Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-43284
A vulnerability exists in the Linux kernel that concerns the handling of shared skb fragments during the decryption process in ESP-in-UDP packets. When pages are attached from a pipe directly to an skb using MSG_SPLICE_PAGES, the kernel marked these SKBs with SKBFL_SHARED_FRAG, which plays a cruc...
PoC for CVE-2026-54121
A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...
PoC for CVE-2026-16723
A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...
Discovered 18 minutes ago
PoC for CVE-2026-54121
A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...
Discovered 2 hours ago
PoC for CVE-2021-1931
This security vulnerability is caused by improper validation of the buffer length when processing fast boot commands across various Qualcomm Snapdragon products. An attacker could exploit this flaw to execute arbitrary code or cause unintended behavior, potentially compromising the affected devices.
Discovered 10 hours ago
PoC for CVE-2022-24903
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execu...
Discovered 11 hours ago
PoC for CVE-2026-14862
The Support Genix plugin for WordPress versions prior to 1.4.48 is vulnerable to an improper access control issue that permits unauthenticated users to download private ticket attachments. This flaw occurs due to insufficient checks on access rights, allowing individuals who know the stored attac...
PoC for CVE-2026-14919
The ShopMonitor.io plugin for WordPress before version 1.2.0 contains a flaw that allows unauthorized users to exploit the email rerouting feature. This security gap allows attackers to redirect sensitive outgoing emails, such as password reset notifications for the WordPress administrator accoun...
PoC for CVE-2026-12376
The Academy LMS WordPress plugin prior to version 3.8.2 contains an access control vulnerability that permits authenticated users with subscriber-level access or higher to view quiz attempt records belonging to other users. This oversight allows anyone enrolled in any course to access sensitive i...
PoC for CVE-2026-12695
The miniOrange Two-Factor Authentication plugin for WordPress, prior to version 6.2.6, is vulnerable to an authentication bypass. This vulnerability allows an unauthenticated attacker, who is aware of a user's password, to bypass the two-factor authentication mechanism. The flaw exists because th...
PoC for CVE-2026-12697
The wpForo Forum plugin for WordPress, prior to version 3.1.2, lacks adequate verification to confirm whether an AI chat conversation belongs to the user making the request. This oversight allows individuals with just a subscriber-level account to delete the AI chat message histories of other use...
PoC for CVE-2026-13609
The Frontend Admin by DynamiApps WordPress plugin prior to version 3.29.9 contains a vulnerability where HTML entities are decoded in form field submissions after being sanitized. This flaw allows a double-encoded malicious payload submitted by an unauthenticated user to be stored as executable H...
PoC for CVE-2026-13393
The ElementsKit Elementor Addons for WordPress prior to version 3.10.01 contains a vulnerability that allows users with administrative privileges to execute stored Cross-Site Scripting (XSS) attacks. This flaw arises due to the failure to properly sanitize and escape certain settings related to m...
PoC for CVE-2026-12720
The Kirki WordPress plugin, prior to version 6.0.13, fails to adequately restrict the classes that can be instantiated when it deserializes data stored by unauthenticated users. This oversight creates a path for PHP Object Injection, which can be exploited when an administrator later reviews the ...
PoC for CVE-2026-8155
The BuddyPress plugin for WordPress prior to version 14.5.0 possesses an authorization flaw that fails to restrict access to private messaging endpoints. As a result, any authenticated user, including Subscribers, can interact with other users' private messages—allowing them to read, modify, or e...
PoC for CVE-2026-13392
The ElementsKit Elementor Addons for WordPress prior to version 3.10.01 allows users with administrative privileges to define custom widgets that are saved directly into a generated PHP file. This flaw leads to the execution of arbitrary PHP code on the server. In a multisite environment, a subsi...
PoC for CVE-2026-12251
The Ultimate Member plugin for WordPress before version 2.12.1 allows unauthenticated users to exploit a flaw that does not properly filter administrator-level capabilities from selectable roles during registration. Additionally, the default configuration lacks crucial safeguards against account ...
PoC for CVE-2026-12721
The Kirki WordPress plugin prior to version 6.0.13 fails to adequately sanitize and escape user input before incorporating it into SQL statements. This oversight exposes the plugin to SQL injection attacks, which allow unauthenticated attackers to manipulate database queries, potentially leading ...
PoC for CVE-2026-15048
The Geeky Bot WordPress plugin versions prior to 1.2.8 exhibit a serious flaw by failing to properly execute an authorization check for specific AJAX actions. This oversight permits unauthenticated users to access sensitive chat-history metadata. Such unauthorized access includes retrieving cruci...
PoC for CVE-2026-14931
The JS Help Desk WordPress plugin prior to version 3.1.4 mistakenly assigns support-agent capabilities to the Contributor role upon activation. Additionally, it lacks proper capability checks in a user-listing handler, which permits users with Contributor-level access to enumerate the email addre...
PoC for CVE-2026-15381
The WP Go Maps plugin for WordPress contains a significant security flaw where inadequate sanitization and escaping of parameters in SQL queries allow unauthenticated users to exploit this vulnerability. This SQL injection risk can enable attackers to access sensitive data and manipulate the data...
PoC for CVE-2026-15209
The JS Help Desk plugin for WordPress prior to version 3.1.5 contains an access control vulnerability that allows low-privileged authenticated users to access and read content of tickets they do not own. By manipulating ticket IDs, an attacker can gain unauthorized access to sensitive information...
PoC for CVE-2026-15258
The Product Feed Manager for WooCommerce plugin, prior to version 7.6.1, fails to properly sanitize and escape product-feed custom filter rules when utilized in SQL queries. This oversight enables users with Contributor roles and higher to execute SQL injection attacks, potentially compromising t...
PoC for CVE-2026-14927
The FluentCart WordPress plugin prior to version 1.5.3 is susceptible to an authorization bypass vulnerability. Due to the lack of authorization or ownership checks, unauthorized users can access and disclose sensitive customer information, such as names, email addresses, shipping and billing add...
PoC for CVE-2026-14928
The JS Help Desk WordPress plugin prior to version 3.1.4 has a security flaw that allows authenticated users, including Subscribers, to access the content of support tickets belonging to other users. This vulnerability occurs due to the absence of proper authorization checks in the nonce-gated se...
PoC for CVE-2026-14930
The JS Help Desk WordPress plugin prior to version 3.1.4 allows unauthenticated users to upload files by bypassing necessary authorization checks. This vulnerability enables the unintended attachment of uploaded files to any support ticket, potentially leading to misuse or unauthorized access to ...
PoC for CVE-2026-14929
The JS Help Desk WordPress plugin prior to version 3.1.4 contains an input validation flaw that allows any authenticated user, including Subscribers, to overwrite the content of support-ticket replies. This issue arises because the plugin fails to verify the ownership of the targeted reply before...
PoC for CVE-2026-14922
WP Photo Album Plus is exposed to a stored Cross-Site Scripting vulnerability due to a double-encoding flaw within its photo-comment feature. This issue allows an attacker to exploit the comment submission process by sending a specially crafted HTML-encoded payload. The comment sanitation process...
PoC for CVE-2026-14845
The NewStatPress plugin for WordPress, prior to version 1.4.5, fails to properly sanitize and escape user data obtained from unauthenticated visitor inputs. This oversight allows attackers to exploit the plugin by injecting malicious scripts into stored data. When users view the affected widget, ...
PoC for CVE-2026-14849
The Paid Membership Subscriptions plugin for WordPress lacks adequate security measures, allowing exposed member and payment export files to be accessed by unauthenticated users. This vulnerability arises from the predictable location of the export files in the uploads directory, which could lead...
PoC for CVE-2026-14847
The Paid Membership Subscriptions plugin for WordPress before version 3.0.7 contains a vulnerability that allows authenticated users with Subscriber-level access and above to exploit a lack of capability and nonce checks on specific payment-related AJAX actions. This oversight enables these users...
PoC for CVE-2026-14843
The Events Made Easy plugin for WordPress is susceptible to a data manipulation vulnerability that occurs due to inadequate authorization checks for unauthenticated data modification requests. Specifically, prior to version 3.1.4, attackers can leverage a public nonce without any verification of ...
PoC for CVE-2026-14834
The Mailgun for WordPress plugin prior to version 2.2.1 lacks necessary checks for capabilities and nonces on a specific unauthenticated AJAX action. This flaw allows attackers to add arbitrary email addresses to the website owner's mailing lists, leveraging stored API credentials. This vulnerabi...
PoC for CVE-2026-14921
A link rendering vulnerability exists in the Ultimate Addons for WPBakery Page Builder WordPress plugin prior to version 3.21.5. This vulnerability is related to the shared link-rendering function, 'Ultimate_VC_Addons::uavc_link_init()'. Through this weakness, an attacker may exploit the plugin t...
PoC for CVE-2026-14333
The Demi WordPress plugin prior to version 0.0.7 has a significant vulnerability that allows unauthenticated users to download complete backups from a publicly accessible directory. These backups may contain sensitive information, including the site's database and hashed user passwords, posing a ...
PoC for CVE-2026-14554
The Check & Log Email WordPress plugin prior to version 2.0.15 has a serious vulnerability due to inadequate sanitization and escaping of parameters used in SQL queries. This flaw permits users with administrator privileges to execute SQL injection attacks, potentially allowing unauthorized acces...
PoC for CVE-2026-14830
The FlxWoo WordPress plugin prior to version 3.1.1 is susceptible to a vulnerability that fails to verify payment status with the payment processor. This oversight allows unauthenticated attackers to mark WooCommerce orders as paid, potentially leading to unauthorized purchases without actual pay...
PoC for CVE-2026-14833
The Lightbox with PhotoSwipe plugin for WordPress, prior to version 5.9.0, introduces a security flaw that fails to properly sanitize or escape link data attributes in the image lightbox caption. This oversight permits users with author-level access or higher, who typically lack the unfiltered_ht...
PoC for CVE-2026-14317
The GiveWP plugin prior to version 4.16.3 for WordPress has a vulnerability that fails to restrict access to payment gateways based on the administrator's settings. This flaw allows unauthenticated users to initiate donations using payment gateways that the administrator has explicitly disabled, ...
PoC for CVE-2026-14319
The GiveWP plugin for WordPress, prior to version 4.16.3, has a serious flaw that enables unauthorized users to access a REST API endpoint responsible for delivering recurring donation records. This lack of proper access restrictions allows attackers to retrieve sensitive information about anonym...
PoC for CVE-2026-33937
In Handlebars versions 4.0.0 through 4.7.8, a vulnerability exists where `Handlebars.compile()` can accept a pre-parsed AST object directly. This leads to the potential injection of arbitrary JavaScript into the generated code because the `value` field of a `NumberLiteral` AST node is emitted dir...
Discovered 13 hours ago
PoC for CVE-2025-64446
A relative path traversal vulnerability exists in Fortinet FortiWeb products versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.4, 7.4.0 to 7.4.9, 7.2.0 to 7.2.11, and 7.0.0 to 7.0.11. This vulnerability allows an attacker to potentially execute unauthorized administrative commands on the system by sending sp...
Discovered 20 hours ago
PoC for CVE-2022-24355
This vulnerability exists in the TP-Link TL-WR940N router, allowing attackers in the network vicinity to execute arbitrary code due to insufficient validation of user-supplied data lengths when parsing file name extensions. This flaw can be exploited without authentication, enabling attackers to ...
Discovered 21 hours ago
PoC for CVE-2026-67207
Wolf CMS versions up to 0.8.3.1 contain an authorization bypass vulnerability in the BackupRestoreController component. This flaw allows authenticated non-administrative users to gain access to sensitive backup functionalities. The issue arises from a PHP operator precedence flaw in the expressio...
PoC for CVE-2026-67206
Wolf CMS versions up to 0.8.3.1 are susceptible to a remote code execution vulnerability due to inadequate file extension validation in the FileManagerController. This flaw enables authenticated attackers with the 'file_manager_mkfile' capability to craft arbitrary PHP files. By exploiting this v...
Discovered 22 hours ago
PoC for CVE-2020-7882
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
Discovered 23 hours ago
PoC for CVE-2024-28000
The CVE-2024-28000 vulnerability is found in the widely-used LiteSpeed Cache Plugin for WordPress websites, allowing unauthenticated users to gain administrator-level access and create new user accounts with the administrator role. This critical privilege escalation vulnerability has a high CVSS ...
Discovered 1 day ago
PoC for CVE-2026-16723
A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...
PoC for CVE-2026-67349
The OpenCost application prior to version 1.121.0 exhibits significant security vulnerabilities that jeopardize sensitive information. It fails to authenticate requests to the GET /helmValues endpoint, which allows unauthorized access to base64-decoded HELM_VALUES, potentially revealing critical ...
PoC for CVE-2026-67348
The Julep software is exposed to an insecure direct object reference vulnerability within the get_execution_details endpoint. This flaw permits authenticated users to access execution data of other tenants by manipulating the execution_id parameter. Unauthorized retrieval of sensitive execution r...