Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 2 hours ago
PoC for CVE-2026-108521
A vulnerability exists in the Add Remote Node API Endpoint within Studio-Saelix Sencho versions up to 0.97.1. This weakness can be exploited through the isValidRemoteUrl function in the backend's validation utilities. By manipulating the API URL, an authenticated user with node-management permiss...
Discovered 3 hours ago
PoC for CVE-2026-108693
ImageMagick versions on Windows prior to 7.1.2-33 and 6.9.13-58 are susceptible to an uncontrolled search path vulnerability within the NTGhostscriptEXE() function. This flaw allows attackers to execute arbitrary code with ImageMagick's privileges by placing a malicious version of gswin64c.exe in...
Discovered 4 hours ago
PoC for CVE-2026-108708
Wukong_HRM contains a significant missing authorization vulnerability due to a flaw in the EmployeeAspect component, which inadvertently assigns every authenticated user the HR administrator role. This allows low-privileged employees to access sensitive information, such as payslips and personal ...
PoC for CVE-2026-108707
Wukong HRM is susceptible to an authentication bypass vulnerability in its ParamAspect component, allowing unauthenticated malicious actors to access all HRM API endpoints by omitting the required AUTH-TOKEN header. This flaw can lead to unauthorized access to sensitive HR data, including employe...
PoC for CVE-2026-108706
The eladmin framework, through a specific commit, has a vulnerability in its S3 storage download handler that lacks proper authorization checks. As a result, any authenticated user can exploit this flaw to access stored object URLs, bypassing necessary permissions. By sequentially enumerating IDs...
PoC for CVE-2026-108707
Wukong HRM is susceptible to an authentication bypass vulnerability in its ParamAspect component, allowing unauthenticated malicious actors to access all HRM API endpoints by omitting the required AUTH-TOKEN header. This flaw can lead to unauthorized access to sensitive HR data, including employe...
PoC for CVE-2026-108705
CordysCRM versions up to 1.9.3 are susceptible to a missing authorization vulnerability that affects the POST /custom-form/data/import endpoint. This flaw enables authenticated users, including those with low privileges, to exploit the customFormId parameter, thereby allowing unauthorized data im...
PoC for CVE-2026-108703
CordysCRM versions up to 1.9.3 are susceptible to a missing authorization issue in the endpoint /approval-resource/push. This security flaw allows any authenticated user, regardless of their privilege level, to submit resource requests for approval without proper ownership validations. Attackers ...
PoC for CVE-2026-108704
CordysCRM versions up to 1.9.3 are susceptible to an authorization bypass vulnerability, allowing authenticated users with low privileges to circumvent permission checks. By altering the owner field to their own user ID, attackers can exploit this flaw through various endpoints such as follow, re...
PoC for CVE-2026-108702
The CordysCRM application lacks a necessary permission check on the webhook endpoint, allowing authenticated users to send arbitrary requests to any URL. This vulnerability enables attackers to bypass the SSRF validation process and probe internal resources based on responses from GET requests. T...
PoC for CVE-2026-108701
The CordysCRM application prior to version 1.9.2 is susceptible to a missing authorization vulnerability within its ContractController sortModule handler. This flaw allows authenticated users without the appropriate contract update permissions to manipulate any contract by supplying unauthorized ...
PoC for CVE-2026-108700
The 1Panel-dev CordysCRM product prior to version 1.9.2 has been found to possess a missing authorization vulnerability. Authenticated users can exploit this weakness to access business titles by sending a POST request to /field/source/business-title without appropriate permission checks. This fl...
PoC for CVE-2026-108691
An improper authorization vulnerability exists in mall4j version 4.0 that allows authenticated storefront customers to manipulate other users' cart items. Exploiting an operator precedence error in the cleanExpiryProdList SQL query, attackers can issue a single DELETE request to the endpoint /p/s...
PoC for CVE-2026-108690
The mall4j version 4.0 contains an information disclosure vulnerability that permits authenticated users to access details from other customers' shopping carts. This flaw arises from an operator precedence issue within the getShopCartExpiryItems SQL filter, allowing attackers with a storefront ac...
PoC for CVE-2026-108689
Wukong AICRM, up to version 20260610, contains an authorization bypass vulnerability that permits authenticated users to gain unintended access to other users' AI chat sessions. This is achieved by manipulating the session ID in POST requests to /chat/send. Attackers can inject messages into anot...
PoC for CVE-2026-108688
Eladmin versions up to 2.7 are affected by a vulnerability in the LocalStorageController's uploadPicture handler. This flaw allows authenticated users with low privileges to bypass required permissions for file uploads. By exploiting this weakness, attackers can issue POST requests with image-nam...
PoC for CVE-2026-84411
The web management service of MikroTik's RouterOS is affected by an integer underflow issue that can be exploited by an unauthenticated attacker. This vulnerability allows for manipulation of HTTP request bodies, which could lead to arbitrary code execution with root privileges or cause a denial ...
PoC for CVE-2025-9548
A local authenticated user could exploit a null pointer dereference vulnerability present in the Lenovo Power Management Driver. This exploitation may lead to system instability, including a Windows blue screen error. It is crucial for users to apply the latest security updates to mitigate this r...
PoC for CVE-2026-69414
A significant vulnerability has been identified within the Microsoft Malware Protection Engine used in Microsoft Defender, allowing for elevation of privilege. This may potentially enable attackers to gain elevated privileges on affected systems. Microsoft is actively working on a security update...
Discovered 7 hours ago
PoC for CVE-2026-108680
JeecgBoot version 3.9.5 is susceptible to a missing authorization flaw that allows authenticated users to exploit the /sys/api/sendTemplateAnnouncement endpoint. This vulnerability can be leveraged by low-privileged attackers to fabricate sender and recipient parameters, modifying the title and t...
PoC for CVE-2026-108676
JeecgBoot version 3.9.5 features a vulnerability in the SysAnnouncementController that permits unauthorized file download access. Specifically, low-privileged authenticated users can manipulate the downLoadFiles handler to obtain ZIP files containing attachments from announcements. This exploitat...
PoC for CVE-2026-108675
JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability in the SysAnnouncementController's editIzTop handler. This flaw enables low-privileged authenticated users to alter the pin status of announcements. Attackers can exploit this vulnerability by sending POST or ...
PoC for CVE-2026-108674
The JeecgBoot platform, versions up to 3.9.5, is impacted by a missing authorization vulnerability located in the OpenApiController's queryById handler. This flaw permits low-privileged authenticated users to access OpenAPI definitions without the requisite permissions. Attackers can exploit this...
PoC for CVE-2026-108673
JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability in the AiragPromptsController's exportXls function. This flaw allows any authenticated user to export sensitive AI prompts from the system. Specifically, attackers with low privileges can access the /airag/pro...
PoC for CVE-2026-108671
JeecgBoot version 3.9.5 is susceptible to a vulnerability that enables authenticated users to access MCP server configurations without proper permissions. Specifically, the lack of a functional permission check in the /airag/app/queryById endpoint allows attackers to exploit this flaw. By retriev...
PoC for CVE-2026-108672
JeecgBoot versions up to 3.9.5 have a vulnerability in the getVideoRecords handler within the VideoGenerationController. This issue allows authenticated users to bypass authorization checks, enabling them to access the video generation history of other users. By manipulating the userId parameter,...
PoC for CVE-2026-108670
JeecgBoot version 3.9.5 is affected by a missing authorization vulnerability in the promptExperiment handler of the AiragPromptsController. This flaw permits any authenticated user to execute AI prompt experiments, potentially allowing low-privileged attackers to specify other users' prompt templ...
PoC for CVE-2026-108668
The JeecgBoot version 3.9.5 software has a missing authorization vulnerability located in the AiragPromptsController's deleteRecycleBin handler. This flaw enables any authenticated user to exploit the system by sending DELETE requests with specific prompt template IDs. As a result, these users ca...
PoC for CVE-2026-108667
JeecgBoot version 3.9.5 is affected by a missing authorization vulnerability that permits low-privileged authenticated users to exploit the revertRecycleBin endpoint. By sending crafted PUT requests to /airag/prompts/revertRecycleBin with specific template IDs, an attacker can bypass administrato...
PoC for CVE-2026-108666
JeecgBoot versions up to 3.9.5 present a security issue in the AiragPromptsController due to a missing authorization check in the deleteBatch handler. This flaw enables authenticated users, including those with low privileges, to delete AI prompt templates created by other users or administrators...
PoC for CVE-2026-108663
JeecgBoot version 3.9.5 contains a vulnerability in the SysTenantController's deleteApply handler, allowing any authenticated user to compromise tenant administrator applications. This flaw enables low-privileged attackers to issue PUT requests with specific tenantId, packId, and userId values, e...
PoC for CVE-2026-108664
JeecgBoot version 3.9.5 contains a vulnerability in the AiragPromptsController's queryById handler, which permits low-privileged authenticated users to access AI prompt templates improperly. By exploiting this vulnerability, attackers can enumerate IDs through the unsecured /airag/prompts/list en...
PoC for CVE-2026-108662
JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability that permits low-privileged authenticated users to remove other users from tenant product packs. By exploiting this flaw via the PUT request to /sys/tenant/deleteTenantPackUser, attackers can supply arbitrary ...
PoC for CVE-2026-108660
JeecgBoot version 3.9.5 is susceptible to a missing authorization vulnerability, allowing authenticated users with low privileges to modify critical tenant settings. By exploiting this flaw, attackers can issue a PUT request to /sys/tenant/updateApplyStatus, altering the applyStatus field by subm...
PoC for CVE-2026-108661
JeecgBoot versions up to 3.9.5 have a vulnerability that permits authenticated users to transfer tenant ownership without adequate authorization. The API endpoint /sys/tenant/changeOwenUserTenant can be exploited by low-privileged attackers who manipulate the userId and tenantId parameters. This ...
PoC for CVE-2026-108659
JeecgBoot through version 3.9.5 has a missing authorization issue within the SysTenantController component. This vulnerability allows authenticated users, including those with low privileges, to exploit the listPackByTenantUserId endpoint. By manipulating the tenantId and userId parameters, attac...
PoC for CVE-2026-108658
JeecgBoot up to version 3.9.5 is susceptible to a missing authorization vulnerability in the SysTenantController's queryTenantAuthInfo handler. This flaw permits any authenticated user to access and read the records of other tenants. Attackers with low privileges can potentially exploit this vuln...
PoC for CVE-2026-108655
JeecgBoot version 3.9.5 has a vulnerability in the QuartzJobController's queryById handler, allowing authenticated users with low privileges to access sensitive scheduled job records. Attackers can exploit this flaw by sending a GET request to /sys/quartzJob/queryById with a specific job ID, ther...
PoC for CVE-2026-108652
JeecgBoot versions up to 3.9.5 have a security flaw in the SystemApiController's updateAvatar handler, allowing authenticated users with low privileges to change the avatars of other users, including administrators. By sending PUT requests with a target user ID and a malicious image URL, attacker...
PoC for CVE-2026-108651
JeecgBoot versions up to 3.9.5 suffer from a missing authorization vulnerability in the getRolesByUserId handler within the SystemApiController. This flaw allows authenticated users with low privileges to exploit the endpoint /sys/api/getRolesByUserId by supplying arbitrary userId values. As a re...
PoC for CVE-2026-108650
JeecgBoot, up to version 3.9.5, contains a vulnerability in the getUserPermissionSet handler of SystemApiController. This flaw allows authenticated users to access sensitive permission codes of other users by supplying an arbitrary userId in the request. Consequently, low-privileged attackers can...
PoC for CVE-2026-108649
JeecgBoot versions up to 3.9.5 contain a vulnerability in the SystemApiController's queryUserRolesById function. This flaw allows authenticated users to access and enumerate user role assignments by sending a user ID to the /sys/api/queryUserRolesById endpoint. This could potentially enable low-p...
PoC for CVE-2026-108647
JeecgBoot version 3.9.5 contains a missing authorization vulnerability that exposes the SysCheckRuleController importExcel handler to low-privileged authenticated users. This flaw allows attackers to manipulate the system by uploading malicious Excel workbooks, bypassing critical access controls,...
PoC for CVE-2026-108646
The JeecgBoot product up to version 3.9.5 is affected by a missing authorization vulnerability within the SysCategoryController's importExcel feature. This vulnerability permits any authenticated user, including those with low privileges, to import maliciously crafted Excel files. As a consequenc...
PoC for CVE-2026-108645
A vulnerability exists in JeecgBoot version 3.9.5, wherein authenticated users can exploit the SysCategoryController functionality. This flaw permits low-privileged attackers to execute POST or PUT requests to manipulate category dictionary nodes via the /sys/category/edit endpoint. Through this ...
PoC for CVE-2026-108644
JeecgBoot version 3.9.5 is prone to a serious vulnerability in the SysCategoryController delete handler. This flaw allows any authenticated user to delete category dictionary nodes without proper authorization. Low-privileged attackers can exploit this vulnerability by retrieving node IDs from ex...
PoC for CVE-2026-108642
The JeecgBoot application up to version 3.9.5 is susceptible to a missing authorization vulnerability in the SysAnnouncementSendController. This flaw enables authenticated users to manipulate the message delivery records of other users. By exploiting this issue, attackers can extract delivery IDs...
PoC for CVE-2026-108641
JeecgBoot version 3.9.5 is vulnerable to an insecure direct object reference (IDOR) that enables authenticated users to access other users’ messages within the application. This vulnerability is exploited through the getOne handler of the SysAnnouncementSendController. Attackers can leverage the ...
PoC for CVE-2026-108639
JeecgBoot version 3.9.5 is susceptible to a missing authorization vulnerability. This flaw permits any authenticated user to execute DELETE requests on the /sys/dict/deletePhysic/{id} endpoint. As a result, they can permanently eliminate data dictionaries and their associated items from the syste...
PoC for CVE-2026-108640
JeecgBoot, up to version 3.9.5, contains a vulnerability in the SysDepartRoleController specifically within the queryById handler. This issue arises due to the absence of necessary Shiro permission annotations, allowing low-privileged authenticated attackers to exploit the vulnerability. These at...