Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-35250

OracleOracle Vm Virtualbox2.3LOW
Core Vulnerability in Oracle VM VirtualBox by Oracle

An exploitable vulnerability exists within Oracle VM VirtualBox, specifically in its core components. A privileged attacker with access to the infrastructure can exploit this weakness to compromise the functionality of Oracle VM VirtualBox. Successful exploitation may result in a partial denial o...

PoC for CVE-2026-3143

WordPressTotal Upkeep – WordPre...5.3MEDIUM
Unauthorized Data Modification in Total Upkeep Plugin by BoldGrid

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid is susceptible to unauthorized data modification due to a missing capability check on the 'wp_ajax_cli_cancel' function. This flaw affects all versions up to and including 1.17.1, allowing unauthenticated attackers to c...

Discovered 1 hour ago

PoC for CVE-2026-7482

OllamaOllama8.8HIGH
Heap Out-of-Bounds Read Vulnerability in Ollama by Ollama

The Ollama application is susceptible to a heap out-of-bounds read vulnerability within its GGUF model loader. This issue arises when the /api/create endpoint processes an attacker-defined GGUF file where the tensor offset and size exceed the file’s actual length. During quantization, the server ...

PoC for CVE-2026-8125

Code-projectsSimple Chat System5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Simple Chat System by ...

A vulnerability has been identified in Code-Projects Simple Chat System version 1.0, specifically affecting the 'sendMessage.php' file. This flaw arises from improper handling of argument types and lengths, allowing attackers to manipulate parameters leading to SQL injection vulnerabilities. Expl...

Discovered 2 hours ago

PoC for CVE-2026-8124

GPACGpac4.8MEDIUM
Resource Allocation Vulnerability in GPAC by GPAC

A vulnerability in GPAC's sidx_box_read function within src/isomedia/box_code_base.c has been identified, which enables local attackers to manipulate resource allocation. This flaw could potentially be exploited to disrupt the services offered by affected systems. To mitigate risks, it is recomme...

PoC for CVE-2026-8123

Open5GSOpen5gs5.3MEDIUM
Denial of Service Vulnerability in Open5GS NSSF by Open5GS

A vulnerability exists in Open5GS's NSSF component, specifically within the ogs_sbi_discovery_option_add_snssais function in the /lib/sbi/message.c file. This flaw enables attackers to execute a denial of service attack remotely, potentially disrupting the service for users. The issue has been pu...

PoC for CVE-2026-8122

Open5GSOpen5gs5.3MEDIUM
Denial of Service Vulnerability in Open5GS NSSF Component

A vulnerability has been identified in the Open5GS project, specifically within the NSSF component where the function ogs_sbi_discovery_option_add_service_names is located. This flaw can lead to a denial of service (DoS), allowing remote attackers to exploit the situation. Although the issue was ...

PoC for CVE-2026-8121

Open5GSOpen5gs5.3MEDIUM
Denial of Service in Open5GS NSSF Component by Open5GS

A vulnerability has been identified in Open5GS NSSF up to version 2.7.7, specifically within the function ogs_sbi_parse_plmn_list located in the /lib/sbi/conv.c file. This flaw enables remote attackers to exploit the affected component, resulting in denial of service conditions. The issue was pre...

Discovered 3 hours ago

PoC for CVE-2026-8120

Open5GSOpen5gs5.3MEDIUM
Denial of Service Vulnerability in Open5GS NSSF Component

A vulnerability exists in the Open5GS NSSF component, specifically in the function nssf_nnrf_nsselection_handle_get_from_amf_or_vnssf located in /src/nssf/nnssf-handler.c. This flaw allows a remote attacker to conduct a denial of service attack, potentially disrupting system availability. Despite...

PoC for CVE-2026-8119

Open5GSOpen5gs4.8MEDIUM
Denial of Service Vulnerability in Open5GS NSSF by Open5GS

A vulnerability has been identified in Open5GS NSSF impacting versions up to 2.7.7. The issue lies within the ogs_sbi_stream_find_by_id function in the nghttp2-server.c library, which when manipulated, can lead to a denial of service. This attack necessitates local access, and exploitation may re...

PoC for CVE-2026-3844

WordPressBreeze Cache🟣 EPSS 13%9.8CRITICAL
Arbitrary File Upload Vulnerability in Breeze Cache Plugin for Word...

The Breeze Cache plugin for WordPress has a security flaw that allows unauthenticated attackers to perform arbitrary file uploads. This vulnerability is due to inadequate file type validation in the 'fetch_gravatar_from_remote' function. The risk is present in all versions up to 2.4.4, specifical...

PoC for CVE-2026-5615

GivanzVvvebjs5.3MEDIUM
Cross-Site Scripting Vulnerability in givanz Vvvebjs File Upload

A vulnerability has been identified in givanz Vvvebjs prior to version 2.0.5, specifically within the file upload functionality of the component File Upload Endpoint. This weakness stems from improper handling of the 'uploadAllowExtensions' parameter, which opens the door to cross-site scripting ...

PoC for CVE-2026-40003

ZteZx297520v3 Bootrom5.1MEDIUM
Arbitrary Memory Write Vulnerability in ZTE ZX297520V3 BootROM

The ZTE ZX297520V3 BootROM is susceptible to an arbitrary memory write vulnerability that can be exploited via USB. This weakness stems from the lack of proper validation for target addresses during USB download mode, allowing attackers to manipulate memory locations within the BootROM runtime. B...

PoC for CVE-2025-6440

WordPressWooCommerce Designer Pro9.8CRITICAL
Arbitrary File Upload Vulnerability in WooCommerce Designer Pro Plu...

The WooCommerce Designer Pro plugin for WordPress has a significant vulnerability that allows unauthenticated attackers to perform arbitrary file uploads. This issue arises from inadequate file type validation in the 'wcdp_save_canvas_design_ajax' function. If exploited, this can lead to unauthor...

PoC for CVE-2026-8116

Huangjunsen0406Xiaozhi-mcphub5.3MEDIUM
Path Traversal Vulnerability in huangjunsen0406 xiaozhi-mcphub

A vulnerability has been discovered in the huangjunsen0406 xiaozhi-mcphub project, specifically impacting the file src/controllers/dxtController.ts. This weakness allows an attacker to manipulate the argument manifest.name, leading to path traversal incidents. The exploit, which poses a significa...

Discovered 4 hours ago

PoC for CVE-2026-8115

GyoridavidShort-video-maker6.9MEDIUM
Path Traversal Vulnerability in gyoridavid Short Video Maker REST API

A security flaw in the gyoridavid short-video-maker, up to version 1.3.4, allows attackers to exploit the REST API component. The issue arises from improper handling of user input, specifically the req.params.tmpFile argument, resulting in unauthorized file access through path traversal. This vul...

Discovered 5 hours ago

PoC for CVE-2026-8114

JeecgJeecgboot5.3MEDIUM
SQL Injection Vulnerability in JeecgBoot Software

A SQL injection vulnerability has been discovered in the JeecgBoot application affecting versions up to 3.9.1. This vulnerability resides in the functionality of the file /sys/dict/loadTreeData within the JSON Object Handler, allowing attackers to manipulate input conditions. The exploit can be e...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 6 hours ago

PoC for CVE-2026-8113

8421bitMiniclaw5.3MEDIUM
Path Traversal Vulnerability in 8421bit MiniClaw Affected by Execut...

A path traversal vulnerability has been identified in the 8421bit MiniClaw, specifically within the isPathInside function located in src/kernel.ts as part of the executeSkillScript component. This flaw allows an attacker to manipulate file paths, potentially leading to unauthorized access to crit...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-8112

8421bitMiniclaw5.3MEDIUM
OS Command Injection Vulnerability in 8421bit MiniClaw

A remote OS command injection vulnerability exists in the 8421bit MiniClaw due to improper handling of data in the executeCognitivePulse function found in src/kernel.ts. This flaw allows attackers to execute arbitrary commands on the system, posing a severe risk. The vulnerability can be exploite...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-8098

Code-projectsFeedback System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Feedback System 1.0

A security vulnerability has been identified in the Code-Projects Feedback System 1.0, specifically affecting an unprotected function in the /admin/checklogin.php file. By manipulating the email parameter, attackers can execute malicious SQL queries, allowing remote exploitation of the system. Th...

Discovered 7 hours ago

PoC for CVE-2026-8097

CodeastroOnline Classroom5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom by CodeAstro

A security vulnerability has been identified in CodeAstro's Online Classroom 1.0 that enables SQL injection through improper handling of user inputs in the /askquery.php file. This flaw allows attackers to manipulate the 'squeryx' argument, which could lead to unauthorized data access or manipula...

PoC for CVE-2026-8088

OsgeoGdal4.8MEDIUM
Out-of-Bounds Read Vulnerability in OSGeo GDAL Software

A weakness exists in the OSGeo GDAL library, particularly within the GDfieldinfo function of the GDapi.c file, which may allow an out-of-bounds read. This vulnerability can be exploited locally with a specific manipulation on affected versions. Publicly available exploits highlight the urgency fo...

Discovered 8 hours ago

PoC for CVE-2026-8087

OsgeoGdal4.8MEDIUM
Heap-based Buffer Overflow in OSGeo GDAL Affects Multiple Versions

A vulnerability in OSGeo GDAL's GDnentries function, located in the GDapi.c file, has been identified that could lead to a heap-based buffer overflow. This issue arises from improper handling of the DataFieldName argument, opening the door for local attackers to exploit the flaw. The exploit has ...

PoC for CVE-2026-8086

OsgeoGdal4.8MEDIUM
Heap-based Buffer Overflow in OSGeo GDAL Affecting Versions up to 3...

A vulnerability exists in OSGeo GDAL affecting the SWnentries function located in the SWapi.c file. This issue arises when an attacker manipulates the DimensionName argument, potentially leading to a heap-based buffer overflow. The attack requires local access, and exploit code for this vulnerabi...

PoC for CVE-2026-8084

OsgeoGdal4.8MEDIUM
Out-of-Bounds Read Vulnerability in OSGeo GDAL HDF-EOS Grid File Ha...

A vulnerability has been identified in OSGeo GDAL affecting the HDF-EOS Grid File Handler. Specifically, the memmove function in the file frmts/hdf4/hdf-eos/SWapi.c can lead to out-of-bounds reads. This vulnerability necessitates local execution for exploitation and has been publicly disclosed. U...

PoC for CVE-2026-8084

OsgeoGdal4.8MEDIUM
Out-of-Bounds Read Vulnerability in OSGeo GDAL HDF-EOS Grid File Ha...

A vulnerability has been identified in OSGeo GDAL affecting the HDF-EOS Grid File Handler. Specifically, the memmove function in the file frmts/hdf4/hdf-eos/SWapi.c can lead to out-of-bounds reads. This vulnerability necessitates local execution for exploitation and has been publicly disclosed. U...

Discovered 9 hours ago

PoC for CVE-2026-8083

SourcecodesterPharmacy Sales And Inv...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

A security flaw has been identified in the SourceCodester Pharmacy Sales and Inventory System, specifically within the file /ajax.php when executing the action save_user. This vulnerability arises from improper handling of the user ID parameter, allowing an attacker to execute SQL injection attac...

PoC for CVE-2026-8081

Router-for-meCliproxyapi5.3MEDIUM
Server-Side Request Forgery in Router-for-Me CLIProxyAPI 6.9.29

A server-side request forgery (SSRF) vulnerability has been identified in Router-for-Me's CLIProxyAPI version 6.9.29, specifically targeting the internal/api/handlers/management/api_tools.go file. This issue arises from inadequate validation of the 'url' argument, allowing an attacker to manipula...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 11 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 14 hours ago

PoC for CVE-2026-40897

JosdejongMathjs8.8HIGH
JavaScript Math Library Vulnerability in Math.js Affects Users

A significant vulnerability has been identified in Math.js, a popular library for mathematics in JavaScript and Node.js. From versions 13.1.1 to earlier than 15.2.0, this vulnerability enables attackers to execute arbitrary JavaScript through the library's expression parser. Applications utilizin...

Discovered 15 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 18 hours ago

PoC for CVE-2025-0133

Palo Alto NetworksCloud Ngfw2.7LOW
Reflected XSS Vulnerability in Palo Alto Networks GlobalProtect PAN-OS

A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks' GlobalProtect gateway and portal features allows attackers to execute malicious JavaScript in the authenticated browser session of Captive Portal users. When users click on specifically crafted links, they may unknowingly...

Discovered 19 hours ago

PoC for CVE-2026-0073

GoogleAndroid8.8HIGH
Logic Error in Wireless ADB Authentication in Android Products

A significant logic error in the adbd_tls_verify_cert function of auth.cpp in various Android versions permits a bypass of the wireless ADB mutual authentication process. This flaw can lead to unauthorized remote code execution by exploiting the vulnerability as the shell user without requiring a...

PoC for CVE-2026-27944

0xjackyNginx-ui9.8CRITICAL
Authentication Bypass in Nginx UI Affects Nginx Web Server

Nginx UI, a web interface for the Nginx web server, has a critical security flaw where the /api/backup endpoint is accessible without authentication. This vulnerability allows unauthenticated attackers to retrieve a complete system backup that includes sensitive information such as user credentia...

Discovered 20 hours ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 64%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-0300

Palo Alto NetworksCloud Ngfw🟣 EPSS 15%8.7HIGH
Buffer Overflow Vulnerability in Palo Alto Networks User-ID™ Authen...

A buffer overflow vulnerability exists within the User-ID™ Authentication Portal of Palo Alto Networks PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by manipulating specially crafted packets. To miti...

Discovered 23 hours ago

PoC for CVE-2026-23918

ApacheApache Http Server8.8HIGH
Double Free and Remote Code Execution Vulnerability in Apache HTTP ...

A double free vulnerability has been identified in Apache HTTP Server that may lead to remote code execution, particularly concerning the HTTP/2 protocol. This issue affects version 2.4.66, and it is crucial for users to upgrade to version 2.4.67 to mitigate any potential security risks associate...

Discovered 1 day ago

PoC for CVE-2026-0073

GoogleAndroid8.8HIGH
Logic Error in Wireless ADB Authentication in Android Products

A significant logic error in the adbd_tls_verify_cert function of auth.cpp in various Android versions permits a bypass of the wireless ADB mutual authentication process. This flaw can lead to unauthorized remote code execution by exploiting the vulnerability as the shell user without requiring a...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-23918

ApacheApache Http Server8.8HIGH
Double Free and Remote Code Execution Vulnerability in Apache HTTP ...

A double free vulnerability has been identified in Apache HTTP Server that may lead to remote code execution, particularly concerning the HTTP/2 protocol. This issue affects version 2.4.66, and it is crucial for users to upgrade to version 2.4.67 to mitigate any potential security risks associate...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-8033

PicotronicaE-clinic Healthcare Sy...6.9MEDIUM
Information Disclosure Vulnerability in PicoTronica e-Clinic Health...

A vulnerability in the PicoTronica e-Clinic Healthcare System ECHS 5.7 has been identified, specifically affecting an undisclosed function of the file /cdemos/echs/api/v2/ within the Response Header Handler component. This flaw allows attackers to exploit the system remotely, leading to unauthori...

PoC for CVE-2026-32710

MariadbServer8.6HIGH
Unauthorized Access Vulnerability in MariaDB Server

An issue has been identified in the JSON_SCHEMA_VALID() function of MariaDB Server, which is derived from MySQL. This vulnerability allows authenticated users to crash versions 11.4 prior to 11.4.10 and 11.8 prior to 11.8.6 of MariaDB server. While under specific conditions, it could lead to remo...

PoC for CVE-2025-70149

CodeAstroMembership Management ...9.8CRITICAL
SQL Injection Vulnerability in CodeAstro Membership Management System

The CodeAstro Membership Management System version 1.0 is prone to an SQL Injection vulnerability via the ID parameter in print_membership_card.php. This flaw allows attackers to manipulate database queries by injecting arbitrary SQL code, potentially leading to unauthorized data access and manip...

PoC for CVE-2026-8032

PicotronicaE-clinic Healthcare Sy...6.9MEDIUM
Remote Credential Exposure in PicoTronica e-Clinic Healthcare System

A significant security flaw has been identified in the PicoTronica e-Clinic Healthcare System ECHS version 5.7, specifically linked to the /cdemos/echs/priv/echs.js file. This vulnerability allows an attacker to manipulate the ADMIN_KEY argument, leading to the exposure of hard-coded credentials....