Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-86272

Beijing Meite Sof...U+smart Enjoyment Website6.9MEDIUM
Unrestricted File Upload Vulnerability in Beijing Meite Software's ...

A vulnerability has been identified in the U+Smart Enjoyment WebSite, specifically within the /Report/Upload/UploadFormImg.ashx file, where an unrestricted file upload is possible. By manipulating the 'File' argument, an attacker could upload potentially harmful files to the server, leading to se...

PoC for CVE-2026-86271

FluentCMSFluentcms5.1MEDIUM
Improper Authorization in FluentCMS Affects Remote Security

A security vulnerability was identified in FluentCMS versions up to 0.0.5, specifically within the GetAccessible function located in the PermissionManager.cs file. This flaw results in inadequate authorization checks, allowing unauthorized access when exploited. The vulnerability is particularly ...

PoC for CVE-2026-18963

Red HatRed Hat Build Of Keycl...9.1CRITICAL
Authorization Flaw in Keycloak Services by Red Hat

A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...

PoC for CVE-2026-86270

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0, particularly in the settings_edit.php file. An attacker can exploit this vulnerability by manipulating the argument ID, allowing for unauthorized database queries and potential exposure of sensitive i...

PoC for CVE-2026-86269

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A vulnerability has been identified in itsourcecode Sales and Inventory System 1.0, specifically within an undisclosed function located in the /pages/emp_edit1.php file. This flaw allows for SQL injection attacks due to improper handling of the argument ID, which can be exploited remotely. Attack...

Discovered 4 hours ago

PoC for CVE-2026-86268

ItsourcecodeSchool Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode School Management System

A vulnerability affecting the itsourcecode School Management System 1.0 has been identified, where an unknown function in the User_Login.php file allows for SQL injection through the manipulation of the email argument. This flaw can be exploited remotely, raising concerns about unauthorized datab...

PoC for CVE-2026-86267

ItsourcecodeInformation System Soc...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Information System Soci...

A security vulnerability has been identified in the itsourcecode Information System Society Membership System version 1.0, specifically in the file /society/check_student.php. This flaw allows an attacker to manipulate the student_id parameter, leading to potential SQL injection attacks. Such vul...

PoC for CVE-2026-86265

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A remote code execution vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0. Specifically, the issue lies within an unknown functionality of the file /pages/us_transac.php, where inadequate sanitization of user input allows for SQL injection through manipu...

PoC for CVE-2026-86264

SfturingSsm Pro5.3MEDIUM
Cross Site Scripting Vulnerability in sfturing ssm_pro by Sfturing

A cross site scripting vulnerability exists in the ssm_pro application from Sfturing due to an issue in the Order Endpoint functionality. Specifically, the flaw lies in the handling of input parameters such as hospitalName, officesName, and doctorName in the OrderController.java file. This weakne...

Discovered 5 hours ago

PoC for CVE-2026-86263

SfturingHosp Order6.9MEDIUM
Authorization Bypass in sfturing hosp_order Order Cancellation Comp...

A significant vulnerability has been identified in the sfturing hosp_order application which affects the order cancellation functionality. The issue arises in the method orderRecordsService.cancelOrder located in the OrderController.java file. By manipulating the argument ID, an unauthorized acto...

PoC for CVE-2026-86262

SfturingHosp Order6.9MEDIUM
Authorization Bypass in Sfturing Hosp_Order Order Handler

A significant security flaw has been identified in Sfturing's Hosp_Order software, specifically within the Order Handler component. An attacker can exploit this vulnerability through remote manipulation of the userID/id argument in the updateOrderSta1/updateOrderdiseaseInfo function of OrderContr...

PoC for CVE-2026-86261

SfturingHosp Order6.9MEDIUM
Authorization Bypass in Sfturing Hosp_Order Product by Sfturing

A vulnerability exists in the Sfturing Hosp_Order product that allows remote attackers to bypass authorization controls. This issue is linked to a mismanaged parameter within the Order Controller. Manipulating the userIdenf argument can enable unauthorized access to certain functionalities. The f...

PoC for CVE-2026-86260

SfturingHosp Order6.9MEDIUM
Unverified Password Change Vulnerability in sfturing hosp_order Pro...

A security flaw exists in the hosp_order's password recovery functionality, specifically within the modifyPassWord method of the CommonUserController.java file. This vulnerability enables an attacker to change user passwords without proper verification, potentially compromising user accounts. Sin...

Discovered 6 hours ago

PoC for CVE-2026-86245

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection in itsourcecode Sales and Inventory System

A vulnerability has been identified in the itsourcecode Sales and Inventory System 1.0 related to a remote exploitable SQL injection through the '/pages/sup_transac.php' file. By manipulating the 'companyname' argument, attackers can execute arbitrary SQL queries on the database. This flaw poses ...

PoC for CVE-2026-86244

FastAdminFastadmin5.3MEDIUM
Cross Site Scripting Vulnerability in FastAdmin User Controller

A security vulnerability exists in the FastAdmin User Controller, specifically in the register/login functionality within the User.php file. This flaw permits attackers to manipulate the URL argument, which can lead to cross site scripting (XSS). The vulnerability is remotely exploitable and pose...

PoC for CVE-2026-86241

LiufeeFeehicms5.3MEDIUM
Cookie Validation Vulnerability in liufee FeehiCMS by liufee

A vulnerability has been discovered in liufee FeehiCMS versions up to 2.1.1 that affects the cookie validation component within the main-local.php configuration file. The flaw arises from the unsecure handling of the cookieValidationKey, which utilizes a hard-coded cryptographic key. This can be ...

PoC for CVE-2026-86240

LiufeeFeehicms5.1MEDIUM
Server-Side Request Forgery Vulnerability in Liufee FeehiCMS UEditor

A security flaw has been identified in Liufee FeehiCMS versions up to 2.1.1, specifically within the UEditor component's catchImage function located in backend/widgets/ueditor/Uploader.php. This vulnerability allows an attacker to manipulate the argument 'source[]', leading to server-side request...

Discovered 7 hours ago

PoC for CVE-2026-86239

LiufeeFeehicms6.9MEDIUM
Unrestricted File Upload Vulnerability in FeehiCMS UEditor Widget b...

A vulnerability has been discovered in the UEditor Widget component of FeehiCMS, specifically in the function UeditorAction::init within the file backend/widgets/ueditor/UeditorAction.php. This flaw allows for unrestricted file uploads, which could be exploited by remote attackers to upload malic...

Discovered 8 hours ago

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 100%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

PoC for CVE-2026-86235

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0, where improper validation in the /pages/pos_transac.php file can lead to SQL injection attacks. By manipulating the 'Customer' argument, an attacker can execute arbitrary SQL queries against the databa...

PoC for CVE-2026-86234

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0, specifically affecting the /pages/cust_transac.php endpoint with the action parameter set to add. By manipulating the firstname argument, attackers can execute arbitrary SQL commands. Thi...

PoC for CVE-2026-86233

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A security vulnerability exists in the itsourcecode Sales and Inventory System version 1.0, specifically within the /pages/us_del.php?type=user file. This vulnerability arises from improper handling of user-supplied input, allowing attackers to manipulate the 'ID' argument. As a result, attackers...

PoC for CVE-2026-86232

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0, specifically within the functionality of the file /pages/sup_del.php?type=supplier. This flaw allows attackers to manipulate the ID argument, leading to SQL injection. The resulting exploit can be exec...

Discovered 9 hours ago

PoC for CVE-2026-86231

MwiedeJsch6.3MEDIUM
Improper Certificate Revocation Check in mwiede jsch by jcraft

A vulnerability has been identified in mwiede jsch versions up to 2.28.5 related to the function getRevokedKeys found in the KnownHosts.java file. This flaw allows attackers to manipulate the argument known_hosts, resulting in an improper verification process for certificate revocation. The remot...

PoC for CVE-2026-86228

JeecgJeecgboot5.3MEDIUM
Access Control Flaw in JeecgBoot Affects Remote Exploitation Potential

A security vulnerability has been identified in JeecgBoot versions prior to 3.9.4, specifically in the exportXls function of the AiragModelController.java file. This flaw allows for improper access control, enabling attackers to manipulate credentials and gain unauthorized access. The issue can b...

PoC for CVE-2026-86227

Valkey-ioValkey2.3LOW
Out-of-Bounds Read Vulnerability in Valkey Software by Valkey-IO

A weakness has been found in Valkey software, specifically within the kvstoreGetHashtable function of the src/kvstore.c file. This vulnerability allows an attacker to manipulate the 'didx' argument, leading to an out-of-bounds read, which could potentially reveal sensitive information. Remote exp...

PoC for CVE-2026-86226

ProjectwoldsOnline Attendance System5.1MEDIUM
Cross Site Scripting Vulnerability in Projectwolds Online Attendanc...

A serious security flaw has been identified in the Projectwolds Online Attendance System version 1.0. The vulnerability exists in an unknown function within the profile.php file, where manipulating the 'email' argument leads to cross site scripting attacks. This flaw can be exploited remotely, po...

Discovered 10 hours ago

PoC for CVE-2026-86225

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A security vulnerability has been discovered in the SourceCodester Class and Exam Timetabling System 1.0, specifically within the function 'mysqli_query' located in the file '/admin/modal_add_room.php'. This vulnerability can be exploited through the manipulation of the 'room_name' argument, allo...

PoC for CVE-2026-67276

MikrotikRouteros9.2CRITICAL
SSH Authentication Vulnerability in MikroTik RouterOS

MikroTik RouterOS contains a vulnerability in its SSH authentication mechanism, which fails to fully compare RSA public keys. While it checks the key type and modulus, the exponent is overlooked. An attacker with knowledge of an authorized RSA modulus can exploit this flaw by supplying a crafted ...

PoC for CVE-2026-86224

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A security flaw exists in the SourceCodester Class and Exam Timetabling System version 1.0. This vulnerability arises in the `mysqli_query` function situated within the `admin/modal_add_product.php` file. Manipulating the argument `fname` can permit an unauthorized user to execute SQL injection a...

Discovered 12 hours ago

PoC for CVE-2026-86223

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A SQL injection vulnerability exists in the SourceCodester Class and Exam Timetabling System version 1.0, specifically impacting the mysqli_query function in the /admin/modal_add_coursea.php file. This vulnerability allows malicious users to manipulate the 'course' argument, which can lead to una...

PoC for CVE-2026-86222

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

The SourceCodester Class and Exam Timetabling System version 1.0 contains a vulnerability in the /admin/modal_add_course2.php file, specifically within the mysqli_query function. This security flaw allows an attacker to manipulate the 'course' argument, potentially leading to SQL injection attack...

Discovered 13 hours ago

PoC for CVE-2026-86221

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A vulnerability exists in SourceCodester's Class and Exam Timetabling System 1.0 due to improper handling of user input in the mysqli_query function within the file /admin/modal_add_course1.php. This flaw enables attackers to execute arbitrary SQL commands remotely, potentially compromising the u...

Discovered 14 hours ago

PoC for CVE-2026-86220

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A SQL injection vulnerability exists in the SourceCodester Class and Exam Timetabling System version 1.0. This flaw is identified in the mysqli_query function located in the file /admin/modal_add_course.php. By manipulating the 'course' argument, an attacker may conduct a remote SQL injection att...

Discovered 17 hours ago

PoC for CVE-2026-86217

Code-projectsHotel And Tourism Rese...6.9MEDIUM
Information Disclosure in Hotel and Tourism Reservation System by C...

A vulnerability exists in the Hotel and Tourism Reservation system developed by Code-Projects, specifically within the Database Backup Handler component. An unknown function in the file '/ht/hotel_db%20(1).sql' can be exploited to disclose sensitive information. This vulnerability can be exploite...

Discovered 18 hours ago

PoC for CVE-2026-86216

Code-projectsHotel And Tourism Rese...5.3MEDIUM
Cross-Site Scripting Vulnerability in Hotel and Tourism Reservation...

A cross-site scripting vulnerability has been identified in the Hotel and Tourism Reservation system (PHP version 1.0) by Code-Projects. This security flaw exists within the /ht/details.php file, where improper handling of the 'room' parameter allows attackers to inject malicious scripts. The exp...

PoC for CVE-2026-86215

MstfaktsCollege-management-system5.3MEDIUM
Session Expiration Vulnerability in Mstfakts College-Management-System

A flaw has been detected in the Logout Handler component of the Mstfakts College-Management-System, specifically within the function located in the server.php file. This vulnerability allows an attacker to manipulate the 'log_out' argument, resulting in premature session expiration. The attack ca...

PoC for CVE-2026-86214

MstfaktsMstfakts College-manag...6.9MEDIUM
Improper Authentication in Mstfakts College-Management-System

A vulnerability exists in the Mstfakts College-Management-System, particularly within the login.php file, where the manipulation of the email argument can lead to improper authentication. This issue allows attackers to perform remote exploitation, potentially compromising user accounts. While the...

Discovered 19 hours ago

PoC for CVE-2026-86213

MstfaktsCollege-management-system6.9MEDIUM
SQL Injection Vulnerability in Mstfakts College-Management-System A...

A SQL injection vulnerability exists in the Mstfakts College-Management-System, specifically in the Search Handler component found in the Front-end/university.php file. An attacker can exploit this vulnerability through the manipulated input parameters 'book_name' and 'book_author', allowing unau...

Discovered 20 hours ago

PoC for CVE-2026-86212

Open5GSOpen5gs5.3MEDIUM
Improper Authorization Vulnerability in Open5GS by Open5GS

A vulnerability has been identified in Open5GS versions 2.7.7 and 2.8.0 that affects the AMF/MME component. This weakness allows for improper authorization, which can be exploited remotely by attackers. As a result, unauthorized actions may be executed, posing significant risks to application int...

Discovered 21 hours ago

PoC for CVE-2026-86211

RabindralamsalInventory-management-s...6.9MEDIUM
SQL Injection Vulnerability in rabindralamsal Inventory Management ...

A vulnerability exists in the login functionality of the rabindralamsal inventory-management-system version 1.0.0, specifically within the index.php file. This flaw allows for remote exploitation through SQL injection, where improper handling of the username and password inputs can enable attacke...

Discovered 22 hours ago

PoC for CVE-2026-86210

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A vulnerability has been found in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the file /delete_user_account.php. This vulnerability allows for remote SQL injection through the manipulation of the argument ID. Attackers can leverage this exploit to execute...

PoC for CVE-2026-80437

WordPressNinja Forms4.8MEDIUM
Remote Code Execution Vulnerability in Ninja Forms Plugin by WordPress

The Ninja Forms plugin for WordPress, specifically versions prior to 3.15.2, contains a vulnerability where it fails to prevent shortcodes in request-derived values from executing. This flaw allows unauthenticated users to run any shortcode available on the site, potentially leading to unauthoriz...

PoC for CVE-2026-80439

WordPressRedirection For Contac...4.8MEDIUM
Shortcode Execution Vulnerability in Contact Form 7 Plugin for Word...

The Contact Form 7 plugin for WordPress prior to version 3.2.11 is prone to a vulnerability that allows unauthenticated users to exploit form submissions. By injecting shortcodes into form fields, these users can execute any registered shortcode on the site, gaining access to its output. This cou...

PoC for CVE-2026-19859

WordPressJetformbuilder6.5MEDIUM
Arbitrary Code Execution Vulnerability in JetFormBuilder Plugin for...

The JetFormBuilder plugin for WordPress versions prior to 3.6.5.2 is susceptible to an arbitrary code execution vulnerability. This issue stems from the failure to properly sanitize a request parameter before it is utilized in rendering message content. Consequently, unauthenticated users may exp...

PoC for CVE-2026-19862

WordPressJetformbuilder4.8MEDIUM
Email Header Injection in JetFormBuilder Plugin by WordPress

The JetFormBuilder plugin for WordPress, prior to version 3.6.5.2, contains a vulnerability allowing unauthenticated users to manipulate email headers through unvalidated address values sourced from form submissions. This flaw permits the injection of arbitrary email headers, facilitating hidden ...

PoC for CVE-2026-86209

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A vulnerability has been detected in the SourceCodester Class and Exam Timetabling System 1.0. This issue involves an inadequately protected function within the /delete_user.php file, which can be exploited through remote SQL injection via manipulated argument IDs. Attackers can potentially execu...

PoC for CVE-2026-86208

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A security vulnerability has been identified in the Class and Exam Timetabling System version 1.0 that allows remote attackers to manipulate the ID parameter within the /delete_teacher.php file, leading to SQL injection. This flaw can let unauthorized users execute arbitrary SQL commands, potenti...

PoC for CVE-2026-86183

Diem-projectDiem6.9MEDIUM
Authorization Bypass Vulnerability in Diem Project Diem

A vulnerability exists in the Diem Project's dmWidget component, specifically within the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php. This flaw enables unauthorized users to bypass security measures by manipulating the 'widget_id' argument. As a result, remote attackers ...

Discovered 23 hours ago

PoC for CVE-2026-86182

Diem-projectDiem5.3MEDIUM
Cross-Site Request Forgery in diem-project's dmConsole Component

A vulnerability has been identified in the dmConsole component of diem-project, specifically in the executeCommand function of actions.class.php. This issue allows an attacker to manipulate the dm_command argument, potentially leading to cross-site request forgery (CSRF). Given that the attack ca...