Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2025-21298

MicrosoftWindows 10 Version 18099.8CRITICAL
Windows OLE Remote Code Execution Vulnerability in Microsoft Products

The Windows OLE Remote Code Execution Vulnerability allows an attacker to execute arbitrary code on an affected system via maliciously crafted OLE objects. Successful exploitation could enable attackers to install programs; view, change, or delete data; or create new accounts with full user right...

PoC for CVE-2021-1732

MicrosoftWindows 10 Version 18037.8HIGH
Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability

Discovered 3 hours ago

PoC for CVE-2024-6387

Red HatRed Hat Enterprise Lin...8.1HIGH
Signal Handler Race Condition in OpenSSH's Server

A regression vulnerability discovered in OpenSSH's server (sshd) involves a race condition affecting the handling of signals. This vulnerability allows an attacker to exploit the sshd service by failing to authenticate within a specified timeframe. If successfully triggered, this flaw could alter...

Discovered 5 hours ago

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 97%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

Discovered 18 hours ago

PoC for CVE-2024-9796

WP-Advanced-SearchWP-advanced-search9.8CRITICAL
Unauthorized SQL Injection Attacks via T Parameter in WP-Advanced-S...

The WP-Advanced-Search WordPress plugin, prior to version 3.3.9.2, contains a vulnerability that arises from improper handling of user input in the t parameter. This lack of sanitization and escaping before usage in SQL statements allows unauthenticated users to execute arbitrary SQL queries. As ...

Discovered 19 hours ago

PoC for CVE-2025-0581

CampcodesSchool Management Soft...5.3MEDIUM
Cross Site Scripting Vulnerability in CampCodes School Management S...

A cross site scripting vulnerability has been identified in version 1.0 of CampCodes School Management Software. The issue is found within the Chat History component, specifically in the /chat/group/send file. An attacker can manipulate the 'message' argument to execute malicious scripts remotely...

PoC for CVE-2025-0580

ShiprocketShiprocket Module6.3MEDIUM
Improper Authorization in Shiprocket Module for OpenCart

A vulnerability exists in the Shiprocket Module for OpenCart that affects its REST API functionality, specifically in the handling of the 'contentHash' argument within the /index.php?route=extension/module/rest_api&action=getOrders endpoint. This flaw can potentially lead to improper authorizatio...

PoC for CVE-2025-0579

OpenCartShiprocket Module6.9MEDIUM
SQL Injection Vulnerability in Shiprocket Module for OpenCart

A SQL injection vulnerability has been identified in the Shiprocket Module for OpenCart, specifically within the REST API functionality exposed through /index.php?route=extension/shiprocket/module/restapi. The issue stems from improper handling of the 'x-username' argument, allowing for remote ex...

Discovered 22 hours ago

PoC for CVE-2024-41570

Havoc 2Havoc9.8CRITICAL
Arbitrary Network Traffic Execution via SSRF in Havoc 2.0.7

An unauthenticated server-side request forgery (SSRF) vulnerability in the demon callback handling of Havoc 2 0.7 allows attackers to exploit the system by sending arbitrary network traffic originating from the team server. This flaw enables attackers to make requests from the server to any inter...

Discovered 2 days ago

PoC for CVE-2025-0566

TendaAc158.7HIGH
Stack-based Buffer Overflow in Tenda AC15 Router

The Tenda AC15 router suffers from a stack-based buffer overflow vulnerability in the formSetDevNetName function found in the /goform/SetDevNetName file. This flaw arises from improper handling of the 'mac' argument, allowing attackers to exploit the vulnerability remotely. Once publicly disclose...

PoC for CVE-2025-0565

ZZCMSZzcms6.9MEDIUM
SQL Injection Vulnerability in ZZCMS 2023

A SQL injection vulnerability exists in the ZZCMS 2023 product, specifically within the /index.php file. This weakness arises from improper validation of the 'id' argument, allowing attackers to manipulate SQL queries and potentially gain unauthorized access to sensitive data. Exploitation can be...

PoC for CVE-2025-0564

Code-projectsFantasy-cricket6.9MEDIUM
SQL Injection Vulnerability in Fantasy-Cricket by Code-Projects

A vulnerability exists in the Fantasy-Cricket application, specifically in the /authenticate.php file. This flaw allows attackers to manipulate the 'uname' parameter, leading to SQL injection attacks. The nature of this vulnerability enables remote exploitation, exposing the application to signif...

PoC for CVE-2024-13375

SpoonthemesAdifier System9.8CRITICAL
Privilege Escalation Vulnerability in Adifier System Plugin for Wor...

The Adifier System plugin for WordPress has a vulnerability that allows for privilege escalation through account takeover. This issue arises from the plugin's failure to properly authenticate users prior to permitting updates to sensitive account details, including passwords. As a result, malicio...

PoC for CVE-2025-0560

CampcodesSchool Management Soft...5.1MEDIUM
Cross-Site Scripting Vulnerability in CampCodes School Management S...

A cross-site scripting vulnerability in CampCodes School Management Software version 1.0 affects the Photo Gallery Page component. The issue arises from inadequate input validation in the '/photo-gallery' function, allowing attackers to manipulate the argument 'Description'. This can lead to the ...

PoC for CVE-2025-0559

CampcodesSchool Management Soft...5.1MEDIUM
Cross Site Scripting in Campcodes School Management Software

A vulnerability has been discovered in Campcodes School Management Software, specifically within the Create Id Card Page component found at the /create-id-card path. This flaw allows for the manipulation of the ID Card Title argument, leading to a cross site scripting (XSS) attack. Attackers may ...

PoC for CVE-2025-0558

TduckcloudTduck-platform5.3MEDIUM
SQL Injection Vulnerability in TDuckCloud tduck-platform

A vulnerability has been identified in the TDuckCloud tduck-platform which allows attackers to perform SQL injection through the QueryProThemeRequest function. This flaw arises from improper manipulation of the color argument found in the file src/main/java/com/tduck/cloud/form/request/QueryProTh...

Discovered 3 days ago

PoC for CVE-2024-9020

WordPressList Category Posts
Stored Cross-Site Scripting Vulnerability in List Category Posts Pl...

The List Category Posts Plugin for WordPress, prior to version 0.90.3, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises because the plugin fails to properly validate and escape certain shortcode attributes when rendering pages or posts that incorporate these ...

PoC for CVE-2024-57727

SimpleHelpSimpleHelp Remote Supp...7.5HIGH
Path Traversal Vulnerabilities in SimpleHelp Remote Support Software

The SimpleHelp Remote Support Software version 5.5.7 and earlier is susceptible to multiple path traversal vulnerabilities. These vulnerabilities allow unauthenticated remote attackers to exploit the system by crafting specific HTTP requests. Through this exploitation, attackers can download arbi...

PoC for CVE-2022-34169

ApacheApache Xalan-j7.5HIGH
Apache Xalan Java XSLT library is vulnerable to an integer truncati...

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 o...

PoC for CVE-2025-0541

CodezipsGym Management System5.3MEDIUM
SQL Injection Vulnerability in Codezips Gym Management System by Co...

A SQL injection vulnerability exists in the Codezips Gym Management System 1.0, specifically affecting the /dashboard/admin/edit_member.php file. This flaw allows attackers to manipulate the 'name' argument, potentially leading to unauthorized database access. Exploitation can occur remotely, and...

PoC for CVE-2024-43468

MicrosoftMicrosoft Configuratio...9.8CRITICAL
Remote Code Execution Vulnerability Affects Microsoft Configuration...

The vulnerability in Microsoft Configuration Manager allows remote code execution, potentially enabling attackers to gain control over affected systems. This security flaw can be exploited if an attacker sends a specially crafted request to the vulnerable application, leading to unauthorized exec...

PoC for CVE-2025-0540

ItsourcecodeTailoring Management S...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Tailoring Management Sy...

A vulnerability exists within the itsourcecode Tailoring Management System 1.0, specifically in the expadd.php file. This flaw is due to insufficient validation of the 'expcat' argument, which allows for SQL injection attacks. As a result, attackers can manipulate the query structure, potentially...

PoC for CVE-2025-0538

Code-projectsTourism Management System5.3MEDIUM
Cross-Site Scripting Vulnerability in Code-Projects Tourism Managem...

A Cross-Site Scripting (XSS) vulnerability has been identified in the Tourism Management System version 1.0, specifically within the /admin/manage-pages.php file. This vulnerability arises from improper handling of the 'pgedetails' argument, which allows attackers to inject malicious scripts. Suc...

PoC for CVE-2025-0538

Code-projectsTourism Management System5.3MEDIUM
Cross-Site Scripting Vulnerability in Code-Projects Tourism Managem...

A Cross-Site Scripting (XSS) vulnerability has been identified in the Tourism Management System version 1.0, specifically within the /admin/manage-pages.php file. This vulnerability arises from improper handling of the 'pgedetails' argument, which allows attackers to inject malicious scripts. Suc...

PoC for CVE-2025-0537

Code-projectsCar Rental Management ...5.1MEDIUM
Cross-Site Scripting Vulnerability in Code-Projects Car Rental Mana...

A vulnerability has been discovered in the Car Rental Management System version 1.0 developed by code-projects. Specifically, this issue resides in the file /admin/manage-pages.php, where improper handling of the 'pgdetails' argument allows for cross-site scripting (XSS) attacks. When exploited, ...

PoC for CVE-2025-0537

Code-projectsCar Rental Management ...5.1MEDIUM
Cross-Site Scripting Vulnerability in Code-Projects Car Rental Mana...

A vulnerability has been discovered in the Car Rental Management System version 1.0 developed by code-projects. Specifically, this issue resides in the file /admin/manage-pages.php, where improper handling of the 'pgdetails' argument allows for cross-site scripting (XSS) attacks. When exploited, ...

PoC for CVE-2025-0536

1000 ProjectsAttendance Tracking Ma...5.3MEDIUM
SQL Injection Vulnerability in Attendance Tracking Management Syste...

A vulnerability has been identified in the Attendance Tracking Management System, specifically within the /admin/edit_action.php file. This flaw allows for SQL injection through the manipulation of the attendance_id parameter. Attackers can exploit this vulnerability remotely, potentially comprom...

PoC for CVE-2025-0535

CodezipsGym Management System5.3MEDIUM
SQL Injection Vulnerability in Codezips Gym Management System

A vulnerability has been identified within the Codezips Gym Management System version 1.0, specifically impacting the file /dashboard/admin/edit_mem_submit.php. The issue arises from improper handling of the uid parameter, which can lead to SQL injection attacks. Malicious actors can exploit this...

PoC for CVE-2025-0534

1000 ProjectsCampaign Management Sy...6.9MEDIUM
SQL Injection Vulnerability in 1000 Projects Campaign Management Sy...

A SQL injection vulnerability has been identified in the 1000 Projects Campaign Management System Platform for Women version 1.0, specifically within the login functionality of the file /Code/loginnew.php. The flaw allows for manipulation of the Username argument, enabling attackers to execute ar...

PoC for CVE-2025-0533

1000 ProjectsCampaign Management Sy...6.9MEDIUM
SQL Injection Vulnerability in 1000 Projects Campaign Management Sy...

A vulnerability exists in the 1000 Projects Campaign Management System Platform for Women 1.0, specifically in the file /Code/sc_login.php. An attacker can exploit this vulnerability through the manipulation of the 'uname' argument, allowing for SQL injection attacks that can be executed remotely...

PoC for CVE-2025-0532

CodezipsGym Management System5.3MEDIUM
SQL Injection Vulnerability in Codezips Gym Management System by Co...

A vulnerability in the Codezips Gym Management System, specifically within the /dashboard/admin/new_submit.php file, allows for SQL injection through improper handling of the m_id argument. This flaw can be exploited remotely by attackers, potentially compromising the integrity and confidentialit...

PoC for CVE-2025-0531

Code-projectsChat System5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Chat System by Code-Pr...

A SQL injection vulnerability exists in the Code-Projects Chat System 1.0, specifically in the user input processing of /user/leaveroom.php. By manipulating the 'id' parameter, an attacker can execute unauthorized SQL queries, potentially compromising the underlying database. This vulnerability c...

PoC for CVE-2025-0530

Code-projectsJob Recruitment5.3MEDIUM
Cross-Site Scripting Vulnerability in Job Recruitment by Code-Projects

A cross-site scripting vulnerability exists in the Job Recruitment 1.0 application by Code-Projects, specifically in the handling of user input in the file /_parse/_feedback_system.php. This issue allows remote attackers to inject malicious scripts, potentially compromising user data and performi...

PoC for CVE-2025-0529

Code-projectsTrain Ticket Reservati...4.8MEDIUM
Stack-based Buffer Overflow in Login Form of Train Ticket Reservati...

A stack-based buffer overflow vulnerability exists in the Train Ticket Reservation System 1.0, specifically in the Login Form component. This issue arises when the 'username' argument is manipulated by an attacker, allowing for potential exploitation. The attack must be conducted locally, thus li...

PoC for CVE-2025-0528

TendaAc88.6HIGH
Command Injection Vulnerability in Tenda AC8, AC10 and AC18 Routers

A command injection vulnerability exists in Tenda AC8, AC10, and AC18 routers due to improper handling of the /goform/telnet functionality by the HTTP Request Handler. This flaw allows an attacker to execute arbitrary commands on the affected devices remotely, potentially gaining unauthorized acc...

PoC for CVE-2025-0527

Code-projectsAdmission Management S...6.9MEDIUM
SQL Injection Vulnerability in Admission Management System by Code-...

A significant SQL injection vulnerability has been identified in the Admission Management System v1.0, specifically affecting the /signupconfirm.php file. The vulnerability arises from improper handling of the 'in_eml' parameter, enabling attackers to manipulate SQL queries remotely. This exploit...

Discovered 4 days ago

PoC for CVE-2024-9474

Palo Alto NetworksCloud Ngfw🟣 EPSS 97%7.2HIGH
Palo Alto Networks PAN-OS Privilege Escalation Vulnerability Affect...

A privilege escalation vulnerability exists in Palo Alto Networks PAN-OS software, allowing an administrator with access to the management web interface to execute actions on the firewall with heightened root privileges. This could potentially lead to unauthorized control and management of the fi...

PoC for CVE-2025-0282

IvantiConnect Secure🟣 EPSS 15%9CRITICAL
Stack-Based Buffer Overflow in Ivanti Connect Secure and Policy Secure

A stack-based buffer overflow vulnerability exists in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways, prior to designated versions. This flaw allows a remote unauthenticated attacker to execute arbitrary code on the affected systems, posing significant risks to s...

PoC for CVE-2022-31814

NetgatePfblockerng🟣 EPSS 97%9.8CRITICAL
Netgate - Pfblockerng

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

PoC for CVE-2019-5029

Exhibitor ProjectExhibitor🟣 EPSS 68%9.8CRITICAL
Exhibitor Project - Exhibitor

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker...

PoC for CVE-2022-40684

FortinetFortinet FortiOS, Fort...🟣 EPSS 97%9.8CRITICAL
Fortinet - Fortinet FortiOS, Fortiproxy, Fortiswitchmanager

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform ope...

PoC for CVE-2023-25136

OpensshOpenssh6.5MEDIUM
Openssh

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third...

Discovered 5 days ago

PoC for CVE-2025-21385

MicrosoftMicrosoft Purview8.8HIGH
Server-Side Request Forgery Vulnerability in Microsoft Purview

A Server-Side Request Forgery (SSRF) vulnerability exists in Microsoft Purview, enabling an authorized attacker to exploit the application to disclose sensitive information over a network. This flaw can allow unauthorized access to internal resources, leading to potential data leakage and comprom...

PoC for CVE-2025-0282

IvantiConnect Secure🟣 EPSS 15%9CRITICAL
Stack-Based Buffer Overflow in Ivanti Connect Secure and Policy Secure

A stack-based buffer overflow vulnerability exists in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways, prior to designated versions. This flaw allows a remote unauthenticated attacker to execute arbitrary code on the affected systems, posing significant risks to s...

PoC for CVE-2025-0492

D-linkDir-823x8.7HIGH
Null Pointer Dereference in D-Link DIR-823X

A vulnerability exists in the D-Link DIR-823X models 240126 and 240802 due to improper handling of a function resulting in a null pointer dereference. This flaw allows remote attackers to exploit the device, potentially leading to a denial of service. Awareness of this vulnerability is crucial as...

PoC for CVE-2025-0491

Fanli2012Native-PHP-cms5.3MEDIUM
SQL Injection Vulnerability in Fanli2012 Native-PHP-CMS Product

A SQL injection vulnerability exists in a specific function of the Fanli2012 native-php-cms version 1.0, located in the file /fladmin/cat_dodel.php. By manipulating the 'id' argument, attackers can execute arbitrary SQL queries against the database. This flaw allows for remote exploitation, posin...

PoC for CVE-2025-0490

Fanli2012Native-PHP-cms5.3MEDIUM
SQL Injection Vulnerability in Fanli2012 Native-PHP-CMS 1.0

A SQL injection vulnerability exists in the Fanli2012 native-php-cms version 1.0, specifically affecting the processing of the file /fladmin/article_dodel.php. The flaw allows an attacker to manipulate the 'id' argument, enabling unauthorized database operations. This vulnerability can be exploit...

PoC for CVE-2025-0489

Fanli2012Native-PHP-cms5.3MEDIUM
SQL Injection Vulnerability in Fanli2012 Native-PHP-CMS

A SQL injection vulnerability has been discovered in Fanli2012's native-php-cms version 1.0, specifically in the /fladmin/friendlink_dodel.php file. The issue arises from improper handling of the 'id' parameter, which allows attackers to manipulate SQL queries. This flaw can be exploited remotely...

PoC for CVE-2025-0488

Fanli2012Native-PHP-cms5.3MEDIUM
SQL Injection Vulnerability in Fanli2012 Native-PHP-CMS 1.0

A security vulnerability has been identified in the Fanli2012 native-php-cms version 1.0, located specifically in the product_list.php file. This issue allows attackers to manipulate the 'cat' argument, potentially leading to SQL injection attacks. The vulnerability can be exploited remotely, mak...

PoC for CVE-2025-0487

Fanli2012Native-PHP-cms5.3MEDIUM
SQL Injection Vulnerability in Fanli2012 Native-PHP-CMS 1.0

A security flaw has been identified in Fanli2012 native-php-cms version 1.0, specifically affecting the functionality of the file /fladmin/cat_edit.php. The vulnerability stems from improper handling of the 'id' parameter, allowing for SQL injection attacks that can be executed remotely. Since de...