Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered just now...

PoC for CVE-2026-21986

OracleOracle Vm Virtualbox7.1HIGH
Unauthenticated Access Vulnerability in Oracle VM VirtualBox

A vulnerability exists in Oracle VM VirtualBox that allows an unauthenticated attacker with access to the infrastructure where the software is deployed to exploit the system. This can lead to unauthorized control over Oracle VM VirtualBox, resulting in potential service disruptions such as freque...

PoC for CVE-2026-33453

ApacheApache Camel10CRITICAL
Remote Code Execution Vulnerability in Apache Camel's CoAP Component

A vulnerability exists within Apache Camel's camel-coap component that allows an unauthenticated attacker to exploit message header injection. By sending a single CoAP UDP packet to a Camel route that accepts coap:// input, attackers can inject arbitrary Camel internal headers into the Exchange. ...

Discovered 2 hours ago

PoC for CVE-2026-33439

OpenidentityplatformOpenam9.3CRITICAL
Remote Code Execution in OpenIdentityPlatform OpenAM Access Managem...

OpenIdentityPlatform's OpenAM, an access management solution, is susceptible to a pre-authentication Remote Code Execution vulnerability due to unsafe Java deserialization. This issue arises from the handling of the jato.clientSession HTTP parameter, allowing unauthenticated attackers to execute ...

Discovered 4 hours ago

PoC for CVE-2026-7200

SourcecodesterPharmacy Sales And Inv...5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Pharmacy Sales...

A flaw has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0, specifically affecting an unknown functionality of the file /index.php?page=types. By manipulating the argument ID, an attacker could potentially execute cross-site scripting (XSS) attacks, which can be performe...

PoC for CVE-2026-7199

SourcecodesterPharmacy Sales And Inv...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

A SQL injection vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0, specifically within the AJAX functionality at /ajax.php?action=delete_product. Maliciously crafted requests targeting the argument ID can lead to unauthorized access and potential manipulation of the d...

PoC for CVE-2026-7196

CodeastroOnline Classroom5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom by CodeAstro

A security vulnerability has been identified in CodeAstro Online Classroom version 1.0, specifically within the /guestdetails file. The vulnerability arises from improper handling of an argument, 'deleteid', which allows remote attackers to execute SQL injection attacks. This manipulation can lea...

Discovered 5 hours ago

PoC for CVE-2026-7194

SourcecodesterPharmacy Sales And Inv...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

A security weakness has been discovered in the SourceCodester Pharmacy Sales and Inventory System 1.0, specifically within the file /ajax.php when processing the action save_product. This vulnerability allows attackers to manipulate the argument ID, leading to SQL injection. The flaw can be explo...

PoC for CVE-2026-7179

OspgBinwalk4.8MEDIUM
Path Traversal Vulnerability in OSPG binwalk by Open Source Community

A security vulnerability has been identified in the OSPG binwalk tool, specifically in versions up to 2.4.3, affecting the read_null_terminated_string function within the WinCE Extraction Plugin. This flaw allows local attackers to manipulate the function's arguments and potentially exploit path ...

PoC for CVE-2026-7178

ChatgptnextwebNextchat6.9MEDIUM
Server-Side Request Forgery Vulnerability in ChatGPTNextWeb NextChat

A security flaw exists in the ChatGPTNextWeb NextChat application up to version 2.16.1, primarily affecting the 'storeUrl' function within the 'app/api/artifacts/route.ts' file. This vulnerability allows for server-side request forgery (SSRF) through manipulation of the argument ID, enabling remo...

Discovered 6 hours ago

PoC for CVE-2026-7177

ChatgptnextwebNextchat6.9MEDIUM
Server-Side Request Forgery Vulnerability in ChatGPTNextWeb NextChat

A security flaw in NextChat versions up to 2.16.1 allows attackers to exploit the proxyHandler function within app/api/[provider]/[...path]/route.ts, posing a server-side request forgery vulnerability. This issue can be exploited remotely, potentially allowing unauthorized access to internal reso...

PoC for CVE-2026-7160

TendaHg38.7HIGH
Command Injection Vulnerability in Tenda HG3 Router

A vulnerability has been identified in the Tenda HG3 router involving command injection through the formTracert function located in the /boaform/formTracert file. This flaw allows an attacker to manipulate the datasize argument, potentially enabling remote code execution. Given the public disclos...

PoC for CVE-2026-7159

DouincMkdocs-mcp-plugin6.9MEDIUM
Path Traversal Vulnerability in douinc mkdocs-mcp-plugin Software

A path traversal vulnerability has been identified in the douinc mkdocs-mcp-plugin version 0.4.1. This issue allows attackers to manipulate inputs intended for the read_document and list_documents functions within the server.py file. An attacker could potentially trick the affected function into ...

PoC for CVE-2026-7158

DmitryglhfMcp-url-downloader6.9MEDIUM
Server-Side Request Forgery Vulnerability in Dmitryglhf MCP-URL-Dow...

A vulnerability exists in the dmitryglhf MCP-URL-Downloader that allows for server-side request forgery due to improper validation of URLs in the _validate_url_safe function. This issue can be exploited remotely, allowing attackers to manipulate the URL argument and potentially access sensitive d...

Discovered 7 hours ago

PoC for CVE-2026-7157

DislerAider-mcp-server6.9MEDIUM
Command Injection Vulnerability in disler aider-mcp-server by Disler

A command injection vulnerability exists in the disler aider-mcp-server, specifically within the functionality of src/aider_mcp_server/server.py. This flaw allows attackers to manipulate the argument 'relative_editable_files', making remote exploitation possible. The vulnerability is present in v...

PoC for CVE-2026-7156

TotolinkA8000ru9.3CRITICAL
OS Command Injection Vulnerability in Totolink A8000RU

A vulnerability has been identified in the Totolink A8000RU, specifically in the CGI Handler component's CsteSystem function. This flaw allows for manipulation of the HTTP argument, leading to potential OS command injection. Attackers can exploit this vulnerability remotely, posing a significant ...

PoC for CVE-2026-7155

TotolinkA8000ru9.3CRITICAL
OS Command Injection Vulnerability in Totolink A8000RU

A vulnerability has been found in the Totolink A8000RU version 7.1cu.643_b20200521, specifically within the CGI component. This flaw resides in the setLoginPasswordCfg function within the cgi-bin/cstecgi.cgi file. By manipulating the admpass argument, an attacker can execute arbitrary OS commands...

PoC for CVE-2026-7154

TotolinkA8000ru9.3CRITICAL
OS Command Injection Vulnerability in Totolink A8000RU Product

A security vulnerability has been identified in the Totolink A8000RU version 7.1cu.643_b20200521, particularly in the functionality of the CGI Handler. This weakness arises from the setAdvancedInfoShow method, where an improperly handled input parameter, tty_server, allows an attacker to conduct ...

Discovered 8 hours ago

PoC for CVE-2026-7153

TotolinkA8000ru9.3CRITICAL
OS Command Injection Vulnerability in Totolink A8000RU Router

A security flaw has been identified in the Totolink A8000RU router, specifically within the CGI Handler component. The vulnerability arises from improper handling of the 'sys_info' argument in the 'setMiniuiHomeInfoShow' function of the /cgi-bin/cstecgi.cgi file. This oversight allows an attacker...

PoC for CVE-2026-7152

TotolinkA8000ru9.3CRITICAL
OS Command Injection Vulnerability in Totolink A8000RU

An OS command injection vulnerability exists in the Totolink A8000RU router firmware version 7.1cu.643_b20200521. Specifically, the flaw lies in the 'setTelnetCfg' function within the '/cgi-bin/cstecgi.cgi' CGI Handler component. This vulnerability enables remote attackers to exploit the telnet_e...

PoC for CVE-2026-35022

AnthropicClaude Code9.3CRITICAL
OS Command Injection Vulnerability in Anthropic Claude Code CLI and...

The Anthropic Claude Code CLI and Claude Agent SDK are susceptible to an OS command injection vulnerability in the authentication helper execution. This flaw arises from the lack of input validation in the execution of helper configuration values, allowing an attacker with the ability to manipula...

PoC for CVE-2026-7151

TendaHg38.7HIGH
Stack-based Buffer Overflow in Tenda HG3 Affected by Vulnerability

A stack-based buffer overflow exists in the Tenda HG3 model 2.0 due to insufficient validation in the formUploadConfig function located in the /boaform/formIPv6Routing file. This insecurity can be exploited remotely by manipulating the destNet parameter, potentially allowing an attacker to execut...

PoC for CVE-2026-7150

Dh1011Auto-favicon5.3MEDIUM
Server-Side Request Forgery in dh1011 Auto-Favicon MCP Tool

A vulnerability exists in the dh1011 Auto-Favicon MCP Tool within the generate_favicon_from_url function. The flaw allows an attacker to manipulate the image_url argument, leading to potential server-side request forgery. This manipulation can be executed remotely, putting systems at risk of unau...

Discovered 9 hours ago

PoC for CVE-2026-7149

DexhunterKaggle-mcp6.9MEDIUM
Path Traversal Vulnerability in dexhunter kaggle-mcp Product by dex...

A path traversal vulnerability exists in the dexhunter kaggle-mcp project, specifically within the prepare_kaggle_dataset function located in the src/kaggle_mcp/server.py file. An attacker can exploit this vulnerability by manipulating the competition_id argument, allowing unauthorized access to ...

PoC for CVE-2026-7148

CodeastroOnline Classroom5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom by CodeAstro

A security vulnerability has been identified in CodeAstro Online Classroom 1.0. The flaw exists in the /addnewfaculty file, where improper handling of the 'fname' argument allows for SQL injection. This can enable an attacker to manipulate database queries from a remote location, exposing sensiti...

PoC for CVE-2026-7147

JoecastromMcp-chat-studio6.9MEDIUM
Server-Side Request Forgery Vulnerability in JoeCastrom mcp-chat-st...

A vulnerability exists in JoeCastrom's mcp-chat-studio product, specifically in the LLM Models API component. The issue stems from improper handling of the req.query.base_url argument in the file server/routes/llm.js. This flaw permits a server-side request forgery, allowing attackers to manipula...

PoC for CVE-2026-7146

AlejandroarciniegasMcp-data-vis6.9MEDIUM
Server-Side Request Forgery in AlejandroArciniegas mcp-data-vis Pro...

A security vulnerability has been identified within the mcp-data-vis product by AlejandroArciniegas that exposes the system to server-side request forgery (SSRF). This flaw arises from the handling of HTTP requests in the axios function located in the src/servers/web-scraper/server.js file. Malic...

PoC for CVE-2026-38934

DiskoverdataDiskover Community8.8HIGH
Cross Site Request Forgery Vulnerability in Diskover Community by D...

A Cross Site Request Forgery vulnerability exists in Diskover Community versions prior to 2.3.5, allowing remote attackers to exploit the public/settings_process.php endpoint. This could potentially lead to privilege escalation and unauthorized access to sensitive information, putting user data a...

Discovered 10 hours ago

PoC for CVE-2026-7144

1000 ProjectsPortfolio Management S...5.3MEDIUM
Authorization Bypass Vulnerability in 1000 Projects Portfolio Manag...

A security flaw in the 1000 Projects Portfolio Management System MCA 1.0 allows attackers to bypass authorization through manipulation of the temp_user argument in the update_passwd_process.php file. This flaw can be exploited remotely, raising significant security concerns as it may lead to unau...

PoC for CVE-2026-7143

1000 ProjectsPortfolio Management S...5.3MEDIUM
SQL Injection Vulnerability in 1000 Projects Portfolio Management S...

A vulnerability has been discovered in the 1000 Projects Portfolio Management System MCA affecting versions up to 1.0. This vulnerability resides in the /admin/block_status.php file, where improper handling of the query parameter 'q' can lead to SQL injection. Such a flaw enables remote attackers...

PoC for CVE-2026-7142

WooeyWooey5.3MEDIUM
Improper Authorization in Wooey API Endpoint by Wooey

A vulnerability exists in Wooey's API Endpoint, particularly in the 'add_or_update_script' function found in the file 'wooey/api/scripts.py'. This issue can be exploited to perform improper authorization, allowing for remote attacks. It's crucial for users running versions up to 0.13.2 to upgrade...

Discovered 11 hours ago

PoC for CVE-2026-7141

vllm-projectVllm6.3MEDIUM
Uninitialized Resource Vulnerability in vllm by vllm-project

A vulnerability was identified in the vllm library, affecting versions up to 0.19.0, specifically within the has_mamba_layers function of the KV Block Handler component. This issue stems from uninitialized resources, which could potentially enable remote exploitation. Although the complexity of c...

PoC for CVE-2026-7140

TotolinkA8000ru9.3CRITICAL
OS Command Injection in Totolink A8000RU by Totolink

A security vulnerability exists in the Totolink A8000RU, where manipulation of the argument HTTP within the CsteSystem function of the CGI Handler can lead to OS command injection. This vulnerability allows remote attackers to execute arbitrary commands on the device, posing a significant threat ...

PoC for CVE-2026-7139

TotolinkA8000ru9.3CRITICAL
OS Command Injection in Totolink A8000RU Router

A significant vulnerability has been identified in the Totolink A8000RU router, specifically within the setWiFiAclRules function located in the /cgi-bin/cstecgi.cgi file of the CGI Handler component. This flaw allows remote attackers to manipulate the mode argument, potentially leading to unautho...

PoC for CVE-2026-7138

TotolinkA8000ru9.3CRITICAL
OS Command Injection Vulnerability in Totolink A8000RU Router

A security flaw has been identified in the Totolink A8000RU router, specifically within the CGI Handler component's setNtpCfg function. This vulnerability allows an attacker to manipulate the 'tz' argument, facilitating an OS command injection. The attack can be executed remotely, potentially com...

Discovered 12 hours ago

PoC for CVE-2026-7137

TotolinkA8000ru9.3CRITICAL
OS Command Injection Vulnerability in Totolink A8000RU by Totolink

A security vulnerability has been identified in Totolink A8000RU routers, specifically in the setStorageCfg function of the /cgi-bin/cstecgi.cgi component. This issue arises from improper handling of the sambaEnabled argument, which could allow an attacker to execute arbitrary OS commands remotel...

PoC for CVE-2026-7136

TotolinkA8000ru9.3CRITICAL
Command Injection Vulnerability in Totolink A8000RU by Totolink

A command injection vulnerability exists in the CGI Handler of the Totolink A8000RU router, specifically within the setDmzCfg function found in /cgi-bin/cstecgi.cgi. This security flaw allows an attacker to manipulate the wanIdx argument to execute arbitrary commands on the operating system. With...

PoC for CVE-2026-7135

GPACGpac4.8MEDIUM
Security Flaw in GPAC MP4Box Affects Media Processing Capabilities

A security flaw has been identified in GPAC's MP4Box component, specifically within the elng_box_read function located in src/isomedia/box_code_base.c. This vulnerability facilitates an out-of-bounds read when the elng argument is manipulated. The exploit requires local access and has been made p...

PoC for CVE-2026-41467

ProjeqtorProjeqtor5.1MEDIUM
Stored Cross-Site Scripting Vulnerability in ProjeQtor by ProjeQtor

ProjeQtor versions from 7.0 to 12.4.3 feature a stored cross-site scripting vulnerability that arises from inadequate restrictions on file uploads. Specifically, the checkValidFileName() function allows authenticated users to upload HTML files containing malicious JavaScript. As a result, users a...

PoC for CVE-2026-41466

ProjeqtorProjeqtor5.1MEDIUM
Stored Cross-Site Scripting Vulnerability in ProjeQtor by ProjeQtor

ProjeQtor versions 7.0 to 12.4.3 are susceptible to a stored cross-site scripting (XSS) vulnerability due to inadequate input sanitization in the checkValidHtmlText() function within Security.php. This vulnerability allows adversaries to inject malicious scripts that can be stored and executed in...

PoC for CVE-2026-41465

ProjeqtorProjeqtor7.1HIGH
Path Traversal Vulnerability in ProjeQtor by ProjeQtor

The ProjeQtor application versions 7.0 to 12.4.3 has a vulnerability in its log file viewer located at dynamicDialog.php. This vulnerability allows authenticated attackers to exploit the logname parameter, which fails to properly validate input against directory traversal sequences. By injecting ...

PoC for CVE-2026-41464

ProjeqtorProjeqtor7.1HIGH
Missing Authorization Vulnerability in ProjeQtor by ProjeQtor

ProjeQtor versions 7.0 through 12.4.3 are affected by a vulnerability that allows authenticated users with guest-level privileges to access sensitive data, including password hashes and API keys. The flaw exists in the objectDetail.php endpoint, which lacks adequate authorization checks. This per...

PoC for CVE-2026-41463

ProjeqtorProjeqtor8.7HIGH
ZipSlip Path Traversal Vulnerability in ProjeQtor by ProjeQtor

ProjeQtor, versions 7.0 through 12.4.3, is susceptible to a ZipSlip path traversal vulnerability. This security flaw is present in the plugin's upload functionality, allowing authenticated attackers with upload permissions to exploit unvalidated archive extraction. By using specially crafted ZIP ...

PoC for CVE-2026-41462

ProjeqtorProjeqtor9.3CRITICAL
Unauthenticated SQL Injection in ProjeQtor by ProjeQtor

ProjeQtor versions 7.0 to 12.4.3 are susceptible to an unauthenticated SQL injection vulnerability within the login functionality. This occurs when the application dynamically constructs SQL queries without proper parameterization or sanitization of user inputs. Attackers can exploit this vulnera...

PoC for CVE-2026-7134

Code-projectsOnline Lot Reservation...5.1MEDIUM
Unrestricted File Upload Vulnerability in Code-Projects Online Lot ...

A manipulation vulnerability exists in the Online Lot Reservation System version 1.0, specifically in the /edithousepic.php file. By exploiting improper handling of the image argument, an attacker could perform an unrestricted file upload, potentially allowing the execution of unauthorized script...

Discovered 13 hours ago

PoC for CVE-2026-7133

Code-projectsOnline Lot Reservation...5.1MEDIUM
Unrestricted Upload Vulnerability in code-projects Online Lot Reser...

The Online Lot Reservation System 1.0 from code-projects contains a vulnerability in the /activity.php file that allows remote attackers to manipulate the argument directory, leading to unrestricted file uploads. This flaw can be exploited to upload malicious files to the server, potentially comp...

PoC for CVE-2026-7132

Code-projectsOnline Lot Reservation...6.9MEDIUM
Path Traversal Vulnerability in code-projects Online Lot Reservatio...

A vulnerability exists in the Online Lot Reservation System up to version 1.0, specifically within the readfile function of the /download.php file. This issue allows remote attackers to manipulate the 'File' argument, leading to potential path traversal attacks. The vulnerability can expose sensi...

PoC for CVE-2026-7131

Code-projectsOnline Lot Reservation...6.9MEDIUM
SQL Injection Vulnerability in code-projects Online Lot Reservation...

A SQL injection vulnerability has been identified in the code-projects Online Lot Reservation System up to version 1.0. The vulnerability resides in the '/loginuser.php' file, which enables an attacker to manipulate the email and password arguments. This manipulation could potentially allow for u...

PoC for CVE-2026-7130

SourcecodesterPharmacy Sales And Inv...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

The SourceCodester Pharmacy Sales and Inventory System 1.0 contains a vulnerability due to improper input validation in an unknown function within the /ajax.php file. An attacker can exploit this flaw by manipulating the argument ID during a remote request, potentially leading to unauthorized acc...

Discovered 14 hours ago

PoC for CVE-2026-7129

SourcecodesterPharmacy Sales And Inv...5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Pharmacy Sales...

A vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System version 1.0, specifically in the /index.php?page=categories file. An attacker can manipulate the 'ID' argument to execute cross-site scripting attacks remotely. This exploit has become public, posing significant secu...

PoC for CVE-2026-7128

SourcecodesterPharmacy Sales And Inv...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

A vulnerability has been discovered in the SourceCodester Pharmacy Sales and Inventory System version 1.0 that allows for remote SQL injection through manipulation of parameters in the file /ajax.php?action=save_type. This exploitation can lead to unauthorized access and manipulation of the datab...