Publicly Disclosed
PoC Exploits

πŸ”΄ Alway take caution when working with PoC Exploits πŸ”΄

Discovered just now...

PoC for CVE-2026-49975

ApacheApache Http Server7.5HIGH
Apache HTTP Server: mod_http2 denial of service

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

PoC for CVE-2024-20154

MediaTekMt2735, Mt6767, Mt6768...🟣 EPSS 33%8.8HIGH
Out of Bounds Write Vulnerability in MediaTek Modem

A vulnerability has been identified in MediaTek Modem due to a missing bounds check, resulting in a possible out of bounds write. This flaw allows for remote code execution if an unwitting user connects to a malicious base station operated by an attacker. No local execution privileges or user int...

PoC for CVE-2026-25089

FortinetFortisandbox9.1CRITICAL
Fortinet - Fortisandbox

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 m...

Discovered 12 minutes ago

PoC for CVE-2026-44963

VeeamBackup And Replication9.4CRITICAL
Veeam - Backup And Replication

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

Discovered 4 hours ago

PoC for CVE-2026-45247

MirasvitFull Page Cache Warmer...9.3CRITICAL
PHP Object Injection Vulnerability in Mirasvit Full Page Cache Warm...

The Mirasvit Full Page Cache Warmer, specifically for Magento 2, is susceptible to a PHP object injection flaw that permits unauthenticated attackers to execute arbitrary code. This vulnerability arises from an unrestricted invocation of PHP's native unserialize() function when handling malformed...

PoC for CVE-2026-9067

WordPressSchema & Structured Da...
Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbi...

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any fil...

PoC for CVE-2026-9060

WordPressStore Locator WordPress
Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style

The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks ...

PoC for CVE-2026-8071

WordPressAnti-spam By Cleantalk...
Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthen...

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (incl...

PoC for CVE-2026-3326

WordPressXstore
XStore < 9.7.3 - Unauthenticated SQLi

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Discovered 5 hours ago

PoC for CVE-2025-48595

GoogleAndroid8.4HIGH
Integer Overflow Vulnerability in Android Components from Google

The integer overflow vulnerability in multiple Android components allows for unintended code execution, potentially leading to local privilege escalation. This flaw does not require additional execution privileges or user interaction, making it a significant concern for system security. Organizat...

Discovered 7 hours ago

PoC for CVE-2024-42327

ZabbixZabbix🟣 EPSS 91%9.9CRITICAL
SQL Injection Vulnerability in Zabbix API for Non-Admin Users

A vulnerability exists in the Zabbix frontend that permits non-administrative users with certain roles to manipulate API functions due to an SQL injection flaw. Specifically, the issue arises within the CUser class's addRelatedObjects function, which is invoked by the CUser.get function. This fun...

Discovered 13 hours ago

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 83%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

PoC for CVE-2026-48598

Elixir-teslaTesla2.1LOW
Improper Encoding in Tesla Affects Elixir Applications

An improper encoding vulnerability in Tesla allows for multipart part header injection due to the lack of validation on CR, LF, and double-quote characters in the Content-Disposition header values. When parameters are passed without proper validation, an attacker can manipulate header values, lea...

PoC for CVE-2026-25860

FrankverbekeOpenclinic Ga5.3MEDIUM
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScr...

PoC for CVE-2026-25860

FrankverbekeOpenclinic Ga5.3MEDIUM
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScr...

PoC for CVE-2026-34417

Brian-rufOscal-gui5.1MEDIUM
OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php

OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious content through the project request parameter in oscal-forms.php. The parameter value is URL-decoded and assigned to...

Discovered 14 hours ago

PoC for CVE-2026-25557

EvolutedPHP Directory Listing ...5.1MEDIUM
Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir p...

Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inj...

Discovered 17 hours ago

PoC for CVE-2026-42271

BerriaiLitellm🟣 EPSS 61%8.7HIGH
Arbitrary Command Execution Vulnerability in LiteLLM Proxy Server b...

The LiteLLM proxy server by BerriAI, used to interface with LLM APIs, has a significant vulnerability that allows authenticated users to execute arbitrary commands on the host system. This issue arises from two endpoints that accept a complete server configuration in the request body, which inclu...

Discovered 19 hours ago

PoC for CVE-2026-49948

Mem0aiMem08.6HIGH
Mem0 0.2.8 Missing Authorization via POST /configure Endpoint

Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validati...

Discovered 20 hours ago

PoC for CVE-2022-39996

TeldatsRs123 Firmware4.8MEDIUM
Cross Site Scripting Vulnerability in Teldats Router RS123/RS123w

A Cross Site Scripting (XSS) vulnerability exists in the Teldat Router RS123 and RS123w models. This vulnerability arises from improper handling of user inputs in the cmdcookie parameter of the upgrade/query.php page. Attackers can exploit this flaw to execute arbitrary code, potentially leading ...

Discovered 22 hours ago

PoC for CVE-2024-52011

VitejsLaunch-editor7.5HIGH
Command Injection Vulnerability in Launch Editor by Vite

The Launch Editor by Vite suffers from a command injection vulnerability due to insufficient sanitization of the `file` argument in the `launchEditor` function. This flaw allows attackers to execute arbitrary commands on Windows systems by manipulating the filename with special characters before ...

PoC for CVE-2026-8054

DotcmsDotcms Core10CRITICAL
SQL Injection Vulnerability in dotCMS Core Affecting Publishing APIs

A vulnerability in the Publish Audit API endpoints of dotCMS Core allows remote unauthenticated attackers to exploit improper neutralization of special elements in SQL commands. This can lead to unauthorized reading, modification, or destruction of database content. The API endpoints (/api/auditP...

Discovered 23 hours ago

PoC for CVE-2017-20251

WordPressWoody Code Snippets9.3CRITICAL
WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint w...

PoC for CVE-2017-20250

WordPressMac Photo Gallery8.7HIGH
WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download

Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside...

PoC for CVE-2017-20248

WordPressApptha Slider Gallery8.7HIGH
WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Down...

Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory traversal sequences ../ to access sensitive files outside the...

PoC for CVE-2017-20249

WordPressApptha Slider Gallery8.8HIGH
WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection

Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attackers can send GET requests with crafted SQL payloads in the albid parameter to extract sensitive d...

PoC for CVE-2017-20247

WordPressPica Photo Gallery8.8HIGH
WordPress Plugin PICA Photo Gallery 1.0 SQL Injection

WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid parameter. Attackers can send GET requests with crafted SQL payloads in the aid parameter to extract s...

PoC for CVE-2017-20246

WordPressKittycatfish8.8HIGH
KittyCatfish 2.2 Plugin for WordPress SQL Injection

KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the 'kc_ad' parameter in base.css.php or kittycatfish.php to extract sensit...

PoC for CVE-2017-20245

WordPressWow Viral Signups8.8HIGH
Wow Viral Signups 2.1 WordPress Plugin SQL Injection

Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parameter. Attackers can send crafted requests to the admin-ajax.php endpoint with malicious SQL payload...

PoC for CVE-2017-20244

WordPressWow Forms8.8HIGH
Wow Forms WordPress Plugin 2.1 SQL Injection

Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php ...

PoC for CVE-2017-20243

WordPressCar Park Booking System8.8HIGH
WordPress Car Park Booking Plugin SQL Injection via space_id

WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the space_id parameter. Attackers can send GET requests to the booking-page endpoint with ma...

PoC for CVE-2016-20065

WordPressProduct Catalog 88.8HIGH
Product Catalog 8 1.2 Plugin WordPress SQL Injection

Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selectedCategory parameter. Attackers can submit POST requests to the admin-ajax.php endpoint with the ...

PoC for CVE-2016-20064

MyasuiWP Vault6.9MEDIUM
WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter

WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attackers can supply directory traversal sequences through the wpv-image GET parameter to access sensitiv...

PoC for CVE-2016-20063

WordPressSingle Personal Message7.1HIGH
Single Personal Message 1.0.3 WordPress Plugin SQL Injection

Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attackers can access the admin interface and supply crafted SQL statements in the message parameter to ...

PoC for CVE-2016-20062

WordPressSimply Poll8.8HIGH
Simply Poll 1.4.1 Plugin for WordPress SQL Injection

Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the 'pollid' POST parameter. Attackers can send requests to the admin-ajax.php endpoint with the 'spAjaxResults' actio...

Discovered 1 day ago

PoC for CVE-2026-23111

LinuxLinux7.8HIGH
Local Privilege Escalation Vulnerability in Linux Kernel Utilizing ...

A vulnerability exists in the Linux kernel's netfilter module that affects the nft_map_catchall_activate() function. This function encounters an inverted element activity check, leading to a failure in appropriately handling catchall map elements during a failed transaction. The bug arises when t...

PoC for CVE-2025-59528

FlowiseaiFlowise🟣 EPSS 85%10CRITICAL
Remote Code Execution Vulnerability in Flowise by FlowiseAI

Flowise, a user-friendly platform for creating customized large language model flows, has a significant vulnerability in version 3.0.5 that allows for remote code execution. The flaw lies within the CustomMCP node, where user input is inadequately sanitized. Specifically, the mcpServerConfig stri...

PoC for CVE-2026-8981

WordPressCustom Block Builder3.5LOW
Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML

The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to i...

PoC for CVE-2026-4986

WordPressWPforms5.3MEDIUM
WPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.

PoC for CVE-2026-11623

Tmux2LOW
tmux image.c image_free use after free

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use after free. Local access is required to approach this attack. This attack is characterized by high complexity. The exploitability is told to be di...

PoC for CVE-2026-11621

Dcat-admin5.1MEDIUM
Dcat-Admin User Setting upload editorMDUpload unrestricted upload

A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. This manipulation of the argument editormd-image-file causes unrestricted upload. The attack can be initiated re...

PoC for CVE-2026-11620

TotolinkEx2006.9MEDIUM
TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation

A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been released to the publi...

PoC for CVE-2026-11618

DtstackTaier6.9MEDIUM
DTStack Taier Source Connection Test Endpoint LoginInterceptor.java...

A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/java/com/dtstack/taier/develop/interceptor/LoginInterceptor.java of the component Source Connection Test Endpoint. Executing a manipulation can lead ...

PoC for CVE-2026-24061

GnuInetutils🟣 EPSS 92%9.8CRITICAL
Remote Authentication Bypass in GNU Inetutils Telnetd

The GNU Inetutils telnet daemon (telnetd) is vulnerable to a remote authentication bypass that can occur when an attacker manipulates the USER environment variable by specifying a '-f root' value. This flaw allows unauthorized users to gain access without proper authentication. Affected users sho...

PoC for CVE-2026-49975

ApacheApache Http Server7.5HIGH
Apache HTTP Server: mod_http2 denial of service

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

Discovered 2 days ago

PoC for CVE-2026-50751

CheckpointQuantum Security Gateway🟣 EPSS 18%9.3CRITICAL
User Authentication Bypass in VPN Remote Access and Mobile Access

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

PoC for CVE-2026-27886

StrapiStrapi9.2CRITICAL
Sanitization Flaws in Strapi Headless CMS Affecting Multiple Versions

Strapi, an open-source headless content management system, has a vulnerability in versions ranging from 4.0.0 to 5.36.0 that stems from inadequate sanitization of query parameters during content filtering. This flaw allows unauthenticated attackers to exploit the `where` query parameter on public...

PoC for CVE-2026-11585

CodeastroStudent Attendance Man...5.3MEDIUM
CodeAstro Student Attendance Management System createClassArms.php ...

A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been p...

PoC for CVE-2026-11584

CodeastroStudent Attendance Man...5.3MEDIUM
CodeAstro Student Attendance Management System createClass.php edit...

A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit ...

PoC for CVE-2025-43537

AppleiOS And iPad OS3.5LOW
Path Handling Issue in Apple iOS and iPadOS Products

A path handling flaw in Apple's iOS and iPadOS products may allow attackers to manipulate and modify protected system files by restoring a maliciously crafted backup file. This vulnerability has been addressed through enhanced validation measures in the updated versions of iOS and iPadOS. Users a...