Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 2 hours ago
PoC for CVE-2026-108165
The Immich application, versions up to 3.3.1, contains a vulnerability where authorized partners can access metadata from Locked Folders. This occurs due to insufficient authorization checks in the partner synchronization stream. Specifically, when using the POST /api/sync/stream endpoint with Pa...
PoC for CVE-2026-108164
The Open Source Social Network (OSSN) through version 10.1 contains an insecure direct object reference vulnerability located in components/OssnMessages/ossn_com.php. This vulnerability enables authenticated users to access private message attachments of other users without proper authorization. ...
Discovered 3 hours ago
PoC for CVE-2026-93687
The Micromatch braces library up to version 3.0.3 is susceptible to a stack overflow due to insufficient depth guarding in its recursive Abstract Syntax Tree (AST) walkers. Attackers can exploit this vulnerability by providing deeply nested brace patterns within the character limit, which may lea...
Discovered 10 hours ago
PoC for CVE-2026-94256
The SMS Alert plugin for WordPress, specifically versions prior to 4.0.1, contains a flaw that fails to ensure the legitimacy of the account linked to a one-time verification code. This oversight allows attackers to gain unauthorized access by substituting their phone number for that of any user,...
PoC for CVE-2026-94257
The SMS Alert WordPress plugin has a security flaw where it fails to correctly bind the password reset process to the verified phone number associated with user accounts. This allows attackers, without authentication, to change passwords for any user, including administrators, by leveraging their...
PoC for CVE-2026-87780
The LTL Freight Quotes WordPress plugin versions before 4.2.19 are susceptible to a Stored Cross-Site Scripting vulnerability. This flaw allows attackers to submit unsanitized and unescaped data via an unauthenticated endpoint. When this data is stored and later displayed on an administrative pag...
PoC for CVE-2026-107323
The Gallery PhotoBlocks plugin for WordPress prior to version 1.3.6 presents a security vulnerability where it fails to properly sanitize and escape a gallery setting. This oversight allows users with Contributor-level access and higher to inject JavaScript code that can be executed in the browse...
PoC for CVE-2026-85571
The Tutor LMS plugin for WordPress, prior to version 4.1.1, exhibits improper access control by failing to verify the ownership of posts during course content ordering requests. This flaw permits users with instructor-level permissions to reassign course materials belonging to other instructors. ...
PoC for CVE-2026-107321
The W3 Total Cache plugin for WordPress prior to version 2.10.6 fails to properly constrain media-import file operations. This vulnerability allows users with the Author role or higher to upload files that can be executed when triggered by an admin. The lack of adequate file-type checks and confi...
PoC for CVE-2026-87781
The LTL Freight Quotes plugin for WordPress prior to version 4.2.19 is susceptible to SQL injection due to inadequate sanitization and escaping of user input in SQL statements. This flaw allows unauthenticated users to execute arbitrary SQL queries, potentially leading to unauthorized data access...
PoC for CVE-2026-107120
The Contest Gallery WordPress plugin prior to version 33.0.1 is vulnerable to a brute-force attack during its front-end registration email-verification process. This vulnerability occurs due to the absence of restrictions on the number of attempts to enter a short numeric PIN. As a result, unauth...
PoC for CVE-2026-105976
The Portfolio Filter Gallery plugin for WordPress, versions prior to 2.2.1, contains a vulnerability due to inadequate authorization checks in several AJAX actions. This flaw allows users with Contributor permissions to access, modify, and delete galleries created by other users, as well as to ma...
PoC for CVE-2026-105989
A significant vulnerability exists in the Accept PayPal Payments using Contact Form 7 plugin for WordPress versions prior to 4.0.7. This flaw allows unauthenticated users to exploit an AJAX action that lacks proper authorization and request-validation checks. As a result, attackers can modify the...
PoC for CVE-2026-105995
The Booking Package WordPress plugin prior to version 1.7.30 lacks essential authorization checks, which exposes stored reservation data. This flaw enables unauthorized users to access sensitive personal information and booking cancellation tokens belonging to other customers, representing a sign...
PoC for CVE-2026-105977
The Portfolio Filter Gallery plugin for WordPress versions prior to 2.2.1 contains a vulnerability that permits users with the Contributor role and above to bypass essential per-object authorization checks. This oversight allows them to delete certain media attachments that belong to other users,...
PoC for CVE-2026-105990
The Accept PayPal Payments Plugin for WordPress, prior to version 4.0.7, lacks necessary authorization checks, enabling unauthorized users to access and download sensitive information, including personal data and payment metadata from stored form submissions. This vulnerability can lead to signif...
PoC for CVE-2026-104754
The Rank Math SEO plugin for WordPress, prior to version 1.0.280, is susceptible to a stored cross-site scripting vulnerability. The vulnerability arises from the plugin's failure to properly escape a stored redirection source value when rendering it in an administrative list view. This oversight...
PoC for CVE-2026-104753
The Rank Math SEO plugin for WordPress prior to version 1.0.280 contains a security flaw where it inadequately sanitizes and escapes input parameters in SQL queries. This vulnerability enables high-privilege users, such as administrators, to execute SQL injection attacks, potentially compromising...
PoC for CVE-2026-104752
The Rank Math SEO WordPress plugin before version 1.0.280 contains a vulnerability that fails to properly validate the type of files uploaded via its settings import feature. This oversight allows users with administrative privileges to upload malicious PHP files, leading to the potential for una...
Discovered 12 hours ago
PoC for CVE-2026-21589
This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerat...
Discovered 13 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 19 hours ago
PoC for CVE-2026-28775
An unauthenticated Remote Code Execution vulnerability in the SNMP service of International Datacasting Corporation's SFX Series SuperFlex SatelliteReceiver allows attackers to exploit insecure provisioning of the 'private' SNMP community string, which grants read/write access by default. This se...
Discovered 1 day ago
PoC for CVE-2026-108158
The plugNmeet Server, in version 2.5.2, is affected by a path traversal vulnerability in its whiteboard conversion endpoint. This security flaw allows any participant in a meeting to manipulate filePath parameters to include '../' sequences, which can facilitate access to server files. By exploit...
PoC for CVE-2026-108112
The ruoyi-ai product versions 3.0.0 to 3.1.0 are susceptible to a missing authorization flaw that allows authenticated users to delete workflows belonging to other users. This occurs via the POST request to /workflow/del/{uuid}, whereby attackers can exploit the flaw to acquire workflow UUIDs thr...
PoC for CVE-2026-108110
MOVO versions up to 0.2.3 contain a vulnerability in the chat-api document endpoints, allowing authenticated users to bypass authorization checks. This flaw enables attackers to access the stored objects of other users by supplying arbitrary object paths. By knowing a target's object path, malici...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-104079
Envira Gallery Lite prior to version 1.16.2 features a missing authorization vulnerability in its gallery conversion REST endpoint. This flaw permits lower-privileged authenticated users to create and publish galleries without necessary permissions. The vulnerability arises because the endpoint e...
PoC for CVE-2026-103329
The Super Payments plugin for WooCommerce does not adequately authenticate payment webhook notifications. This flaw arises because the signing key used for signature validation is empty by default. Consequently, this allows malicious actors to create valid signatures, enabling them to indicate th...
PoC for CVE-2026-86851
The Livees Checkout WordPress plugin (up to version 7.0.2) suffers from a serious security flaw where it fails to validate user permissions, nonce tokens, or order keys on the order confirmation page. This lack of security checks enables unauthenticated attackers to change the status of any order...
PoC for CVE-2026-87846
The Nova Poshta Shipping plugin for WordPress versions up to 1.19.8 is exposed to serious security risks due to a lack of authorization, nonce, and ownership checks on an AJAX action. This oversight allows unauthenticated users to delete shipment records associated with arbitrary orders. Attacker...
PoC for CVE-2026-85348
The GDPR Data Request Form plugin for WordPress, up to version 1.7.1, lacks adequate CSRF protections when updating its settings. This oversight allows attackers to exploit the vulnerability by tricking a site administrator into executing a malicious request. If successful, this could lead to una...
PoC for CVE-2026-89235
The Testimonials by BestWebSoft plugin for WordPress, up to version 1.0.8, has a vulnerability where it fails to properly sanitize and escape a user-supplied parameter in a SQL query. This oversight allows unauthenticated attackers to manipulate the SQL query by appending additional SQL commands,...
PoC for CVE-2026-84220
The Kirki WordPress plugin prior to version 6.3.2 is vulnerable to a serious issue where it allows shortcodes in comments to be executed. This happens because the plugin renders comments without properly filtering or moderating them. As a result, unauthenticated users can exploit this vulnerabili...
PoC for CVE-2026-84224
The Kirki WordPress plugin prior to version 6.3.2 contains a flaw that fails to properly validate the host of a provided URL before making a fetch request. This oversight allows users with at least editor-level permissions to send requests to internal services that should ideally be unreachable f...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-93548
The FooSales plugin for WordPress, prior to version 1.43.3, contains a serious vulnerability that allows any authenticated user to impersonate other users, including administrators. This flaw arises from the lack of proper verification to establish if a user is authorized to act on behalf of anot...
PoC for CVE-2026-106097
The Code Snippets plugin for WordPress, prior to version 3.10.0, contains a SQL Injection vulnerability due to improper sanitization and escaping of user-supplied parameters in certain snippet-migration import endpoints. This flaw is particularly concerning for environments utilizing WordPress Mu...
PoC for CVE-2026-87841
The UnitechPay WordPress plugin version 1.0.6.3 suffers from a significant flaw where it fails to authenticate payment notifications. This vulnerability allows attackers to mark orders as paid without any legitimate payment being processed, in addition to the ability to arbitrarily change the sta...
PoC for CVE-2025-15700
The AWP Classifieds plugin for WordPress prior to version 4.4.9 has a significant vulnerability in its listing-import feature. It fails to properly validate the type of files that users can extract from uploaded ZIP archives. Consequently, users with management capabilities can upload arbitrary P...
PoC for CVE-2026-106095
The Code Snippets plugin for WordPress, prior to version 3.10.0, contains a vulnerability that allows an administrator of a single subsite within a multisite network to manipulate snippets for the entire network. This occurs because the plugin does not conduct a proper capability check on certain...
PoC for CVE-2026-92989
The SendPress Newsletters plugin for WordPress fails to adequately restrict user capabilities when managing newsletters. Authenticated users with subscriber-level access can exploit this oversight, allowing them to synchronize all site users into a mailing list and manipulate the newsletter sendi...
PoC for CVE-2026-92990
The SendPress Newsletters plugin for WordPress contains a security flaw where it secures a logging endpoint with a hardcoded token, consistent across all installations. This design flaw allows unauthorized users to access sensitive newsletter sending logs. Consequently, attackers could obtain inf...
PoC for CVE-2026-86850
The SKU Error Fixer for WooCommerce WordPress plugin allows unauthenticated users to execute certain AJAX actions without performing necessary capability or nonce checks. This oversight enables malicious actors to permanently delete product variations deemed obsolete and exposes sensitive details...
PoC for CVE-2026-88931
The Social Web Suite plugin for WordPress prior to version 4.1.12 contains a vulnerability that fails to restrict unverified access to its configuration settings. This oversight allows attackers to exploit an unauthenticated endpoint to manipulate arbitrary plugin options, including critical ones...
PoC for CVE-2026-91940
The crawl4ai tool prior to version 0.9.3 has a vulnerability where the PDFContentScrapingStrategy's _filter_untrusted_fields function fails to properly validate untrusted configuration fields. This flaw enables attackers to submit specially crafted configuration bodies, potentially containing mal...
Discovered 2 days ago
PoC for CVE-2026-92555
The AKINSOFT WOLVOX Control Panel contains a vulnerability that allows sensitive information to be inserted into data sent by the application. This exposure enables unauthorized access to system resources, highlighting the need for users to update to the latest version to mitigate potential risks...
PoC for CVE-2026-21589
This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerat...
PoC for CVE-2021-30535
A double free vulnerability exists in the International Components for Unicode (ICU) library within Google Chrome versions prior to 91.0.4472.77. This flaw allows a remote attacker to potentially exploit heap corruption by crafting a malicious HTML page. Successful exploitation could lead to arbi...
PoC for CVE-2026-11318
Deskin versions up to 3.3.4.3 have a significant vulnerability in the com.deskin.service.installer XPC service. This flaw allows local unprivileged attackers to connect to the root-owned service without authentication, enabling them to execute arbitrary installer packages as the root user. By exp...