Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 6 hours ago

PoC for CVE-2026-31431

LinuxLinux🟣 EPSS 100%7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 7 hours ago

PoC for CVE-2026-6471

PostgreSQLPostgresql7.2HIGH
PostgreSQL Logical Decoding Vulnerability Affecting Multiple Versions

A security vulnerability exists in PostgreSQL's logical decoding feature, where a non-superuser with REPLICATION privileges can exploit missing authorization. This flaw enables the execution of arbitrary code by allowing access to any file that is visible to the operating system account running t...

Discovered 8 hours ago

PoC for CVE-2026-19516

GrafanaGrafana Mcp Server9.1CRITICAL
Server-Side Request Forgery in mcp-grafana Affects Grafana by Grafa...

mcp-grafana allows an attacker to manipulate the X-Grafana-URL request header, which can direct outbound requests to unintended internal destinations, including sensitive network services and metadata endpoints. This oversight permits attackers to exploit the system for unauthorized data access, ...

Discovered 9 hours ago

PoC for CVE-2026-85704

Ramon-victorFreegpt-webui6.3MEDIUM
Race Condition Vulnerability in Ramon-Victor FreeGPT-WebUI

A security flaw has been identified in the Ramon-Victor FreeGPT-WebUI, specifically in the Jailbreak Mode component. This vulnerability arises from a race condition in the getJailbreak function within the server/config.py file. Given its complexity, the attack can be executed remotely, posing sig...

PoC for CVE-2026-85703

Ramon-victorFreegpt-webui6.9MEDIUM
Improper Access Control in Ramon-Victor FreeGPT-WebUI Jailbreak Mode

A vulnerability exists in the Ramon-Victor FreeGPT-WebUI related to the Jailbreak Mode component. Specifically, a flaw in the getJailbreak function found in the server/backend.py file allows for remote manipulation, potentially leading to undesired allocation of system resources. This issue affec...

PoC for CVE-2026-85702

Ramon-victorFreegpt-webui6.9MEDIUM
Missing Authentication in Ramon-Victor FreeGPT-WebUI Backend API

A security issue exists in the Ramon-Victor FreeGPT-WebUI that affects the Backend Conversation API, specifically the _conversation function in server/backend.py. This vulnerability allows an attacker to manipulate the model argument, which can result in missing authentication checks. The exploit...

PoC for CVE-2026-85046

GoogleChrome8.8HIGH
Type Confusion Vulnerability in Google Chrome

A type confusion vulnerability has been identified in the V8 JavaScript engine of Google Chrome. Prior to version 152.0.7977.82, this flaw allows malicious attackers to execute arbitrary code within the browser's sandbox environment by crafting a specially designed HTML page. This vulnerability p...

PoC for CVE-2026-85701

Ramon-victorFreegpt-webui6.9MEDIUM
Authentication Vulnerability in ramon-victor freegpt-webui Product

A vulnerability exists in the ramon-victor freegpt-webui affecting the ChatCompletion.create function within the authentication check component found in g4f/__init__.py. This manipulation results in missing authentication, allowing remote attackers to exploit the flaw. The product operates under ...

Discovered 10 hours ago

PoC for CVE-2026-85643

Code-projectsOnline Shopping System5.1MEDIUM
SQL Injection Vulnerability in Code-Projects Online Shopping System

A vulnerability exists in the Online Shopping System by Code-Projects, specifically in the admin/adduser.php file's mysqli_query function. By manipulating the 'mobile' argument, an attacker can execute SQL injection attacks, potentially allowing unauthorized access or data manipulation. The explo...

Discovered 11 hours ago

PoC for CVE-2026-85639

JofpinTrape6.3MEDIUM
Telemetry Endpoint Vulnerability in jofpin trape Software

A security vulnerability has been identified within the jofpin trape 2.0 software that affects the telemetry endpoint feature. Specifically, the issue lies in the core/user.py file, where improper handling of the vId argument can lead to a race condition. This weakness allows an attacker to explo...

PoC for CVE-2026-85638

JofpinTrape6.9MEDIUM
Authorization Bypass in jofpin Trape 2.0 Affecting User Management

A vulnerability in jofpin Trape 2.0 has been discovered in the file core/user.py, allowing unauthorized access through argument manipulation of vId/id. This flaw enables remote exploitation, offering attackers potential access to sensitive functionalities without proper authorization. Despite bei...

PoC for CVE-2026-80119

Passmark SoftwarePerformancetest8.5HIGH
Information Disclosure Vulnerability in PassMark Products

An information disclosure vulnerability exists in DirectIo64.sys, affecting several PassMark products. Local attackers can exploit this vulnerability by supplying a caller-controlled file path to an exposed IOCTL mechanism. This allows the attacker to dump complete physical memory contents, inclu...

PoC for CVE-2026-85637

JofpinTrape6.9MEDIUM
Missing Authentication in jofpin trape Admin Endpoint

A security vulnerability has been identified in jofpin trape affecting versions 1.0.0 and 2.0. This flaw is located in the 'join_room' function of the 'core/sockets.py' component, which lacks sufficient authentication controls. As a consequence, an attacker may exploit this weakness to gain unaut...

Discovered 12 hours ago

PoC for CVE-2026-85636

JofpinTrape6.9MEDIUM
Missing Authentication in jofpin trape Affects Login Functionality

A vulnerability has been identified in the jofpin trape version 1.0.0, affecting the functionality of the file core/stats.py within the Login Endpoint. This flaw allows unauthorized remote access due to missing authentication measures, posing significant security risks. The exploit is publicly av...

PoC for CVE-2026-82329

JfrogArtifactory9.8CRITICAL
Authentication Weakness in JFrog Artifactory Affects Unauthenticate...

JFrog Artifactory has a significant authentication weakness that could permit an attacker with network access to gain administrative privileges without authentication, particularly when the product is left in its default configuration. This vulnerability can expose sensitive resources and operati...

PoC for CVE-2020-5741

PlexPlex Media Server (win...🟣 EPSS 73%7.2HIGH
Deserialization Vulnerability in Plex Media Server by Plex

A security flaw in Plex Media Server for Windows enables remote, authenticated attackers to exploit deserialization of untrusted data. This vulnerability allows the execution of arbitrary Python code, potentially compromising the system’s security. Users are urged to update their software to miti...

PoC for CVE-2026-85046

GoogleChrome8.8HIGH
Type Confusion Vulnerability in Google Chrome

A type confusion vulnerability has been identified in the V8 JavaScript engine of Google Chrome. Prior to version 152.0.7977.82, this flaw allows malicious attackers to execute arbitrary code within the browser's sandbox environment by crafting a specially designed HTML page. This vulnerability p...

Discovered 14 hours ago

PoC for CVE-2026-44402

Voltronic PowerSnmp Web Pro9.3CRITICAL
Unauthenticated Remote Code Execution in Voltronic Power SNMP Web Pro

The Voltronic Power SNMP Web Pro 1.1 is susceptible to an unauthenticated remote code execution vulnerability through the upload.cgi firmware update interface. This flaw enables remote attackers to execute commands with root privileges simply by uploading a specially crafted tar archive, bypassin...

Discovered 15 hours ago

PoC for CVE-2026-6958

Invicti Security ...Acunetix8.5HIGH
Local Privilege Escalation Vulnerability in Acunetix for Windows

A local privilege escalation vulnerability exists in Acunetix 25.11.251107123 due to the missing hardcoded directory path for OpenSSL-related files in the Web Vulnerability Scanning Engine (wvsc.exe). Low-privileged local attackers can exploit this flaw by creating the missing directory and placi...

PoC for CVE-2026-6958

Invicti Security ...Acunetix8.5HIGH
Local Privilege Escalation Vulnerability in Acunetix for Windows

A local privilege escalation vulnerability exists in Acunetix 25.11.251107123 due to the missing hardcoded directory path for OpenSSL-related files in the Web Vulnerability Scanning Engine (wvsc.exe). Low-privileged local attackers can exploit this flaw by creating the missing directory and placi...

Discovered 16 hours ago

PoC for CVE-2025-8518

GivanzVvveb5.1MEDIUM
Code Injection Vulnerability in Vvveb 1.0.5 by Givanz

A code injection vulnerability has been identified in the Vvveb 1.0.5 Code Editor component, specifically within the Save function of the file admin/controller/editor/code.php. This flaw allows an attacker to execute arbitrary code remotely, significantly compromising the security of affected sys...

PoC for CVE-2026-85522

Valkey-ioValkey6.9MEDIUM
Out-of-Bounds Read Vulnerability in Valkey Slot Migration by Valkey-IO

A security flaw has been identified in the Valkey component related to Slot Migration, specifically within the createSlotImportJob function of the src/cluster_migrateslots.c file. This vulnerability allows a malicious actor to manipulate the job_name argument, leading to out-of-bounds read condit...

PoC for CVE-2026-85517

Code-projectsVehicle Management System6.9MEDIUM
Information Disclosure in Code-Projects Vehicle Management System S...

A security flaw exists in the code-projects Vehicle Management System version 1.0, specifically within an unknown function related to the SQL Database Backup File Handler. This vulnerability allows for remote exploitation, leading to potential information disclosure. Malicious actors could manipu...

Discovered 17 hours ago

PoC for CVE-2026-85516

Code-projectsVehicle Management System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Vehicle Management System

A vulnerability has been identified in the Vehicle Management System version 1.0 developed by Code-Projects. An SQL injection flaw exists in an unspecified function within the file /busprofile.php. This vulnerability allows attackers to manipulate the 'busid' argument, enabling them to execute un...

PoC for CVE-2020-1938

ApacheApache Tomcat🟣 EPSS 99%9.8CRITICAL
Apache Tomcat AJP Connector Insecure Configuration Vulnerability

The Apache JServ Protocol (AJP) Connector in Apache Tomcat allowed for misconfigured connections that could be exploited by attackers. By default, the AJP Connector is enabled, listening on all configured IP addresses. This elevated trust can lead to unauthorized access and manipulation of files ...

PoC for CVE-2026-85514

StackstormSt25.3MEDIUM
Improper Privilege Management in StackStorm API Key Handler

A vulnerability has been identified in the StackStorm st2 API Key Handler, affecting versions up to 3.9.0. This issue arises from an unidentified flaw in the file st2api/st2api/controllers/v1/auth.py, specifically concerning the manipulation of the api_key_api.user argument, leading to improper p...

PoC for CVE-2026-85513

StackstormSt25.3MEDIUM
Improper Privilege Management in StackStorm st2 by OpenStack

A vulnerability has been identified in StackStorm st2 versions up to 3.9.0, specifically in the NoOp RBAC backend. The flaw lies within the function handling user privileges, which can be exploited remotely due to improper management of user authorization. Attackers can manipulate user query para...

Discovered 19 hours ago

PoC for CVE-2026-85512

SourcecodesterClass And Exam Timetab...6.9MEDIUM
Missing Authorization in SourceCodester Class and Exam Timetabling ...

The SourceCodester Class and Exam Timetabling System 1.0 contains a security flaw located in the /admin/session.php file, where improper handling of the argument ID leads to missing authorization. This vulnerability allows an attacker to exploit the system remotely, potentially gaining unauthoriz...

Discovered 20 hours ago

PoC for CVE-2026-31787

LinuxLinux
Double Free Vulnerability in Linux Kernel Affecting Xen Privileged ...

A vulnerability exists in the Linux kernel's privcmd module that can lead to a double free situation due to improper management of virtual memory areas (VMAs). When a partial unmap operation is performed on a privcmd mapping, the kernel can erroneously split the VMA without the necessary controls...

PoC for CVE-2026-84045

WordPressE-cab Taxi Booking Man...5.3MEDIUM
Input validation issue in E-cab Taxi Booking Manager for Woocommerc...

The E-cab Taxi Booking Manager for WooCommerce plugin prior to version 2.0.5 lacks necessary validation for client-supplied trip distance and base price values. This oversight permits unauthenticated users to exploit the system, allowing them to set the order total to zero. Consequently, attacker...

PoC for CVE-2026-84044

WordPressRestaurant Menu And Fo...5.3MEDIUM
Insufficient PayPal Payment Notification Verification in Restaurant...

The Restaurant Menu and Food Ordering WordPress plugin, prior to version 2.4.12, is vulnerable due to its failure to validate PayPal payment notifications. This oversight allows attackers to exploit the system by submitting fraudulent payment notifications, thereby marking their orders as paid wi...

PoC for CVE-2026-82923

WordPressAi Website Builder (gi...9.8CRITICAL
Authorization Bypass in AI Website Builder Plugin for WordPress

The AI Website Builder plugin for WordPress (version 1.0.0) is susceptible to an authorization bypass vulnerability due to the absence of authentication checks on its REST API routes. This flaw permits unauthenticated attackers to carry out a range of malicious activities, such as installing and ...

PoC for CVE-2026-84043

WordPressEpayco Payment Gateway...5.3MEDIUM
Payment Gateway Authentication Flaw in ePayco for WooCommerce by Wo...

The ePayco Payment Gateway for WooCommerce WordPress plugin prior to version 8.4.7 features a critical flaw in its payment confirmation request verification process. This vulnerability allows unauthenticated attackers to fraudulently mark orders as paid without a valid signature from the payment ...

Discovered 21 hours ago

PoC for CVE-2026-20212

CiscoCisco Nx-os Software9.8CRITICAL
Remote Code Execution Vulnerability in Cisco Nexus 9000 Series Swit...

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches permits unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability arises from the accessibility of TCP ports 43210 and 43211 within the default Layer 3 (L3) virtual routin...

Discovered 23 hours ago

PoC for CVE-2023-54391

Proxmox Server So...Proxmox Virtual Enviro...9.3CRITICAL
Authentication Bypass Vulnerability in Proxmox Virtual Environment

Proxmox Virtual Environment versions from 7.0 to 8.0 are affected by an authentication bypass vulnerability in the libpve-access-control component. Attackers can exploit this vulnerability by sending an arbitrary tfa-challenge value to the API login endpoint, which allows them to bypass password ...

Discovered 1 day ago

PoC for CVE-2026-84066

WordPressDirectorist: Ai-powere...3.1LOW
Insecure Permissions in Directorist Plugin for WordPress

The Directorist plugin for WordPress prior to version 8.9 has a security vulnerability that does not adequately verify whether a user requesting to modify a post's metadata is the actual owner of that post. This oversight allows users with subscriber-level permissions and above to modify image me...

PoC for CVE-2026-84146

WordPressXpro Addons — 140+ Wid...5.3MEDIUM
Information Exposure in Xpro Addons for Elementor Plugin by WordPress

The Xpro Addons for Elementor WordPress plugin prior to version 1.7.8 is susceptible to information exposure due to a lack of proper capability checks. This flaw permits unauthenticated users to access detailed information about WooCommerce products, including title, price, SKU, description, and ...

PoC for CVE-2026-82194

WordPressWPvivid — Backup, Migr...5.5MEDIUM
File Deletion Vulnerability in WPvivid Backup WordPress Plugin

A vulnerability exists in the WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.134, allowing unauthorized file deletions. The plugin fails to properly validate user-supplied paths in its file deletion routine. As a result, an attacker, potentially an administrator, ca...

PoC for CVE-2026-80438

WordPressNinja Forms5.9MEDIUM
Access Control Flaw in Ninja Forms Plugin by WordPress

The Ninja Forms plugin for WordPress, up to version 3.15.2, has a significant access control issue that allows unauthorized users with specific capabilities to access sensitive data. This vulnerability enables such users to read the plugin's configuration settings and stored form submissions. Fur...

PoC for CVE-2026-82186

WordPressWPlp Cookie Consent4.1MEDIUM
SQL Injection Vulnerability in WPLP Cookie Consent Plugin by WordPress

The WPLP Cookie Consent plugin for WordPress prior to version 4.4.2 has a flaw in the validation of the pagination parameter utilized in SQL queries. This vulnerability enables users with administrative access to execute malicious SQL queries, potentially compromising the database. Administrators...

PoC for CVE-2026-82193

WordPressWPvivid — Backup, Migr...5.5MEDIUM
File Write Vulnerability in WPvivid Plugin by WPvivid Team

The WPvivid Backup, Migration & Staging plugin for WordPress allows an attacker with administrative access to exploit insufficient validation of user-supplied file names. This leads to arbitrary file write capabilities, permitting administrators to save files to unintended locations on the server...

PoC for CVE-2026-81347

WordPressFrontend Admin By Dyna...5.9MEDIUM
Directory Traversal Vulnerability in Frontend Admin by DynamiApps

The Frontend Admin plugin for WordPress, developed by DynamiApps, has a vulnerability that allows unauthenticated attackers to exploit improper validation of user-controllable directory paths. This flaw permits the deletion of critical files such as index.php and .htaccess, which can severely dis...

PoC for CVE-2026-79632

WordPressWPfunnels5.3MEDIUM
Authorization Flaw in WPFunnels Plugin for WordPress

The WPFunnels WordPress plugin before version 3.13.0 has a significant vulnerability that lacks proper authorization or nonce checks in an opt-in submission handler. This oversight enables unauthenticated users to exploit the system, potentially sending emails to any recipient with a chosen subje...

PoC for CVE-2026-79631

WordPressWPfunnels5.3MEDIUM
Access Control Vulnerability in WPFunnels WordPress Plugin

The WPFunnels plugin for WordPress prior to version 3.13.0 features an access control oversight, permitting unauthenticated users to download sensitive log files stored in a predictable location within the public uploads directory. This issue arises when logging is enabled, potentially exposing c...

PoC for CVE-2026-19224

WordPressHummingbird Performance7.2HIGH
Arbitrary Code Execution Vulnerability in Hummingbird Performance P...

The Hummingbird Performance plugin for WordPress is vulnerable due to improper restrictions on network-wide settings. This flaw enables an administrator of any individual site within a multisite network to execute arbitrary code, thereby compromising the entire network's security. This vulnerabil...

PoC for CVE-2026-74853

WordPressPods6.8MEDIUM
Vulnerability in Pods WordPress Plugin Allows Unauthorized File Access

The Pods WordPress plugin versions earlier than 3.3.9.2 have a vulnerability that permits users with the author role and higher to access unauthorized files on the server. This occurs due to insufficient restrictions on display callback functions, enabling the retrieval of arbitrary files, includ...

PoC for CVE-2026-79630

WordPressWPfunnels5.3MEDIUM
Checkout Order Bump Exploit in WPFunnels WordPress Plugin

The WPFunnels plugin for WordPress, prior to version 3.13.0, contains a security issue where it fails to properly verify that the product selected through a checkout order bump corresponds to the product intended for the discount. As a result, this flaw allows unauthenticated users to exploit the...

PoC for CVE-2026-16281

WordPressClassified Listing7.1HIGH
Improper Authorization in Classified Listing WordPress Plugin

The Classified Listing WordPress plugin before version 6.1.1 contains a vulnerability due to insufficient authorization checks. This flaw permits authenticated users, including those with minimal privileges such as subscribers, to execute AI image-editing actions via AJAX. Consequently, these use...

PoC for CVE-2026-17517

WordPressContent Views5.3MEDIUM
Access Control Flaw in Content Views WordPress Plugin by WordPress

The Content Views plugin for WordPress prior to version 4.5.1.2 is susceptible to an access control vulnerability. It fails to verify whether a user requesting a view has the appropriate permissions to access the posts it returns. As a result, unauthenticated attackers can gain access to the titl...

PoC for CVE-2025-15691

WordPressWPfunnels5.3MEDIUM
User Account Creation Vulnerability in WPFunnels Plugin by WordPress

The WPFunnels plugin for WordPress prior to version 3.13.0 has a vulnerability that permits unauthenticated attackers to create user accounts without verifying if user registration is enabled. This flaw stems from the plugin's reliance on request-supplied values, which compromises site security b...