Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 1 hour ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 3 hours ago
PoC for CVE-2026-103687
A vulnerability exists in the Rhukster DOM-Sanitizer component related to SVG sanitization. The flaw lies in the handling of the function 'url' in the src/DOMSanitizer.php file, which creates an incomplete blacklist for input validation. This allows a potential attacker to exploit the vulnerabili...
PoC for CVE-2024-58388
Sharp and Toshiba Tec multifunction printers are susceptible to an unauthenticated local file inclusion vulnerability. This issue arises from improper validation of user input in the installed_emanual_down.html endpoint. By manipulating the path parameter, attackers can execute directory traversa...
Discovered 4 hours ago
PoC for CVE-2026-103686
A security flaw exists in rhukster's dom-sanitizer component, specifically in the URL validation functionality. The issue lies within the DOMSanitizer::isDangerousUrl method, which can be exploited for cross-site scripting attacks. This vulnerability can allow attackers to initiate remote exploit...
PoC for CVE-2024-55591
A vulnerability exists in FortiOS and FortiProxy that allows a remote attacker to exploit an authentication bypass through crafted requests targeting the Node.js websocket module. This weakness could enable unauthorized users to attain super-admin privileges, compromising system security. Users o...
Discovered 6 hours ago
PoC for CVE-2026-88771
An improper input validation vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway, enabling unauthenticated attackers to execute arbitrary commands. This potentially compromises system integrity and security, allowing unauthorized control over the affected product.
Discovered 7 hours ago
PoC for CVE-2026-59310
VMware vCenter features a directory traversal vulnerability in its Syslog server component. This flaw allows attackers with network access to exploit the vulnerability, potentially leading to unauthorized execution of arbitrary code. Proper safeguards and patching are essential to mitigate the ri...
PoC for CVE-2026-103585
A Cross-Site Scripting (XSS) vulnerability exists in the MediaWiki MediaSearch extension, allowing attackers to inject malicious scripts through improperly neutralized HTML tags in web pages. This affects versions 1.46, 1.45, and 1.43, posing a risk to users by enabling the execution of harmful s...
PoC for CVE-2026-103584
The Wikimedia Foundation MediaWiki CommonsMetadata extension is susceptible to a Cross-Site Scripting vulnerability due to improper neutralization of script-related HTML tags. This flaw permits attackers to inject malicious scripts into web pages viewed by users, which can lead to unauthorized ac...
Discovered 11 hours ago
PoC for CVE-2026-103544
A significant vulnerability affects the OpenConstructionERP software, specifically in the Al Provider Configuration Handler. An unknown function within the ai_client.py file can lead to improper access control, allowing data elements to be exposed to unauthorized sessions. This vulnerability is r...
PoC for CVE-2026-96173
The Payments for Hubtel WordPress plugin, prior to version 1.0.2, is susceptible to an authorization flaw that fails to validate whether the requester is authorized to access order information. This vulnerability permits unauthenticated attackers to redirect public payment-callback requests, ther...
PoC for CVE-2026-92412
The Five Star Restaurant Reviews plugin for WordPress, prior to version 2.3.14, is vulnerable to Cross-Site Scripting (XSS). This vulnerability arises from improper escaping of user-supplied input, allowing unauthenticated attackers to inject malicious scripts. As a result, any user, including lo...
PoC for CVE-2026-90974
The WP Fusion Lite plugin for WordPress, prior to version 3.48.0, is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated users to access critical settings within the WordPress admin area. By exploiting this weakness, attackers can manipulate the site's CRM inte...
PoC for CVE-2026-90972
The WP Fusion Lite plugin for WordPress prior to version 3.48.0 has a significant security flaw where it fails to conduct proper capability checks on two of its admin AJAX handlers. This oversight enables any authenticated subscriber to access other users' email addresses, leading to unauthorized...
PoC for CVE-2026-96255
The Payments for Hubtel WordPress plugin prior to version 1.0.2 has a serious flaw that permits unauthorized public access to a debug log. This log stores sensitive information, including the API credentials for the payment gateway, in an unsecured plain text format. As a result, unauthenticated ...
PoC for CVE-2026-96200
The Payments for Hubtel WordPress plugin prior to version 1.0.2 is susceptible to a vulnerability that lacks verification of payment notifications received through its payment callback mechanism. This oversight permits unauthenticated attackers to falsely mark arbitrary orders as paid, leading to...
PoC for CVE-2026-87973
The If-So Dynamic Content plugin for WordPress prior to version 1.10.2 is susceptible to a JavaScript injection vulnerability. This issue arises because the plugin fails to properly sanitize conversion names before saving them and does not escape content during the rendering of the analytics page...
PoC for CVE-2026-81809
The Paytm Payment Gateway WordPress plugin versions before 2.8.9 is susceptible to SQL injection due to improper data escaping from payment callbacks. Malicious users can exploit this vulnerability, particularly when the gateway operates without the required credentials, enabling them to manipula...
PoC for CVE-2026-89296
The Pro Like Button plugin for WordPress prior to version 2.0 contains a vulnerability that fails to properly sanitize and escape input parameters used in SQL queries. This flaw allows unauthenticated attackers to manipulate the queries, potentially executing arbitrary SQL commands. As a result, ...
PoC for CVE-2026-86610
The Download Manager plugin for WordPress prior to version 3.3.71 has a vulnerability that arises from inadequate sanitization of user inputs. This allows users with the Author role or higher to exploit the system by injecting malicious scripts into the package settings. When a visitor accesses t...
PoC for CVE-2026-87970
The If-So Dynamic Content plugin for WordPress prior to version 1.10.2 is susceptible to an improper input validation vulnerability. This flaw arises from the plugin's failure to adequately escape user-supplied values in AJAX responses. As a consequence, unauthenticated attackers can inject and e...
PoC for CVE-2026-101147
The Featured Image from URL (FIFU) plugin for WordPress is susceptible to Cross-Site Request Forgery due to improper enforcement of the REST API nonce in versions prior to 6.0.8 and 8.2.8 for the Premium variant. This security flaw enables attackers to exploit the vulnerability through crafted UR...
PoC for CVE-2026-19253
The Cache Enabler WordPress plugin, prior to version 1.8.17, contains a vulnerability that allows unauthenticated users to exploit the URL handling in its cache purge process. By failing to validate a user-supplied URL, the plugin can generate a filesystem path that extends beyond its intended ca...
PoC for CVE-2026-101148
The BackupSheep WordPress Backup Plugin, prior to version 1.8, fails to impose adequate validation checks on its integration key, mistakenly allowing an unset or blank key to be treated as valid. This loophole enables unauthenticated users to access sensitive functionalities, such as creating and...
PoC for CVE-2026-81739
The Paytm Payment Gateway plugin for WordPress prior to version 2.8.9 is vulnerable due to the lack of proper sanitization and escaping of payment callback data. This allows unauthenticated users to manipulate the data stored on admin pages, potentially injecting malicious scripts. Furthermore, t...
PoC for CVE-2026-103543
A vulnerability exists in the itsourcecode Leave Management System 1.0 that allows attackers to exploit an unknown function within the /module/leavetype/controller.php file. By manipulating the LEAVTID argument, an attacker can execute SQL injection attacks remotely. This vulnerability has been d...
Discovered 12 hours ago
PoC for CVE-2026-103542
A security flaw has been identified in Form Tools, specifically within the smart_fill function located in the AJAX Endpoint's actions.php file. This vulnerability allows attackers to manipulate the 'url' argument, leading to server-side request forgery (SSRF). It poses a significant risk as the a...
PoC for CVE-2026-103541
A vulnerability was discovered in Form Tools that allows for unrestricted file uploads due to a flaw in the uploadFile function within the Ajax Handler component. This issue is present in versions up to 3.1.1. The flaw enables remote attackers to exploit the vulnerability and upload arbitrary fil...
PoC for CVE-2026-103540
A security vulnerability has been identified in the Form Tools application, specifically impacting versions up to 3.1.1. This flaw affects the function 'Clients::updateClientSettingsTab' within the Client Settings component, located in 'global/code/Clients.class.php'. The issue arises from the im...
PoC for CVE-2026-103539
A vulnerability has been identified in the ZongXR SuperMarket version 1.0.0.0, specifically within the Instant Buy component. This weakness allows for a manipulation of the 'Username' argument during the execution of the 'startBuy' function located in the InstantBuyController.java file. As a resu...
Discovered 13 hours ago
PoC for CVE-2026-103538
A significant security vulnerability has been identified in the ZongXR SuperMarket version 1.0.0.0, specifically within the Order Deletion Endpoint function. This flaw arises from improper handling of the orderId parameter in the OrderController.deleteOrder method, leading to a situation where au...
PoC for CVE-2026-103536
A significant security flaw has been identified in the ZongXR Supermarket application, specifically within the OrderController component. The issue lies in the addOrder function, located in the order/src/main/java/com/supermarket/order/controller/OrderController.java file. This vulnerability allo...
Discovered 14 hours ago
PoC for CVE-2026-103446
An authorization bypass vulnerability exists in the WikiLambda extension of MediaWiki, allowing unauthorized users to bypass authentication mechanisms. This flaw is triggered by user-controlled keys, enabling potentially malicious actions. The vulnerability affects the MediaWiki WikiLambda extens...
PoC for CVE-2026-103445
The MediaWiki Page_Forms extension from Wikimedia Foundation contains a vulnerability that allows for stored cross-site scripting (XSS). This issue arises from the improper neutralization of script-related HTML tags within web pages, potentially enabling attackers to inject malicious scripts that...
PoC for CVE-2026-103442
A vulnerability exists in the MediaWiki CentralAuth extension that allows external entities to manipulate system or configuration settings, leading to potential code injection. This issue impacts versions 1.46, 1.45, and 1.43. Users of affected versions are encouraged to update their installation...
PoC for CVE-2026-103441
A deserialization of untrusted data vulnerability exists in the Wikimedia Foundation MediaWiki Wikibase extension, potentially enabling the execution of executable code in files that are not typically executable. This issue raises significant security concerns as it affects multiple versions of t...
PoC for CVE-2026-103440
A vulnerability in the MediaWiki PageTriage extension enables the exposure of sensitive information through improper data queries. Attackers can potentially elicit data that should be protected, impacting user privacy and system integrity. This issue affects specific versions of the PageTriage ex...
PoC for CVE-2026-103437
A reflected XSS vulnerability exists in the MediaWiki ReadingLists extension developed by Wikimedia Foundation. This vulnerability stems from improper neutralization of script-related HTML tags in web pages, allowing attackers to execute malicious scripts in the context of a user's browser. Users...
PoC for CVE-2026-103534
A vulnerability has been identified in David-Crty databasement that affects versions up to 1.7.1. Specifically, the issue lies within the SnapshotPolicy.viewAny and SnapshotPolicy.view functions in the /api/v1/snapshots component of the Snapshot Model. This flaw may allow unauthorized users to by...
PoC for CVE-2026-12227
The Visual Composer Website Builder plugin for WordPress allows local file inclusion through the `vcv-template` parameter in all versions up to and including 45.16.0. This vulnerability enables unauthenticated attackers to include and execute arbitrary files on the server, potentially leading to ...
PoC for CVE-2026-102427
The OrdaSoft Joomla CCK extension prior to version 8.3.16 is susceptible to unauthenticated remote code execution due to inadequate handling of file uploads. The vulnerability allows attackers to upload malicious files disguised as images, which can then be executed on the server. This occurs bec...
PoC for CVE-2025-29927
A security flaw exists in the Next.js framework that allows an attacker to bypass authorization checks if such checks are implemented in middleware. This vulnerability arises in versions prior to 14.2.25 and 15.2.3. To mitigate risk, it is recommended to restrict incoming requests that include th...
Discovered 15 hours ago
PoC for CVE-2026-103533
A path traversal vulnerability in David-Crty Databasement affects versions up to 1.7.1. It arises from improper validation of the 'schema_name' argument in the database-servers API Endpoint, allowing attackers to potentially access unauthorized files. This type of exploit may be performed remotel...
Discovered 17 hours ago
PoC for CVE-2026-94545
The Satori library, developed by Vercel for converting HTML and CSS into SVG, contains a vulnerability in versions prior to 0.33.5. In these affected versions, the library fails to properly escape certain values before embedding them in the generated SVG output. This oversight can lead to the exe...
Discovered 21 hours ago
PoC for CVE-2023-54403
The Yonyou U8 CRM software versions before V16.5 and V18 contain a vulnerability in the /ajax/getemaildata.php file, which allows unauthenticated users to bypass authentication by manipulating the DontCheckLogin parameter. This vulnerability permits the reading of arbitrary files through an unval...
PoC for CVE-2024-58387
Inspur Haiyue HCM Cloud features a vulnerability that allows remote attackers to read arbitrary files through the /api/model_report/file/download endpoint. By exploiting unvalidated parameters such as 'index' and 'ext', attackers can craft malicious requests that enable directory traversal, leadi...
Discovered 22 hours ago
PoC for CVE-2026-103387
A weakness exists in the Mailto Header Handler of garycourt's uri-js library up to version 4.4.1, specifically in the URI.parse function located in src/schemes/mailto.ts. This vulnerability can lead to uncaught exceptions due to improper handling of parsed arguments. An attacker may exploit this ...
Discovered 1 day ago
PoC for CVE-2026-103241
A flaw has been identified in the vLLM software by vllm-project, specifically within the Gemma4UnifiedParser component. This vulnerability allows for a denial of service, which can be exploited remotely through manipulation of certain code segments within the parser. The vulnerable versions of vL...
PoC for CVE-2026-103233
A security vulnerability exists in the AdithyaYelloju Restaurant Management System, affecting the admin area. This vulnerability allows an attacker to manipulate the argument ID, resulting in an unauthorized access control condition. The issue can be exploited remotely, leading to potential unaut...
PoC for CVE-2026-103232
A vulnerability has been detected in the AdithyaYelloju Restaurant-Management-System that could be exploited to perform SQL injection attacks through the mysqli_query function in the admin/table_booking.php file. This flaw allows attackers to manipulate input parameters, particularly the argument...