Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 21 minutes ago

PoC for CVE-2024-37890

WebsocketsWs7.5HIGH
ws: WebSocket Client and Server Vulnerability

The ws library, an open-source WebSocket client and server for Node.js, is susceptible to a vulnerability that can lead to server crashes when excessive headers are sent in a request. When headers exceed the threshold defined by server.maxHeadersCount, the server may become unresponsive. This iss...

Discovered 5 hours ago

PoC for CVE-2026-0303

Palo Alto NetworksCheckov By Prisma Cloud2.4LOW
Code Execution Vulnerability in Palo Alto Networks Checkov

Palo Alto Networks Checkov is susceptible to a code execution vulnerability that enables an attacker to execute arbitrary code when the tool scans a directory containing a configuration file under their control. This flaw can expose systems to potential threats, making it crucial for users to ass...

Discovered 8 hours ago

PoC for CVE-2026-73786

HP (HP)Clearpass Policy Manag...7.5HIGH
Denial-of-Service Vulnerability in CPPM Management Interface by HPE

A vulnerability exists in the web-based management interface of HPE's CPPM, enabling unauthenticated remote attackers to perform Denial-of-Service (DoS) attacks. This could lead to a degradation in performance and instability of the CPPM server, impacting availability and reliability for users.

Discovered 10 hours ago

PoC for CVE-2026-73699

FilerunFilerun8.6HIGH
PHP Object Injection Vulnerability in FileRun by Akruto

FileRun versions before 2026.3.0 are susceptible to a PHP object injection flaw, which allows authenticated attackers to execute arbitrary code. This vulnerability arises from incorrect options being supplied to the unserialize() function within the Perms::getPerms() method. Instead of using the ...

Discovered 12 hours ago

PoC for CVE-2026-88898

Appflowy-ioAppflowy-cloud7.1HIGH
AppFlowy-Cloud Vulnerability in Bulk Publish Endpoint for Authoriza...

The AppFlowy-Cloud product from AppFlowy has a security flaw in its bulk publish endpoint, which does not adequately verify the authorization of users against workspaces. This oversight allows authenticated users to publish content to other tenants' namespaces. As a result, attackers could potent...

Discovered 15 hours ago

PoC for CVE-2026-86060

MikrotikRouteros9.2CRITICAL
Argument-handling Flaw in RouterOS by MikroTik

MikroTik's RouterOS is vulnerable due to an argument-handling flaw in the SSH login process, specifically affecting usernames that start with a prohibited character. This flaw allows an attacker to manipulate the trusted RouterOS policy mask, facilitating privilege escalation. The exploitation of...

PoC for CVE-2016-3223

MicrosoftWindows Rt 8.1🟣 EPSS 21%8.1HIGH
Group Policy Elevation of Privilege Vulnerability in Microsoft Windows

This vulnerability occurs in several versions of Microsoft Windows where LDAP authentication is improperly managed. It allows attackers to exploit the way group-policy updates are processed. By manipulating this data stream within a domain controller, an attacker can escalate privileges, potentia...

Discovered 19 hours ago

PoC for CVE-2019-18394

IgniterealtimeOpenfire🟣 EPSS 32%9.8CRITICAL
Server Side Request Forgery Vulnerability in Openfire by Ignite Rea...

A security flaw exists in the FaviconServlet.java component of Openfire, allowing attackers to exploit the Server Side Request Forgery (SSRF) vulnerability. This enables unauthorized HTTP GET requests to be sent, potentially exposing sensitive data or enabling further attacks on the network. User...

Discovered 21 hours ago

PoC for CVE-2026-77771

WordPressMiniorange 2fa7.5HIGH
Authentication Bypass in miniOrange 2FA Plugin for WordPress

The miniOrange 2FA plugin for WordPress prior to version 6.3.1 and 19.3 allows an attacker with knowledge of a victim's password to bypass authentication limits. This occurs because the plugin does not properly associate second-factor authentication attempt limits with user accounts, enabling unl...

PoC for CVE-2026-78361

WordPressZipmoney(zip Co) Payme...9.1CRITICAL
Authorization Bypass in zipMoney Payments Plugin for WooCommerce by...

The zipMoney Payments Plugin for WooCommerce prior to version 2.4.0 contains a flaw that allows unauthenticated users to bypass authorization checks. This vulnerability enables unauthorized deletion of WordPress options which can compromise site configuration and access controls. Attackers could ...

PoC for CVE-2026-77770

WordPressMiniorange 2fa10CRITICAL
Authentication Bypass Vulnerability in miniOrange 2FA WordPress Plu...

The miniOrange 2FA WordPress plugin prior to version 6.3.1 and version 19.3 is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated users to delete site options via unvalidated transaction inputs. As a consequence, any visitor can potentially remove critical set...

PoC for CVE-2026-81431

WordPressRegistration Form For ...7.2HIGH
Role Assignment Vulnerability in WooCommerce WordPress Plugin

The WooCommerce plugin for WordPress, prior to version 1.1.3, contains a vulnerability in its Registration Form functionality. It fails to properly validate the legitimacy of the registration form, inadvertently allowing users with post-creation capabilities (Contributors and above) to register w...

PoC for CVE-2026-82925

WordPressSite Reviews8.1HIGH
Deserialization Vulnerability in Site Reviews Plugin for WordPress

The Site Reviews WordPress plugin prior to version 8.3.0 is vulnerable to a serious deserialization flaw that allows unauthenticated users to inject arbitrary PHP objects. This vulnerability arises from the plugin's failure to properly secure request data during deserialization. It computes a key...

PoC for CVE-2026-19436

WordPressUltimate Gift Cards Fo...7.5HIGH
WooCommerce Plugin Vulnerability in Ultimate Gift Cards Allows Exce...

The Ultimate Gift Cards for WooCommerce plugin, prior to version 3.2.10, contains a vulnerability where it fails to properly match the issued gift card coupon values with the actual transaction amounts at checkout. This oversight allows unauthenticated users to exploit the system, effectively obt...

PoC for CVE-2026-19439

WordPressUltimate Gift Cards Fo...7.5HIGH
Unauthorized Data Exposure in Ultimate Gift Cards for WooCommerce P...

The Ultimate Gift Cards for WooCommerce plugin prior to version 3.2.10 lacks necessary authorization checks, enabling unauthorized users to access sensitive gift card information. This vulnerability permits retrieval of attached gift cards from arbitrary orders, exposing significant customer pers...

PoC for CVE-2026-19840

WordPressNotiqoo6.5MEDIUM
AJAX Action Vulnerability in Notiqoo WordPress Plugin Affects User ...

The Notiqoo WordPress plugin prior to version 1.4.14 contains a security flaw that lacks proper capability checks on several AJAX actions. This vulnerability permits users, even those with minimal roles like 'contributor', to manipulate WordPress options via user input. By exploiting this flaw, a...

Discovered 22 hours ago

PoC for CVE-2023-6063

WordpressWP Fastest Cache🟣 EPSS 74%7.5HIGH
WP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection

The WP Fastest Cache plugin for WordPress is susceptible to a SQL injection vulnerability due to inadequate sanitization and escaping of user-supplied data in SQL statements. This flaw enables unauthenticated attackers to execute arbitrary SQL queries, potentially compromising the integrity of th...

Discovered 1 day ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 99%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-87933

DavegambleCjson6.9MEDIUM
Use After Free Vulnerability in cJSON by DaveGamble

A significant vulnerability has been identified in cJSON, specifically within the function cJSONUtils_MergePatch in the file cJSON_Utils.c. This flaw can lead to a use after free condition, which allows attackers to exploit the issue remotely. Once this vulnerability is triggered, it can potentia...

PoC for CVE-2026-87926

Rizwan17Inventory-management-s...5.3MEDIUM
Cross Site Scripting Flaw in Rizwan17 Inventory Management System L...

A vulnerability has been identified in the Rizwan17 inventory management system that permits cross site scripting (XSS) attacks through the manipulation of the 'msg' argument in the index.php file associated with the Login Page component. This flaw allows attackers to execute code remotely, poten...

PoC for CVE-2026-87925

Rizwan17Inventory-management-s...6.9MEDIUM
SQL Injection Vulnerability in Rizwan17 Inventory Management System

A SQL injection vulnerability has been identified in the Rizwan17 inventory-management-system, specifically within the storeCustomerOrderInvoice function located in the includes/manage.php file. An attacker can exploit this vulnerability by manipulating the 'pro_name[]' argument, thereby executin...

PoC for CVE-2026-87924

Rizwan17Inventory-management-s...6.9MEDIUM
Missing Authentication in Rizwan17 Inventory Management System

A security vulnerability exists in the Rizwan17 inventory-management-system, specifically in the invoice generation component. The issue pertains to the file includes/invoice_bill.php, where improper handling of the arguments order_date and invoice_no allows for missing authentication. This weakn...

PoC for CVE-2026-87923

Rizwan17Inventory-management-s...5.3MEDIUM
Cross-Site Scripting Vulnerability in Rizwan17 Inventory Management...

A cross-site scripting (XSS) vulnerability has been detected in the Rizwan17 inventory-management-system, particularly in the file includes/DBOperation.php used by the List Handler component. By manipulating the parameters such as category_name, brand_name, or product_name, an attacker can execut...

PoC for CVE-2026-87922

Rizwan17Inventory-management-s...6.9MEDIUM
Missing Authentication in Rizwan17 Inventory Management System

A security flaw has been identified in the Rizwan17 inventory management system affecting the DBOperation.addCategory function within includes/process.php. The vulnerability arises due to insufficient authentication checks, specifically related to the manipulation of the 'userid' argument. This a...

PoC for CVE-2026-87921

Rizwan17Inventory-management-s...6.9MEDIUM
SQL Injection Vulnerability in Rizwan17 Inventory Management System

A vulnerability exists in the Rizwan17 inventory management system due to improper input validation in the update_record function located within includes/manage.php. This flaw allows an attacker to manipulate the arguments update_category, cid, update_brand, and update_product, leading to SQL inj...

PoC for CVE-2026-67276

MikrotikRouteros9.2CRITICAL
SSH Authentication Vulnerability in MikroTik RouterOS

MikroTik RouterOS contains a vulnerability in its SSH authentication mechanism, which fails to fully compare RSA public keys. While it checks the key type and modulus, the exponent is overlooked. An attacker with knowledge of an authorized RSA modulus can exploit this flaw by supplying a crafted ...

PoC for CVE-2024-44625

GogsGogs🟣 EPSS 16%8.8HIGH
Gogs Directory Traversal Vulnerability

Gogs, an open-source Git service, has a significant directory traversal vulnerability in its codebase. Specifically, the issue arises from the editFilePost function located in internal/route/repo/editor.go. This vulnerability allows an attacker to access arbitrary directories and files on the ser...

PoC for CVE-2026-67401

WebprosCpanel9.9CRITICAL
SQL Injection Vulnerability in cPanel's EmailTrack Component

A vulnerability in cPanel's EmailTrack component enables mail-enabled accounts to execute remote code with root privileges through an SQL injection exploit. This security flaw allows unauthorized users to manipulate SQL queries, leading to potential system compromise and disruption of services. S...

PoC for CVE-2015-5736

FortinetForticlient
Kernel Code Execution Vulnerability in FortiClient by Fortinet

The Fortishield.sys driver in Fortinet's FortiClient prior to version 5.2.4 contains vulnerabilities that allow local users to execute arbitrary code with kernel privileges. This is achieved by manipulating the callback function via specific ioctl calls, namely 0x220024 and 0x220028. Unauthorized...

PoC for CVE-2026-67401

WebprosCpanel9.9CRITICAL
SQL Injection Vulnerability in cPanel's EmailTrack Component

A vulnerability in cPanel's EmailTrack component enables mail-enabled accounts to execute remote code with root privileges through an SQL injection exploit. This security flaw allows unauthorized users to manipulate SQL queries, leading to potential system compromise and disruption of services. S...

PoC for CVE-2026-87929

MaxsiteMaxsite Cms9.3CRITICAL
Authentication Bypass in MaxSite CMS by Hardcoded Encryption Key

MaxSite CMS versions up to 109.6 contain a significant vulnerability where a hardcoded session encryption key is embedded in 'application/config/config.php'. This constant key is never altered during installation, rendering the system vulnerable to authentication bypass by unauthenticated attacke...

PoC for CVE-2026-87930

MaxsiteMaxsite Cms9.2CRITICAL
PHP Object Injection Vulnerability in MaxSite CMS by MaxSite

MaxSite CMS, in versions up to 109.6, is vulnerable to a PHP object injection flaw due to the improper handling of the ci_session cookie. This vulnerability allows unauthorized attackers to manipulate session cookies leveraging a hardcoded encryption key, enabling them to exploit magic methods an...

PoC for CVE-2026-87928

MaxsiteMaxsite Cms5.1MEDIUM
Cross-Site Scripting Vulnerability in MaxSite CMS by MaxSite

MaxSite CMS versions 0.94 through 109.6 are plagued by a cross-site scripting vulnerability located within the admin_page upload handler. This flaw permits any authenticated user to upload HTML files, which may contain malicious scripts. Once these files are placed in the uploads/_pages/ director...

PoC for CVE-2026-87927

MaxsiteMaxsite Cms8.8HIGH
Local File Inclusion Vulnerability in MaxSite CMS by MaxSite

MaxSite CMS versions up to 109.6 are susceptible to a local file inclusion vulnerability that can be exploited via the ajax and require-maxsite dispatchers. This security flaw enables unauthenticated attackers to perform path traversal by providing base64-encoded sequences, allowing them to bypas...

Discovered 2 days ago

PoC for CVE-2026-49881

GoogleAndroid7.8HIGH
Arbitrary Code Execution Vulnerability in Android Services

The vulnerability lies in the InCallController.java file, specifically within the serviceClassExists function. This flaw allows for arbitrary code execution due to a logic error, enabling local escalation of privileges without the need for additional execution rights. The issue can be exploited w...

PoC for CVE-2026-54121

MicrosoftWindows 10 Version 16078.8HIGH
Elevation of Privilege Vulnerability in Microsoft Active Directory ...

A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...

PoC for CVE-2026-87827

KguardKguard Firmware10CRITICAL
Remote Command Execution Flaw in KGUARD DVR Devices

Certain KGUARD DVR devices with outdated firmware exhibit a serious vulnerability, exposing a system command execution service on all network interfaces without authentication. This flaw enables remote attackers to execute arbitrary commands, potentially compromising the device entirely. Exploits...

PoC for CVE-2026-83991

MicrosoftWindows 10 Version 18095.5MEDIUM
Tampering Vulnerability in Windows Cloud Files Mini Filter Driver b...

The Windows Cloud Files Mini Filter Driver contains a vulnerability due to missing authentication for critical functions. This flaw allows an unauthorized attacker to perform local tampering, which can impact the integrity of files and data within the affected operating systems, such as Windows 1...

PoC for CVE-2026-86776

KeepassKeepass4.6MEDIUM
Memory Exhaustion Vulnerability in KeePass by Dominik Reichl

The KeePass password manager, specifically versions 2.35 through 2.61.1, contains a vulnerability that stems from inadequate validation of KDBX header field sizes during memory allocation. This flaw allows attackers to create specially crafted KDBX files that specify excessively large header fiel...

PoC for CVE-2026-19089

WordPressProduct Input Fields F...9.8CRITICAL
File Upload Vulnerability in WooCommerce WordPress Plugin

The WooCommerce WordPress plugin prior to version 2.0.2 is susceptible to a file upload vulnerability due to its failure to validate the types of files that can be uploaded when its accepted-types setting is left empty. This lack of validation opens the door for unauthenticated attackers to uploa...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-85117

WordPressContact Form 7 Captcha6.5MEDIUM
Arbitrary Code Execution Vulnerability in Contact Form 7 Captcha Pl...

The Contact Form 7 Captcha plugin for WordPress contains a vulnerability that allows unauthenticated users to exploit the shortcode parser functionality. Specifically, earlier versions of the plugin, prior to 0.1.9, process the entire Contact Form 7 form’s output, which includes user-submitted da...

PoC for CVE-2026-83537

WordPressWP Express Checkout5.3MEDIUM
Unauthorized Payment Confirmation in WP Express Checkout Plugin

The WP Express Checkout plugin for WordPress prior to version 2.5.0 is susceptible to a significant security flaw that fails to properly validate the completion of payment transactions on the server-side. This oversight allows unauthorized users to simulate the payment process, marking orders as ...

PoC for CVE-2026-19855

WordPressCleantalk6.5MEDIUM
Arbitrary Shortcode Execution in CleanTalk WordPress Plugin

The CleanTalk WordPress plugin prior to version 6.87 is susceptible to an arbitrary shortcode execution vulnerability. This flaw allows unauthenticated users to submit comment content that is processed by the WordPress shortcode engine. As a result, malicious visitors can register and execute arb...

PoC for CVE-2026-80440

WordPressHustle4.8MEDIUM
WordPress Hustle Plugin Shortcode Execution Vulnerability

The Hustle plugin for WordPress prior to version 7.8.14.2 contains a security flaw that permits unauthenticated users to execute shortcodes through form submissions. The plugin fails to sufficiently sanitize shortcodes in user-provided input, allowing potential attackers to exploit this weakness ...

PoC for CVE-2026-85418

WordPressOrbit Fox: Duplicate P...5.4MEDIUM
Cross-Site Scripting in Orbit Fox Plugin for WordPress

The Orbit Fox plugin for WordPress, prior to version 3.0.9, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw arises from inadequate validation of user-supplied HTML tag names within specific Beaver Builder widgets. As a result, users possessing contributor-level access or h...

PoC for CVE-2026-85133

WordPressWPlp Cookie Consent5.4MEDIUM
Unauthorized Access Vulnerability in WPLP Cookie Consent Plugin for...

The WPLP Cookie Consent plugin for WordPress prior to version 4.4.2 suffers from an access control weakness due to the absence of nonce and capability checks on various AJAX actions. This flaw permits any authenticated user, including those with minimal privileges such as subscribers, to gain una...

PoC for CVE-2026-84222

WordPressKirki5.3MEDIUM
Improper Access Control in Kirki WordPress Plugin

The Kirki WordPress plugin, prior to version 6.3.0, contains a vulnerability that allows unauthenticated users to access private content. This issue arises because the plugin fails to verify whether a requester is authorized to view certain pages, including those marked as private, draft, or tras...

PoC for CVE-2026-85037

WordPressSunshine Photo Cart5.3MEDIUM
Insufficient Price Validation in Sunshine Photo Cart Plugin for Wor...

The Sunshine Photo Cart plugin for WordPress prior to version 3.7 is susceptible to a vulnerability that arises due to insufficient validation of client-supplied price identifiers. This flaw allows unauthenticated users to manipulate price information during the cart process, enabling them to pur...

PoC for CVE-2026-84113

WordPressQuentn WP4.1MEDIUM
SQL Injection Vulnerability in Quentn WP Plugin for WordPress

The Quentn WP plugin for WordPress prior to version 1.2.15 is vulnerable due to improper sanitization and escaping of user input in SQL queries. This flaw can allow high privilege users, such as administrators, to execute malicious SQL commands, potentially compromising the integrity of the datab...