Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 3 hours ago

PoC for CVE-2026-105315

WordPressDjango-haystack5.1MEDIUM
Improper Input Validation in django-haystack Affects Multiple Versions

A security issue has been identified in django-haystack versions up to 3.3.0, specifically in the _to_python function found in the haystack/backends/elasticsearch_backend.py file. The vulnerability arises from improper handling of the 'result_class' argument, potentially allowing for the executio...

PoC for CVE-2011-2523

VsftpdVsftpd🟣 EPSS 96%9.8CRITICAL
Backdoor Vulnerability in vsftpd 2.3.4 by Academy of Linux

A serious backdoor vulnerability was discovered in vsftpd 2.3.4, affecting downloads made between June 30 and July 3, 2011. This vulnerability allows an attacker to exploit the software and open a remote shell on port 6200/tcp, granting unauthorized access to the system. It poses significant risk...

Discovered 4 hours ago

PoC for CVE-2026-86881

AppleiOS And iPad OS9.1CRITICAL
Certificate Validation Issue in Apple Software Products

A vulnerability affecting various Apple products has been identified, relating to a flaw in certificate validation procedures. This issue, linked to compromised intermediate certificate authorities, allows attackers to potentially issue certificates with arbitrary extended key usages, undermining...

Discovered 5 hours ago

PoC for CVE-2026-105291

Feelec-yishuFeelcrm-os5.3MEDIUM
Cross Site Scripting Vulnerability in Feelcrm-os by FeelEC

A security flaw has been detected in the feelcrm-os 1.0.0 product from FeelEC, specifically within the GroupController::index function in 'App/Feelcrm/Index/Controller/GroupController.class.php'. This issue arises from improper handling of the 'keyword' argument, allowing for remote cross site sc...

PoC for CVE-2026-105290

Feelec-yishuFeelcrm-os6.9MEDIUM
Server-Side Request Forgery in FeelCRM by Feelec-Yishu

A vulnerability in Feelec-Yishu's FeelCRM version 1.0.0 arises from a flaw in the getCurlData endpoint found in the GoogleController.class.php file. This issue permits an attacker to manipulate the URL argument, potentially leading to unauthorized server-side request forgery (SSRF). Due to the na...

PoC for CVE-2026-105289

Feelec-yishuFeelcrm-os5.1MEDIUM
Cross-Site Scripting Vulnerability in feelec-yishu FeelCRM OS

A vulnerability in the FeelCRM OS version 1.0.0 was identified that enables Cross-Site Scripting (XSS) through the customer_form[remark] parameter. This issue resides within the htmlspecialchars_decode function located in the App/Feelcrm/Common/Model/CrmDefineFormModel.class.php file of the Creat...

Discovered 6 hours ago

PoC for CVE-2026-105288

Feelec-yishuFeelcrm-os5.3MEDIUM
Cross Site Scripting Vulnerability in feelec-yishu feelcrm-os by Fe...

A security flaw exists in the feelec-yishu feelcrm-os 1.0.0 version, specifically within the IndexController::index function located in the App/ThinkPHP/Common/functions.php file. This vulnerability allows attackers to manipulate the redirect_url argument, potentially leading to cross site script...

PoC for CVE-2026-105287

Feelec-yishuFeelcrm-os5.3MEDIUM
SQL Injection Vulnerability in Feelcrm-os by Feelec-yishu

A vulnerability has been identified in the Feelcrm-os version 1.0.0, specifically within the getMemberByGroups endpoint located in AjaxRequestController.class.php. The flaw arises from improper handling of input parameters, which allows for SQL injection attacks that can be executed remotely. The...

PoC for CVE-2026-40281

GotenbergGotenberg10CRITICAL
Injection Vulnerability in Gotenberg PDF Processing API

The Gotenberg PDF API, a Docker-based tool for PDF file processing, has a significant vulnerability affecting versions 8.30.1 and earlier. It allows unauthenticated attackers to exploit the metadata write endpoint, which inadequately sanitizes metadata values. By including a newline character in ...

PoC for CVE-2026-105286

TotolinkA3002mu5.3MEDIUM
Path Traversal Vulnerability in Totolink A3002MU Product

A vulnerability has been identified in the Totolink A3002MU product, specifically in the File Upload Handler's function sub_44B250. This issue allows for path traversal due to improper handling of the 'filename' argument, enabling attackers to remotely manipulate file uploads. The flaw is now pub...

PoC for CVE-2026-105285

TotolinkA3002mu10CRITICAL
Stack-Based Buffer Overflow in Totolink A3002MU QoS Rule Handler

A vulnerability has been identified in Totolink A3002MU that allows for remote exploitation through a stack-based buffer overflow in the QoS Rule Handler. The issue arises from improper handling of user input in the /boafrm/formIpQoS function, specifically when manipulating arguments such as addQ...

Discovered 7 hours ago

PoC for CVE-2026-105284

TotolinkA3002mu10CRITICAL
Improper Authorization in Totolink A3002MU by Totolink

A vulnerability has been discovered in the Totolink A3002MU router related to the Authentication Check component. An issue exists in the function sub_40FCFC within the /bin/boa file that allows unauthorized remote manipulation. This vulnerability could enable attackers to bypass authorization che...

PoC for CVE-2026-105254

ItsourcecodeOnline Admission System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System...

An SQL injection vulnerability has been discovered in the itsourcecode Online Admission System version 1.0. This flaw resides in an unspecified function located in the file /admin/schoolyear.php, where manipulation of the 'sy' argument enables unauthorized SQL commands to be executed. The vulnera...

PoC for CVE-2026-105253

ItsourcecodeOnline Admission Syste...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System

A significant vulnerability exists in itsourcecode's Online Admission System Project 1.0, specifically in the /admin/login1.php file. An attacker can exploit improper handling of the User argument to execute SQL injection attacks remotely. This vulnerability allows unauthorized interference with ...

Discovered 8 hours ago

PoC for CVE-2026-105314

PapermergePapermerge7.5HIGH
Remote Code Execution Vulnerability in Papermerge by Papermerge

The Papermerge version 3.5.3 is susceptible to a remote code execution vulnerability due to improper handling of directory traversal within the /api/documents/upload endpoint. A standard user can exploit this flaw to write malicious Python .pth files to the site-packages directory. When the Pytho...

Discovered 9 hours ago

PoC for CVE-2026-105247

SourcecodesterOnline Reviewer Manage...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Online Reviewer Manag...

A SQL injection vulnerability exists in the SourceCodester Online Reviewer Management System version 1.0, specifically in the file /reviewer_0/admins/assessments/Subject/btn_functions.php. An attacker can exploit this vulnerability by manipulating the 'Subject' argument, allowing for unauthorized...

PoC for CVE-2026-105246

SourcecodesterOnline Reviewer Manage...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Online Reviewer Manag...

A vulnerability exists in the SourceCodester Online Reviewer Management System 1.0, specifically in the file /reviewer_0/admins/assessments/Subject/btn_functions.php. Through improper handling of input in the action parameter for 'update', an attacker can manipulate the argument 'Subject' to exec...

PoC for CVE-2026-105245

Sgl-projectSglang6.3MEDIUM
Cleartext Transmission Vulnerability in sgl-project sglang HTTP End...

A vulnerability exists in sgl-project sglang that allows an attacker to exploit the server_info function in the HTTP Endpoint. This issue arises from improper handling of the api_key argument, which can result in sensitive information being transmitted in cleartext. The vulnerability is present i...

PoC for CVE-2026-105238

ChatgptnextwebNextchat6.9MEDIUM
Server-Side Request Forgery Vulnerability in ChatGPTNextWeb NextChat

A vulnerability exists in ChatGPTNextWeb's NextChat application, specifically in the proxyHandler function of the app/api/proxy.ts file. This flaw arises from improper handling of the 'x-base-url' argument, which allows attackers to perform server-side request forgery. This can be exploited remot...

Discovered 10 hours ago

PoC for CVE-2026-13607

WordPressFile Uploads Addon For...5.9MEDIUM
File Upload Vulnerability in WooCommerce Plugin by WordPress

The File Uploads Addon for WooCommerce, Version 1.7.6, poses a risk by allowing customer-uploaded files to be stored in a publicly accessible uploads directory. The addon attempts to restrict access to these files; however, this restriction is not effectively enforced. Consequently, an unauthenti...

PoC for CVE-2026-84169

WordPressUpi Qr Code Payment Ga...5.3MEDIUM
Authentication Bypass in UPI QR Code Payment Gateway Plugin for Wor...

The UPI QR Code Payment Gateway Plugin for WordPress, up to version 1.4.3, is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated attackers to manipulate payment-confirmation requests, enabling them to falsely mark any order as paid without completing the payme...

PoC for CVE-2026-78371

WordPressFile Uploads Addon For...5.9MEDIUM
File Upload Vulnerability in WooCommerce Plugin for WordPress

The File Uploads Addon for WooCommerce prior to version 1.7.6 is susceptible to an improper authorization issue. The plugin fails to ensure that the requester of a customer-uploaded file is indeed the customer who uploaded it. This oversight allows unauthenticated attackers to potentially downloa...

PoC for CVE-2026-105237

LinlinjavaLitemall6.3MEDIUM
Improper Authentication Management in Linlinjava Litemall Login End...

A vulnerability exists in Linlinjava Litemall that allows for improper management of excessive authentication attempts at the Login Endpoint. This issue resides within the AdminAuthController.java file, potentially enabling remote attackers to cause a denial of service through excessive login att...

PoC for CVE-2026-105233

Kishor-23Food-waste-management-...5.3MEDIUM
Session Fixation Vulnerability in Kishor-23 Food Waste Management S...

An identified vulnerability within the Kishor-23 food-waste-management-system's login functionality in login.php allows for session fixation attacks through manipulation of the PHPSESSID parameter. This flaw enables remote attackers to hijack user sessions, posing a significant security risk. The...

PoC for CVE-2026-105232

Kishor-23Food-waste-management-...6.9MEDIUM
SQL Injection Vulnerability in Registration Page of Kishor-23 Food ...

A vulnerability has been identified in the Kishor-23 Food Waste Management System's registration page, specifically within the deliverysignup.php file. This flaw allows for SQL injection via manipulated username, email, or location parameters, enabling remote attacks. Details have been disseminat...

PoC for CVE-2026-105231

Kishor-23Food-waste-management-...6.9MEDIUM
SQL Injection Vulnerability in Kishor-23 Food Waste Management Syst...

A vulnerability has been identified in the Kishor-23 Food Waste Management System, specifically within the Admin Registration component in the admin/signup.php file. This vulnerability allows for SQL injection through the manipulation of parameters such as email, username, and location. Attackers...

Discovered 11 hours ago

PoC for CVE-2026-105230

Kishor-23Food-waste-management-...6.9MEDIUM
SQL Injection Vulnerability in Kishor-23 Food Waste Management System

A security flaw has been identified in the Kishor-23 Food Waste Management System, specifically in the deliverymyord.php file. The vulnerability arises from the insecure handling of parameters like delivery_person_id and order_id, which allows for SQL injection attacks. This flaw can be exploited...

PoC for CVE-2026-105229

Kishor-23Food-waste-management-...6.9MEDIUM
SQL Injection Vulnerability in kishor-23 Food Waste Management Syst...

A vulnerability has been discovered in the kishor-23 food-waste-management-system, specifically within the User Registration Endpoint located in the signup.php file. This vulnerability allows attackers to exploit parameters such as email, name, and gender to perform SQL injection attacks remotely...

PoC for CVE-2026-105226

OscommerceOscommerce25.1MEDIUM
Code Injection Vulnerability in osCommerce Newsletter Management Mo...

A code injection vulnerability has been identified in the Newsletter Management module of osCommerce versions up to 2.3.4.1. This security flaw resides in the 'include' function within the admin/newsletters.php file. By manipulating the argument module, an attacker can potentially execute remote ...

PoC for CVE-2026-105225

OscommerceOscommerce24.8MEDIUM
Code Injection Vulnerability in osCommerce2 Payment Page by osCommerce

A code injection vulnerability has been identified in the osCommerce osCommerce2 Payment Page feature, specifically in the 'include' function of the 'includes/classes/payment.php' file. This vulnerability arises from improper handling of the MODULE_PAYMENT_INSTALLED argument, allowing attackers t...

Discovered 12 hours ago

PoC for CVE-2026-105188

Code-projectsHuman Resource Managem...5.1MEDIUM
Cross Site Scripting Vulnerability in Human Resource Management Sys...

A vulnerability exists in the Human Resource Management System (HRMS) 1.0 developed by Code-Projects, specifically within the Live Event History component located at /views/admin/liveEventHistory.php. This issue allows for remote exploitation through the manipulation of the 'eventSubject' paramet...

PoC for CVE-2026-105187

ItsourcecodeOnline Admission System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System

A vulnerability exists within the itsourcecode Online Admission System version 1.0 that allows for SQL injection through the manipulation of the 'ID' parameter in the /admin/key.php file. This vulnerability can be exploited by attackers remotely, potentially leading to unauthorized access to sens...

PoC for CVE-2026-105186

ItsourcecodeOnline Admission System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System

A security flaw exists in the itsourcecode Online Admission System 1.0 affecting the function located in /new.php. By manipulating the argument 'schedid', an attacker can execute a SQL injection attack, allowing unauthorized access to the database. This vulnerability can be exploited remotely, po...

PoC for CVE-2022-40684

FortinetFortinet FortiOS, Fort...🟣 EPSS 100%9.8CRITICAL
Fortinet Authentication Bypass Vulnerability

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform ope...

PoC for CVE-2026-105185

ItsourcecodeOnline Admission System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System

A SQL injection vulnerability exists in the itsourcecode Online Admission System 1.0, specifically affecting the /admin/examinee.php file. Malicious actors can manipulate the 'ID' argument, enabling unauthorized remote access to the database. This flaw may lead to data leakage, corruption, or fur...

Discovered 13 hours ago

PoC for CVE-2026-105184

ItsourcecodeOnline Admission System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System

A security flaw has been identified in the itsourcecode Online Admission System, specifically within the /admin/creteria.php file. This vulnerability arises due to improper handling of user input, allowing remote attackers to manipulate the argument ID. Such exploitation can lead to SQL injection...

PoC for CVE-2026-105183

ItsourcecodeOnline Admission System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System...

A SQL injection vulnerability has been found in the itsourcecode Online Admission System 1.0, specifically affecting the /admin/confirm.php file. The vulnerability allows an attacker to manipulate the argument 'schedid', enabling unauthorized SQL commands to be executed remotely. This could poten...

PoC for CVE-2026-105182

SourcecodesterOnline Reviewer Manage...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Online Reviewer Manag...

A security flaw exists in the SourceCodester Online Reviewer Management System’s admin panel, specifically within the handling of update actions in the file /reviewer_0/admins/assessments/activities/btn_functions.php. The vulnerability allows attackers to manipulate the input parameter 'Title', l...

PoC for CVE-2026-13247

WordPressLogo Slider WP – Respo...6.4MEDIUM
Stored Cross-Site Scripting Vulnerability in Logo Slider Plugin for...

The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase plugin for WordPress contains a vulnerability that allows stored cross-site scripting due to insufficient input sanitization and output escaping in the 'lgx_tooltip_position' parameter. This flaw enables authenticated attackers ...

PoC for CVE-2026-105181

ItsourcecodeOnline Admission System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System

A security flaw has been discovered in the itsourcecode Online Admission System, specifically within the register1.php file. The vulnerability arises from improper processing of the filename parameter, allowing an attacker to execute SQL injection attacks remotely. This vulnerability can be explo...

Discovered 14 hours ago

PoC for CVE-2026-105180

WMZJeebase5.3MEDIUM
Dynamic Object Attribute Manipulation in Jeebase by WMZ

A vulnerability in Jeebase version 0.0.1 affects the updateUser function within the UserService component. This flaw allows unauthorized manipulation of the user/tempUser argument, leading to dynamic determination of object attributes. This exploitation can be executed remotely, posing a signific...

Discovered 15 hours ago

PoC for CVE-2026-105173

Code-projectsHuman Resource Management5.1MEDIUM
Cross Site Scripting Vulnerability in Human Resource Management by ...

A vulnerability exists in version 1.0 of Human Resource Management developed by Code-Projects, specifically in the Event Creation component located at /humanresourcemanagementsystem/src/store/EventStore.php. The flaw allows for exploitation through improper handling of the eventSubject argument, ...

Discovered 16 hours ago

PoC for CVE-2026-105171

Kishor-23Food-waste-management-...5.3MEDIUM
Authorization Bypass in kishor-23 Food Waste Management System Admi...

A security vulnerability has been identified within the kishor-23 food-waste-management-system that affects the admin/admin.php file associated with the Role Attribute Handler component. This flaw allows an attacker to manipulate the argument Name, potentially bypassing authorization checks. The ...

PoC for CVE-2026-105170

Kishor-23Food-waste-management-...6.9MEDIUM
Missing Authentication Issue in Kishor-23 Food Waste Management System

A vulnerability has been discovered within the Kishor-23 food waste management system, specifically affecting the admin/signup.php file. This flaw enables unauthorized access due to a missing authentication mechanism when manipulating the signup argument. Attackers can exploit this weakness remot...

PoC for CVE-2026-103355

WordPressUnlimited Elements For...9.3CRITICAL
SQL Injection Vulnerability in Unlimited Elements for Elementor Plu...

A SQL Injection vulnerability has been identified in the Unlimited Elements for Elementor plugin, specifically affecting versions from n/a through 2.0.20. This flaw allows attackers to execute unauthorized SQL commands, potentially leading to data exposure. Proper input validation is critical to ...

PoC for CVE-2026-105169

Kishor-23Food-waste-management-...6.9MEDIUM
SQL Injection Vulnerability in Kishor-23 Food Waste Management System

A security issue has been uncovered in the Kishor-23 Food Waste Management System, specifically in the Take Order Handler's delivery.php file. The vulnerability arises from improper handling of parameters such as order_id and delivery_person_id, leading to potential SQL injection attacks. This fl...

Discovered 17 hours ago

PoC for CVE-2026-105168

Kishor-23Food-waste-management-...5.3MEDIUM
SQL Injection Vulnerability in Order Assignment Block of kishor-23 ...

A SQL injection vulnerability has been detected in the Order Assignment Block of the kishor-23 food-waste-management-system. The issue arises from the manipulation of the 'order_id' and 'delivery_person_id' parameters in the 'admin.php' file. This flaw enables attackers to exploit the system remo...

PoC for CVE-2026-105167

Kishor-23Food-waste-management-...6.9MEDIUM
SQL Injection Vulnerability in Kishor-23 Food Waste Management System

A security flaw exists in the Kishor-23 Food Waste Management System, specifically in the admin/donate.php file, where an unprotected function allows for SQL injection through manipulation of the 'location' argument. This vulnerability can be exploited remotely, enabling attackers to execute arbi...

PoC for CVE-2026-105166

Kishor-23Food-waste-management-...6.9MEDIUM
SQL Injection Vulnerability in Food Donation Form of Kishor-23 Food...

A SQL injection vulnerability exists in the Food Donation Form within the Kishor-23 Food Waste Management System, specifically in the insert function of the fooddonateform.php file. This flaw arises from improper handling of user inputs, particularly the 'image-choice' argument. Attackers can exp...

Discovered 20 hours ago

PoC for CVE-2026-92084

WordPressBeaver Builder Page Bu...9.1CRITICAL
Arbitrary Shortcode Execution Vulnerability in Beaver Builder Page ...

The Beaver Builder Page Builder plugin for WordPress contains a vulnerability that permits unauthenticated attackers to execute arbitrary shortcodes. This flaw arises from insufficient validation of values prior to processing do_shortcode, notably within pages that leverage the Sidebar module. At...