Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 11 hours ago

PoC for CVE-2026-72530

TrueconfTrueconf Server9.5CRITICAL
Remote Code Execution Vulnerability in TrueConf Server by TrueConf

A vulnerability in TrueConf Server allows remote unauthorized attackers with access to port 4307/TCP to exploit the server versions 5.3.X up to 5.3.9, 5.4.X up to 5.4.9, and 5.5.X up to 5.5.5. By using a crafted script, the attacker can break out of the isolated execution environment and execute ...

Discovered 12 hours ago

PoC for CVE-2026-77790

WordPressRegistrationmagic
SQL Injection Vulnerability in RegistrationMagic WordPress Plugin

The RegistrationMagic plugin for WordPress, prior to version 6.0.9.4, is susceptible to SQL injection due to improper sanitization and escaping of input parameters in SQL statements. This vulnerability enables users with high privileges, such as administrators, to execute malicious SQL queries, p...

PoC for CVE-2026-77758

WordPressStripe Payment Forms B...5.3MEDIUM
Vulnerability in Stripe Payment Forms by WP Full Pay Plugin from Wo...

The Stripe Payment Forms by WP Full Pay plugin for WordPress prior to version 8.5.1 contains a vulnerability where it fails to accurately verify the completion of a customer portal session. This oversight allows unauthenticated users to access sensitive information, such as subscription and billi...

PoC for CVE-2026-78146

WordPressSimple Newsletter Plugin6.5MEDIUM
Data Disclosure Vulnerability in Simple Newsletter Plugin for WordP...

The Simple Newsletter Plugin for WordPress, prior to version 4.3.3, has a security flaw that allows unauthenticated users to access and disclose personal data of subscribers. This occurs due to the plugin's failure to validate that a requester is indeed the authorized subscriber before presenting...

PoC for CVE-2026-77789

WordPressStripe Payment Forms B...4.3MEDIUM
Authorization Flaw in Stripe Payment Forms Plugin by WP Full Pay

The Stripe Payment Forms plugin by WP Full Pay for WordPress prior to version 8.5.1 contains an authorization flaw that allows a user with a valid session to manipulate subscriptions that do not belong to them. Specifically, this vulnerability permits unauthorized actions such as canceling, react...

PoC for CVE-2026-77695

WordPressReturn Refund And Exch...6.5MEDIUM
Unauthorized Order Access in Return Refund and Exchange Plugin for ...

The Return Refund and Exchange For WooCommerce plugin for WordPress prior to version 4.6.4 contains a vulnerability that fails to properly verify guest order ownership during certain AJAX operations. This oversight permits unauthenticated users to gain access to private order communications, enab...

PoC for CVE-2026-77757

WordPressDirectorist: Ai-powere...5.4MEDIUM
File Manipulation Vulnerability in Directorist AI-Powered Business ...

The Directorist plugin for WordPress, designed for business directory listings, can be exploited due to insufficient sanitization of user-supplied image references. This flaw permits users with subscriber-level accounts to manipulate server-readable image files, allowing them to move these files ...

PoC for CVE-2026-77693

WordPressOrder Tip For WooCommerce8.7HIGH
File Deletion Vulnerability in WooCommerce Order Tip Plugin by Word...

The Order Tip for WooCommerce plugin prior to version 1.6.0 lacks proper user capability checks for file deletion requests and does not restrict deletion paths. This oversight permits users with the Shop Manager role and above to delete arbitrary files from the server, potentially compromising th...

PoC for CVE-2026-77694

WordPressEventin5.3MEDIUM
Unauthenticated Order Manipulation Vulnerability in Eventin Plugin ...

The Eventin WordPress plugin prior to version 4.1.19 contains a security flaw that permits unauthorized users to exploit the guest checkout token mechanism. This vulnerability enables unauthenticated individuals to manipulate their own unpaid orders, marking them as completed and receiving valid ...

PoC for CVE-2026-75798

WordPressAi Engine5.3MEDIUM
Improper Authorization in AI Engine Plugin for WordPress

The AI Engine plugin for WordPress prior to version 3.7.2 lacks essential authorization checks on specific administrative features. Instead of validating permissions, it issues a token to anonymous users. This design flaw permits unauthenticated attackers to execute AI queries on behalf of the si...

PoC for CVE-2026-77754

WordPressKirki5.3MEDIUM
Unauthorized Access in Kirki WordPress Plugin Exposes Sensitive Use...

The Kirki WordPress plugin prior to version 6.0.14 contains a serious vulnerability that lacks proper capability checks on certain public AJAX actions. This oversight allows attackers to exploit these endpoints, enabling them to access sensitive information including email addresses of registered...

PoC for CVE-2026-74930

WordPressProject Manager4.3MEDIUM
Information Disclosure in Project Manager by WordPress

The Project Manager WordPress plugin prior to version 4.0.7 contains a security flaw in its REST API routes. This vulnerability enables any authenticated user, including those with minimal access rights like subscribers, to maliciously access activity records of other users. Consequently, sensiti...

PoC for CVE-2026-74929

WordPressProject Manager5.4MEDIUM
Project Manager WordPress Plugin Vulnerability Exposes User Data an...

The Project Manager plugin for WordPress, prior to version 4.0.7, features a significant vulnerability that fails to enforce proper access controls on multiple REST API routes. This oversight allows authenticated users, including those with limited permissions, to gain unauthorized access to sens...

PoC for CVE-2026-75797

WordPressAi Engine7.7HIGH
File Reading Vulnerability in AI Engine Plugin for WordPress

The AI Engine plugin for WordPress, prior to version 3.7.2, has a vulnerability that allows users with subscriber-level accounts to access arbitrary files on the server. This occurs when a caller-supplied URL is improperly handled and mapped to a local filesystem path. If a public API feature is ...

PoC for CVE-2026-74928

WordPressProject Manager7.5HIGH
Unauthorized Account Creation in Project Manager Plugin for WordPress

The Project Manager plugin for WordPress, prior to version 4.0.7, lacks essential authorization checks on its import routes. This flaw enables unauthenticated users to create new WordPress accounts with predetermined passwords, effectively bypassing the site's standard registration settings and p...

PoC for CVE-2026-74851

WordPressPods7.2HIGH
Arbitrary Code Execution Vulnerability in Pods WordPress Plugin

The Pods WordPress plugin prior to version 3.3.9.1 contains a security flaw that fails to appropriately verify a display callback against its list of restricted functions. This oversight permits users with the author role or higher to execute arbitrary code on the server. Notably, this vulnerabil...

PoC for CVE-2026-19718

WordPressBlogvault Backup & Sta...8.1HIGH
Unauthenticated User Data Exposure in Backup & Security Plugins by ...

Multiple WordPress plugins, specifically the BlogVault Backup & Staging Plugin, MalCare WordPress Security Plugin, and WP Remote Plugin, prior to version 6.65, are susceptible to a serious data exposure vulnerability. This arises from their failure to sufficiently restrict unauthenticated users f...

PoC for CVE-2026-16986

WordPressBooking Package5.3MEDIUM
Payment Processing Flaw in Booking Package Plugin for WordPress

The Booking Package plugin for WordPress prior to version 1.7.25 is vulnerable due to inadequate server-side validation of payment amounts. This flaw allows an unauthenticated attacker to manipulate the payment process, potentially paying significantly less than the actual service price. The atta...

PoC for CVE-2026-19226

WordPressRoyal Addons For Eleme...6.8MEDIUM
Stored Cross-Site Scripting Vulnerability in Royal Addons for Eleme...

The Royal Addons for Elementor WordPress plugin, prior to version 1.7.1066, fails to properly validate certain widget settings before rendering them as HTML attributes. This oversight permits users with Contributor roles and higher to exploit the plugin, potentially leading to Stored Cross-Site S...

PoC for CVE-2026-19220

WordPressForminator Forms3.7LOW
Site Signup Vulnerability in Forminator Plugin for WordPress

The Forminator Forms plugin for WordPress, prior to version 1.57.1, lacks the necessary verification to ensure that site registration is enabled on the network. This oversight allows unauthenticated users to create new sites on a WordPress multisite network, potentially granting them administrato...

PoC for CVE-2026-16984

WordPressPrivacy Policy Generat...6.5MEDIUM
Authorization Bypass in Privacy Policy Generator Plugin for WordPress

The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates plugin for WordPress prior to version 3.7.1 lacks crucial authorization checks on a critical REST route. This oversight allows unauthenticated users to access sensitive account information, includin...

PoC for CVE-2026-19094

WordPressTutor Lms5.3MEDIUM
SQL Injection Vulnerability in Tutor LMS Plugin for WordPress

The Tutor LMS plugin for WordPress prior to version 4.0.6 is susceptible to an SQL injection vulnerability. This issue arises due to inadequate validation of values used in constructing database queries. It allows unauthenticated users to manipulate queries to extract sensitive information, speci...

PoC for CVE-2026-14550

WordPressWPcafe5.3MEDIUM
Authorization Bypass in WPCafe Plugin for WordPress

The WPCafe WordPress plugin prior to version 3.0.18 exhibits a significant vulnerability where it fails to implement essential authorization checks during the reservation process via its REST API. This oversight allows unauthenticated users to create reservations without proper validation, using ...

PoC for CVE-2026-13406

WordPressRoyal Addons For Eleme...5.3MEDIUM
Arbitrary Taxonomy Data Disclosure in Royal Addons for Elementor Pl...

The Royal Addons for Elementor plugin prior to version 1.7.1066 is vulnerable to an arbitrary data exposure flaw, where it fails to implement necessary capability or nonce checks. This oversight allows unauthenticated users to gain access to sensitive taxonomy term data, including names and IDs, ...

PoC for CVE-2026-14216

WordPressBooking For Appointmen...5.3MEDIUM
Unauthenticated Access Vulnerability in Booking for Appointments an...

The Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.7 is susceptible to an unauthenticated access vulnerability. This flaw permits an unauthorized user to manipulate the pending notification queue without requiring authentication. As a result, such users can...

PoC for CVE-2026-14212

WordPressBooking For Appointmen...4.7MEDIUM
Account Takeover Vulnerability in Booking for Appointments and Even...

A security flaw in the Booking for Appointments and Events Calendar plugin allows authenticated employees to update the account details of other employees without verifying ownership. This means that any employee with valid access can unjustly change another employee's cabinet password, potential...

PoC for CVE-2026-13404

WordPressRoyal Addons For Eleme...5.3MEDIUM
Unprotected Metadata Manipulation in Royal Addons for Elementor Plugin

The Royal Addons for Elementor WordPress plugin prior to version 1.7.1066 lacks proper capability and ownership checks, relying solely on a publicly accessible nonce. This oversight permits unauthorized users to alter like-counts and visitor-tracking metadata for arbitrary posts, which includes p...

PoC for CVE-2026-13172

WordPressEventin5.3MEDIUM
Access Control Flaw in Eventin WordPress Plugin Allows Unauthorized...

The Eventin WordPress plugin prior to version 4.1.22 is susceptible to an access control vulnerability that permits unauthenticated users to access non-published content. This flaw arises from inadequate restrictions applied to a specific REST API namespace, enabling unauthorized retrieval of dra...

Discovered 15 hours ago

PoC for CVE-2026-80214

LibrenmsLibrenms8.6HIGH
Command Line Injection Vulnerability in LibreNMS Virtualization Dis...

The Virtualization Discovery module of LibreNMS is susceptible to a command line injection vulnerability that allows an authenticated admin user to execute arbitrary commands on the host server. This substantial flaw poses a risk to system integrity and confidentiality, enabling potential attacke...

Discovered 16 hours ago

PoC for CVE-2026-18963

Red HatRed Hat Build Of Keycl...9.1CRITICAL
Authorization Flaw in Keycloak Services by Red Hat

A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...

PoC for CVE-2020-1472

MicrosoftWindows Server Version...🟣 EPSS 100%5.5MEDIUM
Netlogon Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a...

Discovered 17 hours ago

PoC for CVE-2026-32635

@angularCompiler8.6HIGH
Cross-Site Scripting Vulnerability in Angular Runtime and Compiler

A Cross-Site Scripting (XSS) vulnerability exists in the Angular runtime and compiler, allowing attackers to inject malicious scripts via security-sensitive attributes. This issue arises when internationalization is enabled on attributes like 'href' while binding to untrusted user data, circumven...

PoC for CVE-2018-16763

ThedaylightstudioFuel Cms🟣 EPSS 83%9.8CRITICAL
PHP Code Evaluation Vulnerability in FUEL CMS by Daylight Studio

FUEL CMS version 1.4.1 is susceptible to a significant vulnerability that allows for PHP code execution. By manipulating the 'pages/select/' filter parameter or the 'preview/' data parameter, an attacker can execute arbitrary PHP code remotely without authentication. This flaw poses a severe risk...

PoC for CVE-2026-26211

CreativeitemEkushey Project Manage...4.8MEDIUM
Stored XSS in Ekushey Project Manager CRM Affected by Improper Outp...

The Ekushey Project Manager CRM contains a vulnerability that allows stored Cross-Site Scripting (XSS) attacks through improper output encoding of the administrator-configured system name. When this name is displayed on the login page, it is rendered without adequate encoding, permitting any HTML...

PoC for CVE-2026-18963

Red HatRed Hat Build Of Keycl...9.1CRITICAL
Authorization Flaw in Keycloak Services by Red Hat

A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...

Discovered 19 hours ago

PoC for CVE-2026-17532

WordPressSeraphinite Accelerator6.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in Seraphinite Acceler...

The Seraphinite Accelerator plugin for WordPress is susceptible to a reflected cross-site scripting (XSS) vulnerability. This issue arises through improper validation of the 'seraph_accel_prep' parameter in versions 2.29.15 and earlier. Specifically, the CacheExtractPreparePageParams() function f...

PoC for CVE-2026-79912

TotolinkN600r6.9MEDIUM
Command Injection Vulnerability in TOTOLINK N600R Router

A security flaw has been discovered in the TOTOLINK N600R router that allows for a command injection via the ntp_server argument in the getCurrentTime function located in the /cgi-bin/cstecgi.cgi file. This vulnerability enables an attacker to send specially crafted commands remotely, potentially...

PoC for CVE-2026-79911

TotolinkN600r10CRITICAL
Stack-Based Buffer Overflow in TOTOLINK N600R Router

A security vulnerability exists in the TOTOLINK N600R router, specifically in the setSystemConfig function within the CGI Handler component. The flaw arises due to inadequate handling of the Hostname argument, which can lead to a stack-based buffer overflow. This vulnerability allows attackers to...

Discovered 20 hours ago

PoC for CVE-2026-79845

Code-projectsSimple Inventory System6.9MEDIUM
SQL Injection Vulnerability in Simple Inventory System by Code-Proj...

A vulnerability exists in the Simple Inventory System version 1.0, specifically within the edit.php file. By manipulating the ID argument, an attacker can execute SQL injection attacks, allowing unauthorized access and manipulation of the database. This vulnerability can be exploited remotely and...

PoC for CVE-2026-4692

MozillaFirefox9.6CRITICAL
Sandbox Escape Vulnerability in Mozilla Firefox

An issue has been identified in the Responsive Design Mode component of Mozilla Firefox that allows for a sandbox escape. This vulnerability impacts users running versions prior to Firefox 149, as well as Firefox ESR versions below 115.34 and 140.9. The flaw could potentially enable an attacker t...

PoC for CVE-2026-79804

SililawijesingheFood Ordering System6.9MEDIUM
SQL Injection Vulnerability in SililaWijesinghe Food Ordering System

A vulnerability exists within the SililaWijesinghe Food Ordering System relating to improper handling of user input in the /search.php file. An attacker can exploit this flaw by manipulating the search_box parameter, leading to potential SQL injection attacks. Such exploitation can allow unauthor...

Discovered 21 hours ago

PoC for CVE-2026-79793

Code-projectsOnline Shopping System5.3MEDIUM
Reflected XSS Vulnerability in code-projects Online Shopping System

A cross site scripting vulnerability exists in the Online Shopping System 1.0, specifically in the /admin/sumit_form.php file. This vulnerability allows attackers to manipulate the 'Success' argument, which can lead to the execution of malicious scripts in the context of the user's session. The e...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-79792

ZackeesTranscribe-anything6.3MEDIUM
OS Command Injection Vulnerability in Zackees Transcribe-Anything S...

A security flaw has been identified in Zackees Transcribe-Anything up to version 4.1.0, specifically within the function ytdlp_download located in the ytldp_download.py file. This vulnerability allows attackers to manipulate the input URL, potentially leading to OS command injection. The attack c...

PoC for CVE-2026-74932

WordPressWP Fastest Cache7.5HIGH
Host Header Vulnerability in WP Fastest Cache Plugin by WordPress

The WP Fastest Cache plugin for WordPress, prior to version 1.5.1, is susceptible to a vulnerability stemming from the lack of Host header validation. This deficiency allows unauthenticated attackers to manipulate cached pages by embedding references to a malicious server. Consequently, this can ...

Discovered 22 hours ago

PoC for CVE-2026-74970

MozillaFirefox5.4MEDIUM
Site Isolation Flaw in Firefox Graphics Component

A site isolation vulnerability exists in the Graphics component of Mozilla Firefox, which could allow attackers to execute unauthorized actions across different sites. This issue has been addressed in Firefox version 154 and Firefox Extended Support Release (ESR) version 153.1, enhancing user sec...

PoC for CVE-2026-74945

MozillaFirefox6.5MEDIUM
Information Disclosure in Firefox's Graphics: Text Component

A vulnerability within the Graphics: Text component of Firefox allows for unintended information disclosure. This issue could potentially expose sensitive data that should remain protected. Mozilla has addressed this vulnerability in various versions, ensuring enhanced security and privacy for us...

PoC for CVE-2026-6765

MozillaFirefox5.3MEDIUM
Information Disclosure in Firefox and Firefox ESR Products by Mozilla

This vulnerability involves an information disclosure flaw in the Form Autofill component of Firefox and Firefox ESR. When exploited, it can reveal sensitive user data. Mozilla has addressed this issue in versions 150 of Firefox and 140.10 of Firefox ESR, emphasizing the importance of updating to...

PoC for CVE-2026-74943

MozillaFirefox9.8CRITICAL
Use-After-Free Vulnerability in Firefox ImageLib Component

A use-after-free vulnerability has been discovered in the Graphics: ImageLib component of Firefox. This issue may allow an attacker to cause a crash or potentially execute arbitrary code on the affected system. Mozilla has released updates addressing this vulnerability in Firefox version 154, and...

Discovered 23 hours ago

PoC for CVE-2026-80049

AirbytehqAirbyte-platform8.7HIGH
Cross-Workspace Authorization Bypass in Airbyte Platform by Airbyte

The Airbyte Platform has a vulnerability that allows an attacker to bypass workspace authorization checks. This issue arises from the platform's dependency on the caller-supplied workspace ID without proper validation against the actual owning workspace. When handling requests, the system extract...