Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2026-95270

DgtlmoonChangedetection.io6.3MEDIUM
Timing Discrepancy in Hash Comparison Function of dgtlmoon Changede...

A vulnerability in dgtlmoon Changedetection.io has been identified, affecting versions up to 0.60.7. This flaw resides in the check_password function within the Hash Comparison component, specifically in the file flask_app.py. An attacker can exploit this vulnerability to create observable timing...

Discovered 6 hours ago

PoC for CVE-2026-64638

WordPressWordPress🟣 EPSS 31%8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

Discovered 7 hours ago

PoC for CVE-2026-91827

WordPressNinja Forms7.5HIGH
PHP Object Injection Risk in Ninja Forms WordPress Plugin

The Ninja Forms plugin version 3.15.3 for WordPress has a critical security flaw that allows unauthorized attackers to exploit user-submitted form data. When form submissions are exported to CSV by an administrator, the plugin fails to properly sanitize the deserialized data, creating an opportun...

PoC for CVE-2026-92438

WordPressNinja Forms8.8HIGH
Improper Input Handling in Ninja Forms Plugin Affecting WordPress

The Ninja Forms plugin for WordPress, specifically version 3.15.3, is susceptible to a vulnerability due to its failure to properly escape submitted form field values. This oversight allows unauthenticated users to submit data through publicly accessible forms. When these values are displayed on ...

PoC for CVE-2026-88788

WordPressText Styler6.8MEDIUM
Cross-Site Scripting Vulnerability in Text Styler Plugin for WordPress

The Text Styler WordPress plugin, up to version 1.1.1, is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user-supplied styling values. This vulnerability enables users with contributor-level access or higher to introduce malicious JavaScript into the output. As...

Discovered 12 hours ago

PoC for CVE-2026-94493

GigatechPdv570110CRITICAL
WebSocket Service Missing Authentication in Gigatech PDV5701

The Gigatech PDV5701 has been identified with a vulnerability in its WebSocket Service, specifically affecting the processing of the /index.html file. This security flaw allows for missing authentication, making it possible for attackers to exploit the system remotely. The potential for exploitat...

Discovered 13 hours ago

PoC for CVE-2026-94492

YonyouU8cloud5.3MEDIUM
SQL Injection Vulnerability in Yonyou U8cloud OpenAPI Component

A security vulnerability has been uncovered within the Yonyou U8cloud 5.x software, specifically in the OpenAPI component located at /u8cloud/openapi/so.saleorder.sendaudit. This vulnerability enables attackers to manipulate the 'operator' argument, leading to potential SQL injection attacks. Suc...

PoC for CVE-2026-43786

AppleMac OS7.8HIGH
Privilege Escalation Vulnerability in Apple macOS Products

A privilege escalation issue has been discovered in Apple's macOS, which may allow an application to obtain unauthorized root privileges. This vulnerability arises from insufficient entitlement checks in the system, leading to potential exploitation that can compromise system integrity. It is cru...

Discovered 15 hours ago

PoC for CVE-2026-94426

XuxueliXxl-job5.1MEDIUM
Cross-Site Scripting Vulnerability in xuxueli XXL-Job Software

A vulnerability exists in the xuxueli XXL-Job software that allows for cross-site scripting (XSS) through a flaw in the `jobgroup/insert` function. This vulnerability can be exploited remotely by manipulating the argument 'Name'. The potential for exploitation is heightened as the flaw has been p...

PoC for CVE-2026-28618

GoogleAndroid8.8HIGH
Heap Buffer Overflow Vulnerability in Android OS

A vulnerability in the Android OS identified as a heap buffer overflow can allow potential attackers to execute remote code without requiring any user interaction. This weakness resides in the 'dec_frm_prepare' function of the 'oapv.c' file, which can be exploited to conduct out-of-bounds writes,...

Discovered 16 hours ago

PoC for CVE-2026-94540

MrpearDesktopsms7.4HIGH
Unauthorized Access Vulnerability in DesktopSMS by MrPear

DesktopSMS 1.11.0 by MrPear is susceptible to an unauthorized access vulnerability, enabling local attackers to utilize the application's local service. This flaw allows attackers to send SMS messages and retrieve SMS-derived content without requiring user interaction or pairing confirmation. An ...

PoC for CVE-2026-94536

DromaraLamp-cloud5.3MEDIUM
Unauthorized Information Disclosure in Lamp-cloud by Dromara

The Lamp-cloud software, up to version 5.10.0, is susceptible to an information disclosure vulnerability due to inadequate validation of the 'employeeId' parameter in the '/anyone/visible/resource' endpoint. This flaw permits authenticated users to exploit the system, enabling them to read roles ...

PoC for CVE-2026-94535

DromaraLamp-cloud7.1HIGH
Authorization Bypass Vulnerability in lamp-cloud by dromara

An authorization bypass vulnerability exists in the deleteMyNotice endpoint of lamp-cloud (versions up to 5.10.0). This flaw allows authenticated users to craft malicious DELETE requests, targeting arbitrary notice IDs, thus enabling them to delete notifications that belong to other users without...

PoC for CVE-2026-94534

DromaraLamp-cloud7.1HIGH
User Profile Vulnerability in Lamp-Cloud by Dromara

Lamp-Cloud versions up to 5.10.0 are susceptible to a serious security issue where user identity is not properly validated during profile updates. This vulnerability allows authenticated attackers to manipulate user profiles by sending requests with targeted user IDs. Attackers can alter critical...

PoC for CVE-2026-94534

DromaraLamp-cloud7.1HIGH
User Profile Vulnerability in Lamp-Cloud by Dromara

Lamp-Cloud versions up to 5.10.0 are susceptible to a serious security issue where user identity is not properly validated during profile updates. This vulnerability allows authenticated attackers to manipulate user profiles by sending requests with targeted user IDs. Attackers can alter critical...

PoC for CVE-2026-94533

DromaraLamp-cloud7.1HIGH
Authorization Bypass in lamp-cloud Vulnerability Allowing File Access

The lamp-cloud product, specifically through version 5.10.0, suffers from an authorization bypass vulnerability in the FileAnyoneController. This flaw permits authenticated users to download arbitrary attachments from other users. By manipulating valid attachment identifiers, attackers can exploi...

PoC for CVE-2026-94532

DromaraLamp-cloud7.1HIGH
Authorization Bypass in Lamp-Cloud by Dromara

Lamp-Cloud, up to version 5.10.0, has a vulnerability in the getUserInfoById endpoint which allows authenticated users to bypass authorization checks. This flaw enables individuals to access full profiles of any user within the system by manipulating the userId parameter. As a consequence, attack...

PoC for CVE-2026-77078

MulterMulter7.5HIGH
Denial of Service in multer Middleware for Node.js by Express.js

The multer middleware used for handling multipart/form-data in Node.js applications has a vulnerability that can be exploited to trigger a denial of service (DoS). This occurs when a multipart request containing two specially crafted text field names is sent. The first field attempts to create an...

Discovered 18 hours ago

PoC for CVE-2025-6325

WordPressKing Addons For Elementor9.8CRITICAL
Privilege Escalation Vulnerability in King Addons for Elementor by ...

A vulnerability exists in King Addons for Elementor, developed by KingAddons.com, that allows attackers to escalate their privileges. This Incorrect Privilege Assignment flaw enables unauthorized users to gain elevated access to restricted functionalities within the plugin. The issue affects all ...

Discovered 19 hours ago

PoC for CVE-2026-94501

JishenghuaJsherp8.7HIGH
Authorization Bypass in jshERP Affects User Business CRUD Operations

The jshERP software version 3.6 is susceptible to an authorization bypass vulnerability within its userBusiness CRUD endpoints. This flaw enables authenticated users to perform operations on authorization-related rows without proper privilege checks. As a result, attackers can alter user-role map...

PoC for CVE-2026-94497

JishenghuaJsherp8.7HIGH
Unauthorized Access Vulnerability in jshERP by Jishenghua

The jshERP product version 3.6 has a significant vulnerability related to improper validation of object ownership in its API endpoints for information retrieval, updates, and deletions across various resource types. This oversight allows authenticated users to exploit the system by directly submi...

PoC for CVE-2026-94496

JishenghuaJsherp8.7HIGH
Privilege Escalation Vulnerability in jshERP Software by jishenghua

The jshERP software version 3.6 contains a vulnerability in its role management endpoints that fails to properly validate caller permissions. This oversight allows authenticated users to manipulate role data and potentially delete roles. Consequently, attackers can exploit the vulnerable /role/up...

PoC for CVE-2026-94495

JishenghuaJsherp7.1HIGH
Improper User Privilege Validation in jshERP Product by JSH

jshERP versions prior to 3.6 contain a flaw that allows authenticated users to bypass authorization checks within the SystemConfigService.updateSystemConfig function. This vulnerability enables attackers to manipulate tenant-specific system configurations, including critical parameters related to...

PoC for CVE-2026-94494

JishenghuaJsherp5.3MEDIUM
Tenant Isolation Bypass in jshERP by jishenghua

The jshERP application, up to version 3.6, contains a vulnerability that allows authenticated users to bypass tenant isolation. This flaw enables these users to access sensitive records of other tenants through the GET /tenant/info endpoint. By iterating the primary key, attackers can enumerate v...

PoC for CVE-2026-94414

JishenghuaJsherp5.3MEDIUM
Authorization Bypass in jshERP Affects Role Button-Permission Settings

jshERP prior to version 3.6 contains a vulnerability in the POST /userBusiness/updateBtnStr endpoint. This flaw occurs due to the absence of an authorization check, allowing authenticated users to potentially alter role-specific button-permission configurations. Malicious actors can exploit this ...

PoC for CVE-2026-94413

JishenghuaJsherp7.1HIGH
Password Hash Exposure in jshERP through 3.6

An issue in jshERP versions up to 3.6 allows authenticated users to access unsalted MD5 password hashes through the /user/info endpoint. This enables attackers to request arbitrary user information by supplying specific user IDs, exposing sensitive password digests. These hashes can be exploited ...

PoC for CVE-2026-94412

JishenghuaJsherp8.7HIGH
Authorization Bypass in jshERP Product by Vendor jshERP

The jshERP application through version 3.6 contains a significant vulnerability in its password reset functionality. Specifically, the authorization bypass affects the POST /user/resetPwd endpoint, which allows authenticated users to reset passwords of any other user by simply specifying a target...

PoC for CVE-2026-94411

JishenghuaJsherp8.7HIGH
Privilege Escalation Vulnerability in jshERP 3.6 by jishenghua

jshERP version 3.6 is susceptible to a privilege escalation vulnerability found within the updateOneValueByKeyIdAndType endpoint. This flaw allows authenticated users to manipulate their access privileges unlawfully. By submitting a POST request containing their user ID and a list of role IDs des...

Discovered 20 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-94488

TelegramTelegram Desktop8.3HIGH
Cross-Site Scripting Vulnerability in Telegram Desktop by Telegram

A cross-site scripting vulnerability exists in Telegram Desktop prior to version 6.9.4, allowing attackers to exploit the HTML export functionality. The issue is present in the method button.text.toUtf8 within export_output_html.cpp. An attacker must entice a victim to utilize the HTML export fea...

Discovered 23 hours ago

PoC for CVE-2026-94129

BiOStarValkyrie Aurora9.3CRITICAL
Local IOCTL Handler Vulnerability in BioStar VALKYRIE AURORA Software

A vulnerability exists in the BioStar VALKYRIE AURORA software, specifically in the IOCTL handler within the BS_RVSIO64.sys file. This vulnerability allows for a write-what-where condition via manipulation of the PhysicalAddress argument. As a result, local attackers could exploit this vulnerabil...

Discovered 1 day ago

PoC for CVE-2026-94216

St Engineering Id...Evolution5.3MEDIUM
Open Redirect Vulnerability in ST Engineering iDirect Evolution and...

A security weakness has been found in ST Engineering's iDirect Evolution and Velocity WebServer products, where the 'authorize' function in the HTTP Header Handler component allows for manipulation of request arguments. Specifically, altering the 'Success' parameter can lead to an open redirect, ...

PoC for CVE-2026-94214

St Engineering Id...Evolution5.3MEDIUM
Open Redirect Vulnerability in ST Engineering iDirect Evolution and...

A security flaw has been identified in ST Engineering iDirect Evolution and Velocity WebServer affecting the Management Service's login component. The vulnerability arises from improper handling of the Host header in the /login.html file, enabling attackers to manipulate URL requests resulting in...

PoC for CVE-2026-94211

Hyve5Leantime4.8MEDIUM
Cross-Site Scripting Vulnerability in Hyve5 Leantime Project Dashboard

A vulnerability has been identified in Hyve5 Leantime up to version 3.9.8, specifically affecting the Project Dashboard component. This flaw allows malicious actors to inject cross-site scripting (XSS) payloads through the '/app/Domain/Dashboard/Templates/show.blade.php' file. The manipulation of...

PoC for CVE-2026-74469

LinuxLinux8.8HIGH
SCTP Transport Count Overflow in Linux Kernel Products

A vulnerability exists in the Linux kernel related to SCTP (Stream Control Transmission Protocol) which allows for a transport count overflow. The function sctp_assoc_add_peer() increments a 16-bit transport_count for each unique peer. When the transport_count exceeds 65,536, it wraps around to z...

PoC for CVE-2026-68121

LinuxLinux7.8HIGH
PPPoE Header Vulnerability in Linux Kernel

A vulnerability in the Linux kernel's PPPoE implementation allows for header pointer mismanagement during device header callbacks. When a send action is blocked, it can lead to an invalidated pointer within the socket buffer (skb) head. This issue arises specifically when transitioning from a non...

PoC for CVE-2026-94210

Hyve5Leantime5.1MEDIUM
Cross-Site Scripting Vulnerability in Hyve5 Leantime Kanban Board

A vulnerability has been identified in the Hyve5 Leantime Kanban Board affecting versions up to 3.9.8. This specific flaw in the function getAllGrouped located in the file app/Domain/Tickets/Services/Tickets.php allows attackers to execute cross-site scripting (XSS) attacks remotely. Successful e...

PoC for CVE-2026-81000

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in TUN and TAP Networking Interfaces

The vulnerability in the Linux kernel's TUN and TAP interfaces arises from incorrect management of packet data when tun_get_user() operates with oversized headroom requests. This flaw can lead to an improper allocation of packet data storage, potentially allowing skb->data to be located outside o...

PoC for CVE-2026-80844

LinuxLinux
Vulnerability in Linux Kernel Affecting AH6 Routing Header Validation

A flaw exists within the Linux kernel's AH6 module related to the validation of routing header segments. The function ipv6_rearrange_rthdr() improperly assumes that the 'segments_left' field of a routing header will not exceed the number of addresses defined in the hdrlen field. However, this hol...

PoC for CVE-2026-8932

CurlCurl7.5HIGH
Connection Pool Reuse Flaw in libcurl Affects Multiple Products

A vulnerability in libcurl arises from its connection pooling mechanism, where previously established connections can be reused despite changes to mTLS configuration settings. This flaw occurs because certain TLS parameters associated with client certificates are not adequately checked during the...

PoC for CVE-2026-92400

WordPressPayment Gateway For Pa...5.3MEDIUM
Payment Notification Verification Flaw in WooCommerce PayPal Plugin

The WooCommerce PayPal Payment Gateway plugin for WordPress contains a vulnerability where it fails to validate incoming payment notifications properly. Specifically, prior to version 9.2.1, the plugin does not confirm that a payment notification is associated with the store's own merchant accoun...

PoC for CVE-2026-86802

WordPressTo Do List Member3.7LOW
Authorization Flaw in To Do List Member Plugin for WordPress

The To Do List Member plugin for WordPress is affected by a vulnerability that lacks adequate authorization and nonce checks in its import routine. This flaw permits unauthenticated users to generate arbitrary published posts and taxonomy terms. Moreover, the plugin does not validate the source o...

PoC for CVE-2026-85113

WordPressGiveWP6.5MEDIUM
Shortcode Execution Vulnerability in GiveWP Plugin for WordPress

The GiveWP plugin for WordPress, up to version 4.16.9, is susceptible to a vulnerability that allows unauthenticated users to execute arbitrary shortcodes. This occurs because the plugin fails to adequately remove shortcode delimiters from user-supplied input before rendering it on public pages. ...

PoC for CVE-2026-85010

WordPressRestropress5.3MEDIUM
Server-Side Price Manipulation Vulnerability in RestroPress Plugin ...

The RestroPress plugin for WordPress is susceptible to a significant vulnerability that enables unauthenticated users to manipulate the pricing of item add-ons. Specifically, prior to version 3.4.6, the plugin fails to perform adequate validation of the item add-on price supplied by the client wh...

PoC for CVE-2026-94152

Omega SolutionFbp Fulfillment By People5.3MEDIUM
Authorization Bypass Vulnerability in Omega Solution FBP Fulfillmen...

A significant security flaw has been identified in Omega Solution's FBP Fulfillment by People 2025, specifically within the User Profile API component. This vulnerability arises from improper handling of the user ID argument, which can facilitate an unauthorized access scenario. Attackers can exp...

PoC for CVE-2026-94151

Omega SolutionHrm Os6.9MEDIUM
Weakness in Omega Solution HRM OS Role Permission API Exposes Vulne...

A vulnerability has been detected in Omega Solution's HRM OS affecting the Role Permission API within the file /role-permission/permission. This weakness arises from a manipulation of the roleId argument, which could allow attackers to bypass authentication measures. The vulnerability can be expl...

PoC for CVE-2026-94150

Omega SolutionHrm Os4.8MEDIUM
Cross Site Scripting Vulnerability in Omega Solution HRM OS Software

A security flaw has been identified within the Omega Solution HRM OS, specifically affecting the SVG File Upload component. This vulnerability allows an attacker to manipulate an unknown function in the /media/view/ directory, leading to potential cross site scripting (XSS) attacks. Such attacks ...

PoC for CVE-2026-94149

Omega SolutionHrm Os5.3MEDIUM
Improper Resource Control in Omega Solution HRM OS by Omega Solution

A vulnerability has been discovered in Omega Solution HRM OS, specifically within the Role Permission Retrieval Endpoint. The issue arises from improper management of resource identifiers due to the manipulation of the argument roleId. This vulnerability allows attackers to potentially exploit th...

PoC for CVE-2026-33439

OpenidentityplatformOpenam🟣 EPSS 10%9.3CRITICAL
Remote Code Execution in OpenIdentityPlatform OpenAM Access Managem...

OpenIdentityPlatform's OpenAM, an access management solution, is susceptible to a pre-authentication Remote Code Execution vulnerability due to unsafe Java deserialization. This issue arises from the handling of the jato.clientSession HTTP parameter, allowing unauthenticated attackers to execute ...

PoC for CVE-2026-94145

XuxueliXxl-job5.1MEDIUM
Cross-Site Scripting Vulnerability in xuxueli XXL-Job Task Manageme...

A vulnerability has been identified in xuxueli XXL-Job, affecting the Task Management Interface. An improper handling of user input in the JobInfoController.java file enables attackers to execute cross-site scripting (XSS) attacks. The vulnerability allows for remote exploitation by manipulating ...