Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered just now...

PoC for CVE-2024-22019

NodejsNode7.5HIGH
Node.js HTTP Servers Vulnerable to Resource Exhaustion Attacks

A vulnerability exists within Node.js HTTP servers that permits attackers to send specially crafted HTTP requests utilizing chunked encoding. This manipulation can lead to resource exhaustion, as the server is induced to read an unbounded number of bytes from a single connection. The flaw takes a...

Discovered 4 hours ago

PoC for CVE-2026-7228

SourcecodesterPizzafy Ecommerce System6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Pizzafy Ecommerce System

A vulnerability exists in the Pizzafy Ecommerce System 1.0, specifically within the get_cart_count function located in the /admin/ajax.php file. This flaw allows attackers to manipulate the ID argument, enabling them to execute SQL injection attacks remotely. Exploiting this vulnerability could l...

Discovered 6 hours ago

PoC for CVE-2026-65711

NuxsminSyspass8.6HIGH
OS Command Injection Vulnerability in sysPass by sysPass

The sysPass application, specifically version 3.2.11, is susceptible to an OS command injection flaw. This vulnerability allows authenticated administrators to exploit the backup functionality by maliciously altering the backup path. When the FileBackupService concatenates this input to construct...

PoC for CVE-2026-65710

NuxsminSyspass7.1HIGH
Missing Authorization Vulnerability in sysPass by Caycon

The vulnerability in sysPass version 3.2.11 arises from insufficient authorization checks during public link creation, enabling users with the PUBLICLINK_CREATE profile flag to exploit this flaw. An attacker can trigger unauthorized decryption of vault account passwords by invoking the saveCreate...

PoC for CVE-2026-65709

NuxsminSyspass8.7HIGH
Missing Object-Level Authorization in sysPass JSON-RPC API

The sysPass version 3.2.11 vulnerability arises from a missing object-level authorization in its JSON-RPC API. This flaw permits API token holders to improperly enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without necessary per-account access contro...

PoC for CVE-2026-65708

NuxsminSyspass8.6HIGH
Insecure Direct Object Reference Vulnerability in sysPass by Caycon

The sysPass application version 3.2.11 has a vulnerability that enables authenticated users to exploit insecure direct object references. By manipulating file IDs through various actions such as download, view, delete, upload, and list, attackers can gain unauthorized access to account file attac...

Discovered 7 hours ago

PoC for CVE-2026-65707

Likeadmin-likeshopLikeshop8.5HIGH
Authenticated SQL Injection in Likeshop Product by Likeshop

Likeshop versions up to 3.0.5 are susceptible to an authenticated SQL injection vulnerability that allows admin users to extract arbitrary data from the database. The flaw occurs in the adjustAccount endpoint, where unsanitized POST parameters are processed without proper validation or parameter ...

PoC for CVE-2026-65693

MicroweberMicroweber8.6HIGH
Server-Side Template Injection Vulnerability in Microweber CMS

Microweber CMS up to version 2.0.20 contains a vulnerability allowing authenticated administrators to execute arbitrary operating system commands. This occurs through the injection of Twig expressions into unsanitized mail templates. Due to the absence of necessary security mechanisms like Sandbo...

PoC for CVE-2026-66027

Kortix-aiSuna8.7HIGH
Broken Access Control in Suna Messaging API by Kortix AI

The Suna messaging API in versions prior to 0.9.102 is susceptible to a broken access control vulnerability, enabling authenticated attackers to exploit inadequate isolation measures. Attackers can gain unauthorized access to message queues belonging to other users, which allows them to read pend...

PoC for CVE-2026-66007

HuggingfaceDatasets6.9MEDIUM
Path Traversal Vulnerability in Hugging Face Datasets Product

The vulnerability in Hugging Face Datasets allows attackers to exploit the file_name metadata field in folder-based dataset builders. Due to inadequate validation, an attacker can input crafted values that include directory traversal sequences. As a result, this could lead to unauthorized access ...

PoC for CVE-2026-66006

TreeverseLakefs6.9MEDIUM
Authentication Bypass Vulnerability in lakeFS by Treeverse

The lakeFS product by Treeverse contains an authentication bypass vulnerability located at the /setup_comm_prefs endpoint. This flaw allows unauthenticated attackers to overwrite critical operator metadata, including sensitive information like email, name, and company details, after the setup pha...

PoC for CVE-2026-66005

JanhqJan5.3MEDIUM
CORS Misconfiguration in Jan API Server Affects Local Network Security

The Jan API Server possesses a CORS misconfiguration that allows network-adjacent attackers to bypass trusted host restrictions via a flaw in the server’s handling of user-configured trusted hosts. This issue enables attackers to manipulate the server, replacing user-defined trusted hosts with a ...

Discovered 8 hours ago

PoC for CVE-2026-66004

AhujasidBlender-mcp6MEDIUM
Path Traversal Vulnerability in BlenderMCP Affects File Security

BlenderMCP prior to commit 30a3308 features a path traversal vulnerability within the download_polyhaven_asset method. This flaw enables attackers to write arbitrary files by injecting harmful traversal sequences into API response keys. If an attacker successfully executes a MITM (Man-In-The-Midd...

Discovered 11 hours ago

PoC for CVE-2026-60206

OracleOracle Weblogic Server9.9CRITICAL
SAML Exploitation Vulnerability in Oracle WebLogic Server by Oracle

A vulnerability in Oracle WebLogic Server's Core component permits low-privileged attackers with network access to exploit SAML, potentially compromising the server's functionality. This can lead to unauthorized access, impacting not only the WebLogic Server but also additional interconnected pro...

Discovered 16 hours ago

PoC for CVE-2026-12981

WordPressCafehaus Api
Authentication Bypass in CAFEHAUS API Plugin for WordPress

The CAFEHAUS API WordPress plugin prior to version 1.0.0 is vulnerable to an authentication bypass issue that permits attackers to reset user passwords without any form of authentication or authorization. This flaw enables attackers to gain unauthorized access to any user's account, including tho...

PoC for CVE-2026-12877

WordPressProject Management, Bu...
SQL Injection Vulnerability in Project Management WordPress Plugin

The Project Management, Bug and Issue Tracking Plugin for WordPress, prior to version 5.1.0, is susceptible to SQL injection due to inadequate sanitization and escaping of user-supplied input in SQL queries. This vulnerability allows unauthenticated attackers to manipulate database queries, poten...

PoC for CVE-2026-14603

WordPressWowoptin: Next-gen Pop...
Unauthorized Access Flaw in WowOptin Popup Plugin for WordPress

The WowOptin: Next-Gen Popup Maker plugin for WordPress, prior to version 1.4.38, is vulnerable due to insufficient authorization checks on a REST endpoint. This flaw allows unauthenticated users to disable all opt-in forms across the site and to inject new template-based opt-in entries into the ...

PoC for CVE-2026-12690

WordPressProfilegrid
Insufficient License Management in ProfileGrid Plugin for WordPress

The ProfileGrid plugin for WordPress contains a vulnerability related to its license management functionality. This flaw arises from the absence of a proper capability check, as it solely relies on a nonce that is accessible to any logged-in user. Consequently, this allows authenticated users wit...

PoC for CVE-2026-12689

WordPressProfilegrid
Authorization Flaw in ProfileGrid WordPress Plugin by ProfileGrid

The ProfileGrid WordPress plugin prior to version 5.9.9.7 contains a significant authorization flaw that enables authenticated users with Subscriber-level access and higher to interact maliciously with others' private-message threads. This includes the ability to soft-delete threads, alter metada...

PoC for CVE-2026-12688

WordPressProfilegrid
Improper Input Validation in ProfileGrid WordPress Plugin Allows Fo...

The ProfileGrid WordPress plugin prior to version 5.9.9.7 is susceptible to an improper input validation vulnerability. This flaw allows unauthenticated attackers to exploit the plugin's handling of PayPal Instant Payment Notification (IPN) messages. By forging a valid PayPal notification, an att...

PoC for CVE-2026-12497

WordPressPaid Membership Plugin...
Improper Role Restriction in Paid Membership Plugin for WordPress

The Paid Membership Plugin for WordPress prior to version 4.16.18 fails to consistently enforce role restrictions in its front-end registration process. This vulnerability arises because the role options presented to users and the roles accepted by the registration handler are evaluated by differ...

Discovered 18 hours ago

PoC for CVE-2011-2523

VsftpdVsftpd🟣 EPSS 96%9.8CRITICAL
Backdoor Vulnerability in vsftpd 2.3.4 by Academy of Linux

A serious backdoor vulnerability was discovered in vsftpd 2.3.4, affecting downloads made between June 30 and July 3, 2011. This vulnerability allows an attacker to exploit the software and open a remote shell on port 6200/tcp, granting unauthorized access to the system. It poses significant risk...

PoC for CVE-2026-54121

MicrosoftWindows 10 Version 16078.8HIGH
Elevation of Privilege Vulnerability in Microsoft Active Directory ...

A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...

Discovered 19 hours ago

PoC for CVE-2026-59880

Immutable-jsImmutable-js8.7HIGH
Denial of Service in Immutable.js Affecting Data Structures

Immutable.js exhibits a vulnerability in its data structures, specifically in Immutable.Map and Immutable.Set. Prior to versions 4.3.9 and 5.1.8, these structures use a linear search method in a HashCollisionNode bucket containing keys with the same 32-bit hash. An attacker controlling the input ...

PoC for CVE-2026-58057

FlowiseFlowise2.3LOW
Custom MCP Environment Variable Bypass in Flowise by FlowiseAI

Flowise versions prior to 3.1.3 suffer from a vulnerability due to improper validation of Custom MCP standard input/output environment variables against a denylist. The case-sensitive nature of the comparison allows an authenticated user to exploit this flaw on Windows systems where environment v...

Discovered 20 hours ago

PoC for CVE-2020-1472

MicrosoftWindows Server Version...🟣 EPSS 100%5.5MEDIUM
Netlogon Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a...

Discovered 1 day ago

PoC for CVE-2026-16767

Ne-lexaPHP-zip6.9MEDIUM
Path Traversal Vulnerability in Ne-Lexa php-zip ZIP Handler

A vulnerability has been identified in Ne-Lexa's php-zip library versions up to 4.0.2. It occurs within the ZipFile::extractTo function located in src/ZipFile.php, where inadequate validation of the entryName argument allows for malicious path traversal attacks. This vulnerability can be exploite...

PoC for CVE-2026-16765

CodeastroOnline Classroom6.9MEDIUM
SQL Injection Vulnerability in CodeAstro Online Classroom by CodeAstro

A SQL injection vulnerability has been identified within the CodeAstro Online Classroom application at the '/OnlineClassroom/loginlinkadmin.php' endpoint. By manipulating the 'aid' parameter, an attacker may execute arbitrary SQL commands, potentially leading to unauthorized access to the databas...

PoC for CVE-2026-65694

MicroweberMicroweber8.7HIGH
Path Traversal Vulnerability in Microweber CMS by Microweber

Microweber CMS, up to version 2.0.20, has a significant path traversal flaw in its static file controller. This vulnerability allows remote, unauthenticated attackers to exploit the failure of the normalize_path() function. By supplying specially crafted directory traversal sequences in the path ...

PoC for CVE-2026-16763

LocalstackServerless-localstack4.8MEDIUM
OS Command Injection in Localstack Serverless-Localstack by Localstack

A vulnerability exists in Localstack Serverless-Localstack versions up to 1.4.0, specifically within the Configuration Handler's index.js file. This security flaw allows an attacker to manipulate the 'custom.localstack.docker.compose_file' argument, potentially leading to OS command injection. Al...

PoC for CVE-2026-42533

F5Nginx Plus9.2CRITICAL
Heap Buffer Overflow in NGINX Plus and Open Source during Regex Map...

A vulnerability in NGINX Plus and NGINX Open Source arises when a map directive improperly utilizes regex matching in conjunction with string expressions referencing the map’s regex capture variables before the map output variable, or when non-cacheable variables are used under specific condition...

PoC for CVE-2021-41773

ApacheApache Http Server🟣 EPSS 100%7.5HIGH
Path traversal and file disclosure vulnerability in Apache HTTP Ser...

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default config...

PoC for CVE-2026-65010

HuggingfaceDatasets4.4MEDIUM
Symlink-Following Vulnerability in Hugging Face Datasets by Hugging...

Hugging Face Datasets prior to version 5.00 is susceptible to a symlink-following vulnerability. This issue arises within the Extractor.extract() function, whereby local attackers can exploit predictable output paths to pre-plant symbolic links. As a result, these attackers can redirect the extra...

PoC for CVE-2026-63765

ChatwootChatwoot8.8HIGH
Authentication Bypass in Chatwoot by Chatwoot Inc.

Chatwoot, prior to version 4.16.0, is susceptible to an authentication bypass in the direct uploads controller. This flaw allows attackers without authorization to create arbitrary ActiveStorage blobs within any tenant account. By exploiting the absence of proper authentication checks, attackers ...

PoC for CVE-2026-65920

HuggingfaceDiffusers5.3MEDIUM
Path Traversal Vulnerability in Diffusers by Hugging Face

The Diffusers library by Hugging Face encountered a path traversal issue in the _get_checkpoint_shard_files function, allowing attackers to exploit the vulnerability by providing malicious weight_map values in model index JSON. This flaw enables them to utilize ../ sequences or absolute paths, th...

PoC for CVE-2026-65918

PytorchVision7.1HIGH
Out-of-bounds Heap Read Vulnerability in PyTorch torchvision Software

The torchvision component of PyTorch is vulnerable to an out-of-bounds heap read in the GIF decoder's read_from_tensor callback. The issue arises when the decoder processes malicious or corrupted GIF files, potentially leading to a denial of service through segmentation faults or the exposure of ...

PoC for CVE-2026-65702

Vanna-aiVanna8.8HIGH
Path Traversal Vulnerability in Vanna by Vanna Ltd.

The Vanna application prior to version 2.0.2 has a path traversal flaw within its FileSystemConversationStore persistence integration. This vulnerability permits unauthenticated remote attackers to exploit the conversation_id parameter in the chat API. By injecting path traversal sequences, attac...

PoC for CVE-2026-65701

Svc-develop-teamSo-vits-svc9.3CRITICAL
Path Traversal Vulnerability in SoftVC VITS Singing Voice Conversion

The SoftVC VITS Singing Voice Conversion product contains a path traversal vulnerability within its full-song inference server. This flaw allows unauthenticated remote attackers to exploit the system by supplying malicious filesystem paths through the 'audio_path' field in an unauthenticated POST...

PoC for CVE-2026-65700

H2oaiH2ogpt9.3CRITICAL
Path Traversal Vulnerability in h2oGPT Product by OpenAI

The h2oGPT application, up to version 0.2.1, contains a vulnerability allowing unauthenticated attackers to exploit the OpenAI-compatible files API. By leveraging traversal sequences within the bearer token, attackers can bypass authentication mechanisms, leading to unauthorized file reading, wri...

PoC for CVE-2026-65699

ReworkdAgentgpt2.3LOW
Authorization Bypass Vulnerability in AgentGPT by Geo Chen

AgentGPT version 1.0.0 has a critical flaw that permits authenticated users to bypass authorization checks by manipulating request parameters. This vulnerability allows users to attach tasks to agent runs belonging to other users without verifying ownership, posing a significant risk of task hist...

PoC for CVE-2026-65698

VoideditorVoid6MEDIUM
Path Traversal Vulnerability in Void AI Agent File-Reading Tools

Void versions up to 1.3.4 exhibit a path traversal vulnerability in their AI agent file-reading tools, which can be exploited by network-adjacent attackers. This flaw enables unauthorized access to arbitrary host files outside the designated workspace by injecting instructions into the content be...

PoC for CVE-2026-65697

UsefathomFathom5.1MEDIUM
Stored Cross-Site Scripting in Fathom Lite Analytics by Fathom

Fathom Lite versions up to 1.3.1 are vulnerable to a stored cross-site scripting (XSS) issue that affects the analytics collection functionality. This vulnerability allows unauthenticated attackers to inject malicious JavaScript code via crafted hostname and pathname inputs directed to the /colle...

PoC for CVE-2026-65696

SctOverseerr5.3MEDIUM
Authorization Bypass in Overseerr Affects User Record Confidentiality

Overseerr version 1.35.0 contains a significant vulnerability within its push subscription API that allows authenticated users to bypass authorization controls. By manipulating the userId in the API path, attackers can illicitly list, view, and delete push subscriptions belonging to other users. ...

PoC for CVE-2026-65695

GongrzheOffice-word-mcp-server7.6HIGH
Path Traversal Vulnerability in Office-Word-MCP-Server by Geo Chen

The Office-Word-MCP-Server, up to version 1.1.11, has a path traversal vulnerability in its document handling tools. This flaw allows unauthenticated attackers to manipulate the filename argument to read or overwrite .docx files beyond the designated working directory. The vulnerability arises fr...

PoC for CVE-2026-65917

UsmannasirCyberpanel8.7HIGH
Insecure Direct Object Reference Found in CyberPanel's Backup Manag...

CyberPanel, up to version 1.9.1, is susceptible to an insecure direct object reference (IDOR) vulnerability in its IncBackups application. Authenticated users can exploit this flaw to access or manipulate the backup resources of other tenants using a globally sequential IncJob ID that is not rest...

PoC for CVE-2026-65916

UsmannasirCyberpanel7.2HIGH
Authorization Bypass in CyberPanel Affects Backup Management

CyberPanel versions up to 1.9.1 are susceptible to a missing authorization vulnerability in the cancelBackupCreation handler. This flaw permits authenticated users to manipulate backup processes of other tenants, including terminating backups, deleting archives, and corrupting status files. By cr...

PoC for CVE-2026-16735

Release-itConventional-changelog4.8MEDIUM
OS Command Injection Vulnerability in release-it conventional-chang...

A security vulnerability exists in the release-it conventional-changelog component, specifically within the writeChangelog function found in index.js. By manipulating the infile argument, an attacker could execute OS commands, leading to potential exploitation. This vulnerability requires local a...

PoC for CVE-2024-37054

MlflowMlflow8.8HIGH
Arbitrary Code Execution Vulnerability in MLflow Platform

A significant security vulnerability exists within the MLflow platform developed by Databricks. This issue arises from the deserialization of untrusted data in versions 0.9.0 and later. Attackers exploit this vulnerability by uploading a malicious PyFunc model that, once interacted with, can exec...

PoC for CVE-2026-16733

BahmutovFind-cypress-specs4.8MEDIUM
OS Command Injection Vulnerability in bahmutov find-cypress-specs

A vulnerability exists in the bahmutov find-cypress-specs package, specifically in the shell.exec function located in src/index.js of the Branch Handler component. By manipulating the --branch argument, an attacker can execute arbitrary operating system commands. This vulnerability is limited to ...

Discovered 2 days ago

PoC for CVE-2026-46331

LinuxLinux7.8HIGH
Page Cache Corruption Vulnerability in Linux Kernel - Vendor: Linux

An issue exists in the Linux Kernel where improper handling of copy-on-write (COW) operations can lead to page cache corruption. This is due to the tcf_pedit_act() function, which computes the COW range without considering runtime header offsets added by typed keys. As a result, portions of the w...