Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-21514

MicrosoftMicrosoft 365 Apps For...7.8HIGH
Security Feature Bypass in Microsoft Office Word

A vulnerability in Microsoft Office Word arises from a reliance on untrusted inputs during security decisions, potentially allowing unauthorized attackers to bypass critical local security features. This flaw highlights the importance of ensuring all inputs are properly validated to maintain robu...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-33320

TomwrightDasel6.2MEDIUM
Denial of Service Vulnerability in Dasel Command-Line Tool by Tom W...

The Dasel command-line tool, widely used for querying and transforming data structures, has a vulnerability that can lead to Denial of Service. Versions 3.0.0 through 3.3.0 allow an attacker to exploit the YAML reader's `UnmarshalYAML` implementation. By providing specially crafted YAML files, an...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 28%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 2 hours ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 28%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 28%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

Discovered 3 hours ago

PoC for CVE-2026-41927

Shenzhen Yipu Com...Wdr201a Wifi Extender8.3HIGH
Stack-Based Buffer Overflow Vulnerability in WDR201A WiFi Extender ...

The WDR201A WiFi Extender suffers from a stack-based buffer overflow vulnerability found in the firewall.cgi and makeRequest.cgi binaries. This flaw allows unauthenticated attackers to send specially crafted POST requests with a Content-Length header exceeding 512 bytes, leading to the potential ...

Discovered 4 hours ago

PoC for CVE-2026-41471

WordPressEasy-paypal-events-tic...8.2HIGH
Information Disclosure Vulnerability in Easy PayPal Events & Ticket...

The Easy PayPal Events & Tickets plugin for WordPress versions 1.3 and earlier is affected by an information disclosure vulnerability that allows unauthenticated attackers to access and enumerate customer order records via the vulnerable QR code scanning endpoint (scan_qr.php). By sequentially it...

PoC for CVE-2026-32834

WordPressEasy-paypal-events-tic...8.7HIGH
Authentication Bypass in Easy PayPal Events & Tickets Plugin for Wo...

The Easy PayPal Events & Tickets plugin for WordPress is susceptible to a vulnerability that allows attackers to bypass authentication mechanisms through the QR code scanning feature. By exploiting this flaw, unauthenticated remote attackers can utilize the 'test' value as a hash parameter to gai...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 6 hours ago

PoC for CVE-2026-29514

Netbox-communityNetbox8.7HIGH
Remote Code Execution Vulnerability in NetBox by NetBox Community

NetBox versions 4.3.5 through 4.5.4 have a vulnerability that allows authenticated users with specific permissions to perform remote code execution. By manipulating the environment_params field in the RenderTemplateMixin.get_environment_params() method, attackers can bypass protections that Jinja...

Discovered 7 hours ago

PoC for CVE-2026-27778

EpowerEpower.ie8.7HIGH
WebSocket API Vulnerability in E-Power Products

The WebSocket Application Programming Interface in E-Power systems is vulnerable due to a lack of restrictions on the number of authentication requests. This vulnerability can be exploited by attackers to perform denial-of-service attacks, which may disrupt legitimate charger telemetry. Additiona...

Discovered 9 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2019-13132

ZeroMQLibzMQ🟣 EPSS 28%9.8CRITICAL
Buffer Overflow Vulnerability in ZeroMQ Library by iMatix Corporation

In earlier versions of the ZeroMQ library (libzmq), a significant vulnerability exists that allows a remote and unauthenticated client to connect and potentially cause a stack overflow. This vulnerability arises from improper handling of buffers, leading to arbitrary data being written to the sta...

Discovered 10 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 12 hours ago

PoC for CVE-2026-7669

Sgl-projectSglang6.3MEDIUM
Deserialization Vulnerability in SGLang by sgl-project

A deserialization vulnerability exists in the SGLang component of sgl-project, specifically within the get_tokenizer function in the HuggingFace Transformer Handler. This flaw allows attackers to manipulate data remotely, potentially leading to unauthorized access or data corruption. The vulnerab...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 13 hours ago

PoC for CVE-2026-7750

TotolinkN300rh8.7HIGH
Buffer Overflow Vulnerability in Totolink N300RH Router Product

A buffer overflow vulnerability has been identified in the Totolink N300RH router, specifically in the setMacFilterRules function within the POST Request Handler of the /cgi-bin/cstecgi.cgi file. The vulnerability arises from improper handling of the mac_address argument, which allows remote atta...

PoC for CVE-2026-7749

TotolinkN300rh8.7HIGH
Buffer Overflow Vulnerability in Totolink Product

A security vulnerability has been identified in the Totolink N300RH router, specifically within the function setWanConfig located in /cgi-bin/cstecgi.cgi. This issue arises from improper handling of the priDns argument, leading to a potential buffer overflow. The vulnerability can be exploited re...

PoC for CVE-2026-7748

TotolinkN300rh8.7HIGH
Buffer Overflow Vulnerability in Totolink N300RH Router Firmware

A vulnerability has been identified in the Totolink N300RH router firmware version 3.2.4-B20220812, specifically within the setUpgradeFW function located in the /cgi-bin/cstecgi.cgi file. This weakness arises from the improper handling of the FileName argument, which can be exploited to trigger a...

Discovered 14 hours ago

PoC for CVE-2026-7747

TotolinkN300rh9.3CRITICAL
Buffer Overflow Vulnerability in Totolink N300RH Router

A buffer overflow vulnerability exists in the loginauth function of the Parameter Handler component in Totolink N300RH routers running firmware version 3.2.4-B20220812. This flaw can be exploited remotely by manipulating the Password argument, leading to potential unauthorized access and adverse ...

PoC for CVE-2026-7746

SourcecodesterWeb-based Pharmacy Pro...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Web-based Pharmacy Pr...

A vulnerability exists in the SourceCodester Web-based Pharmacy Product Management System version 1.0, specifically in the edit-admin.php file. This issue arises from improper handling of the argument ID, enabling attackers to execute remote SQL injection attacks. Given that exploits are publicly...

PoC for CVE-2026-7745

CodeastroOnline Classroom5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom Software

A security flaw has been identified in CodeAstro's Online Classroom software, specifically in the faculty details functionality. This vulnerability arises from improper handling of user input in the 'deleteid' parameter, leading to SQL injection. Attackers can exploit this weakness remotely, pote...

PoC for CVE-2026-7744

CodeastroOnline Classroom5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom by CodeAstro

A vulnerability has been identified in CodeAstro Online Classroom 1.0 that affects the unspecified functionality of the addnewstudent endpoint. Manipulation of the 'fname' parameter can lead to SQL injection attacks, allowing adversaries to interact with the database through crafted queries. This...

Discovered 15 hours ago

PoC for CVE-2026-7743

CodeastroOnline Classroom5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom by CodeAstro

A SQL injection vulnerability exists in the CodeAstro Online Classroom 1.0, specifically in an unidentified function within the /OnlineClassroom/studentdetails file. This vulnerability allows for malicious manipulation of the 'deleteid' argument, enabling an attacker to execute remote SQL queries...

PoC for CVE-2026-7742

CodeastroOnline Classroom5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom Application

A vulnerability has been identified in CodeAstro's Online Classroom version 1.0, specifically in an undisclosed function located in the faculty login script. Manipulating the 'fid' argument allows for SQL injection attacks, which can be executed remotely. This exposure enables unauthorized users ...

PoC for CVE-2026-7741

CodeastroOnline Classroom5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom Application

The CodeAstro Online Classroom application version 1.0 is vulnerable to SQL injection through the student login function. This vulnerability allows attackers to manipulate the 'sid' argument, potentially leading to unauthorized access to sensitive data. Exploitation can be executed remotely, and ...

PoC for CVE-2026-7740

Justdan96Tsmuxer4.8MEDIUM
Denial of Service Vulnerability in justdan96 tsMuxer Software

A vulnerability has been identified in justdan96 tsMuxer software, specifically in the function VvcVpsUnit::setFPS located in tsMuxer/vvc.cpp. This flaw allows an attacker to manipulate the track_id argument, potentially leading to a denial of service. The vulnerability requires local access to e...

Discovered 16 hours ago

PoC for CVE-2026-7739

Justdan96Tsmuxer4.8MEDIUM
Denial of Service Vulnerability in tsMuxer by justdan96

A local vulnerability has been discovered in the tsMuxer software developed by justdan96, specifically affecting the HevcVpsUnit::setFPS function located in hevc.cpp file. This issue arises from improper handling of the 'track_id' argument, potentially leading to a denial of service condition. Ex...

PoC for CVE-2026-7738

PuchunjieDoc-tools-mcp5.3MEDIUM
Path Traversal Vulnerability in Puchunjie Doc-Tools-MCP by Puchunjie

A security flaw affecting Puchunjie's doc-tools-mcp version 1.0.18 has been identified, specifically within the functions create_document and open_document of the MCP Interface. This vulnerability can be exploited through path traversal techniques by manipulating the filePath argument. Attackers ...

PoC for CVE-2026-5335

WordPressMagic Export & Import5.3MEDIUM
CSV File Exposure in Magic Export & Import Plugin by WordPress

The Magic Export & Import WordPress plugin prior to version 1.2.0 exposes exported CSV files in a publicly accessible location. This vulnerability allows unauthorized visitors to access and download sensitive user information contained within these files, posing significant privacy and security r...

Discovered 17 hours ago

PoC for CVE-2026-7733

FunAdminFunadmin6.9MEDIUM
Unrestricted Upload Vulnerability in Funadmin Frontend Chunked Uplo...

A vulnerability has been identified in Funadmin versions up to 7.1.0-rc6 within the Frontend Chunked Upload Endpoint. It stems from a flaw in the UploadService::chunkUpload function located in app/common/service/UploadService.php. This weakness allows an attacker to manipulate the File argument, ...

PoC for CVE-2026-7732

Code-projectsBloodbank Managing System5.3MEDIUM
Unrestricted File Upload Vulnerability in BloodBank Managing System...

An unrestricted file upload vulnerability exists in the BloodBank Managing System 1.0, specifically in the request_blood.php file. This issue allows an attacker to remotely upload files without proper validation, potentially leading to the execution of arbitrary code. As the exploit is now public...

Discovered 18 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-7731

Code-projectsBloodbank Managing System5.3MEDIUM
SQL Injection Vulnerability in Code-Projects BloodBank Managing System

A security vulnerability has been identified in the BloodBank Managing System version 1.0, specifically within the 'get_state.php' file. This vulnerability arises from inadequate validation of the G_STATE_ID parameter, allowing for SQL injection attacks. Attackers can exploit this vulnerability r...

PoC for CVE-2026-7730

PrivsimMcp-test-runner5.3MEDIUM
OS Command Injection Vulnerability in privsim mcp-test-runner Product

A vulnerability has been detected in the privsim mcp-test-runner version 0.2.0 affecting the child_process.spawn function located in src/index.ts. By manipulating the command argument, an attacker could execute arbitrary OS commands, potentially leading to severe security breaches. This vulnerabi...

PoC for CVE-2026-7729

PixelsockDirectus-mcp5.3MEDIUM
Server-Side Request Forgery in pixelsock directus-mcp by pixelsock

A security flaw has been identified in the pixelsock directus-mcp version 1.0.0. This vulnerability resides in the validateUrl function located in index.ts of the MCP Interface component. An attacker can manipulate the fileUrl argument, potentially leading to servers being tricked into making una...

PoC for CVE-2026-7728

RyanjoachimMcp-rtfm5.3MEDIUM
Path Traversal Vulnerability in MCP Interface by Ryanjoachim

A security vulnerability has been identified in the MCP Interface of the mcp-rtfm product. This issue allows an attacker to manipulate the function get_doc_content/read_doc/update_doc through the argument docFile, leading to unauthorized access to files outside the intended directory structure. T...

Discovered 19 hours ago

PoC for CVE-2026-7725

PrefecthqPrefect5.3MEDIUM
Argument Injection Flaw in PrefectHQ's GitRepository Pull Handler

A vulnerability exists in PrefectHQ's product related to the GitRepository Pull Handler, specifically within the file src/prefect/runner/storage.py. The issue arises from improper handling of arguments, specifically the 'commit_sha' and 'directories' parameters, leading to potential argument inje...

PoC for CVE-2026-7724

PrefecthqPrefect2.3LOW
Time-of-Check Time-of-Use Vulnerability in PrefectHQ Prefect Webhoo...

A vulnerability exists in the PrefectHQ Prefect software within the Webhook/Notification component. The specific flaw lies in the validate_restricted_url function, which is susceptible to a time-of-check time-of-use condition. This vulnerability allows remote attackers to exploit the system under...

PoC for CVE-2026-7723

PrefecthqPrefect6.9MEDIUM
Missing Authentication in PrefectHQ Prefect WebSocket Endpoint

A security flaw has been identified in the WebSocket Endpoint of the PrefectHQ Prefect application, affecting versions up to 3.6.13. This vulnerability permits remote exploitation, as it allows an attacker to manipulate the system due to a lack of proper authentication mechanisms. To mitigate thi...

Discovered 20 hours ago

PoC for CVE-2026-7722

PrefecthqPrefect6.9MEDIUM
Improper Authentication in PrefectHQ Health Check API

A vulnerability was identified in the Health Check API of PrefectHQ's Prefect, affecting versions up to 3.6.21. This flaw allows for improper authentication through the 'endswith' function in the /api/health endpoint. Attackers could exploit this vulnerability remotely, increasing the risk of una...

PoC for CVE-2026-7721

TotolinkWa3005.3MEDIUM
Command Injection Vulnerability in Totolink WA300 Router

A security vulnerability has been identified in the Totolink WA300 router, specifically within the NTPSyncWithHost function located in the /cgi-bin/cstecgi.cgi file. This flaw allows an attacker to manipulate the 'hostTime' argument, leading to the possibility of command injection. The vulnerabil...

PoC for CVE-2026-7720

TotolinkWa3005.3MEDIUM
Command Injection Vulnerability in Totolink WA300 by Totolink

A vulnerability has been discovered in the Totolink WA300 router's POST Request Handler, specifically within the setLanguageCfg function in the /cgi-bin/cstecgi.cgi script. This weakness allows an attacker to manipulate the langType argument, potentially leading to command injection. The exploit ...

PoC for CVE-2026-7719

TotolinkWa3009.3CRITICAL
Buffer Overflow Vulnerability in Totolink WA300 by Totolink

A security flaw has been identified in the Totolink WA300 access point, specifically in the 'loginauth' function located in the cstecgi.cgi file of the POST Request Handler. The vulnerability arises from improper handling of the 'http_host' argument, leading to a buffer overflow that can be explo...

Discovered 21 hours ago

PoC for CVE-2026-7718

TotolinkWa3005.3MEDIUM
Command Injection Vulnerability in Totolink WA300 Router

A vulnerability has been identified in the Totolink WA300 router, specifically within the function setWebWlanIdx located in /cgi-bin/cstecgi.cgi of the POST Request Handler. An attacker can manipulate the webWlanIdx argument, resulting in command injection, which may be initiated remotely. The ex...

PoC for CVE-2026-7717

TotolinkWa3008.7HIGH
Buffer Overflow Vulnerability in Totolink WA300 Router

A buffer overflow vulnerability exists in the UploadCustomModule function of the Totolink WA300 router's POST Request Handler. This issue stems from improper handling of input on the /cgi-bin/cstecgi.cgi script, allowing attackers to manipulate the 'File' argument. If successfully exploited, this...