Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-97286

WordPressStrong Testimonials6.5MEDIUM
Cross Site Scripting Vulnerability in Strong Testimonials Plugin by...

The Strong Testimonials plugin for WordPress contains a Cross Site Scripting (XSS) vulnerability that affects versions up to 3.3.11. An attacker could exploit this weakness to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions or data theft. Websi...

Discovered 4 hours ago

PoC for CVE-2025-6867

SourcecodesterSimple Company Website5.1MEDIUM
SQL Injection Flaw in SourceCodester Simple Company Website 1.0

A vulnerability exists within the SourceCodester Simple Company Website 1.0, specifically affecting the processing of the file /admin/services/manage.php. An attacker can exploit this vulnerability through a manipulation of the argument ID, enabling SQL injection attacks. This issue poses a risk ...

Discovered 7 hours ago

PoC for CVE-2025-21479

QualcommSnapdragon8.6HIGH
Memory Corruption Vulnerability in Qualcomm GPU Micronode

This vulnerability allows unauthorized command execution in the GPU micronode, leading to potential memory corruption when a specific sequence of commands is executed. Attackers could exploit this weakness to disrupt system functionality or gain access to sensitive areas of memory, posing risks t...

Discovered 9 hours ago

PoC for CVE-2026-105957

SourcecodesterPerformance Indicator ...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Performance Indicator...

A vulnerability affecting the SourceCodester Performance Indicator System 1.0 has been identified, which allows for SQL injection through the manipulation of the 'Category' argument in the /opils/admin/view_product.php file. This flaw facilitates remote exploitation, raising significant security ...

Discovered 10 hours ago

PoC for CVE-2026-105922

Vllm-projectVllm5.3MEDIUM
Denial of Service Vulnerability in vLLM by vllm-project

A security flaw has been identified in the vLLM product of vllm-project, affecting versions up to 0.31.0. This vulnerability is rooted in the function get_token_bin_counts_and_mask located in the utils.py file of the Penalty Handler component. An attacker could exploit this issue to manipulate th...

Discovered 11 hours ago

PoC for CVE-2026-105921

KusalkasilvaLearning-management-sy...5.3MEDIUM
SQL Injection Vulnerability in Kusalkasilva Learning-Management-Sys...

A vulnerability exists in the Kusalkasilva Learning-Management-System that allows an attacker to manipulate the argument 'school_year' via the file search_class.php. This SQL injection vulnerability can be exploited remotely, potentially leading to unauthorized access or modification of the syste...

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 100%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

Discovered 12 hours ago

PoC for CVE-2026-105920

KusalkasilvaLearning-management-sy...6.9MEDIUM
SQL Injection Vulnerability in Kusalkasilva Learning-Management-Sys...

The Kusalkasilva Learning-Management-System is subject to a SQL injection vulnerability in the student_signup.php file within the Student Registration Endpoint component. This vulnerability enables an attacker to execute arbitrary SQL queries, potentially compromising sensitive data. The vulnerab...

PoC for CVE-2026-105919

KusalkasilvaLearning-management-sy...6.9MEDIUM
SQL Injection Vulnerability in Kusalkasilva Learning-Management-Sys...

A SQL injection vulnerability has been identified in the Kusalkasilva Learning-Management-System, specifically within the Administrator Login Endpoint function mysql_query located in admin/login.php. By manipulating the arguments for the username and password, attackers can exploit this vulnerabi...

Discovered 13 hours ago

PoC for CVE-2026-105918

KusalkasilvaLearning-management-sy...6.9MEDIUM
SQL Injection Vulnerability in Kusalkasilva Learning-Management-Sys...

A vulnerability exists in the Kusalkasilva Learning-Management-System affecting the login endpoint's mysql_error function in the login.php file. By manipulating the username and password arguments, an attacker can perform SQL injection attacks remotely. Despite early notifications regarding this ...

Discovered 15 hours ago

PoC for CVE-2026-96940

MicrosoftMicrosoft Exchange Ser...8.8HIGH
Privilege Elevation Vulnerability in Microsoft Exchange Server

A weakness in the authorization mechanisms of Microsoft Exchange Server can be exploited by authenticated attackers, allowing them to gain elevated privileges over the network. This vulnerability poses significant risks as it can enable attackers to manipulate sensitive data or compromise additio...

Discovered 17 hours ago

PoC for CVE-2026-105809

SourcecodesterSimple Student Informa...5.3MEDIUM
Cross-Site Scripting in SourceCodester Simple Student Information S...

A cross-site scripting vulnerability has been identified in the SourceCodester Simple Student Information System 1.0. This issue specifically affects the processing of user input in the file /register.php, where the arguments 'firstname' and 'lastname' can be manipulated. This allows attackers to...

PoC for CVE-2026-105808

SourcecodesterSimple Student Informa...5.1MEDIUM
Cross Site Scripting Vulnerability in SourceCodester Simple Student...

A vulnerability exists in the SourceCodester Simple Student Information System version 1.0 within the searchresults.php file's clean function. This flaw allows for remote cross site scripting attacks through manipulation of the searchbox argument. Attackers can execute payloads that may compromis...

Discovered 18 hours ago

PoC for CVE-2026-105778

TendaAc59.4CRITICAL
Stack-Based Buffer Overflow in Tenda AC5 WiFi Handler

A vulnerability has been identified in the Tenda AC5 router, specifically within the Wifi Handler component at the /goform/setWifi endpoint. This flaw allows for manipulation of the wifiPwd argument, potentially leading to a stack-based buffer overflow. The exploitation of this vulnerability can ...

Discovered 19 hours ago

PoC for CVE-2026-86786

WordPressSlider Pro5.3MEDIUM
Authorization Bypass in Slider Pro for WordPress by Slider Revolution

The Slider Pro plugin for WordPress, up to version 1.0.0, contains a vulnerability that allows unauthenticated users to exploit an AJAX action without any capability or authorization checks. This could enable these users to access sensitive information such as the titles, excerpts, and permalinks...

PoC for CVE-2026-89289

WordPressFast Courier5.3MEDIUM
Unauthenticated REST Route Vulnerability in Fast Courier WordPress ...

The Fast Courier WordPress plugin, up to version 5.2.3, contains a significant security flaw that exposes a REST API endpoint without proper authentication. This vulnerability allows unauthorized attackers to modify order fulfillment data, including the courier status and customer-facing tracking...

PoC for CVE-2026-94278

WordPressFile Media Renamer5.5MEDIUM
Unauthorized Access in File Media Renamer Plugin for WordPress

The File Media Renamer plugin for WordPress has a flaw that fails to validate user authorization for modifying media attachments. This vulnerability allows any user with file-upload privileges to rename media files belonging to other users, including site administrators. As a result, it can lead ...

PoC for CVE-2026-94299

WordPressElegro Crypto Payment6.5MEDIUM
Unauthenticated Payment Confirmation Exploit in elegro Crypto Payme...

The elegro Crypto Payment WordPress plugin prior to version 1.0.1 has a serious security flaw that allows attackers to deceive the payment system. Specifically, it fails to enforce the requirement for a shared secret, enabling unauthorized individuals to send fraudulent payment notifications. As ...

PoC for CVE-2026-94271

WordPressDeema Payment Gateway5.3MEDIUM
Unauthenticated Payment Processing Issue in Deema Payment Gateway f...

The Deema Payment Gateway for WordPress, up to version 1.1.2, contains a vulnerability that permits unauthenticated users to mark orders as paid without any legitimate payment verification with the payment provider. This occurs due to the plugin's failure to verify the payment status or amount wh...

PoC for CVE-2026-94270

WordPressDeema Payment Gateway5.3MEDIUM
Payment Gateway Plugin Vulnerability in Deema by WordPress

The Deema Payment Gateway plugin for WordPress, up to version 1.1.2, has a significant security issue due to its failure to verify the authenticity of incoming payment provider notifications. This vulnerability occurs because the verification feature is disabled by default, enabling unauthorized ...

PoC for CVE-2026-105776

Bhagya3929Employee-movement-trac...6.9MEDIUM
SQL Injection Vulnerability in Employee-Movement-Tracking System by...

A vulnerability has been identified in the Employee-Movement-Tracking-and-Monitoring-Website developed by bhagya3929, specifically within the /admin_transaction.php file. The vulnerability arises from improper handling of the 'Username' argument, allowing remote attackers to exploit the system th...

PoC for CVE-2026-105775

Vllm-projectVllm5.3MEDIUM
Out-of-Bounds Read Vulnerability in vLLM by vllm-project

A security vulnerability has been identified in the vLLM software developed by vllm-project, specifically within the Completions Request Handler's conv_ssm_forward function. The flaw allows for out-of-bounds reading of memory, posing a significant security risk. This vulnerability can be exploite...

Discovered 20 hours ago

PoC for CVE-2026-105708

imgproxyImgproxy5.3MEDIUM
Cross Site Scripting Vulnerability in imgproxy by imgproxy

A vulnerability exists in imgproxy versions up to 4.0.17, specifically within the sanitizeElement function of the SVG Handler module located in the file processing/svg/svg.go. This flaw facilitates a cross site scripting (XSS) attack, enabling attackers to execute malicious scripts remotely. The ...

PoC for CVE-2026-105707

UptraceUptrace6.9MEDIUM
Information Exposure Vulnerability in Uptrace by Uptrace

A security vulnerability has been identified in the Uptrace product, specifically in the 'Login' function within the file pkg/org/user_handler.go. This issue allows for information exposure through error messages, potentially enabling remote attackers to gain sensitive information. Despite report...

PoC for CVE-2026-105706

SourcecodesterDrug Recommendation Sy...5.3MEDIUM
Cross-Site Request Forgery in SourceCodester Drug Recommendation Sy...

A vulnerability has been detected in SourceCodester Drug Recommendation System 1.0, which allows for cross-site request forgery (CSRF) attacks. This weakness occurs in an undisclosed function, enabling an attacker to manipulate requests from a remote location. The exploit is publicly available, p...

Discovered 21 hours ago

PoC for CVE-2026-105705

SourcecodesterDrug Recommendation Sy...5.3MEDIUM
Cross Site Scripting Vulnerability in SourceCodester Drug Recommend...

A security flaw has been identified in the SourceCodester Drug Recommendation System version 1.0, specifically targeting an unknown function within the file Admin/add_drug.php. This vulnerability allows attackers to perform cross site scripting (XSS) attacks, which can be executed remotely. The e...

PoC for CVE-2026-105704

SourcecodesterDrug Recommendation Sy...6.9MEDIUM
Improper Authentication Vulnerability in SourceCodester Drug Recomm...

The SourceCodester Drug Recommendation System 1.0 is vulnerable due to an improper authentication flaw in the Auth Guard component. An attacker can manipulate the user_id argument, allowing for unauthorized access. This vulnerability can be exploited remotely, with existing public exploits making...

PoC for CVE-2026-105703

PHPgurukulUser Registration & Lo...5.1MEDIUM
Authorization Flaw in PHPGurukul User Registration & Login System

A vulnerability was identified in the PHPGurukul User Registration & Login and User Management System version 3.3, specifically within the Change Password Handler located in loginsystem/admin/change-password.php. The flaw arises from the improper handling of the currentpassword argument, leading ...

Discovered 22 hours ago

PoC for CVE-2026-105621

JishenghuaJsherp5.3MEDIUM
Improper Authorization Vulnerability in jishenghua jshERP Financial...

A security flaw has been identified in the jishenghua jshERP software, specifically within the Financial Receipt Update Handler. The vulnerability resides in the updateAccountHeadAndDetail function of the AccountHeadService.java class. It allows an attacker to perform unauthorized actions remotel...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-105611

ChillzhuangSpringblade5.1MEDIUM
Improper Authorization in Chillzhuang SpringBlade User Detail Endpoint

A vulnerability has been identified in Chillzhuang's SpringBlade framework that affects the User Detail Endpoint within the RoleController.java file. This vulnerability arises from improper handling of argument ID manipulation, allowing remote attackers to gain unauthorized access to user details...

PoC for CVE-2026-105610

ChillzhuangSpringblade5.1MEDIUM
Improper Authorization in Chillzhuang SpringBlade Parameter Submit ...

A security vulnerability has been identified in the Chillzhuang SpringBlade framework, specifically within the Parameter Submit Management component. An improper authorization issue arises from the manipulation of the 'initPassword' argument in the ParamController.java file. This flaw allows for ...

PoC for CVE-2026-105573

Newbee-ltdNewbee-mall5.3MEDIUM
Business Logic Flaw in Newbee-Mall Shopping Cart by Newbee Ltd

A vulnerability exists in the Newbee-Mall's Shopping Cart Quantity Handler, affecting versions up to 2.7.5. This flaw lies within the updateAccountHeadAndDetail function, where improper handling of the 'goodsCount' argument can lead to unintended business logic errors. It poses a security risk as...

Discovered 23 hours ago

PoC for CVE-2026-93687

MicromatchBraces8.7HIGH
Stack Overflow Vulnerability in Micromatch Braces Product

The Micromatch braces library up to version 3.0.3 is susceptible to a stack overflow due to insufficient depth guarding in its recursive Abstract Syntax Tree (AST) walkers. Attackers can exploit this vulnerability by providing deeply nested brace patterns within the character limit, which may lea...

PoC for CVE-2026-105572

PickMallPickmall Lilishop5.3MEDIUM
Authorization Bypass in PickMall Lilishop Affects Buyer Invoice List

A significant vulnerability in PickMall's Lilishop, specifically in the Buyer Invoice List component, allows for an authorization bypass via manipulation of the 'memberId' parameter. This weakness enables attackers to potentially gain unauthorized access to sensitive functionalities, which can be...

PoC for CVE-2021-1931

QualcommSnapdragon Auto, Snapd...6.7MEDIUM
Buffer Overflow Vulnerability in Qualcomm Snapdragon Products

This security vulnerability is caused by improper validation of the buffer length when processing fast boot commands across various Qualcomm Snapdragon products. An attacker could exploit this flaw to execute arbitrary code or cause unintended behavior, potentially compromising the affected devices.

PoC for CVE-2026-105571

PickMallPickmall Lilishop6.9MEDIUM
Improper Authorization in PickMall Lilishop Affects Mobile Binding ...

A vulnerability in the PickMall Lilishop application version 4.2.4 and earlier has been identified, affecting the Mobile Binding component. The issue arises from an unspecified function within the '/buyer/passport/member/bindMobile' file, where inappropriate handling of the 'Username' argument ca...

PoC for CVE-2020-23546

IrfanviewIrfanview7.8HIGH
Denial of Service Vulnerability in IrfanView by Irfan Skiljan

IrfanView 4.54 has a vulnerability that allows attackers to trigger a denial of service or potentially other unspecified effects by using specially crafted XBM files. This issue arises when the application mishandles problematic data during processing, particularly at the point where it reads a m...

PoC for CVE-2026-105487

YogeshojhaRengine5.3MEDIUM
OS Command Injection in yogeshojha reNgine affecting its listTarget...

A vulnerability exists in the yogeshojha reNgine, particularly within the listTargets Endpoint's subdomain_discovery function in tasks.py. This flaw allows for OS command injection through improper argument handling. Attackers can exploit this vulnerability remotely, leading to potential unauthor...

Discovered 1 day ago

PoC for CVE-2026-105486

OssrsSrs6.9MEDIUM
Missing Authentication in OSSRS System API Affects Remote Functiona...

A vulnerability in OSSRS srs versions up to 7.0-a1 was identified that allows for missing authentication within the System API component, specifically in the function systemAPI.Run located at internal/proxy/api.go. This issue enables unauthorized remote access, which could be exploited by attacke...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-105471

GirishsarafOnline-appointment-boo...6.9MEDIUM
SQL Injection Vulnerability in girishsaraf Online-Appointment-Booki...

A security vulnerability has been identified in the girishsaraf Online-Appointment-Booking-System, particularly affecting the signup.php file within its Registration Handler component. This flaw allows attackers to manipulate the 'fname' parameter, leading to SQL injection vulnerabilities. As a r...

PoC for CVE-2026-105470

GirishsarafOnline-appointment-boo...6.9MEDIUM
SQL Injection Vulnerability in Online Appointment Booking System by...

A vulnerability has been discovered in the Online-Appointment-Booking-System created by girishsaraf. This security flaw is present in the Doctor Search Endpoint's locateus.php file, specifically within its mysqli_query function. An attacker can manipulate the 'doctorname' argument, potentially le...

PoC for CVE-2026-105469

GirishsarafOnline-appointment-boo...6.9MEDIUM
SQL Injection Vulnerability in girishsaraf Online-Appointment-Booki...

A vulnerability exists in the girishsaraf Online-Appointment-Booking-System that affects the AJAX Endpoint component. The flaw is found in the get_town.php file, where improper handling of parameters like countryid, townid, cid, didval, and cidval can lead to SQL injection attacks. Attackers may ...

PoC for CVE-2026-105468

GirishsarafOnline-appointment-boo...6.9MEDIUM
SQL Injection Vulnerability in girishsaraf Online-Appointment-Booki...

A critical vulnerability exists in the girishsaraf Online-Appointment-Booking-System that could allow attackers to execute arbitrary SQL queries via the 'uname' and 'pass' parameters in the Admin/mlogin.php file. This SQL injection vulnerability may be exploited remotely, putting user data at ris...

PoC for CVE-2026-105438

O2OAO2oa5.3MEDIUM
Server-Side Request Forgery in O2OA General Module

A vulnerability has been identified in the O2OA General Module, specifically in the action function responsible for uploading Excel files through a URL. This issue revolves around improper validation of the 'fileUrl' parameter, which could be exploited to carry out a server-side request forgery (...

PoC for CVE-2026-77226

CamundaCamunda 79.2CRITICAL
Authorization Flaw in Camunda Admin Web Application

An incorrect authorization flaw in the Camunda Admin web application's first-run setup endpoint allows an unauthenticated remote attacker to exploit the system when the camunda-admin group is empty. The vulnerability arises from the SetupResource's failure to accurately assess setup availability,...

PoC for CVE-2026-105392

LybbnDjango-vue-lyadmin6.9MEDIUM
Insecure JWT Signing Configuration in Lybbn Django-Vue-Lyadmin

A security flaw exists in the JWT Signing configuration of Lybbn Django-Vue-Lyadmin up to version 3.2.12, where the SECRET_KEY argument is hard-coded within the backend/application/settings.py file. This weakness allows for potential remote exploitation, as the hard-coded key can be manipulated. ...

PoC for CVE-2026-105389

Feelec-yishuFeelcrm-os5.3MEDIUM
Unrestricted Upload Vulnerability in Feelcrm-os by FeelEc-Yishu

A security flaw has been identified in the file UploadController.class.php of the UploadTicketFile Endpoint in Feelcrm-os version 1.0.0. This vulnerability enables unauthorized file uploads due to improper handling of the 'cmd' argument. The issue can be exploited remotely, allowing attackers to ...

PoC for CVE-2026-105388

Feelec-yishuFeelcrm-os5.3MEDIUM
SQL Injection Vulnerability in Feelcrm-os by Feelec-Yishu

A vulnerability has been detected in the Feelcrm-os product version 1.0.0, specifically in the index function of MemberController.class.php. This flaw enables attackers to manipulate the 'group_id' argument, resulting in SQL injection attacks that can be executed remotely. The exploit is publicly...