Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 4 hours ago

PoC for CVE-2026-19975

AzuriomCms2.3LOW
Time-of-Check Time-of-Use Vulnerability in Azuriom CMS Money Transf...

A vulnerability has been discovered in Azuriom CMS versions up to 1.2.12, affecting the money transfer functionality in the ProfileController. This weakness allows a remote attacker to manipulate the time-of-check time-of-use condition, potentially leading to unauthorized financial operations. Th...

Discovered 5 hours ago

PoC for CVE-2026-59827

MetabaseMetabase9.9CRITICAL
Deserialization Flaw in Metabase's H2 Database Connection

Metabase, an open-source business intelligence and embedded analytics tool, suffers from a deserialization vulnerability in versions prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4. When configured with an H2 database connection, including the default sample database, this flaw permits authenti...

PoC for CVE-2025-57819

FreepbxEndpoint🟣 EPSS 85%10CRITICAL
Unauthenticated Access Vulnerability in FreePBX by Sangoma Technolo...

FreePBX, an open-source web-based GUI, suffers from a vulnerability that permits unauthenticated users to gain access to the FreePBX Administrator interface. This is primarily due to insufficient sanitization of user-provided data. The flaw can lead to unauthorized database manipulation and may a...

Discovered 7 hours ago

PoC for CVE-2026-92921

CjbiAdmin36.9MEDIUM
Weak Password Hashing Vulnerability in admin3 Product by cjbi

The admin3 product by cjbi is vulnerable due to its reliance on single-round MD5 hashing for storing user account passwords. This method utilizes only the username as the salt and lacks a proper key derivation function, making it susceptible to offline dictionary and brute-force attacks. Attacker...

PoC for CVE-2026-92920

CjbiAdmin35.3MEDIUM
Session Management Flaw in Admin3 Product by CJBI

The Admin3 product by CJBI contains a session management flaw where user sessions are not invalidated upon account deactivation. This allows attackers to maintain their previous authenticated status, thereby accessing resources with the user's original permissions. The vulnerability arises from t...

PoC for CVE-2026-92918

CjbiAdmin38.7HIGH
Session Token Disclosure in admin3 by WeTech

In admin3 versions up to 3.0.0, user session tokens are stored in the audit log's event body during UserLoggedIn events. This vulnerability allows attackers with log:view permissions to access the JSON response from the '/logs' endpoint, enabling them to extract session tokens. These tokens can b...

PoC for CVE-2026-92919

CjbiAdmin37.2HIGH
Path Traversal Vulnerability in admin3 Product by CJBI

The admin3 product, through version 3.0.0, is susceptible to a path traversal vulnerability that allows authenticated users to exploit unsanitized client-supplied filenames within the upload handler. On Windows deployments, this weakness enables attackers to use dot-dot path segments to navigate ...

Discovered 9 hours ago

PoC for CVE-2025-8061

LenovoDispatcher 3.0 Driver7.3HIGH
Insufficient Access Control in Lenovo Dispatcher Drivers for Consum...

An insufficient access control vulnerability was identified in the Lenovo Dispatcher drivers (versions 3.0 and 3.1) used in certain Lenovo consumer notebooks. This vulnerability could potentially allow an authenticated local user to execute arbitrary code with elevated privileges, compromising th...

Discovered 11 hours ago

PoC for CVE-2025-32432

CraftcmsCms🟣 EPSS 100%10CRITICAL
Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic

Craft CMS, a customizable content management system, has a remote code execution vulnerability present in specific versions. Attackers could exploit this flaw to execute arbitrary code on the server, posing a significant security risk. The affected versions span from 3.0.0-RC1 to just before 3.9....

Discovered 12 hours ago

PoC for CVE-2026-87831

WordPressCheckout Field Manager...4.3MEDIUM
Improper Attachment Deletion in WooCommerce Checkout Manager Plugin

The Checkout Field Manager for WooCommerce plugin, prior to version 7.9.7, contains a flaw that allows authenticated users to delete arbitrary media attachments belonging to other users due to inadequate validation of ownership before an attachment is deleted. This vulnerability can be exploited ...

PoC for CVE-2026-87829

WordPressCheckout Field Manager...4.3MEDIUM
Improper Attachment Deletion in WooCommerce Checkout Field Manager ...

The Checkout Field Manager for WooCommerce plugin prior to version 7.9.7 contains a security flaw that allows any authenticated user to delete arbitrary media attachments owned by other users. This vulnerability arises from inadequate validation of attachment ownership, which can lead to unauthor...

Discovered 13 hours ago

PoC for CVE-2026-91017

WordPressRobokassa Payment Gate...3.7LOW
Payment Notification Forgery in Robokassa WooCommerce Plugin

The Robokassa payment gateway for the WooCommerce WordPress plugin, prior to version 1.8.9, contains a flaw that fails to adequately authenticate incoming payment notifications when the non-default deferred-payment feature is enabled. This allows unauthorized attackers to manipulate payment notif...

PoC for CVE-2026-87963

WordPressYo8.6HIGH
SQL Injection Vulnerability in Yo WordPress Plugin from Vendor

The Yo WordPress plugin versions 1.1 through 1.3.1 are susceptible to a SQL injection vulnerability due to improper handling of the username request parameter. This flaw allows unauthenticated attackers to craft malicious SQL queries, potentially accessing sensitive information within the databas...

PoC for CVE-2026-86801

WordPressTo Do List Member8.8HIGH
File Upload Vulnerability in To Do List Member WordPress Plugin

The To Do List Member plugin for WordPress, versions 1.4 to 1.6, features a file upload endpoint that bypasses WordPress's core security features. This vulnerability allows unauthenticated users to upload files without necessary authentication, capability, or nonce checks. The plugin only checks ...

Discovered 14 hours ago

PoC for CVE-2026-91019

WordPressEvent Booking Manager ...4.9MEDIUM
Payment Gateway Configuration Exposure in WooCommerce Plugin by Wor...

The Event Booking Manager for WooCommerce plugin for WordPress prior to version 5.6.0 suffers from improper access control. This vulnerability permits users with Contributor-level access and higher to access sensitive payment gateway configurations. Specifically, it exposes PayPal and Stripe cred...

PoC for CVE-2026-91015

WordPressMaster Addons For Elem...5.3MEDIUM
Unauthorized Access Vulnerability in Master Addons for Elementor Pl...

The Master Addons for Elementor plugin for WordPress prior to version 3.1.9 contains a serious security issue. It lacks adequate authorization checks for its AJAX actions related to the Popup Builder functionality. This vulnerability allows unauthenticated users to exploit the non-restricted AJAX...

PoC for CVE-2026-91014

WordPressRealtyna Organic Idx P...7.1HIGH
Reflected XSS Vulnerability in Realtyna Organic IDX and WPL Real Es...

The Realtyna Organic IDX plugin and WPL Real Estate plugin prior to version 5.4.2 exhibit a serious flaw where certain parameters are not properly sanitized or escaped. This lack of validation enables unauthenticated attackers to inject arbitrary web scripts into a visitor's browser. If a user is...

PoC for CVE-2026-91016

WordPressMotors5.3MEDIUM
Unauthorized Access Vulnerability in Motors Plugin for WordPress

The Motors plugin for WordPress prior to version 1.4.121 is susceptible to a vulnerability that allows unauthorized users to access unpublished listings. This issue arises from inadequate verification of requests, permitting unauthenticated attackers to retrieve details of awaiting publication co...

PoC for CVE-2026-91010

WordPressInvisible Anti-spam & ...4.3MEDIUM
Message Deletion Vulnerability in Invisible Anti-Spam & CAPTCHA Wor...

The Invisible Anti-Spam & CAPTCHA plugin for WordPress prior to version 5.1.1 lacks proper validation for user capabilities during the AJAX action for message deletion. This oversight allows any authenticated user, including those with the lowest permission levels, to delete all stored form submi...

PoC for CVE-2026-91011

WordPressEwww Image Optimizer6.8MEDIUM
Security Flaw in EWWW Image Optimizer Plugin for WordPress

The EWWW Image Optimizer plugin for WordPress versions prior to 8.7.7 lacks proper escaping of image attributes in the rewritten page output. This vulnerability permits authenticated users with author-level permissions or higher to inject arbitrary JavaScript code into published content. When uns...

PoC for CVE-2026-91008

WordPressEvent Booking Manager ...3.7LOW
Information Disclosure Vulnerability in Event Booking Manager for W...

The Event Booking Manager for WooCommerce plugin for WordPress prior to version 5.3.8 has a vulnerability that permits unauthenticated attackers to access sensitive information of registered attendees. Specifically, the plugin fails to implement necessary ownership and authorization checks for bo...

PoC for CVE-2026-88904

WordPressPuppyfw8.8HIGH
Improper Authorization in PuppyFW WordPress Plugin Affects User Per...

The PuppyFW WordPress plugin, up to version 0.4.4, is vulnerable due to improper authorization mechanisms in its REST API routes. This flaw permits any authenticated user—including those with basic subscriber roles—to manipulate blog settings arbitrary. As a result, users can add, modify, or dele...

PoC for CVE-2026-91009

WordPressActive Woot Products T...4.3MEDIUM
Authorization Flaws in Active Woot Products Tables for WooCommerce ...

The Active Woot Products Tables plugin for WooCommerce, available for free on WordPress, has critical weaknesses in its AJAX action handling. Specifically, it lacks adequate authorization and CSRF protections, permitting any authenticated user—including those with subscriber privileges—to modify ...

PoC for CVE-2026-90922

WordPressPaid Membership Subscr...5.3MEDIUM
Payment Processing Flaw in Paid Membership Subscriptions WordPress ...

A flaw in the Paid Membership Subscriptions WordPress plugin prior to version 3.0.9 allows unauthenticated users to gain access to paid memberships by completing payments with amounts that do not match the expected payment criteria. This occurs because the plugin fails to verify the accuracy of a...

PoC for CVE-2026-90923

WordPressAutopay6.5MEDIUM
Payment Callback Vulnerability in Autopay Plugin for WordPress by C...

The Autopay WordPress plugin prior to version 5.0.1 is susceptible to an improper authentication vulnerability that fails to validate the signature on specific payment callbacks. This oversight permits unauthorized users to access sensitive payment details and potentially manipulate or delete the...

PoC for CVE-2026-88795

WordPressWPshopgermany It-recht...9CRITICAL
Weak API Authentication in wpShopGermany Plugin

The wpShopGermany IT-RECHT KANZLEI WordPress plugin prior to version 2.4 has a significant security flaw in its API authentication process. The plugin incorrectly generates an authentication token based on user-controlled data. This token generation flaw allows unauthenticated attackers to predic...

PoC for CVE-2026-86824

WordPressNewsletter4.8MEDIUM
Email Tracking Vulnerability in Newsletter Plugin for WordPress

The Newsletter WordPress plugin prior to version 9.3.8 has a critical flaw in its email tracking mechanism due to inadequate entropy used for generating the signing key. This vulnerability allows unauthenticated attackers to exploit the poorly secured tracking links. By recovering the signing key...

PoC for CVE-2026-87836

WordPressComments Import & Export2.7LOW
Data Exposure Vulnerability in Comments Import & Export Plugin for ...

The Comments Import & Export plugin for WordPress versions prior to 2.5.4 suffers from a significant data exposure issue, allowing users with the Author role and above to export all comments across the site. This includes sensitive information such as commenter email addresses, IP addresses, and ...

PoC for CVE-2026-87786

WordPressDewa Kirim8.8HIGH
JavaScript Injection Vulnerability in Dewa Kirim WordPress Plugin

The Dewa Kirim WordPress plugin, version 1.0.0, is susceptible to JavaScript injection due to improper escaping of delivery coordinates submitted at checkout. This vulnerability allows unauthenticated users to input malicious scripts that execute within the session of an administrator upon review...

PoC for CVE-2026-88792

WordPressDictionary8.8HIGH
Security Flaw in Dictionary WordPress Plugin by WordPress

The Dictionary WordPress plugin, version 1.0, contains a significant vulnerability that lacks proper authorization, sanitization, and escaping mechanisms when adding or updating dictionary entries. This allows unauthenticated users to insert arbitrary web scripts, which can be executed when any u...

PoC for CVE-2026-86707

WordPressPrivate Feed Key9.8CRITICAL
Authentication Bypass in Private Feed Key WordPress Plugin

The Private Feed Key WordPress plugin, prior to version 0.1, contains a vulnerability that fails to properly validate the authentication key used to access feed requests. This oversight enables unauthenticated attackers to potentially log in as any user on the WordPress site, including those with...

PoC for CVE-2026-86788

WordPressHt Mega Addons For Ele...6.8MEDIUM
Arbitrary JavaScript Execution Vulnerability in HT Mega Addons for ...

The HT Mega Addons for Elementor plugin for WordPress, prior to version 3.2.6, contains a security flaw where it fails to validate the HTML tag names used in various widgets and blocks. This oversight allows users with contributor-level access and above to inject crafted HTML tag names that can e...

PoC for CVE-2026-86710

WordPressLogin With Qr9.8CRITICAL
Authentication Bypass in Login with QR Plugin for WordPress

The Login with QR plugin for WordPress, up to version 1.0.0, is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated users to log in as any user, including those with administrative privileges, without the need for proper authentication. The plugin fails to vali...

PoC for CVE-2026-86709

WordPressThe Pressengine9.8CRITICAL
Authentication Bypass in Pressengine WordPress Plugin

The Pressengine WordPress plugin, prior to version 1.0, contains a significant flaw in its login handler that fails to properly prevent session issuance upon failed authentication attempts. This vulnerability exposes the system to unauthenticated attackers who could potentially exploit this weakn...

PoC for CVE-2025-15697

WordPressDictionary7.1HIGH
Reflected Cross-Site Scripting in Dictionary Plugin for WordPress

The Dictionary plugin for WordPress, in versions up to 1.0, fails to properly escape user input before reflecting it in responses from multiple accessible scripts. This gap allows unauthorized attackers to exploit the vulnerability and launch reflected cross-site scripting (XSS) attacks. By submi...

PoC for CVE-2026-86446

WordPressLearnpress3.7LOW
Information Disclosure Vulnerability in LearnPress WordPress Plugin

The LearnPress plugin for WordPress, prior to version 4.4.7, presents a vulnerability that enables unauthorized users to access specific flags related to quiz answers without proper validation. This weakness permits attackers to retrieve correct answers along with instructor explanations for quiz...

PoC for CVE-2026-85130

WordPressWPlp Cookie Consent8.8HIGH
Cross-Site Scripting Vulnerability in WPLP Cookie Consent Plugin by...

The WPLP Cookie Consent plugin for WordPress, prior to version 4.4.4, is susceptible to a cross-site scripting (XSS) vulnerability. This arises from the failure to properly escape values submitted through a public endpoint, which are later rendered in the JavaScript context on an administrative s...

PoC for CVE-2026-85128

WordPressChoose User Role At Re...7.5HIGH
Unauthorized Role Assignment in Choose User Role at Registration Pl...

The Choose User Role at Registration plugin for WordPress, prior to version 1.3.3, has a significant flaw where it fails to validate user role requests against predefined options set by administrators. This oversight allows unauthenticated users to request any user role during account registratio...

Discovered 18 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 20 hours ago

PoC for CVE-2022-22715

MicrosoftWindows 10 Version 1809🟣 EPSS 13%7.8HIGH
Named Pipe File System Elevation of Privilege Vulnerability

Named Pipe File System Elevation of Privilege Vulnerability

PoC for CVE-2026-12793

WordPressJetformbuilder — Dynam...9.8CRITICAL
Privilege Escalation Vulnerability in JetFormBuilder Plugin for Wor...

The JetFormBuilder plugin for WordPress is exposed to a privilege escalation vulnerability due to inadequate validation of form IDs during submission. This flaw allows attackers, without authentication, to craft a request that creates an administrator-level user account, potentially compromising ...

Discovered 21 hours ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 99%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

Discovered 22 hours ago

PoC for CVE-2026-0994

PythonProtobuf8.2HIGH
Denial-of-Service Vulnerability in Google Protocol Buffers by Google

A denial-of-service vulnerability has been identified in the Google Protocol Buffers library, specifically within the json_format.ParseDict() method in Python. This issue arises from a flaw in handling recursion depth when processing nested google.protobuf.Any messages. Attackers can craft deeply...

PoC for CVE-2026-89034

TchQring7.1HIGH
Unauthenticated Bluetooth Low Energy Vulnerability in TCH QRing Sma...

The TCH QRing smart ring model R20_B006, running firmware RT09R20_1.00.00_250318, exhibits a significant vulnerability that allows attackers within range to exploit the unsecured Nordic UART Service. This flaw permits nearby attackers to connect to the device without requiring any form of pairing...

Discovered 23 hours ago

PoC for CVE-2021-29447

WordPressWordPress-develop🟣 EPSS 86%7.1HIGH
WordPress Authenticated XXE attack when installation is running PHP 8

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has...

PoC for CVE-2026-92816

Comfy-orgComfyui8.5HIGH
Path Traversal Vulnerability in ComfyUI Allowing Arbitrary File Writes

ComfyUI versions prior to 0.30.0 have a vulnerability where the application fails to sanitize the 'folder_name' input in dataset save nodes, enabling attackers to exploit this flaw. By crafting a malicious workflow, an attacker can write files to unintended locations outside the designated output...

PoC for CVE-2026-92815

DgtlmoonChangedetection.io8.7HIGH
Server-Side Request Forgery Vulnerability in changedetection.io by ...

The vulnerability in changedetection.io versions up to 0.60.6 allows attackers to exploit the Goto URL action in browser steps without authentication. By manipulating the optional_value parameter, attackers can bypass URL validation and access sensitive internal resources. This flaw represents a ...

PoC for CVE-2026-92814

DgtlmoonChangedetection.io2.3LOW
Stored HTML Markup Injection in Changedetection.io Notifications

The Changedetection.io product, up to version 0.60.6, contains a vulnerability where it fails to properly escape scraped page titles in HTML notifications. This oversight can be exploited by attackers to inject malicious markup into monitored page titles. When the watch_title token is used in not...

PoC for CVE-2026-92813

MetabaseMetabase6.9MEDIUM
Server-Side Request Forgery in Metabase Allows Unauthenticated Access

The recent vulnerability in Metabase, affecting versions up to 0.63.18, stems from a failure to correctly validate GeoJSON URLs. By using the address 0.0.0.0 in custom GeoJSON entries, an unauthenticated attacker can orchestrate requests that connect to internal loopback services. This can lead t...

PoC for CVE-2026-92812

DecaporgDecap-server7.6HIGH
Path Traversal Vulnerability in Decap Server by Decaporg

Decap Server exhibits a path traversal vulnerability within its local proxy containment guard. This flaw stems from the use of string prefix comparison that does not validate path separators. As a result, attackers can exploit this vulnerability to navigate sibling directories that share the same...