Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 16 minutes ago
PoC for CVE-2026-67919
A vulnerability in Halo version 2.25.4 permits remote attackers to execute arbitrary code. This security flaw arises from the PluginEndpoint.java and installFromUri method, along with the DefaultPluginApplicationContextFactory components. Exploitation of this vulnerability could enable unauthoriz...
Discovered 46 minutes ago
PoC for CVE-2026-54121
A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...
Discovered 2 hours ago
PoC for CVE-2026-15748
The Forminator Forms plugin for WordPress is susceptible to an arbitrary file upload attack due to inadequate file type validation in the handle_file_upload function. Attackers can exploit this vulnerability by using specially crafted MIME types that bypass the system's dangerous-extension blockl...
PoC for CVE-2026-61241
An exploitable vulnerability exists in the Oracle Internet Directory component of Oracle Fusion Middleware. This issue permits an unauthenticated attacker with network access via LDAP to potentially compromise the Oracle Internet Directory, enabling them to take control over the system. Notably, ...
PoC for CVE-2026-76761
A security flaw has been found in the Management API of chenhg5 cc-connect, specifically in the shellExecCommand function located in core/engine.go. This vulnerability allows an attacker to manipulate the exec argument, leading to OS command injection. The exploit can be executed remotely, raisin...
Discovered 3 hours ago
PoC for CVE-2026-76760
A code injection vulnerability exists in the chenhg5 cc-connect software up to version 1.4.1, specifically within the Authenticate function of core/webhook.go. This vulnerability allows attackers to manipulate the argument 'exec', potentially enabling remote code execution. The vulnerability has ...
PoC for CVE-2026-76591
A security flaw has been identified in the TRENDnet TEW-755AP wireless access point, specifically impacting the 'log_email_server' functionality within the '/cgi-bin/email.cgi' component, identified as 'ssi'. This vulnerability allows attackers to execute arbitrary commands on the device remotely...
Discovered 4 hours ago
PoC for CVE-2026-41940
The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...
PoC for CVE-2026-76590
A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-755AP that affects the ssi component, specifically through the '/cgi-bin/wan.cgi' functionality. By manipulating the 'cameo.wan.wan_pppoe_password_00' argument, an attacker can exploit the vulnerability remotely. Publicly avai...
PoC for CVE-2026-76589
A vulnerability has been identified in the TRENDnet TEW-755AP that allows for a stack-based buffer overflow due to improper handling of the SSID argument in the /sbin/mycli file, specifically within the FUN_401000 function. This security flaw can potentially be exploited remotely, enabling attack...
PoC for CVE-2026-76584
A vulnerability in the TRENDnet TV-IP751WIC webcam can be exploited through an insecure file index at /cgi-bin/admin/set_time.cgi, specifically within the alphapd component. The flaw allows an attacker to manipulate the 'Currenttime' argument, leading to a stack-based buffer overflow. This remote...
Discovered 5 hours ago
PoC for CVE-2026-76582
A command injection vulnerability exists in the TRENDnet TEW-821DAP due to improper handling of the 'ipaddr' argument in the /cgi-bin/ping.cgi script within the ssi component. This flaw allows attackers to execute arbitrary system commands remotely, posing a significant risk to users. As the expl...
PoC for CVE-2026-76576
A path traversal vulnerability exists in the RuoYi-Vue framework affecting versions up to 3.9.2. This security flaw is located within the fileDownload/resourceDownload function of the Common Download Endpoint, specifically in CommonController.java. By manipulating the fileName/resource arguments,...
PoC for CVE-2026-76574
A vulnerability exists in the Hospital Information System version 1.0, specifically in the User::login function within the UsersController.php file. This flaw permits attackers to manipulate the email argument, thereby leading to SQL injection vulnerabilities. The exploitation of this issue can b...
Discovered 6 hours ago
PoC for CVE-2026-47858
A security vulnerability exists in Spring Tools that enables attackers to execute arbitrary code remotely via JMX when live information mode is enabled. This affects users of Spring Tools for Eclipse version 5.2.0 and earlier, as well as Spring Tools for VSCode, Cursor, and Theia version 2.2.0 an...
Discovered 8 hours ago
PoC for CVE-2026-61518
The ISPConfig Remote API is susceptible to an authenticated SQL injection vulnerability stemming from improper handling of the primary_id parameter in SQL queries. This flaw allows users with low-privilege permissions to manipulate SQL queries directly, enabling the injection of malicious payload...
Discovered 9 hours ago
PoC for CVE-2026-73072
Vim, a widely used open-source command line text editor, is susceptible to a heap overflow vulnerability due to improper handling of certain spell file sections. Specifically, prior to version 9.2.0846, the function set_sofo() failed to reset values in sl_sal_first[], which can lead to under-coun...
Discovered 12 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-75148
The cgltf library, up to version 1.15, is prone to an integer overflow vulnerability within the cgltf_validate() function. This vulnerability can be exploited by remote attackers who supply specially crafted .gltf or .glb files with malicious accessor count values. The flawed bounds check allows ...
PoC for CVE-2024-8068
Security researchers have discovered critical vulnerabilities in Citrix Virtual Apps and Desktops that could potentially allow remote code execution (RCE) attacks. The vulnerabilities tracked as CVE-2024-8068 and CVE-2024-8069 affect the Session Recording component of Citrix Virtual Apps and Desk...
Discovered 15 hours ago
PoC for CVE-2018-1058
A vulnerability exists in PostgreSQL that enables a user to manipulate the behavior of database queries for others. An attacker with a valid user account can exploit this flaw to execute code with superuser privileges, potentially compromising the integrity and security of the database system. Th...
Discovered 16 hours ago
PoC for CVE-2026-34486
A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...
PoC for CVE-2026-18504
A schema validation bypass in the Fastify web framework can allow unvalidated request bodies to reach the application logic. Affected versions prior to 5.12.1 fail to replace the root request body with a coerced value when a request body schema targets a top-level primitive. This allows invalid d...
Discovered 19 hours ago
PoC for CVE-2026-19416
The KiviCare WordPress plugin, prior to version 4.5.4, lacks sufficient checks to ensure that users are authorized to modify appointments. This flaw allows authenticated patients to manipulate other patients' appointments by canceling or rescheduling them without proper permissions. As a result, ...
PoC for CVE-2026-19782
The WPS Bidouille plugin for WordPress prior to version 1.33.5 lacks adequate authorization checks in an AJAX action, potentially allowing any authenticated user—such as a subscriber—to access and retrieve the email addresses of all registered users. This vulnerability raises significant privacy ...
PoC for CVE-2026-19842
The SAML Single Sign On WordPress plugin, prior to version 5.4.7, contains a serious security flaw that fails to adequately verify the signature of SAML responses before storing the accompanying certificate. This oversight allows an admin-level user to inadvertently promote an unverified certific...
PoC for CVE-2026-19709
The Membership for WooCommerce plugin prior to version 3.1.2 lacks adequate validation to ensure an API consumer secret is generated before allowing access to its REST API routes. This oversight permits unauthenticated attackers to exploit the API, potentially revealing sensitive user membership ...
PoC for CVE-2026-19417
The KiviCare WordPress plugin, versions prior to 4.5.4, is susceptible to an unrestricted file download vulnerability. This security flaw arises from the plugin's failure to properly verify if an authenticated user has the right to access specific media files. As a result, patient-level users may...
PoC for CVE-2026-18779
The TrueBooker WordPress plugin, prior to version 1.2.7, contains a security flaw that lacks appropriate authorization checks in one of its AJAX actions. This vulnerability enables unauthenticated users to potentially delete any appointment records, along with related booking items and payment da...
PoC for CVE-2026-18937
The Broken Link Checker plugin for WordPress, prior to version 2.4.12, is susceptible to a serious security vulnerability. This issue arises from the lack of restrictions on the query variables that the plugin accepts from user input on sites employing plain permalinks. As a result, unauthenticat...
PoC for CVE-2026-19406
The Easy Appointments plugin for WordPress, prior to version 4.0.1, is affected by a vulnerability that permits users with contributor-level access to read and retrieve all appointment records through an unsecured REST endpoint. This oversight exposes sensitive information, including customer nam...
PoC for CVE-2026-19055
The ProSolution WP Client plugin for WordPress contains a reflected Cross-Site Scripting (XSS) vulnerability that can be exploited by attackers. The issue arises from the plugin's failure to adequately sanitize and escape numerous parameters before incorporating them into HTML attributes on publi...
PoC for CVE-2026-19056
The ProSolution WP Client plugin for WordPress, prior to version 2.0.11, contains a flaw that allows for reflected Cross-Site Scripting (XSS). This weakness arises from the improper sanitization and escaping of a parameter that is reflected in an HTML attribute on one of its administrative pages....
PoC for CVE-2026-18466
The WP Maps plugin for WordPress, before version 4.9.8, is susceptible to an improper capability check that does not validate user permissions during certain AJAX actions. This flaw permits users with a Subscriber account to create an unlimited number of options within the database, leading to po...
PoC for CVE-2026-18777
The TrueBooker WordPress plugin, prior to version 1.2.7, is susceptible to an authorization bypass vulnerability in its AJAX actions. This flaw permits unauthenticated users to manipulate the status of any appointment and trigger notification emails to clients involved. Such unauthorized access c...
PoC for CVE-2026-18778
The TrueBooker WordPress plugin prior to version 1.2.7 lacks essential authorization checks in specific AJAX actions. This vulnerability permits unauthorized users to access sensitive customer information, including names, email addresses, phone numbers, and postal addresses, associated with appo...
PoC for CVE-2026-18776
The TrueBooker plugin for WordPress prior to version 1.2.7 contains a significant vulnerability due to inadequate authorization checks within specific AJAX actions. This flaw enables unauthenticated users to alter the email addresses of any user accounts, including those of administrators. By cha...
PoC for CVE-2026-17565
The Animation Addons for Elementor WordPress plugin prior to version 2.7.2 is susceptible to a server-side request forgery (SSRF) vulnerability. This occurs when the plugin fails to validate a user-supplied input, enabling unauthorized users to create HTTP requests to internal resources on the se...
PoC for CVE-2026-18031
The TabaPay Gateway WordPress plugin, up to version 1.4.0, lacks proper validation of payment callbacks. This failure allows attackers to bypass authentication measures, granting them unauthorized access to the accounts of registered users, including administrative accounts. Such vulnerabilities ...
PoC for CVE-2026-18231
A vulnerability exists in the WP Directory Kit WordPress plugin, prior to version 1.5.7, that lacks proper authorization checks on a public AJAX action. This flaw allows unauthorized attackers to query unfiltered database rows, potentially exposing sensitive user data such as usernames and email ...
PoC for CVE-2026-18202
The JetEngine WordPress plugin prior to version 3.8.14 permits the inclusion of SVG files in the allowed upload types without proper sanitization of the file contents. This vulnerability enables users, such as Authors with file upload capabilities, to upload files containing malicious JavaScript....
PoC for CVE-2026-18051
The W3 Total Cache plugin for WordPress prior to version 2.10.5 contains a vulnerability due to improper validation of request paths. This flaw permits unauthenticated attackers to write files to any directory on the server, potentially overwriting existing files, including critical configuration...
PoC for CVE-2026-16979
The SmartCrawl SEO plugin for WordPress, prior to version 3.16.3, has a security flaw that allows users with a Subscriber role to bypass capability checks on certain AJAX actions. This vulnerability enables these users to access titles of private and draft posts by their ID, as well as enumerate ...
PoC for CVE-2026-16570
The NextScripts Social Networks Auto-Poster WordPress plugin prior to version 4.4.8 is susceptible to reflected Cross-Site Scripting (XSS) due to improper escaping of certain query-string parameters. This vulnerability can be exploited by malicious actors to craft special links that, when clicked...
PoC for CVE-2026-16617
The Simple File List plugin for WordPress, up to version 6.3.11, is susceptible to a stored cross-site scripting vulnerability. This arises from the plugin's failure to adequately sanitize and escape file descriptions before displaying them on the public file list. When front-end file management ...
PoC for CVE-2026-16950
The Product Shortlist plugin for WordPress, up to version 1.0.4, is susceptible to SQL injection due to inadequate sanitization and escaping of user input. This vulnerability enables an attacker without authentication to execute malicious SQL queries, potentially compromising the database and exp...
PoC for CVE-2026-16616
The Simple File List WordPress plugin through version 6.3.11 is vulnerable due to its failure to validate the source path during file-move operations. This issue allows unauthenticated users to access arbitrary files on the server. Moreover, it enables them to move critical files out of the web r...
PoC for CVE-2026-15253
The Easy Media Replace plugin for WordPress, through version 0.2.0, contains a vulnerability that allows arbitrary web scripts to be injected into HTML attributes. This occurs because the plugin fails to adequately sanitize and escape attachment titles before rendering them in the media library l...
PoC for CVE-2026-14861
The User Verification by PickPlugins plugin for WordPress, specifically versions up to 2.0.47, reveals a significant security flaw. This issue arises from the plugin's failure to authenticate requests for resending verification emails. As a result, unauthorized users can manipulate the email-veri...
PoC for CVE-2026-16058
The YayCurrency WordPress plugin prior to version 3.3.5 fails to implement necessary capability and ownership checks in its multi-vendor integration handlers. This oversight allows unauthenticated users to access sensitive data, including order totals, vendors' earnings, balance ledgers, and with...