Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2025-59528

FlowiseaiFlowise🟣 EPSS 90%10CRITICAL
Remote Code Execution Vulnerability in Flowise by FlowiseAI

Flowise, a user-friendly platform for creating customized large language model flows, has a significant vulnerability in version 3.0.5 that allows for remote code execution. The flaw lies within the CustomMCP node, where user input is inadequately sanitized. Specifically, the mcpServerConfig stri...

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

PoC for CVE-2026-4282

Red HatRed Hat Build Of Keycl...7.4HIGH
Keycloak Vulnerability Allows Unauthorized Access and Privilege Esc...

A vulnerability has been identified in Keycloak involving the SingleUseObjectProvider, a global key-value store. This flaw allows an unauthenticated attacker to exploit the system by forging authorization codes. If successfully exploited, it could lead to the creation of admin-level access tokens...

Discovered 41 minutes ago

PoC for CVE-2026-41091

MicrosoftMicrosoft Malware Prot...7.8HIGH
Elevation of Privilege Vulnerability in Microsoft Defender

An issue has been identified in Microsoft Defender that could allow an authorized attacker to gain elevated privileges through improper link resolution before file access, also known as link following. This vulnerability could enable attackers to manipulate file paths, potentially leading to unau...

Discovered 3 hours ago

PoC for CVE-2026-19364

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management Sys...

A security weakness has been identified in the itsourcecode Hospital Management System version 1.0, pertaining to the file /viewdoctorconsultancycharge.php. An attacker can exploit this vulnerability by manipulating the 'delid' parameter, which leads to unauthorized SQL queries. This SQL injectio...

Discovered 4 hours ago

PoC for CVE-2026-19361

MacrozhengMall6.3MEDIUM
Vulnerability in Macrozheng Mall Component Affecting User Authentic...

A critical flaw has been identified in the Macrozheng Mall's mall-portal module, specifically within the /sso/getAuthCode functionality. This vulnerability facilitates weak password recovery mechanisms, enabling potential attackers to manipulate the authentication process. The exploit can be exec...

Discovered 5 hours ago

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 100%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

Discovered 8 hours ago

PoC for CVE-2026-19353

DedeCMSDedecms2.3LOW
File Inclusion Vulnerability in DedeCMS Installation Wizard

A file inclusion vulnerability exists in the Installation Wizard of DedeCMS versions up to 5.7.118 UTF8SP2. This issue arises from the manipulation of the _4_Setup function located in the install/index.php file, potentially allowing an attacker to include arbitrary files remotely. The complexity ...

Discovered 9 hours ago

PoC for CVE-2026-19195

V-secureJingyun Antivirus8.5HIGH
Access Control Flaw in V-Secure Jingyun Antivirus by V-Secure

A notable access control vulnerability has been identified in the V-Secure Jingyun Antivirus version 2.4.2.39. This flaw occurs in the ZyArk.sys library of its Kernel Driver component and can be exploited locally, allowing unauthorized access to sensitive functions. The weakness stems from improp...

PoC for CVE-2026-19352

MifiLossless-cut2.3LOW
Server-side Request Forgery Vulnerability in mifi lossless-cut HTTP...

A vulnerability exists in the Built-in HTTP API Service of mifi lossless-cut versions up to 3.69.0, which may allow attackers to manipulate the service leading to server-side request forgery. This attack requires local network access and has a high complexity level, making exploitation challengin...

PoC for CVE-2026-19193

JiangminAntivirus8.5HIGH
Access Control Vulnerability in Jiangmin Antivirus 21

A vulnerability has been identified in Jiangmin Antivirus 21 that affects the MessageNotifyCallback function within the kvcore.sys library of the Minifilter Port. This flaw allows for improper access controls, enabling local attackers to potentially exploit the system through unauthorized manipul...

Discovered 10 hours ago

PoC for CVE-2026-19351

DresendeNode-sql-query6.9MEDIUM
SQL Injection Vulnerability in Node-SQL-Query by Dresende

A SQL injection vulnerability exists in the Request Parameter Handler of the dresende node-sql-query library. The affected function, SelectQuery.from/SelectQuery.build, can be exploited remotely through manipulated requests, potentially allowing attackers to execute unauthorized SQL commands. Thi...

Discovered 11 hours ago

PoC for CVE-2026-19348

Shenzhen AitemiM300 Wi-fi Repeater9.3CRITICAL
Command Injection Vulnerability in Shenzhen Aitemi M300 Wi-Fi Repeater

A security flaw identified in the Shenzhen Aitemi M300 Wi-Fi Repeater allows for a command injection via the sprintf function in the protocol.csp file. Attackers can manipulate parameters such as enable, name, or mac, leading to remote command execution. This vulnerability has been made public an...

PoC for CVE-2026-19347

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A security flaw in the itsourcecode Hospital Management System version 1.0 allows for SQL Injection via manipulated parameters in the /viewdoctor.php file. This vulnerability can be exploited remotely, enabling attackers to interact with the database maliciously. The exploit is publicly accessibl...

PoC for CVE-2026-19346

TendaCh228.7HIGH
Command Injection Vulnerability in Tenda CH22 Router

A command injection vulnerability has been identified in the Tenda CH22 router, specifically in the function formCertListInfo located in the /goform/CertListInfo file. This vulnerability arises from improper handling of the 'Name' argument, allowing an attacker to execute arbitrary commands on th...

Discovered 12 hours ago

PoC for CVE-2026-19345

Code-projectsTask Management System6.9MEDIUM
Authorization Bypass in Code-Projects Task Management System 1.0

A significant vulnerability has been identified in the Task Management System version 1.0 developed by Code-Projects. The issue lies within the /user/UpdateTaskStatus.php file where a manipulation of the task_id/val parameter can lead to a lack of proper authorization checks. This flaw permits re...

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

PoC for CVE-2026-19344

Code-projectsTask Management System6.9MEDIUM
SQL Injection Vulnerability in code-projects Task Management System

A SQL injection vulnerability has been identified in the code-projects Task Management System version 1.0, specifically in the file /user/comment_count_user.php. This flaw allows attackers to manipulate the 'task_id' argument, potentially leading to unauthorized database access. Given that the ex...

Discovered 13 hours ago

PoC for CVE-2026-19343

Code-projectsTask Management System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Task Management System

A vulnerability has been identified in the Code-Projects Task Management System version 1.0. This flaw exists within the '/admin/AdminLogin.php' file's handling of email and password arguments, allowing remote attackers to execute SQL injection attacks. Exploiting this vulnerability could potenti...

Discovered 14 hours ago

PoC for CVE-2026-19342

Code-projectsTask Management System6.9MEDIUM
Improper Authentication Vulnerability in Code-Projects Task Managem...

A security flaw exists in the code-projects Task Management System 1.0 related to the login functionality. This vulnerability arises from improper handling of the password parameter within the /index.php file. An attacker can exploit this loophole remotely, allowing unauthorized access and manipu...

PoC for CVE-2026-19341

UttHiper 1200gw8.7HIGH
Stack-based Buffer Overflow Vulnerability in UTT HiPER 1200GW by UTT

A security vulnerability has been identified in UTT HiPER 1200GW, affecting versions up to 2.5.3-170306. The issue lies within the strcpy function of the /goform/pptpSrvGlobalConfig file, where improper handling of the EncryptionMode argument can lead to a stack-based buffer overflow. This vulner...

Discovered 15 hours ago

PoC for CVE-2026-17017

WordPressCubeWP Framework
SQL Injection Vulnerability in CubeWP Framework WordPress Plugin

The CubeWP Framework WordPress plugin prior to version 1.1.31 contains a significant vulnerability due to improper sanitization and lack of capability checks on an AJAX action. This flaw allows users with Subscriber-level access and higher to execute SQL injection attacks, potentially compromisin...

PoC for CVE-2026-16032

WordPressLws Optimize
Improper Input Validation in LWS Optimize Plugin for WordPress

The LWS Optimize plugin for WordPress prior to version 4.1.2 contains an improper input validation vulnerability. This flaw allows attackers to exploit an unauthenticated analytics endpoint, enabling them to inject arbitrary web scripts into the administrative dashboard. When an administrator acc...

PoC for CVE-2026-15038

WordPressInfiniteWP Client
Authentication Bypass in InfiniteWP Client Plugin for WordPress by ...

The InfiniteWP Client for WordPress contains a security flaw where the plugin fails to verify the connection state and the authenticity of requests at its remote management endpoint, particularly within WordPress Multisite setups. This oversight permits unauthenticated attackers to bind a malicio...

PoC for CVE-2026-18473

WordPressWP Directory Kit
SQL Injection Vulnerability in WP Directory Kit Plugin by WordPress

An SQL injection vulnerability exists in the WP Directory Kit plugin for WordPress, versions prior to 1.5.5. This issue arises due to inadequate sanitization and escaping of user-supplied parameters before they are incorporated into SQL statements. As a result, unauthenticated attackers may explo...

PoC for CVE-2026-18037

WordPressCreate
Authorization Bypass in Create WordPress Plugin by WordPress

The Create WordPress plugin, prior to version 2.5.4, lacks proper authorization checks on one of its public REST API routes. This oversight allows unauthenticated attackers to access unpublished content, which can be rendered and made publicly available through the API. The vulnerability compromi...

PoC for CVE-2026-18464

WordPressWP Maps Pro
Denial of Service Vulnerability in WP MAPS PRO Plugin by WordPress

The WP MAPS PRO plugin for WordPress prior to version 6.1.3 lacks proper capability checks for certain AJAX actions. This oversights allows unauthenticated users to exploit these actions, leading to potential uncontrolled recursion. As a result, attackers may consume server resources excessively,...

PoC for CVE-2026-18357

WordPressWPc Order Tip For WooC...
Authorization Bypass in WooCommerce Plugin by WordPress

The WPC Order Tip for WooCommerce plugin prior to version 3.3.1 is susceptible to an authorization bypass due to the lack of proper nonce verification and authorization checks in its reporting functionality. This oversight permits unauthorized individuals to access sensitive order information for...

PoC for CVE-2026-18603

WordPressPiweb Cancel Order / R...
Authorization Flaw in WooCommerce Plugin for WordPress Allows Unaut...

The PiWeb Cancel order/Refund request feature in the WooCommerce plugin for WordPress versions prior to 1.3.4.34 lacks essential authorization checks. This vulnerability enables unauthenticated users to access and disclose the contents of other customers' orders without permission. Moreover, it a...

PoC for CVE-2026-18465

WordPressWP Maps Pro
Remote Code Execution Vulnerability in WP MAPS PRO WordPress Plugin

The WP MAPS PRO plugin for WordPress prior to version 6.1.3 is prone to a security vulnerability due to the lack of capability checks in AJAX actions accessible to unauthenticated users. This oversight permits unauthorized attackers to exploit file inclusion vulnerabilities by supplying a user-co...

PoC for CVE-2026-18032

WordPressWP Data Access
Vulnerability in WP Data Access Plugin Allows Unauthorized Database...

The WP Data Access plugin for WordPress before version 5.5.79 contains a vulnerability where it fails to properly validate column names in an unauthenticated AJAX action. This oversight permits attackers to manipulate requests and gain unauthorized access to the database. Specifically, they could...

PoC for CVE-2026-16992

WordPressCreate
Authorization Bypass in Create WordPress Plugin

The Create WordPress plugin versions prior to 2.5.4 contain a significant vulnerability where an authorization check is not enforced on certain REST API routes. This oversight allows attackers to access unpublished content without authentication, potentially leading to unauthorized exposure of se...

PoC for CVE-2026-17044

WordPressIptanus File Upload
SQL Injection Vulnerability in Iptanus File Upload Plugin for WordP...

The Iptanus File Upload plugin for WordPress prior to version 5.1.8 contains a vulnerability where a lack of proper sanitization and escaping of a specific parameter allows unauthenticated users to execute SQL injection attacks. This oversight can lead to unauthorized access to sensitive data or ...

PoC for CVE-2026-17011

WordPressNexter Blocks
Arbitrary CSS Injection Vulnerability in Nexter Blocks Plugin for W...

The Nexter Blocks WordPress plugin prior to version 5.0.2 suffers from improper access control, allowing users with a Contributor role to save arbitrary CSS through its REST endpoints. This oversight enables potential attackers to inject CSS that can alter the site's appearance, facilitating meth...

PoC for CVE-2026-17014

WordPressWP Photo Album Plus
WordPress Plugin Vulnerability in WP Photo Album Plus Allowing Unau...

The WP Photo Album Plus plugin for WordPress prior to version 9.2.07.002 lacks proper capability and nonce checks for its public REST endpoint actions. This vulnerability allows unauthenticated users to delete ZIP archives of generated album exports, potentially leading to unauthorized loss of us...

PoC for CVE-2026-16988

WordPressGeodirectory
Authorization Bypass in GeoDirectory WordPress Plugin

The GeoDirectory WordPress plugin, prior to version 2.8.169, lacks necessary authorization checks when returning map marker data for individual listings. This flaw allows unauthorized users to access and reveal details such as the title and geographic coordinates of listings that are pending or i...

PoC for CVE-2026-16965

WordPressSolace Extra
Authentication Bypass in Solace Extra Plugin for WordPress

The Solace Extra plugin for WordPress, prior to version 1.6.1, has a notable design flaw where it lacks proper capability and nonce checks for specific AJAX operations. This vulnerability allows any authenticated user, including subscribers, to make unauthorized modifications to post meta data on...

PoC for CVE-2026-16957

WordPressSlim Seo
Post-Meta Access Vulnerability in Slim SEO Plugin by WordPress

The Slim SEO WordPress plugin prior to version 4.9.11 allows users with the Contributor role to access post-meta data that they should not be able to view. This vulnerability occurs because the plugin does not adequately restrict access to the post-meta preview feature. As a result, users can rea...

Discovered 19 hours ago

PoC for CVE-2026-63030

WordPressWordPress🟣 EPSS 96%9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

Discovered 21 hours ago

PoC for CVE-2026-64600

LinuxLinux7.8HIGH
Data Fork Mapping Issue in Linux Kernel by Linux Foundation

A flaw in the Linux kernel's xfs filesystem can lead to stale data fork mappings during operations involving ILOCK cycles. The xfs_reflink_fill_{cow_hole,delalloc} functions, which manage data and cow fork mappings, may fail to refresh the data fork mapping when reacquiring the ILOCK. This oversi...

Discovered 1 day ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

PoC for CVE-2026-67620

FlowiseaiFlowise6.3MEDIUM
Server-Side Request Forgery Vulnerability in Flowise by Flowise AI

The Flowise application version 3.1.4 is susceptible to a server-side request forgery (SSRF) vulnerability due to an inadequate deny-list configuration in its SSRF guard found in httpSecurity.ts. Specifically, the default configuration omits critical endpoints associated with Oracle Cloud Infrast...

PoC for CVE-2026-18953

AwsAws-transform-mcp-server6.3MEDIUM
Improper Directory Limitation in Amazon awslabs.aws-transform-mcp-s...

The awslabs.aws-transform-mcp-server tool from Amazon contains a vulnerability due to improper validation of the savePath parameter, which could allow an attacker to write files outside the designated working directory. This issue affects versions 0.1.0 through 0.1.4. Users are encouraged to upgr...

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

PoC for CVE-2017-9757

IpfireIpfire🟣 EPSS 38%8.8HIGH
Remote Command Injection Vulnerability in IPFire by IPFire Team

IPFire version 2.19 is susceptible to a Remote Command Injection vulnerability through its ids.cgi component. The issue arises from improper handling of the OINKCODE parameter allowing authenticated users to execute arbitrary shell commands. This vulnerability can be exploited directly or via Cro...

PoC for CVE-2026-63077

JetbrainsTeamcity9.8CRITICAL
Unauthenticated Remote Code Execution in JetBrains TeamCity by JetB...

An unauthenticated remote code execution vulnerability has been identified in JetBrains TeamCity prior to version 2026.1.3 and 2025.11.7. This weakness is exposed through the agent polling protocol, allowing attackers to execute arbitrary code without authentication, posing significant risks to t...

Discovered 2 days ago

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

PoC for CVE-2026-19268

Abdullah1854Mcpgateway5.3MEDIUM
Command Injection Vulnerability in MCPGateway by Abdullah1854

A command injection vulnerability has been identified in the MCPGateway by Abdullah1854, specifically within the 'getUsageByDateRange' function located in the file 'src/services/claude-usage.ts'. This vulnerability arises due to improper handling of input parameters, allowing an attacker to manip...

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...