Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2026-94426

XuxueliXxl-job5.1MEDIUM
Cross-Site Scripting Vulnerability in xuxueli XXL-Job Software

A vulnerability exists in the xuxueli XXL-Job software that allows for cross-site scripting (XSS) through a flaw in the `jobgroup/insert` function. This vulnerability can be exploited remotely by manipulating the argument 'Name'. The potential for exploitation is heightened as the flaw has been p...

Discovered 3 hours ago

PoC for CVE-2026-28618

GoogleAndroid8.8HIGH
Heap Buffer Overflow Vulnerability in Android OS

A vulnerability in the Android OS identified as a heap buffer overflow can allow potential attackers to execute remote code without requiring any user interaction. This weakness resides in the 'dec_frm_prepare' function of the 'oapv.c' file, which can be exploited to conduct out-of-bounds writes,...

PoC for CVE-2026-94540

MrpearDesktopsms7.4HIGH
Unauthorized Access Vulnerability in DesktopSMS by MrPear

DesktopSMS 1.11.0 by MrPear is susceptible to an unauthorized access vulnerability, enabling local attackers to utilize the application's local service. This flaw allows attackers to send SMS messages and retrieve SMS-derived content without requiring user interaction or pairing confirmation. An ...

PoC for CVE-2026-94536

DromaraLamp-cloud5.3MEDIUM
Unauthorized Information Disclosure in Lamp-cloud by Dromara

The Lamp-cloud software, up to version 5.10.0, is susceptible to an information disclosure vulnerability due to inadequate validation of the 'employeeId' parameter in the '/anyone/visible/resource' endpoint. This flaw permits authenticated users to exploit the system, enabling them to read roles ...

PoC for CVE-2026-94535

DromaraLamp-cloud7.1HIGH
Authorization Bypass Vulnerability in lamp-cloud by dromara

An authorization bypass vulnerability exists in the deleteMyNotice endpoint of lamp-cloud (versions up to 5.10.0). This flaw allows authenticated users to craft malicious DELETE requests, targeting arbitrary notice IDs, thus enabling them to delete notifications that belong to other users without...

PoC for CVE-2026-94534

DromaraLamp-cloud7.1HIGH
User Profile Vulnerability in Lamp-Cloud by Dromara

Lamp-Cloud versions up to 5.10.0 are susceptible to a serious security issue where user identity is not properly validated during profile updates. This vulnerability allows authenticated attackers to manipulate user profiles by sending requests with targeted user IDs. Attackers can alter critical...

PoC for CVE-2026-94534

DromaraLamp-cloud7.1HIGH
User Profile Vulnerability in Lamp-Cloud by Dromara

Lamp-Cloud versions up to 5.10.0 are susceptible to a serious security issue where user identity is not properly validated during profile updates. This vulnerability allows authenticated attackers to manipulate user profiles by sending requests with targeted user IDs. Attackers can alter critical...

PoC for CVE-2026-94533

DromaraLamp-cloud7.1HIGH
Authorization Bypass in lamp-cloud Vulnerability Allowing File Access

The lamp-cloud product, specifically through version 5.10.0, suffers from an authorization bypass vulnerability in the FileAnyoneController. This flaw permits authenticated users to download arbitrary attachments from other users. By manipulating valid attachment identifiers, attackers can exploi...

PoC for CVE-2026-94532

DromaraLamp-cloud7.1HIGH
Authorization Bypass in Lamp-Cloud by Dromara

Lamp-Cloud, up to version 5.10.0, has a vulnerability in the getUserInfoById endpoint which allows authenticated users to bypass authorization checks. This flaw enables individuals to access full profiles of any user within the system by manipulating the userId parameter. As a consequence, attack...

Discovered 4 hours ago

PoC for CVE-2026-77078

MulterMulter7.5HIGH
Denial of Service in multer Middleware for Node.js by Express.js

The multer middleware used for handling multipart/form-data in Node.js applications has a vulnerability that can be exploited to trigger a denial of service (DoS). This occurs when a multipart request containing two specially crafted text field names is sent. The first field attempts to create an...

Discovered 6 hours ago

PoC for CVE-2025-6325

WordPressKing Addons For Elementor9.8CRITICAL
Privilege Escalation Vulnerability in King Addons for Elementor by ...

A vulnerability exists in King Addons for Elementor, developed by KingAddons.com, that allows attackers to escalate their privileges. This Incorrect Privilege Assignment flaw enables unauthorized users to gain elevated access to restricted functionalities within the plugin. The issue affects all ...

Discovered 7 hours ago

PoC for CVE-2026-94501

JishenghuaJsherp8.7HIGH
Authorization Bypass in jshERP Affects User Business CRUD Operations

The jshERP software version 3.6 is susceptible to an authorization bypass vulnerability within its userBusiness CRUD endpoints. This flaw enables authenticated users to perform operations on authorization-related rows without proper privilege checks. As a result, attackers can alter user-role map...

PoC for CVE-2026-94497

JishenghuaJsherp8.7HIGH
Unauthorized Access Vulnerability in jshERP by Jishenghua

The jshERP product version 3.6 has a significant vulnerability related to improper validation of object ownership in its API endpoints for information retrieval, updates, and deletions across various resource types. This oversight allows authenticated users to exploit the system by directly submi...

PoC for CVE-2026-94496

JishenghuaJsherp8.7HIGH
Privilege Escalation Vulnerability in jshERP Software by jishenghua

The jshERP software version 3.6 contains a vulnerability in its role management endpoints that fails to properly validate caller permissions. This oversight allows authenticated users to manipulate role data and potentially delete roles. Consequently, attackers can exploit the vulnerable /role/up...

PoC for CVE-2026-94495

JishenghuaJsherp7.1HIGH
Improper User Privilege Validation in jshERP Product by JSH

jshERP versions prior to 3.6 contain a flaw that allows authenticated users to bypass authorization checks within the SystemConfigService.updateSystemConfig function. This vulnerability enables attackers to manipulate tenant-specific system configurations, including critical parameters related to...

PoC for CVE-2026-94494

JishenghuaJsherp5.3MEDIUM
Tenant Isolation Bypass in jshERP by jishenghua

The jshERP application, up to version 3.6, contains a vulnerability that allows authenticated users to bypass tenant isolation. This flaw enables these users to access sensitive records of other tenants through the GET /tenant/info endpoint. By iterating the primary key, attackers can enumerate v...

PoC for CVE-2026-94414

JishenghuaJsherp5.3MEDIUM
Authorization Bypass in jshERP Affects Role Button-Permission Settings

jshERP prior to version 3.6 contains a vulnerability in the POST /userBusiness/updateBtnStr endpoint. This flaw occurs due to the absence of an authorization check, allowing authenticated users to potentially alter role-specific button-permission configurations. Malicious actors can exploit this ...

PoC for CVE-2026-94413

JishenghuaJsherp7.1HIGH
Password Hash Exposure in jshERP through 3.6

An issue in jshERP versions up to 3.6 allows authenticated users to access unsalted MD5 password hashes through the /user/info endpoint. This enables attackers to request arbitrary user information by supplying specific user IDs, exposing sensitive password digests. These hashes can be exploited ...

PoC for CVE-2026-94412

JishenghuaJsherp8.7HIGH
Authorization Bypass in jshERP Product by Vendor jshERP

The jshERP application through version 3.6 contains a significant vulnerability in its password reset functionality. Specifically, the authorization bypass affects the POST /user/resetPwd endpoint, which allows authenticated users to reset passwords of any other user by simply specifying a target...

PoC for CVE-2026-94411

JishenghuaJsherp8.7HIGH
Privilege Escalation Vulnerability in jshERP 3.6 by jishenghua

jshERP version 3.6 is susceptible to a privilege escalation vulnerability found within the updateOneValueByKeyIdAndType endpoint. This flaw allows authenticated users to manipulate their access privileges unlawfully. By submitting a POST request containing their user ID and a list of role IDs des...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-94488

TelegramTelegram Desktop8.3HIGH
Cross-Site Scripting Vulnerability in Telegram Desktop by Telegram

A cross-site scripting vulnerability exists in Telegram Desktop prior to version 6.9.4, allowing attackers to exploit the HTML export functionality. The issue is present in the method button.text.toUtf8 within export_output_html.cpp. An attacker must entice a victim to utilize the HTML export fea...

Discovered 10 hours ago

PoC for CVE-2026-94129

BiOStarValkyrie Aurora9.3CRITICAL
Local IOCTL Handler Vulnerability in BioStar VALKYRIE AURORA Software

A vulnerability exists in the BioStar VALKYRIE AURORA software, specifically in the IOCTL handler within the BS_RVSIO64.sys file. This vulnerability allows for a write-what-where condition via manipulation of the PhysicalAddress argument. As a result, local attackers could exploit this vulnerabil...

Discovered 12 hours ago

PoC for CVE-2026-94216

St Engineering Id...Evolution5.3MEDIUM
Open Redirect Vulnerability in ST Engineering iDirect Evolution and...

A security weakness has been found in ST Engineering's iDirect Evolution and Velocity WebServer products, where the 'authorize' function in the HTTP Header Handler component allows for manipulation of request arguments. Specifically, altering the 'Success' parameter can lead to an open redirect, ...

Discovered 13 hours ago

PoC for CVE-2026-94214

St Engineering Id...Evolution5.3MEDIUM
Open Redirect Vulnerability in ST Engineering iDirect Evolution and...

A security flaw has been identified in ST Engineering iDirect Evolution and Velocity WebServer affecting the Management Service's login component. The vulnerability arises from improper handling of the Host header in the /login.html file, enabling attackers to manipulate URL requests resulting in...

PoC for CVE-2026-94211

Hyve5Leantime4.8MEDIUM
Cross-Site Scripting Vulnerability in Hyve5 Leantime Project Dashboard

A vulnerability has been identified in Hyve5 Leantime up to version 3.9.8, specifically affecting the Project Dashboard component. This flaw allows malicious actors to inject cross-site scripting (XSS) payloads through the '/app/Domain/Dashboard/Templates/show.blade.php' file. The manipulation of...

PoC for CVE-2026-74469

LinuxLinux8.8HIGH
SCTP Transport Count Overflow in Linux Kernel Products

A vulnerability exists in the Linux kernel related to SCTP (Stream Control Transmission Protocol) which allows for a transport count overflow. The function sctp_assoc_add_peer() increments a 16-bit transport_count for each unique peer. When the transport_count exceeds 65,536, it wraps around to z...

PoC for CVE-2026-68121

LinuxLinux7.8HIGH
PPPoE Header Vulnerability in Linux Kernel

A vulnerability in the Linux kernel's PPPoE implementation allows for header pointer mismanagement during device header callbacks. When a send action is blocked, it can lead to an invalidated pointer within the socket buffer (skb) head. This issue arises specifically when transitioning from a non...

PoC for CVE-2026-94210

Hyve5Leantime5.1MEDIUM
Cross-Site Scripting Vulnerability in Hyve5 Leantime Kanban Board

A vulnerability has been identified in the Hyve5 Leantime Kanban Board affecting versions up to 3.9.8. This specific flaw in the function getAllGrouped located in the file app/Domain/Tickets/Services/Tickets.php allows attackers to execute cross-site scripting (XSS) attacks remotely. Successful e...

Discovered 14 hours ago

PoC for CVE-2026-81000

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in TUN and TAP Networking Interfaces

The vulnerability in the Linux kernel's TUN and TAP interfaces arises from incorrect management of packet data when tun_get_user() operates with oversized headroom requests. This flaw can lead to an improper allocation of packet data storage, potentially allowing skb->data to be located outside o...

PoC for CVE-2026-80844

LinuxLinux
Vulnerability in Linux Kernel Affecting AH6 Routing Header Validation

A flaw exists within the Linux kernel's AH6 module related to the validation of routing header segments. The function ipv6_rearrange_rthdr() improperly assumes that the 'segments_left' field of a routing header will not exceed the number of addresses defined in the hdrlen field. However, this hol...

PoC for CVE-2026-8932

CurlCurl7.5HIGH
Connection Pool Reuse Flaw in libcurl Affects Multiple Products

A vulnerability in libcurl arises from its connection pooling mechanism, where previously established connections can be reused despite changes to mTLS configuration settings. This flaw occurs because certain TLS parameters associated with client certificates are not adequately checked during the...

Discovered 16 hours ago

PoC for CVE-2026-92400

WordPressPayment Gateway For Pa...5.3MEDIUM
Payment Notification Verification Flaw in WooCommerce PayPal Plugin

The WooCommerce PayPal Payment Gateway plugin for WordPress contains a vulnerability where it fails to validate incoming payment notifications properly. Specifically, prior to version 9.2.1, the plugin does not confirm that a payment notification is associated with the store's own merchant accoun...

PoC for CVE-2026-86802

WordPressTo Do List Member3.7LOW
Authorization Flaw in To Do List Member Plugin for WordPress

The To Do List Member plugin for WordPress is affected by a vulnerability that lacks adequate authorization and nonce checks in its import routine. This flaw permits unauthenticated users to generate arbitrary published posts and taxonomy terms. Moreover, the plugin does not validate the source o...

PoC for CVE-2026-85010

WordPressRestropress5.3MEDIUM
Server-Side Price Manipulation Vulnerability in RestroPress Plugin ...

The RestroPress plugin for WordPress is susceptible to a significant vulnerability that enables unauthenticated users to manipulate the pricing of item add-ons. Specifically, prior to version 3.4.6, the plugin fails to perform adequate validation of the item add-on price supplied by the client wh...

PoC for CVE-2026-85113

WordPressGiveWP6.5MEDIUM
Shortcode Execution Vulnerability in GiveWP Plugin for WordPress

The GiveWP plugin for WordPress, up to version 4.16.9, is susceptible to a vulnerability that allows unauthenticated users to execute arbitrary shortcodes. This occurs because the plugin fails to adequately remove shortcode delimiters from user-supplied input before rendering it on public pages. ...

PoC for CVE-2026-94152

Omega SolutionFbp Fulfillment By People5.3MEDIUM
Authorization Bypass Vulnerability in Omega Solution FBP Fulfillmen...

A significant security flaw has been identified in Omega Solution's FBP Fulfillment by People 2025, specifically within the User Profile API component. This vulnerability arises from improper handling of the user ID argument, which can facilitate an unauthorized access scenario. Attackers can exp...

Discovered 17 hours ago

PoC for CVE-2026-94151

Omega SolutionHrm Os6.9MEDIUM
Weakness in Omega Solution HRM OS Role Permission API Exposes Vulne...

A vulnerability has been detected in Omega Solution's HRM OS affecting the Role Permission API within the file /role-permission/permission. This weakness arises from a manipulation of the roleId argument, which could allow attackers to bypass authentication measures. The vulnerability can be expl...

PoC for CVE-2026-94150

Omega SolutionHrm Os4.8MEDIUM
Cross Site Scripting Vulnerability in Omega Solution HRM OS Software

A security flaw has been identified within the Omega Solution HRM OS, specifically affecting the SVG File Upload component. This vulnerability allows an attacker to manipulate an unknown function in the /media/view/ directory, leading to potential cross site scripting (XSS) attacks. Such attacks ...

PoC for CVE-2026-94149

Omega SolutionHrm Os5.3MEDIUM
Improper Resource Control in Omega Solution HRM OS by Omega Solution

A vulnerability has been discovered in Omega Solution HRM OS, specifically within the Role Permission Retrieval Endpoint. The issue arises from improper management of resource identifiers due to the manipulation of the argument roleId. This vulnerability allows attackers to potentially exploit th...

PoC for CVE-2026-33439

OpenidentityplatformOpenam🟣 EPSS 10%9.3CRITICAL
Remote Code Execution in OpenIdentityPlatform OpenAM Access Managem...

OpenIdentityPlatform's OpenAM, an access management solution, is susceptible to a pre-authentication Remote Code Execution vulnerability due to unsafe Java deserialization. This issue arises from the handling of the jato.clientSession HTTP parameter, allowing unauthenticated attackers to execute ...

Discovered 18 hours ago

PoC for CVE-2026-94145

XuxueliXxl-job5.1MEDIUM
Cross-Site Scripting Vulnerability in xuxueli XXL-Job Task Manageme...

A vulnerability has been identified in xuxueli XXL-Job, affecting the Task Management Interface. An improper handling of user input in the JobInfoController.java file enables attackers to execute cross-site scripting (XSS) attacks. The vulnerability allows for remote exploitation by manipulating ...

PoC for CVE-2026-94144

DrogonframeworkDrogon6.9MEDIUM
SQL Injection Vulnerability in Drogon Framework by Drogon

A vulnerability exists in the Drogon Framework's ORM component, specifically within the makeCriteria function of orm_lib/src/Criteria.cc. This flaw allows remote attackers to manipulate the filter argument, potentially leading to SQL injection attacks. The exploit is actively known and can be exe...

Discovered 19 hours ago

PoC for CVE-2026-82187

WordPressWeb To Print Online De...9.8CRITICAL
File Upload Vulnerability in Web to Print Online Designer Plugin by...

The Web to Print Online Designer WordPress plugin prior to version 2.15.0 lacks proper validation for the files being uploaded. This flaw allows unauthenticated attackers to upload any type of file, including malicious PHP scripts. Furthermore, the plugin inappropriately exposes access tokens to ...

Discovered 20 hours ago

PoC for CVE-2026-94143

DrogonframeworkDrogon6.9MEDIUM
SQL Injection Vulnerability in DrogonFramework's ORM Mapper Component

A vulnerability in DrogonFramework's ORM Mapper component has been identified, specifically within the `Mapper::orderBy` function located in the Mapper.h library. This flaw allows for SQL injection through manipulation of the 'sort' argument, making it possible for attackers to execute remote exp...

PoC for CVE-2016-10204

ZoneminderZoneminder9.8CRITICAL
SQL Injection Vulnerability in ZoneMinder by ZoneMinder Team

An SQL injection vulnerability in ZoneMinder versions 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the 'limit' parameter in log query requests sent to index.php. This exploit can lead to unauthorized access to sensitive data and possible database manipulation, po...

PoC for CVE-2026-94139

Chengdu Feiyuxing...Feiyu Star Router5.3MEDIUM
Command Injection Vulnerability in Feiyu Star Router by Chengdu Fei...

A command injection vulnerability has been discovered in the cookie handler functionality of the Feiyu Star Router B-MB5E202-210322-r11656. Specifically, the issue arises when the session_id parameter within the /send_order.cgi endpoint is manipulated. This flaw allows attackers to execute arbitr...

Discovered 21 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-86552

ZteSmartlife5.4MEDIUM
Dynamic Authentication Vulnerability in SmartLife App from ZTE

The SmartLife app has a significant vulnerability where it dynamically generates authentication parameters at runtime. This flaw allows attackers to obtain valid authentication credentials, enabling them to complete account registrations with any arbitrary email address. Notably, the application ...

PoC for CVE-2026-94138

Chengdu Feiyuxing...Feiyu Star Router5.1MEDIUM
Command Injection Vulnerability in Chengdu Feiyuxing Technology Fei...

A command injection vulnerability exists in the Feiyu Star Router B-MB5E202-210322-r11656, specifically within the /send_order.cgi?parameter=del_expmac endpoint. By manipulating the 'mac' argument, attackers can execute arbitrary commands on the device remotely. This flaw could lead to significan...