Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 1 hour ago
PoC for CVE-2026-90828
A security flaw has been identified in the GNU Binutils version 2.47, specifically in the ELF Orphan Section Handler's function elf_orphan_compatible. This vulnerability can lead to a null pointer dereference due to improper handling of certain inputs. Attackers situated locally could exploit thi...
Discovered 2 hours ago
PoC for CVE-2026-91143
The goproxy product prior to version 15.4 contains a flaw in its handling of HTTP proxy basic authentication. Specifically, it fails to enforce authentication for CONNECT tunnel requests, enabling unauthenticated clients to forge connections through the proxy. This vulnerability allows attackers ...
PoC for CVE-2026-90827
A vulnerability arises in GPAC's MP4Box version 26.07.0 due to a flaw in the gf_node_deactivate_ex function within the base_scenegraph.c file. This flaw could allow an attacker to exploit a use after free condition, enabling local manipulation of memory that could compromise system stability or s...
PoC for CVE-2026-90826
A vulnerability has been identified in GPAC version 26.07.0, specifically in the gf_node_del function within the scenegraph/base_scenegraph.c file of the MP4Box component. This vulnerability is characterized by out-of-bounds read manipulation, which may permit attackers to exploit the issue, alth...
PoC for CVE-2026-90825
A vulnerability discovered in GPAC version 26.07.0 affects the MP4Box component, specifically within the gf_node_unregister function in the base_scenegraph.c file. This vulnerability can lead to memory corruption through a use after free issue, which can only be exploited locally. An exploit has ...
PoC for CVE-2019-2215
A use-after-free vulnerability exists in the Android Binder service, which could allow attackers to elevate privileges from an application to the Linux Kernel. Exploitation of this vulnerability does not require any interaction from the user; however, it necessitates either the installation of a ...
PoC for CVE-2026-90824
A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to stack-based buffer overflow. The attack can only be performed from a local environment. The exploit has been d...
Discovered 3 hours ago
PoC for CVE-2026-38526
An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...
PoC for CVE-2026-90818
A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. The manipulation results in server-...
Discovered 4 hours ago
PoC for CVE-2026-90815
A vulnerability exists in the FFmpeg Convolution Filter (specifically in the function setup_3x3 of libavfilter/vf_convolution.c), which allows attackers to execute a remote out-of-bounds read by manipulating function parameters. This flaw makes it possible to access unintended memory regions, pot...
PoC for CVE-2026-90814
A vulnerability exists in the Cosmicstack Labs Mercury Agent, specifically within the GitHub API Handler. The issue pertains to the 'githubRequest' function in the src/utils/github.ts file, where improper handling of the argument path can lead to server-side request forgery. This flaw enables pot...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-90813
A vulnerability in the Cosmicstack Labs Mercury Agent allows for improper handling of shell commands due to an incorrect order of validation and canonicalization. The issue is present in the function checkShellCommand within the src/capabilities/permissions.ts file. This flaw can be exploited rem...
PoC for CVE-2026-90812
A vulnerability has been discovered in the Cosmicstack Labs mercury-agent, specifically impacting versions up to 1.2.0. This issue arises within the checkShellCommand function located in src/capabilities/permissions.ts and is characterized by incorrect privilege assignment for Shell Command Permi...
PoC for CVE-2026-72898
Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...
Discovered 5 hours ago
PoC for CVE-2026-90811
A vulnerability exists in the cosmicstack-labs mercury-agent, specifically within the PermissionManager.checkShellCommand function in the Shell Permission Manifest. This flaw could allow unauthorized access to sensitive data during local execution. Although the project team was notified about thi...
PoC for CVE-2026-90810
A security flaw exists in the cosmicstack-labs mercury-agent affecting versions up to 1.1.13, specifically in the function PermissionManager.checkShellCommand. This vulnerability enables improper authorization, which can be exploited remotely. The issue was reported to the developers, but they ha...
PoC for CVE-2026-85706
A vulnerability in GitLab CE/EE allows unauthenticated users to read arbitrary files due to inadequate path confinement and a lack of proper authentication checks in the repository commits API. This issue affects GitLab versions 18.7 prior to 19.1.8, 19.2 prior to 19.2.6, and 19.3 prior to 19.3.2...
PoC for CVE-2026-90942
The Casdoor product until version 4.4.0 has a critical flaw that allows organization administrators to access the built-in certificate's private key through the /api/get-certs and /api/get-cert endpoints. This exposure can be exploited by attackers to create forged JSON Web Tokens (JWT) for any u...
Discovered 6 hours ago
PoC for CVE-2026-90807
A critical vulnerability was identified in the NanoClaw Attachment Handler, specifically in the function forwardAttachedFiles located in the agent-route.ts file. This flaw allows attackers to manipulate link following mechanisms, leading to unauthorized remote file access. Given that the exploit ...
PoC for CVE-2026-90805
A security flaw exists in the online clinic management system developed by Subhajit Khan, where improper handling of user-supplied input located in doctorlogin.php allows for SQL injection. This vulnerability can be exploited remotely by manipulating parameters such as doc_mail and doc_pswd, pote...
PoC for CVE-2026-90804
A buffer overflow vulnerability has been identified in the GNU Binutils version 2.47, specifically in the _bfd_elf_write_section_eh_frame function located within the bfd/elf-eh-frame.c file. This vulnerability arises from improper handling of the cie_length, fde_length, augmentation_data_size, an...
Discovered 7 hours ago
PoC for CVE-2026-90803
A critical buffer overflow vulnerability has been identified in GNU Binutils version 2.47, specifically in the 'elf_x86_64_relocate_section' function within the 'bfd/elf64-x86-64.c' file. This vulnerability arises from improper handling of the roff argument, allowing local attackers to exploit th...
PoC for CVE-2026-90802
A weakness has been identified in GNU Binutils 2.47, specifically in the bfd_putl64 function located in the bfd/libbfd.c file. This vulnerability can lead to a null pointer dereference, an issue that can be exploited by an attacker with local access to the system. Publicly available exploits coul...
PoC for CVE-2026-90801
A security vulnerability has been identified in GNU Binutils version 2.47 which affects the ld component's cache_bwrite function located in bfd/cache.c. This vulnerability arises from improper handling of the argument 'nbytes', leading to a buffer overflow condition. Exploiting this flaw requires...
PoC for CVE-2026-90796
A security vulnerability exists in itsourcecode Leave Management System 1.0, specifically within the /module/company/index.php file. This flaw allows remote attackers to execute SQL injection via manipulated input in the 'ID' argument. The exploit is publicly available, heightening the risk of un...
Discovered 8 hours ago
PoC for CVE-2026-90795
A vulnerability exists in the itsourcecode Loan Management System v1.0 due to an improper handling of user-supplied data within the navbar.php file. By manipulating the 'page' argument, an attacker can perform cross-site scripting, allowing for the possibility of remote code execution. This vulne...
PoC for CVE-2026-90794
A critical vulnerability has been identified in the GPAC MP4Box component, specifically in the gf_sg_script_load function within the vrml_tools.c file. This issue arises from a use after free condition, allowing attackers to execute remote exploitation. The public disclosure of this exploit incre...
PoC for CVE-2026-90793
A vulnerability in GPAC's MP4Box component has been discovered in the function gf_node_get_name located in scenegraph/base_scenegraph.c, leading to potential use after free scenarios. This vulnerability allows attackers to manipulate remote calls effectively. It has been publicly disclosed, neces...
PoC for CVE-2026-90792
A vulnerability exists in GPAC's MP4Box component where manipulation of the argument Target within the function gf_node_list_get_child in the base_scenegraph.c file leads to a null pointer dereference. This flaw can potentially be exploited remotely, allowing attackers to disrupt the functionalit...
Discovered 9 hours ago
PoC for CVE-2026-90791
A vulnerability exists in GPAC's MP4Box component that affects the gf_node_unregister function within the scenegraph/base_scenegraph.c file. This vulnerability allows for a 'use after free' condition, which could be exploited remotely. With the exploit now publicly available, it is crucial for us...
PoC for CVE-2026-90782
A null pointer dereference vulnerability exists in the S2OPC product, specifically in the msg_subscription_publish_bs__alloc_notification_message_items() function. This flaw allows an attacker to exploit heap allocation failures associated with sessions that manage both data-change and event noti...
PoC for CVE-2026-90789
A SQL injection vulnerability has been discovered in version 1.0 of the itsourcecode Leave Management System, specifically in the /login.php file. This weakness allows an attacker to manipulate the user_email parameter, potentially leading to unauthorized database access. The flaw can be exploite...
PoC for CVE-2026-90788
A security flaw has been identified in Magicblack's MacCMS10 version 2026.1000.4055, specifically within the Template Handler component. The vulnerability resides in an obscure functionality linked to the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html. This ...
PoC for CVE-2026-90941
The novel-plus product prior to version 5.3.3 is susceptible to an authorization bypass vulnerability within the BookController download endpoint. This security flaw allows authenticated backend users to export full book text, including chapters that are normally restricted to paying customers. B...
PoC for CVE-2026-90940
The novel-plus product, versions up to 5.3.3, contains an insecure default cache-management password in its CacheController.refreshCache endpoint. This flaw enables anonymous attackers to manipulate the cache state by utilizing a hardcoded default password in the URL path. By accessing the cache/...
PoC for CVE-2026-90939
The Novel-Plus application through version 5.3.3 contains a significant information disclosure vulnerability at the /sys/user/list endpoint, where inadequate permission annotations allow authenticated attackers to access sensitive user data. This flaw enables attackers to retrieve password hashes...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 10 hours ago
PoC for CVE-2026-90787
A flaw was discovered in the Soarkey StudentManagement application, specifically in the RegisterServlet.doPost function of the registration workflow component. This vulnerability allows attackers to manipulate user privilege levels, leading to unauthorized actions. The exploit can be executed rem...
PoC for CVE-2026-90786
A remote assertion vulnerability exists in Dvidelabs Flatcc up to version 0.6.3, specifically in the 'align_order_members' function located in the 'src/compiler/semantics.c' file of the Duplicate Symbol Handler component. This flaw allows an attacker to manipulate the reachable assertions, potent...
PoC for CVE-2026-90785
A vulnerability exists in the analyze_struct function located in src/compiler/semantics.c of the Dvidelabs Flatcc software, affecting versions up to 0.6.3. This issue leads to a reachable assertion that can be exploited remotely. An attack leveraging this vulnerability has been made public, empha...
PoC for CVE-2026-90784
A memory leak vulnerability exists in the Dvidelabs Flatcc software that affects versions up to 0.6.3. The issue arises from the fb_clear_parser function found in the src/Compiler/semantics.c file. This vulnerability could allow remote attackers to exploit the leaked memory, potentially leading t...
Discovered 11 hours ago
PoC for CVE-2026-90716
An out-of-bounds read vulnerability has been identified in the Number Parser component of the marcobambini Gravity software, particularly in the parse_number_expression function within the file src/compiler/gravity_parser.c. This flaw allows remote attackers to manipulate inputs in a way that lea...
PoC for CVE-2026-90715
A vulnerability has been identified in the marcobambini Gravity plugin prior to version 0.9.8, specifically within the udp json-parser component. An integer overflow can occur due to manipulations in the file src/utils/gravity_json.c. This vulnerability may be exploited remotely, allowing attacke...
PoC for CVE-2026-90714
A vulnerability exists in the marcobambini Gravity software, specifically within the JSON parser component located in the file src/utils/gravity_json.c. This flaw can lead to memory corruption and can be exploited remotely, allowing attackers to manipulate data or cause disruptions. Users are adv...
PoC for CVE-2026-90713
A vulnerability has been identified in the vLLM product by vllm-project, specifically within the TiktokenTokenizer::new function located in the tiktoken vocab File Handler. This flaw allows an attacker with local access to manipulate the component, potentially leading to a denial of service. The ...
Discovered 12 hours ago
PoC for CVE-2026-90712
A vulnerability in the Gitlawb Openclaude product has been identified within the xAI OAuth Callback Handler component, specifically in the waitForCallback function. An attacker can manipulate input parameters, potentially leading to a denial of service condition. Current implementations, particul...
PoC for CVE-2026-90710
A vulnerability in Taisan Tarzan-CMS version 1.0.0 has been identified, affecting the Theme Download Function through the openConnection method. Malicious actors can exploit this vulnerability by manipulating the httpUrl argument, resulting in server-side request forgery (SSRF). This issue can be...
PoC for CVE-2026-90709
A security vulnerability found in Yot CMS affects versions up to 3.3.1, specifically within the eval function in the modsys/console/admin.php file. This flaw allows an attacker to manipulate the 'text' argument, leading to potential remote code execution. The exploit has been publicly disclosed a...
PoC for CVE-2026-90708
A vulnerability has been identified in Yot CMS versions up to 3.3.1 within the Login function of the global.php file, specifically in the Cookie Handler component. This flaw allows an attacker to manipulate user credentials (yot3_user/yot3_pass) to execute SQL injection attacks remotely. The expl...