techniques such as boolean-ba...

PoC for CVE-2026-4044

ProjectSendProjectsend5.1MEDIUM
Path Traversal Vulnerability in ProjectSend Delete Handler

A vulnerability in ProjectSend, specifically within the Delete Handler component's realpath function in the import-orphans.php file, allows for a path traversal exploit. By manipulating the argument files[], an attacker may gain unauthorized access to files on the server. This issue became public...

PoC for CVE-2026-4043

TendaI128.7HIGH
Stack-based Buffer Overflow in Tenda i12 by Tenda

A security vulnerability has been identified in Tenda i12 firmware version 1.0.0.6(2204). This vulnerability arises from improper handling of the index parameter in the 'formwrlSSIDget' function within the '/goform/wifiSSIDget' file. An attacker can exploit this weakness to achieve a stack-based ...

PoC for CVE-2026-4042

TendaI128.7HIGH
Stack-based Buffer Overflow in Tenda i12 Wireless Router

A vulnerability in the Tenda i12 wireless router allows for a stack-based buffer overflow through the formWifiMacFilterGet function located in the /goform/WifiMacFilterGet file. This weakness could be exploited remotely, enabling potential attackers to manipulate index arguments. The exploit has ...

PoC for CVE-2026-4041

TendaI128.7HIGH
Stack-based Buffer Overflow in Tenda i12 Router

A security vulnerability has been identified in the Tenda i12 router, specifically within the vos_strcpy function located in the /goform/exeCommand file. This flaw allows an attacker to manipulate the cmdinput argument, leading to a stack-based buffer overflow. The vulnerability can be exploited ...

PoC for CVE-2026-4016

GPACGpac4.8MEDIUM
Out-of-Bounds Write Vulnerability in GPAC SVG Parser Component

A security vulnerability has been identified in GPAC 26.03-DEV affecting the SVG Parsing functionality. The issue arises from an out-of-bounds write in the 'svgin_process' function within the 'src/filters/load_svg.c' file. This vulnerability could potentially allow an attacker with local access t...

PoC for CVE-2026-4015

GPACGpac4.8MEDIUM
Buffer overflow vulnerability in GPAC TeXML File Parser

A vulnerability has been identified in the GPAC software, specifically within the TeXML File Parser's function 'txtin_process_texml'. This issue may allow an attacker to exploit a stack-based buffer overflow by manipulating input data. This vulnerability can potentially be executed locally, which...

PoC for CVE-2026-4014

ItsourcecodeCafe Reservation System6.9MEDIUM
SQL Injection Flaw in itsourcecode Cafe Reservation System

A security flaw has been identified in the Cafe Reservation System version 1.0, specifically within the signup.php file of the Registration component. This vulnerability allows an attacker to manipulate the Username parameter, leading to SQL injection. Remote exploitation of this weakness is poss...

PoC for CVE-2026-4012

RxiFe4.8MEDIUM
Out-of-Bounds Read Vulnerability in rxi fe Software

An out-of-bounds read vulnerability exists in the rxi fe software affecting the function read_ located in the src/fe.c file. This vulnerability arises from improper input handling, allowing attackers who have local access to manipulate the input and potentially access data outside the allocated m...

PoC for CVE-2026-4010

ThakeenatheesPocketlang4.8MEDIUM
Memory Corruption Vulnerability in ThakeeNathees Pocketlang Software

A vulnerability affecting the pkByteBufferAddString function in ThakeeNathees Pocketlang allows for memory corruption due to improper handling of argument lengths. Exploitation of this flaw requires local access and can be executed with an input length of 4294967290. Although the issue was report...

PoC for CVE-2026-4010

ThakeenatheesPocketlang4.8MEDIUM
Memory Corruption Vulnerability in ThakeeNathees Pocketlang Software

A vulnerability affecting the pkByteBufferAddString function in ThakeeNathees Pocketlang allows for memory corruption due to improper handling of argument lengths. Exploitation of this flaw requires local access and can be executed with an input length of 4294967290. Although the issue was report...

PoC for CVE-2026-4010

ThakeenatheesPocketlang4.8MEDIUM
Memory Corruption Vulnerability in ThakeeNathees Pocketlang Software

A vulnerability affecting the pkByteBufferAddString function in ThakeeNathees Pocketlang allows for memory corruption due to improper handling of argument lengths. Exploitation of this flaw requires local access and can be executed with an input length of 4294967290. Although the issue was report...

PoC for CVE-2026-4009

JarikomppaSoloud4.8MEDIUM
Out-of-Bounds Read Vulnerability in SoLoud WAV File Parser by jarik...

A vulnerability exists in the SoLoud WAV File Parser affecting versions up to 20200207. The specific flaw is located in the function drwav_read_pcm_frames_s16__msadpcm within the audio source library, which allows for potential out-of-bounds read operations. This can lead to unauthorized access t...

Discovered 2 days ago

PoC for CVE-2026-4008

TendaW38.7HIGH
Stack-based Buffer Overflow in Tenda W3 Router

A security flaw has been identified in the Tenda W3 router, specifically in the POST Parameter Handler, located at /goform/wifiSSIDset. This vulnerability allows for a stack-based buffer overflow due to improper processing of input arguments, notably index and GO. An attacker with remote access c...

PoC for CVE-2026-4007

TendaW38.7HIGH
Buffer Overflow Vulnerability in Tenda W3 Router

A remote code execution vulnerability has been identified in the Tenda W3 router, specifically within the POST Parameter Handler in the '/goform/wifiSSIDget' file. An attacker can exploit this vulnerability by manipulating the 'index' argument, leading to a stack-based buffer overflow. Once execu...

PoC for CVE-2026-3994

Rui314Mold4.8MEDIUM
Heap-Based Buffer Overflow in rui314 Mold Object File Handler

A heap-based buffer overflow vulnerability has been identified in the Object File Handler of rui314 mold, specifically in the 'mold::ObjectFilemold::X86_64::initialize_sections' function found in 'src/input-files.cc'. This vulnerability affects versions of mold up to 2.40.4 and requires local exp...

PoC for CVE-2026-3993

ItsourcecodePayroll Management System5.3MEDIUM
Cross Site Scripting Vulnerability in itsourcecode Payroll Manageme...

A cross site scripting (XSS) vulnerability has been identified in the itsourcecode Payroll Management System 1.0. This vulnerability stems from improper handling of user input in the /manage_employee_deductions.php file, specifically through manipulation of the argument ID. Attackers can exploit ...

PoC for CVE-2025-15473

WordPressTimetics4.3MEDIUM
Insufficient Authorization in Timetics Booking Plugin for WordPress

The Timetics Booking Plugin for WordPress prior to version 1.0.52 contains a vulnerability where a REST endpoint lacks necessary authorization checks. This allows unauthenticated users to manipulate the payment status and post status of bookings for the custom post type 'timetics-booking.' As a r...

PoC for CVE-2026-2687

WordPressReading Progressbar4.3MEDIUM
Stored Cross-Site Scripting Vulnerability in Reading Progressbar Pl...

The Reading Progressbar plugin for WordPress prior to version 1.3.1 is susceptible to Stored Cross-Site Scripting attacks. This vulnerability arises because the plugin fails to adequately sanitize and escape certain settings. As a result, even users with high privilege access, such as administrat...

PoC for CVE-2026-3992

CodegenieappServerless-express5.3MEDIUM
Remote Code Injection Vulnerability in CodeGenieApp Serverless-Express

A vulnerability has been discovered in the CodeGenieApp serverless-express up to version 4.17.1. This flaw resides in the utils/dynamodb.ts file, specifically within the Users Endpoint functionality. The vulnerability arises from improper handling of arguments, leading to a potential injection ri...

PoC for CVE-2026-3990

CesiumgsCesiumjs5.3MEDIUM
Cross-Site Scripting Flaw in CesiumJS by CesiumGS

A security vulnerability has been identified in CesiumGS's CesiumJS, specifically in the demo code located in Apps/Sandcastle/standalone.html. This flaw allows for the manipulation of parameters leading to cross-site scripting (XSS) attacks, which can be executed remotely. This exploitation can p...

PoC for CVE-2026-3984

CampcodesDivision Regional Athl...5.1MEDIUM
Cross-Site Scripting Vulnerability in Campcodes Division Regional A...

A cross-site scripting vulnerability has been discovered in version 2.1 of the Campcodes Division Regional Athletic Meet Game Result Matrix System. This flaw lies within the 'save_up_athlete.php' file, where improper handling of the 'a_name' argument can lead to an exploit. Attackers can remotely...