Publicly Disclosed
PoC Exploits

πŸ”΄ Alway take caution when working with PoC Exploits πŸ”΄

Discovered just now...

PoC for CVE-2025-14847

MongoDBMongodb Server🟣 EPSS 68%8.7HIGH
Heap Memory Exposure in MongoDB Server Versions by MongoDB

The vulnerability arises from mismatched length fields in Zlib compressed protocol headers within MongoDB Server, potentially allowing an unauthenticated client to access uninitialized heap memory. This could lead to unauthorized information exposure, affecting versions of MongoDB Server across m...

Discovered 3 hours ago

PoC for CVE-2025-4802

The Gnu C LibraryGlibc7.8HIGH
Untrusted Environment Variable Vulnerability in GNU C Library

The GNU C Library contains a vulnerability related to the untrusted LD_LIBRARY_PATH environment variable, which can be exploited by attackers. This issue affects setuid binaries that utilize dynamic link library loading features through the dlopen function, particularly in scenarios involving int...

Discovered 6 hours ago

PoC for CVE-2025-14803

WordPressNex-forms
Stored Cross-Site Scripting Vulnerability in NEX-Forms WordPress Pl...

The NEX-Forms WordPress plugin prior to version 9.1.8 has a security flaw that allows attackers to exploit unsanitized and unescaped settings. This vulnerability can be leveraged by low-privileged users, like subscribers, to inject malicious scripts into web pages. Such attacks can result in the ...

PoC for CVE-2021-43798

GrafanaGrafana🟣 EPSS 94%7.5HIGH
Grafana path traversal

Grafana, an open-source monitoring and observability platform, is susceptible to a directory traversal vulnerability in versions ranging from 8.0.0-beta1 to 8.3.0. This vulnerability enables unauthorized access to local files via specially crafted URL paths which include the identifier for any in...

Discovered 10 hours ago

PoC for CVE-2022-4782

WordpressClickfunnels5.4MEDIUM
ClickFunnels <= 3.1.1 - Contributor+ Stored XSS via Shortcode

The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

Discovered 11 hours ago

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 53%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

Discovered 12 hours ago

PoC for CVE-2024-0368

WordpressHustle – Email Marketi...8.6HIGH
Sensitive Information Exposure in The Hustle Plugin

The Hustle - Email Marketing, Lead Generation, Optins, Popups plugin for WordPress contains a vulnerability that results in Sensitive Information Exposure across all versions up to and including 7.8.3. This weakness arises from hardcoded API keys, which can be exploited by unauthenticated attacke...

Discovered 15 hours ago

PoC for CVE-2025-14505

N/aElliptic5.6MEDIUM
Cryptographic Vulnerability in Elliptic Package by Indutny

The Elliptic package experiences a significant cryptographic vulnerability where the ECDSA implementation generates incorrect signatures. This flaw arises due to an improper computation of the interim value 'k', leading to potential truncation when it has leading zeros. As a result, an attacker c...

PoC for CVE-2019-9624

WebminWebmin🟣 EPSS 51%7.8HIGH
Remote Code Execution in Webmin by Remote Attackers

Webmin 1.900 possesses a vulnerability that allows remote attackers to execute arbitrary code. This exploitation can be carried out by utilizing the 'Java file manager' and 'Upload and Download' privileges. Attackers can upload a specially crafted .cgi file through the /updown/upload.cgi URI, lea...

Discovered 18 hours ago

PoC for CVE-2025-65731

D-LinkDIR-605L Router
Physical Access Vulnerability in D-Link DIR-605L Router

A physical access vulnerability exists in the D-Link DIR-605L Router that can be exploited by an attacker with direct access to the UART pins. This flaw permits the execution of arbitrary commands due to unregulated root terminal access on a serial interface. Without proper access controls, this ...

Discovered 1 day ago

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 53%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

Discovered 2 days ago

PoC for CVE-2022-0847

LinuxKernel🟣 EPSS 84%7.8HIGH
Privilege Escalation Vulnerability in Linux Kernel by Red Hat

A vulnerability exists in the Linux kernel related to improper initialization of the 'flags' member of the new pipe buffer structure. This absence of proper initialization in the copy_page_to_iter_pipe and push_pipe functions can result in the presence of stale values. As a consequence, an unpriv...

PoC for CVE-2019-25284

Guangzhou VV-sol Gpon/epon Olt Pl...5.1MEDIUM
Reflected Cross-Site Scripting Vulnerabilities in V-SOL GPON/EPON O...

The V-SOL GPON/EPON OLT Platform v2.03 is susceptible to multiple reflected cross-site scripting vulnerabilities. These arise from inadequate input sanitization in various script parameters. Malicious actors can exploit these security flaws by injecting harmful HTML and script code, enabling the ...

PoC for CVE-2019-25280

Yahei.netYahei-PHP Prober5.1MEDIUM
Remote HTML Injection Vulnerability in Yahei-PHP Prober by Yahei

Yahei-PHP Prober version 0.4.7 has a vulnerability that permits remote HTML injection via the 'speed' GET parameter in prober.php. This flaw enables attackers to execute arbitrary HTML code, potentially leading to cross-site scripting (XSS) attacks affecting user sessions in their browsers. By ma...

PoC for CVE-2019-25277

Iwt Ltd.Facesentry Access Cont...5.1MEDIUM
Cross-Site Scripting Vulnerability in FaceSentry Access Control Sys...

The FaceSentry Access Control System version 6.4.8 contains a cross-site scripting vulnerability that affects the 'msg' parameter of the pluginInstall.php file. This vulnerability allows attackers to inject malicious scripts through unvalidated input. Once exploited, the injected JavaScript can e...

PoC for CVE-2019-25270

Soca Technology C...Soca Access Control Sy...5.1MEDIUM
Cross-Site Scripting Vulnerability in SOCA Access Control System by...

The SOCA Access Control System 180612 is vulnerable to a cross-site scripting (XSS) attack via the 'senddata' parameter in logged_page.php. This vulnerability enables attackers to execute arbitrary HTML and JavaScript code within the browser session of a victim when crafted POST requests are sent...

PoC for CVE-2019-25291

Inim Electronics ...Smartliving Smartlan/g/si9.3CRITICAL
Hard-Coded Credential Vulnerability in INIM Electronics Smartliving...

The INIM Electronics Smartliving SmartLAN/G/SI devices, running Linux versions up to 6.x, contain hard-coded credentials that are unchangeable through regular device operations. This vulnerability allows malicious actors to exploit these persistent credentials, facilitating unauthorized access to...

PoC for CVE-2019-25291

Inim Electronics ...Smartliving Smartlan/g/si9.3CRITICAL
Hard-Coded Credential Vulnerability in INIM Electronics Smartliving...

The INIM Electronics Smartliving SmartLAN/G/SI devices, running Linux versions up to 6.x, contain hard-coded credentials that are unchangeable through regular device operations. This vulnerability allows malicious actors to exploit these persistent credentials, facilitating unauthorized access to...

PoC for CVE-2019-25290

Inim Electronics ...Smartliving Smartlan/g/si6.9MEDIUM
Unauthenticated Server-Side Request Forgery in Smartliving SmartLAN...

The Smartliving SmartLAN/G/SI product version 6.x and earlier is susceptible to an unauthenticated server-side request forgery (SSRF) vulnerability. This issue exists within the GetImage functionality, where attackers can exploit the 'host' parameter to send crafted requests through the onvif.cgi...

PoC for CVE-2019-25290

Inim Electronics ...Smartliving Smartlan/g/si6.9MEDIUM
Unauthenticated Server-Side Request Forgery in Smartliving SmartLAN...

The Smartliving SmartLAN/G/SI product version 6.x and earlier is susceptible to an unauthenticated server-side request forgery (SSRF) vulnerability. This issue exists within the GetImage functionality, where attackers can exploit the 'host' parameter to send crafted requests through the onvif.cgi...

PoC for CVE-2019-25289

Inim Electronics ...Smartliving Smartlan/g/si8.7HIGH
Remote Command Injection in SmartLiving SmartLAN by Inim

The SmartLiving SmartLAN versions up to 6.x are affected by a significant security vulnerability that allows authenticated users to execute arbitrary commands on the system. This vulnerability arises from the 'par' POST parameter within the web.cgi binary, specifically through the 'testemail' mod...

PoC for CVE-2019-25289

Inim Electronics ...Smartliving Smartlan/g/si8.7HIGH
Remote Command Injection in SmartLiving SmartLAN by Inim

The SmartLiving SmartLAN versions up to 6.x are affected by a significant security vulnerability that allows authenticated users to execute arbitrary commands on the system. This vulnerability arises from the 'par' POST parameter within the web.cgi binary, specifically through the 'testemail' mod...

PoC for CVE-2019-25282

Guangzhou VV-sol Gpon/epon Olt Pl...5.1MEDIUM
Open Redirect Vulnerability in V-SOL GPON/EPON OLT Platform

The V-SOL GPON/EPON OLT Platform version 2.03 is susceptible to an open redirect vulnerability due to improper validation of user input in its redirect mechanism. This flaw enables attackers to craft deceptive links that exploit the functionality of the 'parent' GET parameter. When exploited, log...

PoC for CVE-2019-25279

Iwt Ltd.Facesentry Access Cont...6.8MEDIUM
Cleartext Password Storage Vulnerability in FaceSentry Access Contr...

The FaceSentry Access Control System version 6.4.8 is susceptible to a vulnerability that involves the insecure storage of passwords. This flaw allows attackers to access unencrypted credentials stored in the device's SQLite database. Specifically, sensitive login information can be directly read...

PoC for CVE-2019-25278

Iwt Ltd.Facesentry Access Cont...9.1CRITICAL
Cleartext Transmission Vulnerability in FaceSentry Access Control S...

The FaceSentry Access Control System version 6.4.8 is affected by a cleartext transmission vulnerability. This issue allows remote attackers to intercept sensitive authentication credentials via man-in-the-middle attacks. If an attacker gains access to the network, they can capture HTTP cookie in...

PoC for CVE-2019-25268

NrelBeopt8.6HIGH
DLL Hijacking Vulnerability in NREL BEopt by National Renewable Ene...

The NREL BEopt 2.8.0.0 software is susceptible to a DLL hijacking vulnerability that permits attackers to load arbitrary dynamic link libraries. This attack vector exploits users opening application files sourced from remote shares, enabling malicious actors to execute unauthorized code by levera...

PoC for CVE-2019-25231

Devolo AgDevolo Dlan Cockpit8.5HIGH
Unquoted Service Path Vulnerability in Devolo dLAN Cockpit by Devolo

The Devolo dLAN Cockpit 4.3.1 is vulnerable due to an unquoted service path in the 'DevoloNetworkService'. This weakness allows local non-privileged users to insert malicious code into the system's root path, which can potentially lead to arbitrary code execution with elevated privileges upon app...

PoC for CVE-2019-25259

Leica Geosystems AgLeica Geosystems Gr10/...5.1MEDIUM
Cross-Site Request Forgery in Leica Geosystems GNSS Products

The Leica Geosystems GNSS products (GR10, GR25, GR30, and GR50) with version 4.30.063 are susceptible to a cross-site request forgery vulnerability. This flaw enables attackers to deceive authenticated users into executing unintended actions, effectively compromising the application’s security. B...

PoC for CVE-2019-25259

Leica Geosystems AgLeica Geosystems Gr10/...5.1MEDIUM
Cross-Site Request Forgery in Leica Geosystems GNSS Products

The Leica Geosystems GNSS products (GR10, GR25, GR30, and GR50) with version 4.30.063 are susceptible to a cross-site request forgery vulnerability. This flaw enables attackers to deceive authenticated users into executing unintended actions, effectively compromising the application’s security. B...

PoC for CVE-2017-20215

Flir Systems, Inc.Flir Thermal Camera Fc...8.7HIGH
OS Command Injection Vulnerability in FLIR Thermal Camera FC-S/PT F...

The FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 has a vulnerability that allows authenticated users to perform OS command injection. Attackers can exploit this flaw by injecting unvalidated shell commands through certain input parameters. Successful exploitation results in elevated priv...

PoC for CVE-2017-20215

Flir Systems, Inc.Flir Thermal Camera Fc...8.7HIGH
OS Command Injection Vulnerability in FLIR Thermal Camera FC-S/PT F...

The FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 has a vulnerability that allows authenticated users to perform OS command injection. Attackers can exploit this flaw by injecting unvalidated shell commands through certain input parameters. Successful exploitation results in elevated priv...

PoC for CVE-2017-20216

Flir Systems, Inc.Flir Thermal Camera Pt...9.3CRITICAL
Remote Command Injection Vulnerabilities in FLIR Thermal Camera PT-...

The firmware version 8.0.0.64 of the FLIR Thermal Camera PT-Series is susceptible to multiple unauthenticated remote command injection vulnerabilities. These issues arise due to unsanitized POST parameters within the controllerFlirSystem.php script, particularly through the execFlirSystem() funct...

PoC for CVE-2017-20216

Flir Systems, Inc.Flir Thermal Camera Pt...9.3CRITICAL
Remote Command Injection Vulnerabilities in FLIR Thermal Camera PT-...

The firmware version 8.0.0.64 of the FLIR Thermal Camera PT-Series is susceptible to multiple unauthenticated remote command injection vulnerabilities. These issues arise due to unsanitized POST parameters within the controllerFlirSystem.php script, particularly through the execFlirSystem() funct...

PoC for CVE-2017-20213

Flir Systems, Inc.Flir Thermal Camera F/...8.7HIGH
Unauthenticated Remote Access Vulnerability in FLIR Thermal Camera ...

FLIR Thermal Cameras running firmware version 8.0.0.64 are exposed to a vulnerability that allows attack vectors for unauthorized access to live camera streams without the need for authentication. This flaw enables remote attackers to intercept video feeds from the thermal cameras across various ...

PoC for CVE-2017-20214

Flir Systems, Inc.Flir Thermal Camera F/...9.3CRITICAL
Hard-Coded SSH Credentials in FLIR Thermal Cameras

The FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains hard-coded SSH credentials that cannot be altered during standard camera operations. This vulnerability allows attackers to exploit these unmodifiable credentials to gain unauthorized remote access to the thermal camera system, ...

PoC for CVE-2017-20214

Flir Systems, Inc.Flir Thermal Camera F/...9.3CRITICAL
Hard-Coded SSH Credentials in FLIR Thermal Cameras

The FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains hard-coded SSH credentials that cannot be altered during standard camera operations. This vulnerability allows attackers to exploit these unmodifiable credentials to gain unauthorized remote access to the thermal camera system, ...

PoC for CVE-2017-20213

Flir Systems, Inc.Flir Thermal Camera F/...8.7HIGH
Unauthenticated Remote Access Vulnerability in FLIR Thermal Camera ...

FLIR Thermal Cameras running firmware version 8.0.0.64 are exposed to a vulnerability that allows attack vectors for unauthorized access to live camera streams without the need for authentication. This flaw enables remote attackers to intercept video feeds from the thermal cameras across various ...

PoC for CVE-2017-20212

Flir Systems, Inc.Flir Thermal Camera F/...8.7HIGH
Information Disclosure in FLIR Thermal Camera Products

The firmware of FLIR Thermal Camera F/FC/PT/D version 8.0.0.64 is susceptible to an information disclosure vulnerability. This security flaw enables unauthenticated attackers to exploit the '/var/www/data/controllers/api/xml.php' readFile() function, allowing them to read arbitrary files from the...

PoC for CVE-2017-20212

Flir Systems, Inc.Flir Thermal Camera F/...8.7HIGH
Information Disclosure in FLIR Thermal Camera Products

The firmware of FLIR Thermal Camera F/FC/PT/D version 8.0.0.64 is susceptible to an information disclosure vulnerability. This security flaw enables unauthenticated attackers to exploit the '/var/www/data/controllers/api/xml.php' readFile() function, allowing them to read arbitrary files from the...

PoC for CVE-2025-1974

KubernetesIngress-nginx🟣 EPSS 92%9.8CRITICAL
Arbitrary Code Execution Vulnerability in Ingress-Nginx Controller ...

A security issue in the Kubernetes platform allows an unauthenticated attacker with access to the pod network to execute arbitrary code within the context of the ingress-nginx controller. This vulnerability poses serious security risks, as it can potentially expose sensitive secrets accessible to...

PoC for CVE-2025-12030

WordPressAcf To Rest Api4.3MEDIUM
Insecure Direct Object Reference in ACF to REST API Plugin for Word...

The ACF to REST API plugin for WordPress is susceptible to Insecure Direct Object Reference, enabling attackers with Contributor-level access and above to manipulate ACF fields for posts they do not own. This security issue stems from inadequate capability checks within the update_item_permission...

PoC for CVE-2025-14719

WordPressRelevanssi4.9MEDIUM
SQL Injection Vulnerability in Relevanssi WordPress Plugin by Never5

The Relevanssi plugin, including its premium version, prior to specified updates, fails to properly sanitize and escape user-supplied parameters in SQL statements. This flaw can be exploited by users with contributor roles or higher, allowing them to execute arbitrary SQL queries, potentially com...

PoC for CVE-2025-14804

WordPressFrontend File Manager ...7.7HIGH
Path Traversal Vulnerability in Frontend File Manager for WordPress

The Frontend File Manager Plugin for WordPress prior to version 23.5 is susceptible to a path traversal vulnerability. This issue arises from inadequate validation of a path parameter and the ownership of files. As a result, any authenticated user, including those with subscriber-level access, ma...

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 53%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

PoC for CVE-2025-15474

AuntyfeyAuntyfey Smart Combina...5.3MEDIUM
Denial of Service Vulnerability in AuntyFey Smart Combination Lock ...

The AuntyFey Smart Combination Lock firmware versions up to December 24, 2025, are susceptible to an exploit that enables an unauthenticated attacker within Bluetooth Low Energy (BLE) proximity to initiate an overwhelming number of BLE connection attempts. This barrage of connection requests can ...

PoC for CVE-2025-9611

MicrosoftPlaywright7.2HIGH
DNS Rebinding Vulnerability in Microsoft Playwright MCP Server

The Microsoft Playwright MCP Server, prior to version 0.0.40, is susceptible to a DNS rebinding vulnerability due to inadequate validation of the Origin header in incoming connections. This flaw could allow attackers to exploit a victim's web browser to send unauthorized requests, potentially cau...

PoC for CVE-2025-14847

MongoDBMongodb Server🟣 EPSS 68%8.7HIGH
Heap Memory Exposure in MongoDB Server Versions by MongoDB

The vulnerability arises from mismatched length fields in Zlib compressed protocol headers within MongoDB Server, potentially allowing an unauthenticated client to access uninitialized heap memory. This could lead to unauthorized information exposure, affecting versions of MongoDB Server across m...

Discovered 3 days ago

PoC for CVE-2025-15472

TrendnetTew-811dru8.6HIGH
OS Command Injection Vulnerability in TRENDnet TEW-811DRU Router

A vulnerability exists in the TRENDnet TEW-811DRU router that allows for OS command injection through the manipulation of the setDeviceURL function in the uapply.cgi file. This flaw provides remote attackers the capability to execute arbitrary commands on the affected device, potentially compromi...

PoC for CVE-2025-15471

TrendnetTew-713re9.3CRITICAL
OS Command Injection Vulnerability in TRENDnet TEW-713RE Router

A security vulnerability exists in TRENDnet TEW-713RE version 1.02, specifically in the '/goformX/formFSrvX' file. This unknown function allows an attacker to manipulate the 'SZCMD' argument, leading to the possibility of remote OS command injection. The exploit methodology is now publicly availa...

PoC for CVE-2020-36917

Guangzhou Yeroo T...Ids6 Dsspro Digital Si...8.6HIGH
Sensitive Information Disclosure in iDS6 DSSPro Digital Signage Sys...

The iDS6 DSSPro Digital Signage System version 6.2 is susceptible to a sensitive information disclosure flaw. This vulnerability enables remote attackers to intercept essential authentication credentials transmitted in cleartext through cookies. By exploiting the autoSave feature, attackers can c...

Latest Cyber Security Exploit PoCs