Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 4 hours ago

PoC for CVE-2026-90495

FengofficeFeng Office6.9MEDIUM
SQL Injection Vulnerability in Fengoffice Legacy API

A SQL injection vulnerability exists in Fengoffice's Legacy API within the method Contacts::instance->findAll, located in the file application/models/CompanyWebsite.class.php. This weakness arises from improper argument handling during authentication processes, allowing attackers to manipulate th...

PoC for CVE-2026-90493

TonecInternet Download Manager9.3CRITICAL
Access Control Flaw in Tonec Internet Download Manager for Windows

A local access control vulnerability exists in the Tonec Internet Download Manager for Windows, specifically within the idmwfp.sys file of the kernel driver component. This vulnerability allows an attacker with local access to manipulate permissions improperly. The issue has been made public, hig...

Discovered 6 hours ago

PoC for CVE-2026-90491

SanjevirauGsubs5.3MEDIUM
Code Injection Vulnerability in sanjevirau gsubs by Electron

A code injection vulnerability exists in the sanjevirau gsubs product, specifically in the function showQuerySuccessPage within the renderer/index.js file. By manipulating the argument 'filename', an attacker can execute arbitrary code remotely. The potential exploit has been publicly disclosed, ...

Discovered 8 hours ago

PoC for CVE-2026-90489

XuxueliXxl-job5.1MEDIUM
Cross-Site Scripting Vulnerability in Xuxueli XXL-Job by Xuxueli

A cross-site scripting vulnerability affects the Xuxueli XXL-Job application versions up to 3.5.0. The vulnerability exists in the /jobinfo/insert file, where improper handling of the 'name' and 'author' parameters allows attackers to inject malicious scripts. This can be exploited remotely, risk...

PoC for CVE-2026-75650

AdobeAdobe Commerce10CRITICAL
Arbitrary Code Execution Vulnerability in Adobe Commerce

Adobe Commerce has a vulnerability that allows for improper neutralization of special elements used in a template engine, potentially leading to arbitrary code execution in the context of the current user. An attacker can exploit this issue without requiring any user interaction, posing significa...

PoC for CVE-2026-90648

WebassemblyWabt7.1HIGH
Vulnerability in wasm2c of WebAssembly by WABT allowing arbitrary c...

The vulnerability in wasm2c of WABT allows for a sandbox escape through a flaw in memory allocation handling on certain platforms, particularly 32-bit systems. When the allocation of the funcref table fails, the internal state leads to a scenario where bounds checks pass, permitting unauthorized ...

PoC for CVE-2026-90488

XuxueliXxl-job5.3MEDIUM
Code Injection Vulnerability in Xuxueli XXL-JOB by Xuxueli

A code injection vulnerability exists in Xuxueli XXL-JOB versions up to 3.4.2. This issue arises in the GroovyClassLoader.parseClass function within the GlueFactory.java file. An attacker can exploit this vulnerability remotely to inject malicious code, potentially leading to unauthorized access ...

PoC for CVE-2026-90487

XuxueliXxl-job5.3MEDIUM
Improper Privilege Management in Xuxueli XXL-JOB by Xuxueli

A vulnerability has been identified in Xuxueli XXL-JOB versions up to 3.4.2, specifically related to the JobGroupController.java file. This flaw allows for improper privilege management, which could potentially be exploited by an attacker remotely. Despite early notifications, the vendor has yet ...

Discovered 11 hours ago

PoC for CVE-2026-78006

WordPressThe Events Calendar9.8CRITICAL
Remote Code Execution Vulnerability in The Events Calendar Plugin f...

The Events Calendar plugin for WordPress has a vulnerability that allows unauthenticated attackers to execute arbitrary code on the server. This is made possible due to inadequate protection in the is_safe_widget_instance function. The exploitation occurs when PHP's magic methods are triggered, a...

Discovered 16 hours ago

PoC for CVE-2026-86547

MrubycMrubyc6.9MEDIUM
Null Pointer Dereference Vulnerability in mrubyc by mruby

The mrubyc environment, in versions prior to 4.0.0, has a vulnerability that allows attackers to exploit a null pointer dereference in the op_enter() handler located in src/vm.c. By crafting malicious .mrb bytecode files with OP_ENTER instructions at the top level, an attacker could cause the emb...

PoC for CVE-2023-1326

Canonical Ltd.Apport7.7HIGH
local privilege escalation in apport-cli

A vulnerability has been identified in apport-cli versions 2.26.0 and earlier, which may allow a local attacker to escalate privileges under specific conditions. If a system is misconfigured to allow unprivileged users to execute sudo with apport-cli as the command, and if appropriate settings fo...

Discovered 18 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 19 hours ago

PoC for CVE-2021-28664

ArmBifrost Gpu Kernel Driver8.8HIGH
Privilege Escalation and Denial of Service Vulnerability in Arm Mal...

The Arm Mali GPU kernel driver exhibits a significant vulnerability allowing unprivileged users to obtain read/write access to restricted pages. This flaw can result in privilege escalation or cause a denial of service through memory corruption. The affected versions include various releases of t...

Discovered 1 day ago

PoC for CVE-2026-89013

DolibarrDolibarr8.7HIGH
Authorization Bypass Vulnerability in Dolibarr Software

Dolibarr versions prior to 24.0.1 are susceptible to an authorization bypass vulnerability that enables unauthenticated attackers to read sensitive files. By exploiting a flaw in the document storage endpoints, attackers can leverage a crafted 'hashp' parameter to bypass token validation in criti...

PoC for CVE-2026-89012

DolibarrDolibarr7.1HIGH
Case-Sensitive Denylist Bypass Vulnerability in Dolibarr Software

Dolibarr versions prior to 24.0.1 exhibit a vulnerability tied to the sqlfilters API query parameter, resulting in a case-sensitive denylist bypass. Authenticated attackers can exploit this flaw by entering uppercase variants of denylist-protected field names, thus circumventing the protective ch...

PoC for CVE-2026-85706

GitlabGitlab10CRITICAL
Improper Path Confinement in GitLab CE/EE Affecting User Access

A vulnerability in GitLab CE/EE allows unauthenticated users to read arbitrary files due to inadequate path confinement and a lack of proper authentication checks in the repository commits API. This issue affects GitLab versions 18.7 prior to 19.1.8, 19.2 prior to 19.2.6, and 19.3 prior to 19.3.2...

PoC for CVE-2022-38181

ArmMidguard Gpu Kernel Dr...🟣 EPSS 14%8.8HIGH
Memory Access Vulnerability in Arm Mali GPU Kernel Driver

The Arm Mali GPU kernel driver is vulnerable due to mishandled GPU memory operations, which allows unprivileged users to access freed memory. This issue affects multiple versions across the Bifrost, Valhall, and Midgard architectures, posing potential risks for system integrity and data security.

PoC for CVE-2026-87918

WordPressWPbot5.3MEDIUM
Unauthorized API Access in WPBot Plugin for WordPress

The WPBot plugin for WordPress prior to version 8.5.7 is vulnerable to unauthorized access due to the lack of authorization and nonce checks on several AJAX actions. This flaw allows unauthenticated attackers to exploit these actions to relay requests to configured third-party AI providers, effec...

PoC for CVE-2026-87916

WordPressWPbot5.3MEDIUM
Information Disclosure in WPBot Plugin by WordPress

The WPBot plugin for WordPress prior to version 8.6.0 is susceptible to an information disclosure vulnerability. This issue arises from the lack of proper capability and nonce checks on the AJAX action responsible for listing stored chat sessions. As a result, unauthenticated attackers can exploi...

PoC for CVE-2026-87919

WordPressProduct Xml Feed Manag...4.9MEDIUM
Excessive Object Method Invocation in WooCommerce Plugin by WordPress

The XML Feed Manager for WooCommerce plugin, prior to version 3.1.1, suffers from improper access control issues. Specifically, it fails to limit which object methods can be invoked by the product shortcode. This oversight allows users with contributor-level access to delete any WooCommerce produ...

PoC for CVE-2026-87892

WordPressRox Appointment Booking5.3MEDIUM
Security Flaw in Rox Appointment Booking Plugin for WordPress

The Rox Appointment Booking plugin for WordPress, prior to version 1.2.0, contains a vulnerability that fails to adequately verify the order total and the chosen payment method against its internal server-side pricing. This oversight enables unauthenticated attackers to create confirmed bookings ...

PoC for CVE-2026-87894

WordPressRox Appointment Booking5.3MEDIUM
Unauthorized Access Vulnerability in Rox Appointment Booking Plugin...

The Rox Appointment Booking plugin for WordPress prior to version 1.2.3 lacks proper authorization checks on its endpoint that retrieves booking confirmation details. This oversight permits unauthenticated users to enumerate sequential booking identifiers, thereby gaining access to sensitive cust...

PoC for CVE-2026-87759

WordPressAdd User Autocomplete8.8HIGH
Vulnerability in Add User Autocomplete Plugin for WordPress by the ...

The Add User Autocomplete plugin for WordPress versions prior to 1.2 is susceptible to improper access control. It fails to verify capabilities or nonce checks before allowing the creation of a pending site-membership invitation with a role provided by the user. This vulnerability enables any aut...

PoC for CVE-2026-87842

WordPressZonify7.5HIGH
Authentication Bypass in Zonify WordPress Plugin by Zonify

The Zonify WordPress plugin prior to version 1.0.5 has a significant security flaw that lacks the required capability or authentication checks. This vulnerability enables attackers to access the stored account login token without proper authentication. As a result, unauthorized users can exploit ...

PoC for CVE-2026-87888

WordPressYaypricing8HIGH
Authorization Bypass in YayPricing WordPress Plugin

The YayPricing WordPress plugin prior to version 3.5.7 is susceptible to an authorization bypass vulnerability that affects its REST API. It fails to adequately check user permissions for a specific REST route responsible for storing pricing rules. As a result, unauthorized users with subscriber-...

PoC for CVE-2026-87797

WordPressSprout Invoices4.3MEDIUM
Authorization Flaw in Sprout Invoices Plugin Allows Unauthorized No...

The Sprout Invoices WordPress plugin before version 20.8.16 is vulnerable to an authorization bypass flaw in its AJAX actions. This vulnerability allows authenticated users, including those with lower privileges such as subscribers, to overwrite private notes on records that do not belong to them...

PoC for CVE-2026-87891

WordPressRox Appointment Booking6.5MEDIUM
Unauthorized Access in Rox Appointment Booking Plugin for WordPress

The Rox Appointment Booking plugin for WordPress is susceptible to an authorization bypass, which allows unauthorized users to modify the holiday schedule settings. Specifically, the plugin does not enforce capability or authorization checks when saving its holiday schedule. This flaw can enable ...

PoC for CVE-2026-85681

WordPressWP Component9.8CRITICAL
Remote Code Execution Vulnerability in WordPress Plugin by WP Compo...

The WP Component WordPress plugin prior to version 2.2.4 has a severe security flaw that permits unauthenticated users to execute actions without proper capability or nonce checks. Attackers can manipulate the option name and value from the incoming requests, making it possible to overwrite criti...

PoC for CVE-2026-84171

WordPressWP Images Upload On Pi...9.8CRITICAL
File Upload Vulnerability in piclect WordPress Plugin Exposes Servers

The piclect WordPress plugin version 1.0 has a critical file upload vulnerability that allows unauthenticated attackers to upload arbitrary files. Due to a lack of validation for the name and type of uploaded files, attackers can exploit this weakness to write files to a publicly accessible direc...

PoC for CVE-2026-84047

WordPressAlbum Cover Finder8.6HIGH
SQL Injection Vulnerability in Album Cover Finder Plugin by WordPress

The Album Cover Finder plugin for WordPress, up to version 0.7.0, contains a security flaw that fails to adequately sanitize and escape user input within SQL queries. This oversight allows unauthenticated attackers to execute arbitrary SQL commands, potentially exposing sensitive database informa...

PoC for CVE-2026-84099

WordPressWPstorecart8.1HIGH
Remote Code Execution Vulnerability in wpstorecart Plugin for WordP...

The wpstorecart plugin for WordPress, up to version 5.0.7, is susceptible to a vulnerability that allows direct, unauthenticated access to a bundled add-on. This add-on fails to adequately restrict deserialized user-supplied input, which can enable unauthenticated attackers to inject arbitrary PH...

PoC for CVE-2026-86790

WordPressWP Highlight Box6.8MEDIUM
Stored Cross-Site Scripting in WP Highlight Box Plugin by WordPress

The WP Highlight Box plugin allows for the integration of reusable content blocks through shortcodes. However, versions up to and including 1.0 lack proper escaping for certain shortcode attributes prior to rendering on a page. This oversight can lead to stored cross-site scripting vulnerabilitie...

PoC for CVE-2026-84023

WordPressBear6.5MEDIUM
Cross-Site Request Forgery Vulnerability in BEAR Plugin for WordPress

A vulnerability in the BEAR WordPress plugin, prior to version 1.2.2, allows attackers to exploit a lack of CSRF nonce verification and user capability checks. This can enable unauthorized modifications of taxonomy terms when a privileged user is tricked into visiting a malicious page, potentiall...

PoC for CVE-2026-84024

WordPressBear4.3MEDIUM
CSRF Vulnerability in BEAR WordPress Plugin Allows Configuration Ma...

The BEAR WordPress plugin versions earlier than 1.2.2 suffers from a CSRF vulnerability due to improper nonce verification when saving meta field configurations. This flaw permits attackers to manipulate settings by duping an authenticated administrator into visiting a malicious link, potentially...

PoC for CVE-2026-82847

WordPressMasteriyo Lms6.8MEDIUM
Stored Cross-Site Scripting in Masteriyo LMS Plugin for WordPress

The Masteriyo LMS plugin for WordPress versions prior to 3.4.1 is vulnerable due to a failure to properly sanitize and escape course field inputs in the course editor. This flaw permits users assigned the instructor role to carry out Stored Cross-Site Scripting (XSS) attacks, potentially affectin...

PoC for CVE-2026-82851

WordPressMasteriyo Lms2.7LOW
Unauthorized Access in Masteriyo LMS Plugin for WordPress

The Masteriyo LMS plugin for WordPress, prior to version 3.4.1, inherently lacks mechanisms to verify whether a user has the rightful ownership of requested records. This flaw permits users assigned the instructor role to download unrestricted content and metadata associated with any posts, inclu...

PoC for CVE-2026-84025

WordPressBear2.2LOW
Data Exposure Flaw in BEAR Plugin for WordPress

The BEAR WordPress plugin prior to version 1.2.2 lacks adequate ownership validation on several handlers. This oversight allows users with restrictions to leverage user-supplied identifiers to access confidential product data. Consequently, users can inadvertently view product information belongi...

PoC for CVE-2026-81742

WordPressBe Rest Endpoints8.8HIGH
Authorization Bypass in BE REST Endpoints Plugin for WordPress Allo...

The BE REST Endpoints Plugin for WordPress prior to version 1.0.0 is susceptible to an authorization bypass vulnerability. This flaw permits unauthorized users to read, create, update, and delete widgets without any authentication checks. Furthermore, the plugin fails to sanitize input values, ma...

PoC for CVE-2026-81429

WordPressExport & Import WPbake...7.1HIGH
Stored Cross-Site Scripting Vulnerability in WPBakery Page Builder ...

The WPBakery Page Builder plugin for WordPress lacks proper Cross-Site Request Forgery (CSRF) protection in its template import functionality. This oversight allows an attacker to exploit this vulnerability by crafting a malicious request, enabling an authenticated administrator to unintentionall...

PoC for CVE-2026-81402

WordPressDs Ad Rotator9.8CRITICAL
Remote Code Execution Vulnerability in DS Ad Rotator WordPress Plug...

The DS Ad Rotator plugin for WordPress versions up to 0.8 is susceptible to a serious vulnerability due to the lack of capability checks, nonce validation, and file-type restrictions in its image upload handler. This oversight allows unauthenticated attackers to upload arbitrary files, including ...

PoC for CVE-2026-82845

WordPressMasteriyo Lms9.9CRITICAL
Deserialization Vulnerability in Masteriyo LMS WordPress Plugin

The Masteriyo LMS WordPress plugin versions prior to 3.4.1 contain a deserialization vulnerability that permits unauthorized execution of arbitrary PHP objects. This security flaw allows users with minimal access to insert user-supplied metadata into the application, which can be exploited to exe...

PoC for CVE-2026-80491

WordPressSamo Forms8.6HIGH
SQL Injection Vulnerability in SAMO Forms Plugin for WordPress

The SAMO Forms plugin for WordPress, prior to version 1.0.0, contains a vulnerability that fails to properly sanitize and escape user input in SQL queries during various unauthenticated actions. This flaw enables attackers to potentially execute SQL injection attacks, compromising the integrity a...

PoC for CVE-2026-81090

WordPressGpx2graphics7.2HIGH
CSRF Vulnerability in Gpx2Graphics Plugin for WordPress

The Gpx2Graphics WordPress plugin, up to version 0.3, is susceptible to a cross-site request forgery (CSRF) vulnerability that allows attackers to bypass file upload restrictions. This exploitation occurs because the plugin lacks necessary CSRF checks and type validation for uploaded files. As a ...

PoC for CVE-2026-80494

WordPressYogeta WP Cloud8.6HIGH
File Retrieval Vulnerability in Yogeta WP Cloud Plugin for WordPress

The Yogeta WP Cloud WordPress plugin prior to version 1.0 is susceptible to a file retrieval vulnerability. This flaw arises from the plugin's failure to properly validate user-supplied file paths before using them in file-read functions on a public endpoint, which does not implement any form of ...

PoC for CVE-2026-78152

WordPressSurerank Seo5.3MEDIUM
Email Exposure Flaw in SureRank SEO Plugin by WordPress

The SureRank SEO WordPress plugin, prior to version 1.10.1, inadvertently exposes users' registered email addresses through structured data on public pages. This vulnerability enables unauthenticated visitors to retrieve email addresses of any user who has published content, compromising their pr...

PoC for CVE-2026-77752

WordPressTemporary Login Withou...7.2HIGH
Insufficient User Login Verification in Temporary Login Without Pas...

The Temporary Login Without Password plugin for WordPress, prior to version 1.9.9, lacks robust verification for user permissions. This deficiency enables an administrator of a single site within a multisite network to unwittingly grant super admin rights to an unauthorized user. Additionally, it...

PoC for CVE-2026-77753

WordPressTemporary Login Withou...5.5MEDIUM
Credential Management Flaw in Temporary Login Plugin for WordPress ...

The Temporary Login Without Password plugin for WordPress versions prior to 1.9.9 allows temporary users to create and retain Application Passwords. This vulnerability permits such users to maintain access via REST and XML-RPC even after temporary credentials should have expired or been revoked b...

PoC for CVE-2026-77005

WordPressCode Monkeys Proposals9.6CRITICAL
File Deletion Vulnerability in CODE MONKEYS PROPOSALS Plugin by Wor...

The CODE MONKEYS PROPOSALS WordPress plugin versions up to 1.0.1 suffers from a critical security issue due to its failure to properly validate user-supplied file paths when deleting files. This flaw allows authenticated users, including those with limited permissions such as subscribers, to dele...

PoC for CVE-2026-75800

WordPressFrontegg Saml Sso9.8CRITICAL
SAML Authentication Flaw in Frontegg WordPress Plugin Allows Unauth...

The Frontegg SAML SSO plugin for WordPress, up to version 1.0.1, contains a significant vulnerability that fails to properly validate the signature and issuer of SAML authentication responses. This oversight permits malicious actors to gain unauthorized access to user accounts, including those wi...

PoC for CVE-2026-77006

WordPressWebtotem Backups9.6CRITICAL
File Deletion Vulnerability in WebTotem Backups Plugin for WordPress

The WebTotem Backups plugin for WordPress prior to version 1.0.1 contains a vulnerability where it fails to validate user-supplied file paths and does not adequately check the permissions of users making requests. This oversight allows authenticated users, even those with the lowest privileges (l...