Publicly Disclosed
PoC Exploits
๐ด Alway take caution when working with PoC Exploits ๐ด
Discovered just now...
PoC for CVE-2026-23989
The Reva interoperability platform from OpenCloud contains a vulnerability in the GRPC authorization middleware that allows malicious users to bypass scope verification associated with public links. This flaw can be exploited through the archiver service to create archives (zip or tar files) cont...
Discovered 4 hours ago
PoC for CVE-2022-38694
The vulnerability occurring in UNISOC's BootRom allows a possible unchecked write address, enabling local escalation of privilege without requiring additional execution privileges. This flaw poses a significant security risk, as it can be exploited by malicious actors to gain unauthorized access ...
Discovered 6 hours ago
PoC for CVE-2026-82473
The KubeEdge CloudCore component, up to version 1.23.1, is vulnerable to an authentication bypass that allows attackers to submit node task status reports without any authentication. This flaw is exploitable via the HTTPS service on port 10002, enabling unauthorized users to manipulate the percei...
Discovered 10 hours ago
PoC for CVE-2026-4001
The Woocommerce Custom Product Addons Pro plugin for WordPress has a vulnerability that allows Remote Code Execution due to insufficient sanitization of user inputs. Specifically, in the process_custom_formula() function, user-defined custom pricing formulas are not properly validated before bein...
Discovered 12 hours ago
PoC for CVE-2026-82286
The gpt-crawler, up to version 1.5.1, contains a significant flaw in its handling of the outputFileName parameter in the POST /crawl endpoint. This vulnerability permits unauthenticated users to write arbitrary files to any location within the filesystem. By providing carefully crafted input that...
Discovered 16 hours ago
PoC for CVE-2026-81346
The Frontend Admin plugin developed by DynamiApps suffers from an improper authorization vulnerability due to the absence of a capability check on certain AJAX actions. This flaw permits any authenticated user, including subscribers, to delete arbitrary membership plans. As a result, this vulnera...
PoC for CVE-2026-81342
The MasterStudy LMS WordPress plugin prior to version 3.7.43 contains a vulnerability that fails to properly validate redirect parameters during user registration. This flaw permits unauthenticated users to manipulate the registration process, enabling them to redirect legitimate users to potenti...
PoC for CVE-2026-80488
The WP Ultimate CSV Importer plugin for WordPress prior to version 9.0 has a vulnerability that arises from improper sanitization and escaping of imported field values. This flaw can be exploited by high-privilege users, such as administrators, allowing them to execute arbitrary SQL commands. Suc...
PoC for CVE-2026-80311
The Stripe Payment Forms plugin by WP Full Pay for WordPress contains a vulnerability that allows an authenticated user to cancel subscriptions that do not belong to them. This oversight occurs due to the lack of proper verification to confirm that a subscription is associated with the requesting...
PoC for CVE-2026-81200
The MasterStudy LMS WordPress Plugin prior to version 3.7.42 contains an access control vulnerability that allows users with the instructor role to access sensitive order information of other users. This includes data such as names, email addresses, phone numbers, and postal addresses by simply e...
PoC for CVE-2026-81026
The MasterStudy LMS WordPress Plugin, prior to version 3.7.40, contains a critical vulnerability where payment notifications are not adequately verified. This flaw allows unauthenticated users to mark full-price orders as completed without proper validation of payment details like amount, receive...
PoC for CVE-2026-77704
The Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.9 features an authorization vulnerability that allows users to change appointment statuses without proper capability checks. This flaw enables customers to set arbitrary statuses on their bookings, includin...
PoC for CVE-2026-77786
The Rank Math SEO WordPress plugin, prior to version 1.0.277, contains a flaw in permissions handling. This vulnerability allows users with the Editor role to initiate automated SEO fixes without the necessary privileges, enabling them to alter site-wide core WordPress settings. Such unauthorized...
PoC for CVE-2026-77010
The HEL Online Classroom plugin for WordPress prior to version 1.0.3 lacks proper authorization checks on its REST API routes. This oversight permits unauthenticated users to acquire a signed join link for any classroom, even those secured with an access code. Such vulnerabilities allow unauthori...
PoC for CVE-2026-77012
The ็ฑ้้ๆฐๆฎ้้ๅๅๅธ plugin for WordPress is vulnerable due to its unauthenticated endpoints that use a hardcoded default secret. This flaw permits unauthorized attackers to execute file reading operations, send arbitrary requests, and write content outside designated upload paths, which significantly ...
PoC for CVE-2026-77008
The HEL Online Classroom plugin for WordPress, up to version 1.0.3, lacks proper authorization and authentication checks when saving settings. This oversight allows unauthorized individuals to alter the configuration, potentially rerouting online classrooms and compromising the integrity of sessi...
PoC for CVE-2026-77007
The HEL Online Classroom plugin for WordPress, specifically version 1.0.3, is susceptible to a critical security vulnerability that lacks proper authorization checks on a REST API route. This oversight enables unauthenticated users to access sensitive configuration settings, including a shared se...
PoC for CVE-2026-76586
The Appointment Booking Calendar and Scheduling plugins for WordPress prior to version 1.6.3 exhibit a serious issue where the actual payment amount is not verified against the expected server-side price during the online payment confirmation process. This flaw enables unauthenticated users to se...
PoC for CVE-2026-19430
The Catfolders Document Gallery Pro plugin for WordPress prior to version 2.0.7 exposes REST API routes without proper authorization. This issue allows unauthorized users to generate a forgeable token, enabling them to list and download unpublished folder contents, thereby compromising the privac...
PoC for CVE-2026-76546
The User Profile Builder plugin for WordPress, prior to version 4.0.1, contains a vulnerability due to insufficient output escaping of its optional shortcode. This flaw could allow users with contributor privileges to execute Stored Cross-Site Scripting (XSS) attacks. Any user viewing the affecte...
PoC for CVE-2026-76547
The User Profile Builder WordPress plugin prior to version 4.0.1 exhibits a flaw in its deserialization process, failing to properly validate the data when importing configuration files. This vulnerability enables high privilege users, such as administrators, to potentially perform PHP Object Inj...
PoC for CVE-2026-76548
The User Profile Builder plugin for WordPress prior to version 4.0.1 features a misconfiguration in its front-end file upload functionality. This oversight permits unauthenticated users to upload files, a privilege typically restricted to user roles with higher access rights. As a result, these u...
PoC for CVE-2026-18234
The MStore API plugin for WordPress prior to version 4.21.1 contains a significant vulnerability in its payment handling mechanism. It fails to verify the ownership of the orders being processed, allowing any authenticated user, including those with minimal roles such as Subscribers, to manipulat...
PoC for CVE-2026-16600
The SmartAIPress plugin, utilized in WordPress environments, lacks adequate security checks on certain AJAX actions and fails to validate user-supplied URLs. This oversight permits users with subscriber-level access and above to manipulate the site into fetching arbitrary URLs, both internal and ...
PoC for CVE-2026-18233
The MStore API WordPress plugin prior to version 4.21.1 contains a critical flaw that allows authenticated users, including those with subscriber roles, to manipulate order statuses. Specifically, the plugin does not adequately verify whether the orders accessed through its delivery endpoints bel...
PoC for CVE-2026-16947
The Total Processing plugin for WooCommerce versions up to 7.3 has a significant security flaw that allows attackers to exploit improper path validation. This vulnerability enables unauthenticated users to craft malicious server-side requests, leading to the potential redirection of verification ...
PoC for CVE-2026-17520
The Newsletters plugin for WordPress, prior to version 4.17, is susceptible to a vulnerability that arises from the inadequate randomness in its API key generation process. The API key is derived from a publicly known value, which allows unauthenticated attackers to predict the key. This opens th...
PoC for CVE-2026-17522
The Newsletters WordPress plugin prior to version 4.17 is susceptible to a Cross-Site Request Forgery (CSRF) attack due to the absence of nonce or capability checks when saving settings. This oversight allows logged-in attackers to overwrite arbitrary settings, including sensitive API credentials...
PoC for CVE-2026-10522
The MemberHero plugin for WordPress, up to version 6.9, suffers from a serious security issue where it fails to properly restrict the fields that can be provided during the frontend registration process. This oversight allows unauthorized users to create new accounts with arbitrary roles, includi...
PoC for CVE-2026-16259
The Uix UserCenter plugin for WordPress fails to verify that the account being modified through an unauthenticated profile-update action is associated with the requester. This vulnerability arises from a hardcoded signing key used for token authentication that remains the same across all installa...
PoC for CVE-2026-16061
The Rest Routes plugin for WordPress, specifically versions up to 5.5.5, contains a significant security flaw where user input from a public REST route is not properly sanitized or validated. As a result, this oversight could allow unauthenticated attackers to inject malicious SQL queries, potent...
Discovered 21 hours ago
PoC for CVE-2026-66384
An authenticated user can exploit a specific condition in JFrog Artifactory, allowing them to write data outside the designated Docker cache path when using remote repositories. This could lead to unintended data exposure and potential integrity issues within the environment, necessitating immedi...
Discovered 1 day ago
PoC for CVE-2026-33017
Langflow, a tool for constructing and deploying AI-driven agents and workflows, is susceptible to a vulnerability in the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint in versions before 1.9.0. This vulnerability enables an attacker to build public flows without authentication, leveraging ...
PoC for CVE-2026-33057
The Mesop UI framework, used for building web applications, contains a significant vulnerability in its ai/testing module. This flaw permits the ingestion of untrusted Python code without any authentication measures, leading to Unrestricted Remote Code Execution. By exploiting the /exec-py endpoi...
PoC for CVE-2025-59528
Flowise, a user-friendly platform for creating customized large language model flows, has a significant vulnerability in version 3.0.5 that allows for remote code execution. The flaw lies within the CustomMCP node, where user input is inadequately sanitized. Specifically, the mcpServerConfig stri...
PoC for CVE-2026-82017
The IGEL OS versions prior to 12.7.6 and 11.11.150 are susceptible to a boot parameter injection vulnerability. This vulnerability can be exploited by attackers who have physical access to the device, enabling them to inject malicious Linux loader parameters. This is achieved by modifying an unen...
PoC for CVE-2024-23897
A security issue exists in Jenkins due to the command line interface parser failing to properly handle inputs containing an '@' character followed by a file path. This flaw can be exploited by unauthenticated attackers, allowing them to read arbitrary files from the Jenkins controller's file syst...
PoC for CVE-2025-10952
A security flaw exists in Geyang ML-Logger that affects the stream_handler function within the ml_logger/server.py file of the File Handler component. This vulnerability allows an attacker to exploit the application remotely through manipulation of the argument key, potentially leading to unautho...
PoC for CVE-2026-56100
The SpringBlade framework, specifically in versions 2.7.3 through 3.5.0, is susceptible to a privilege escalation vulnerability. This issue arises from an unprotected internal Feign user-creation endpoint, which is exposed without adequate authorization checks. Authenticated attackers can send cr...
PoC for CVE-2026-23751
Kofax Capture exposes a deprecated .NET Remoting HTTP channel on port 2424, accessible without authentication. This vulnerability allows an unauthenticated remote attacker to utilize .NET Remoting techniques to manipulate various system objects. By leveraging these techniques, attackers may read ...
PoC for CVE-2026-77939
Flextype CMS through v1.0.0-dev is vulnerable to an expression language injection flaw that permits authenticated users with a valid API token to exploit the system. By submitting unsanitized input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint, attackers can gain ac...
PoC for CVE-2023-27350
A vulnerability in PaperCut NG allows remote attackers to bypass authentication due to improper access control within the SetupCompleted class. This can lead to the execution of arbitrary code with SYSTEM privileges, posing significant security risks. Attackers do not need to authenticate to expl...
PoC for CVE-2026-70463
In affected versions of rsync prior to 3.5.0, a vulnerability exists within the parsing of the 'auth users' directive, leading to an authorization bypass. The issue arises from how the parser tokenizes the user list. It incorrectly handles group names containing spaces, resulting in the group mem...
PoC for CVE-2026-82111
A path traversal vulnerability exists in the upload_image component of iswalle Getnote-MCP, affecting versions up to 1.5.0. This issue arises from improper handling of the argument image_path in the fs.readFileSync function found in src/index.ts. An attacker could exploit this vulnerability remot...
Discovered 2 days ago
PoC for CVE-2025-57819
FreePBX, an open-source web-based GUI, suffers from a vulnerability that permits unauthenticated users to gain access to the FreePBX Administrator interface. This is primarily due to insufficient sanitization of user-provided data. The flaw can lead to unauthorized database manipulation and may a...
PoC for CVE-2026-79996
The User Registration & Membership plugin for WordPress, prior to version 5.2.6, lacks essential capability checks during the save process for login settings. This oversight allows authenticated users, who possess specific management rights but not full administrator access, to manipulate site op...
PoC for CVE-2026-79706
The Breeze Cache WordPress plugin fails to properly sanitize user input when constructing file paths for cached files. This flaw allows unauthenticated attackers to exploit the vulnerability, potentially leading to file creation at arbitrary locations on the server. As a result, sensitive data ex...
PoC for CVE-2026-79615
The Quiz and Survey Master plugin for WordPress prior to version 11.2.4 contains a security flaw where it fails to verify authorization when retrieving question bank entries via its REST API. This oversight allows users with minimal roles, such as Contributor, to access sensitive quiz information...
PoC for CVE-2026-79995
The User Registration & Membership plugin for WordPress, prior to version 5.2.5, has a significant flaw that allows authenticated users with Subscriber-level access and above to cancel pending email change requests belonging to any user. This weakness stems from the plugin's failure to verify whe...
PoC for CVE-2026-14567
The User Frontend plugin for WordPress versions prior to 4.3.10 suffers from an access control vulnerability, where the user directory search endpoint lacks proper authentication mechanisms. This oversight permits unauthorized attackers to indiscriminately access sensitive information, including ...