Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-21852
A vulnerability in Claude Code allowed malicious repositories to exfiltrate sensitive user data, including Anthropic API keys, before users could confirm trust. Attackers could leverage a compromised repository to adjust the configuration to point to their own server. Once the repository was open...
Discovered 2 hours ago
PoC for CVE-2025-38352
A race condition has been identified in the Linux kernel's handling of POSIX CPU timers. When a non-autoreaping task reaches the exit_notify() state and subsequently calls handle_posix_cpu_timers() from an interrupt request (IRQ), it may be reaped by its parent or debugger immediately after unloc...
Discovered 3 hours ago
PoC for CVE-2026-23980
A vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands, allowing an authenticated user with read access to perform error-based SQL injection via the sqlExpression or where parameters. This may lead to unauthorized access to sensitive data...
Discovered 5 hours ago
PoC for CVE-2026-90566
A vulnerability has been identified in the Rizwan17 Inventory Management System that allows for improper authorization via the 'createUserAccount' function found in 'register.php'. This weakness occurs when the 'usertype' argument is manipulated, potentially enabling remote attackers to exploit t...
PoC for CVE-2026-90565
A security flaw has been identified in the Rizwan17 inventory management system, specifically within the dashboard.php file. This vulnerability allows attackers to manipulate the userid argument to bypass access controls, enabling remote exploitation. Despite the project being notified early abou...
Discovered 6 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-71294
The Comments plugin of Cotonti CMS contains a serious flaw due to improper deserialization of user-supplied data. Specifically, the `ci` and `cb` parameters in the `CreateAction.php` and `EditAction.php` scripts are processed without restricting the classes that can be instantiated. This vulnerab...
Discovered 7 hours ago
PoC for CVE-2026-90526
A vulnerability has been identified in the SourceCodester School Registration and Fee System, specifically within the /bilal/save_class.php file. This vulnerability allows for the manipulation of the 'Category' argument, resulting in SQL injection. If successfully exploited, an attacker could gai...
PoC for CVE-2026-90525
A vulnerability exists in the itsourcecode Sales and Inventory System version 1.0 that allows for SQL injection through improper handling of the 'firstname' argument in the /pages/cust_pos_trans.php file. Attackers can leverage this weakness to execute unauthorized commands on the database, poten...
PoC for CVE-2025-14659
A security flaw has been identified in the DHCP Daemon of D-Link's DIR-860LB1 and DIR-868LB1 routers, allowing for command injection through manipulation of the Hostname argument. This vulnerability can be exploited remotely, posing a significant risk to users' network security. As the exploit de...
PoC for CVE-2026-90524
A significant vulnerability has been identified in the jaychouchannel Tourism-Management-System that affects an unknown function within the Update Endpoint component. This flaw enables a remote attacker to execute manipulations leading to a lack of essential authentication measures. As the produc...
Discovered 8 hours ago
PoC for CVE-2026-90523
A vulnerability has been identified in the Jaychouchannel Tourism-Management-System, specifically in the User Register Endpoint within the UsersController.java file. This vulnerability arises from improper management of user privileges due to the manipulation of the UsersEntity argument. Attacker...
PoC for CVE-2026-90522
A vulnerability exists in the jaychouchannel Tourism-Management-System affecting the password recovery function in UsersController.java. This flaw allows remote attackers to exploit weak password recovery mechanisms. The vulnerability impacts versions up to d984d172dceca907f8b447efbdb06dc233f7938...
PoC for CVE-2026-90521
A security vulnerability has been identified in the Tourism-Management-System by jaychouchannel. An authorization bypass occurs due to improper handling of user-controlled ID parameters in the MenpiaodingdanController.java file. This flaw can be exploited remotely, allowing attackers to gain unau...
PoC for CVE-2026-90520
A vulnerability has been identified in the Authorization Interceptor component of the Tourism Management System by jaychouchannel. This flaw enables improper authorization, allowing potential attackers to exploit the issue remotely. The affected code resides in the AuthorizationInterceptor.java f...
Discovered 9 hours ago
PoC for CVE-2026-90519
A security vulnerability has been discovered in PHPGurukul's Bank Locker Management System version 1.0. The issue arises from a flaw within an unspecified function in the file /blms/banker/add-locker-form.php, which allows attackers to manipulate the argument 'addressproof' resulting in unrestric...
PoC for CVE-2026-90518
A security flaw has been identified in the PHPGurukul Bank Locker Management System, specifically within the sidebar.php file. This vulnerability arises from improper access controls triggered by the manipulation of the UserType argument. Remote attacks can exploit this flaw, potentially allowing...
PoC for CVE-2026-90517
A security flaw has been discovered in version 1.0 of the PHPGurukul Bank Locker Management System, specifically affecting the file /blms/view-assign-locker.php. This vulnerability arises from improper handling of the 'ltid' parameter, which allows attackers to bypass authentication mechanisms. A...
PoC for CVE-2026-90516
A vulnerability has been identified in the SourceCodester School Registration and Fee System version 1.0, specifically within the 'pay_report.php' file. This issue arises from improper handling of parameters in the 'period' argument, allowing attackers to perform SQL injection. Exploitation of th...
Discovered 10 hours ago
PoC for CVE-2026-90515
A vulnerability has been identified in SourceCodester School Registration and Fee System 1.0 that affects the functionality of '/bilal/normal/delete_stud.php'. An attacker can manipulate the 'selector[]' argument to execute SQL injection attacks, potentially compromising the database. This attack...
PoC for CVE-2026-90514
An SQL injection vulnerability exists in the SourceCodester School Registration and Fee System version 1.0, specifically in the /bilal/normal/save_stud.php file. This security flaw allows attackers to manipulate the 'Status' argument through remote exploitation, potentially compromising the integ...
PoC for CVE-2026-90511
A vulnerability has been identified in GongShengyue OnlineBooks that allows for SQL injection via the listSplit component's BooksServlet.java file. An attacker can manipulate the argument column leading to unapproved database access, potentially exposing sensitive information. This issue impacts ...
Discovered 11 hours ago
PoC for CVE-2026-90510
A security issue has been identified within dromara's Orion-Visor, specifically in the HostKeyServiceImpl.encryptKey function. This vulnerability results from the use of hard-coded cryptographic keys, which can be exploited remotely. The potential unauthorized access to sensitive data, such as SS...
PoC for CVE-2026-90509
A vulnerability has been identified in dromara's orion-visor, specifically in the ExposeApiAspect.beforeExposeApi function within ExposeApiAspect.java. This weakness allows for the execution of remote manipulation, leading to the exposure of hard-coded credentials. The exploit has been publicly d...
PoC for CVE-2026-90508
A security flaw has been identified in the Ludashi software from Chengdu Qilu Technology that affects the MessageNotifyCallback function within the ProtectFilter64.sys library. This vulnerability allows local attackers to exploit missing authentication controls, which could lead to unauthorized a...
PoC for CVE-2026-90507
A vulnerability has been identified in the WARP-Clash-API related to the Subscription Handler's get_surge_subscription function. The issue arises from improper access control due to manipulation of the argument key, which could allow unauthorized access to sensitive information. This flaw may be ...
Discovered 12 hours ago
PoC for CVE-2026-90506
A vulnerability has been identified in the WARP-Clash-API that affects its Save Account Job component, leading to potential race condition exploits. This issue allows an attacker to initiate attacks remotely, exploiting the timing of operations to manipulate data inconsistently. The complexity of...
PoC for CVE-2026-90505
A race condition vulnerability exists in WARP-Clash-API, specifically affecting the doUpdateLicenseKey function. This flaw enables attackers to manipulate the software remotely, but requires a high level of complexity to exploit. The absence of versioning makes it difficult to categorize specific...
PoC for CVE-2026-90504
A significant vulnerability exists within the WARP-Clash-API by vvbbnn00, specifically related to the function authorized. This issue arises from improper handling of the SECRET_KEY argument, which results in missing authentication and allows for unauthorized access. This vulnerability can be exp...
Discovered 13 hours ago
PoC for CVE-2026-90502
A vulnerability in the Stilleshan ServerStatus software allows remote attackers to exploit an unknown function in the Stats Generation component located within the file server/src/main.cpp. By manipulating the 'custom' argument, an attacker can execute cross-site scripting attacks, putting users ...
PoC for CVE-2026-90501
A security vulnerability exists in Lenve VHR 1.0-SNAPSHOT concerning the HrInfoController.updateHr function found in the HrMapper.xml file. This flaw allows attackers to manipulate the password argument, resulting in inadequate management of user privileges. Consequently, this vulnerability can b...
PoC for CVE-2026-90500
A security weakness has been discovered in Lenve VHR 1.0-SNAPSHOT related to its Avatar Upload component. Specifically, the FastDFSUtils.upload function within the userface file is vulnerable to unrestricted file upload. This design flaw allows malicious actors to upload files without proper vali...
Discovered 14 hours ago
PoC for CVE-2026-33439
OpenIdentityPlatform's OpenAM, an access management solution, is susceptible to a pre-authentication Remote Code Execution vulnerability due to unsafe Java deserialization. This issue arises from the handling of the jato.clientSession HTTP parameter, allowing unauthenticated attackers to execute ...
PoC for CVE-2026-90499
A security flaw has been identified in the lenve vhr 1.0-SNAPSHOT product, specifically in the Password Update Handler during the execution of the HrInfoController.updatePass function. This vulnerability arises from improper handling of the hrid argument, enabling potential remote exploitation th...
Discovered 15 hours ago
PoC for CVE-2026-90498
A security vulnerability has been identified in lenve vhr version 1.0-SNAPSHOT, specifically within the file vhr.sql. This issue allows an attacker to exploit the product using default credentials that haven't been changed. The potential for remote exploitation exists, and public exploits for thi...
PoC for CVE-2026-88912
The rtMedia plugin for WordPress, BuddyPress, and bbPress prior to version 4.7.12 is vulnerable due to inadequate ownership verification. This allows users with subscriber-level accounts or higher to manipulate the privacy settings of another user's activity and its associated media. The vulnerab...
PoC for CVE-2026-88995
The Bookit - Booking & Appointment Calendar plugin for WordPress prior to version 2.6.0.1 contains a vulnerability that fails to restrict data return during availability-check requests. This oversight permits unauthenticated individuals to access sensitive information such as appointment details,...
PoC for CVE-2026-89080
The Really Simple Security plugin for WordPress, prior to version 9.8.1, contains a vulnerability that permits unauthorized requests to reset a user account's completed email two-factor enrollment. An attacker with knowledge of the account's password can exploit this flaw to bypass the second aut...
PoC for CVE-2026-80072
The User Registration & Membership plugin for WordPress prior to version 5.2.8 includes a flaw in handling post-login redirects. This vulnerability allows attackers to manipulate the redirect destination, potentially leading users to malicious external URLs. This behavior poses significant securi...
PoC for CVE-2026-86407
The User Registration & Membership Plugin for WordPress prior to version 5.2.8 suffers from an improper access control vulnerability. This flaw allows unauthenticated users to access sensitive information, such as email addresses and membership details, related to other users. Specifically, if a ...
PoC for CVE-2026-88764
The Simple Membership plugin for WordPress, prior to version 4.7.8, is susceptible to an improper input validation vulnerability. This issue arises when the plugin fails to verify that the membership level sent in a PayPal payment notification corresponds with the membership level specified for t...
PoC for CVE-2026-86406
The User Registration & Membership WordPress plugin prior to version 5.2.8 lacks proper checks on user capabilities during membership purchases. This oversight enables authenticated users, such as subscribers, to gain access to premium WordPress roles linked to paid plans without making actual pa...
PoC for CVE-2026-80071
The User Registration & Membership plugin for WordPress prior to version 5.2.8 contains a vulnerability that inadequately enforces role assignments. This flaw enables authenticated users holding Author-level access or higher to improperly assign themselves elevated permissions, including Administ...
PoC for CVE-2026-77773
The Contact Form to Chat Apps | Click to Chat to Order plugin for WordPress, prior to version 2.15.8, is susceptible to an improper authentication vulnerability. This issue arises from the lack of capability, nonce, or session checks on a public AJAX action. As a result, unauthenticated users can...
PoC for CVE-2026-90497
A cross-site scripting vulnerability exists in the Fengoffice software, specifically within the getTitle function of the add_task.php file in the Task Title Output component. An attacker can exploit this issue by manipulating the og_objects.name argument, potentially allowing malicious scripts to...
PoC for CVE-2026-85706
A vulnerability in GitLab CE/EE allows unauthenticated users to read arbitrary files due to inadequate path confinement and a lack of proper authentication checks in the repository commits API. This issue affects GitLab versions 18.7 prior to 19.1.8, 19.2 prior to 19.2.6, and 19.3 prior to 19.3.2...
Discovered 17 hours ago
PoC for CVE-2026-90495
A SQL injection vulnerability exists in Fengoffice's Legacy API within the method Contacts::instance->findAll, located in the file application/models/CompanyWebsite.class.php. This weakness arises from improper argument handling during authentication processes, allowing attackers to manipulate th...
Discovered 18 hours ago
PoC for CVE-2026-90493
A local access control vulnerability exists in the Tonec Internet Download Manager for Windows, specifically within the idmwfp.sys file of the kernel driver component. This vulnerability allows an attacker with local access to manipulate permissions improperly. The issue has been made public, hig...
Discovered 20 hours ago
PoC for CVE-2026-90491
A code injection vulnerability exists in the sanjevirau gsubs product, specifically in the function showQuerySuccessPage within the renderer/index.js file. By manipulating the argument 'filename', an attacker can execute arbitrary code remotely. The potential exploit has been publicly disclosed, ...
Discovered 21 hours ago
PoC for CVE-2026-90489
A cross-site scripting vulnerability affects the Xuxueli XXL-Job application versions up to 3.5.0. The vulnerability exists in the /jobinfo/insert file, where improper handling of the 'name' and 'author' parameters allows attackers to inject malicious scripts. This can be exploited remotely, risk...