Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 2 hours ago
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
Discovered 3 hours ago
PoC for CVE-2026-67620
The Flowise application version 3.1.4 is susceptible to a server-side request forgery (SSRF) vulnerability due to an inadequate deny-list configuration in its SSRF guard found in httpSecurity.ts. Specifically, the default configuration omits critical endpoints associated with Oracle Cloud Infrast...
Discovered 7 hours ago
PoC for CVE-2026-18953
The awslabs.aws-transform-mcp-server tool from Amazon contains a vulnerability due to improper validation of the savePath parameter, which could allow an attacker to write files outside the designated working directory. This issue affects versions 0.1.0 through 0.1.4. Users are encouraged to upgr...
Discovered 9 hours ago
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
PoC for CVE-2017-9757
IPFire version 2.19 is susceptible to a Remote Command Injection vulnerability through its ids.cgi component. The issue arises from improper handling of the OINKCODE parameter allowing authenticated users to execute arbitrary shell commands. This vulnerability can be exploited directly or via Cro...
Discovered 10 hours ago
PoC for CVE-2026-63077
An unauthenticated remote code execution vulnerability has been identified in JetBrains TeamCity prior to version 2026.1.3 and 2025.11.7. This weakness is exposed through the agent polling protocol, allowing attackers to execute arbitrary code without authentication, posing significant risks to t...
Discovered 11 hours ago
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
Discovered 12 hours ago
PoC for CVE-2026-19268
A command injection vulnerability has been identified in the MCPGateway by Abdullah1854, specifically within the 'getUsageByDateRange' function located in the file 'src/services/claude-usage.ts'. This vulnerability arises due to improper handling of input parameters, allowing an attacker to manip...
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
Discovered 13 hours ago
PoC for CVE-2026-71554
The h2 library, which is a pure-Python implementation of the HTTP/2 protocol stack, has a vulnerability that allows for potential request smuggling. This occurs in versions up to and including 4.4.0, where the library incorrectly handles request header blocks containing multiple Host headers. Sub...
PoC for CVE-2026-71554
The h2 library, which is a pure-Python implementation of the HTTP/2 protocol stack, has a vulnerability that allows for potential request smuggling. This occurs in versions up to and including 4.4.0, where the library incorrectly handles request header blocks containing multiple Host headers. Sub...
PoC for CVE-2026-16955
The AI Engine WordPress plugin prior to version 3.6.6 lacks proper validation of caller-supplied file paths, allowing individuals with subscriber-level access to read arbitrary files from the server. This vulnerability can lead to unauthorized data exfiltration when a specific public API feature ...
PoC for CVE-2026-16953
The AI Engine WordPress plugin prior to version 3.6.4 suffers from a vulnerability that allows an unauthenticated attacker to delete user-uploaded chatbot files. This security flaw arises due to insufficient verification of the ownership of uploaded files, relying solely on a client-supplied sess...
PoC for CVE-2026-16948
The Solace Extra plugin for WordPress suffers from an access control vulnerability due to inadequate capability checks in its AJAX actions. This flaw allows users with minimal privileges (such as Subscribers) to manipulate crucial site-wide settings and delete imported site-builder content, there...
PoC for CVE-2026-16608
The Download Monitor plugin for WordPress prior to version 5.2.6 contains a vulnerability that allows unauthenticated users to bypass authorization checks on specific AJAX actions. This inadequacy permits unauthorized parties to inject arbitrary download log entries, leading to the potential infl...
PoC for CVE-2026-16595
The WP Directory Kit plugin for WordPress versions before 1.5.5 is susceptible to an authorization flaw during one of its authenticated AJAX actions. This vulnerability allows any authenticated user, including those with minimal privileges such as Subscribers, to access sensitive site information...
PoC for CVE-2026-16589
The WP Directory Kit plugin for WordPress suffers from a security flaw that allows SQL injection attacks due to inadequate sanitization and escaping of parameters in authenticated AJAX actions. The vulnerability is particularly concerning because it lacks proper authorization and nonce checks. Th...
PoC for CVE-2026-16594
The WP Directory Kit plugin for WordPress, prior to version 1.5.5, contains a significant security flaw that lacks proper authorization and nonce validation on an authenticated AJAX action. This oversight enables any authenticated user, such as a Subscriber, to access and potentially disclose sen...
PoC for CVE-2026-16590
The WP Directory Kit plugin for WordPress is subject to an authorization bypass vulnerability due to improper checks on an authenticated AJAX action. This flaw enables any authenticated user, including those with minimal roles such as Subscriber, to access and retrieve stored contact messages and...
PoC for CVE-2026-16558
The YMC Filter plugin for WordPress, prior to version 3.12.8, contains a significant access control flaw. The plugin fails to properly sanitize and escape a layout builder setting when it is outputted on a public endpoint. Additionally, it lacks verification of object ownership during the saving ...
PoC for CVE-2026-16559
The YMC Filter plugin for WordPress prior to version 3.12.9 is susceptible to an improper input validation vulnerability that fails to sanitize SVG files uploaded via icon upload features. This oversight allows low-privileged users, including those with an Author role, to upload malicious files c...
PoC for CVE-2026-16578
The Admin Safety Guard plugin for WordPress, specifically in versions prior to 1.4.0, suffers from a critical vulnerability due to a lack of capability checks on its REST API endpoint. This oversight permits unauthenticated attackers to access sensitive information, including a comprehensive list...
PoC for CVE-2026-16574
The Dokan plugin for WooCommerce, version prior to 5.0.11, has a significant access control vulnerability. It fails to adequately verify that a downloadable product is associated with the requesting vendor, exposing a risk where an authenticated vendor could inadvertently grant their customers un...
PoC for CVE-2026-16562
The WP Statistics plugin for WordPress, prior to version 14.16.10, is susceptible to a security flaw due to inadequate capability checks on certain AJAX handlers for dashboard analytics. This vulnerability allows users with Subscriber-level access or higher to access and potentially disclose sens...
PoC for CVE-2026-16535
The Link Library plugin for WordPress versions prior to 7.9.4 is susceptible to reflected cross-site scripting (XSS). The plugin fails to properly sanitize and escape a specific parameter that is echoed back in HTTP responses. This oversight allows unauthenticated attackers to exploit the vulnera...
PoC for CVE-2026-16282
The Appointment Hour Booking plugin for WordPress contains a flaw that allows unauthenticated users to submit a booking price that is not validated against the server-side configured service price. This lack of validation means users can set any final price, including zero or negative values, whi...
PoC for CVE-2026-16269
The Newsletters plugin for WordPress is susceptible to an API authentication bypass due to inadequate type comparison of its API authentication key. This flaw enables unauthenticated attackers to exploit the plugin, particularly when the optional API feature is enabled. By leveraging type jugglin...
PoC for CVE-2026-16267
The Newsletters plugin for WordPress, prior to version 4.16, is susceptible to a PHP Object Injection vulnerability. This flaw occurs due to improper handling of unserialised data retrieved from public form submissions. Attackers, without authentication, can exploit this weakness to inject malici...
PoC for CVE-2026-19259
A heap-based buffer overflow vulnerability exists in MZ Automation's libiec61850 product, specifically within the MmsMapping_varAccessSpecToObjectReference function found in the src/iec61850/common/iec61850_common.c file. This vulnerability is triggered by improper handling of the GetNamedVariabl...
Discovered 14 hours ago
PoC for CVE-2026-55957
An authentication vulnerability has been identified in Apache Tomcat, specifically relating to the configuration of JNDIRealm when using GSSAPI for authentication purposes. This flaw enables unauthorized attackers to authenticate without providing the correct password, thereby compromising the se...
Discovered 15 hours ago
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
Discovered 17 hours ago
PoC for CVE-2025-55182
A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
Discovered 19 hours ago
PoC for CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...
Discovered 20 hours ago
PoC for CVE-2026-64638
WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...
Discovered 22 hours ago
PoC for CVE-2026-19246
A server-side request forgery vulnerability exists in the HKUDS Nanobot up to version 0.2.1, specifically in the undocumented function _download_image_data_url within the image_generation.py module. This vulnerability allows remote attackers to exploit the function to execute unauthorized server ...
Discovered 23 hours ago
PoC for CVE-2026-19245
A vulnerability has been identified in the HKUDS Nanobot's Login-shell Environment Handler, specifically in the ExecTool._prepare_command function within the shell.py file. This flaw can lead to the unintentional disclosure of sensitive information when local access is exploited. It arises from t...
PoC for CVE-2026-19244
A significant vulnerability has been identified in HKUDS Nanobot prior to version 0.2.1, specifically within the connect_mcp_servers function of the mcp.py file. This issue involves improper access controls allowing potential unauthorized registration of MCP resources and prompt wrappers outside ...
Discovered 1 day ago
PoC for CVE-2026-19243
A security vulnerability exists in HKUDS Nanobot versions prior to 0.3.0, affecting the Shell Allowlist Handler. Specifically, the issue arises from inadequate validation of shell commands, leading to potential remote command injection. Attackers can exploit this vulnerability by manipulating the...
PoC for CVE-2026-64640
An issue has been identified in Apache Polaris where it fails to consistently validate storage locations during table and view registration. Authenticated users with the necessary permissions can leverage this vulnerability to allow Polaris to access Iceberg metadata files from user-defined locat...
PoC for CVE-2026-19231
A security flaw in SourceCodester's Simple Doctors Appointment System version 1.0 allows an attacker to exploit the /admin/ajax.php?action=delete_appointment endpoint. By manipulating the ID parameter, the attacker can execute SQL injection attacks remotely, compromising the integrity and confide...
PoC for CVE-2026-19230
A vulnerability has been identified in the SourceCodester Photo Share Website version 1.0, specifically within the Comment Input Box component. This issue arises from improper handling of the 'content' argument in the file '/social/ajax.php?action=save_upload', leading to a cross-site scripting (...
PoC for CVE-2026-63077
An unauthenticated remote code execution vulnerability has been identified in JetBrains TeamCity prior to version 2026.1.3 and 2025.11.7. This weakness is exposed through the agent polling protocol, allowing attackers to execute arbitrary code without authentication, posing significant risks to t...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-19213
A vulnerability exists in WonderTrader versions up to 0.9.9 affecting the _undone_qty function in the Pending Order Handler. This security flaw allows remote manipulation of the getUndoneQty argument, leading to unauthorized alterations in behavioral workflows. The exploit is publicly accessible,...
PoC for CVE-2026-19212
A vulnerability exists in the TraderATP Cash Trade Conversion component of WonderTrader, specifically affecting the function within the file src/Includes/WTSTradeDef.hpp. This issue arises from the manipulation of the m_offsetType argument, leading to the use of an uninitialized variable, which c...
PoC for CVE-2026-19211
A SQL injection vulnerability has been identified in the SourceCodester Photo Share Website version 1.0. This issue is triggered when manipulating the email parameter in the /social/ajax.php?action=signup file. Unsanctioned input can lead to unauthorized access, allowing attackers to execute remo...
PoC for CVE-2026-39987
Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...