Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-74970

MozillaFirefox5.4MEDIUM
Site Isolation Flaw in Firefox Graphics Component

A site isolation vulnerability exists in the Graphics component of Mozilla Firefox, which could allow attackers to execute unauthorized actions across different sites. This issue has been addressed in Firefox version 154 and Firefox Extended Support Release (ESR) version 153.1, enhancing user sec...

PoC for CVE-2026-74945

MozillaFirefox6.5MEDIUM
Information Disclosure in Firefox's Graphics: Text Component

A vulnerability within the Graphics: Text component of Firefox allows for unintended information disclosure. This issue could potentially expose sensitive data that should remain protected. Mozilla has addressed this vulnerability in various versions, ensuring enhanced security and privacy for us...

PoC for CVE-2026-6765

MozillaFirefox5.3MEDIUM
Information Disclosure in Firefox and Firefox ESR Products by Mozilla

This vulnerability involves an information disclosure flaw in the Form Autofill component of Firefox and Firefox ESR. When exploited, it can reveal sensitive user data. Mozilla has addressed this issue in versions 150 of Firefox and 140.10 of Firefox ESR, emphasizing the importance of updating to...

PoC for CVE-2026-74943

MozillaFirefox9.8CRITICAL
Use-After-Free Vulnerability in Firefox ImageLib Component

A use-after-free vulnerability has been discovered in the Graphics: ImageLib component of Firefox. This issue may allow an attacker to cause a crash or potentially execute arbitrary code on the affected system. Mozilla has released updates addressing this vulnerability in Firefox version 154, and...

Discovered 2 hours ago

PoC for CVE-2026-41551

SiemensRos#9.3CRITICAL
Path Traversal Vulnerability in ROS# by Siemens

A path traversal vulnerability has been discovered in ROS# that affects all versions prior to V2.2.2. This issue arises from inadequate sanitization of user input, potentially allowing remote attackers to navigate the file system and access sensitive files on the device. Addressing this vulnerabi...

Discovered 3 hours ago

PoC for CVE-2026-79623

FishcodetechMuteki5.3MEDIUM
OS Command Injection Vulnerability in FishCodeTech Muteki by FishCo...

A security flaw has been identified in the FishCodeTech Muteki application up to version 0.2.5, due to an unspecified function within the .claude/settings.json file of the Default Local Worker Backend. This vulnerability permits attackers to perform OS command injection, which can be initiated re...

PoC for CVE-2026-79622

DekdeeAdobe-xd-mcp6.9MEDIUM
Path Traversal Vulnerability in dekdee Adobe XD MCP Product

A path traversal vulnerability has been detected in the dekdee Adobe XD MCP product, specifically within the function of the file-access-from-request endpoint located in src/parsers/xd-parser.ts. This weakness allows attackers to manipulate the outputFile/outputDir arguments, potentially gaining ...

Discovered 4 hours ago

PoC for CVE-2026-57863

Crater-invoice-incCrater8.7HIGH
Path Traversal Vulnerability in Crater Invoice by Crater

Crater Invoice versions up to 6.0.6 are susceptible to a path traversal vulnerability within their self-update API. This weakness allows authenticated company owners to manipulate crafted ZIP archives to bypass directory restrictions, enabling the writing of arbitrary files outside the intended e...

Discovered 5 hours ago

PoC for CVE-2026-16348

Tp-link Systems Inc.Archer Be800 V18.5HIGH
Authenticated Command Injection Vulnerability in TP-Link Archer Router

An authenticated command injection vulnerability exists in the TP-Link Archer BE800 V1 router. With administrative access, an attacker can execute arbitrary system commands with root privileges by injecting shell metacharacters through a VPN connection. This exploitation can lead to serious secur...

PoC for CVE-2026-15469

Tp-link Systems Inc.Deco Xe75 V3 / Xe5300 ...7.7HIGH
Hard-Coded Cryptographic Key Vulnerability in Deco Mesh Products by...

A vulnerability has been identified in the mesh functionality of TP-Link's Deco XE75, XE5300, and WE10800 products, where a shared RSA-512 mesh group private key is hard-coded into the firmware. This key is utilized for node authentication within the mesh protocol. An attacker with local network ...

PoC for CVE-2026-18963

Red HatRed Hat Build Of Keycl...9.1CRITICAL
Authorization Flaw in Keycloak Services by Red Hat

A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...

Discovered 7 hours ago

PoC for CVE-2026-12295

MozillaFirefox9.6CRITICAL
Sandbox Escape Vulnerability in Firefox Navigation Component

A sandbox escape vulnerability exists in the navigation component of Firefox, which could potentially allow attackers to circumvent security restrictions and execute unauthorized scripts. This type of vulnerability may compromise user data and system integrity. Mozilla has addressed this issue in...

Discovered 10 hours ago

PoC for CVE-2026-78656

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A vulnerability exists in the itsourcecode Sales and Inventory System 1.0 that can be exploited through a flaw in the /pages/cust_del.php file. The vulnerability arises from improper handling of the ID parameter, leading to SQL injection attacks. This issue allows an attacker to manipulate SQL qu...

Discovered 11 hours ago

PoC for CVE-2026-78654

CleverbrushFramework6.9MEDIUM
Prototype Pollution Vulnerability in Cleverbrush Framework Deep

A vulnerability identified in the Cleverbrush framework allows for improper control over modifications to object prototype attributes via the deepExtend function in deepExtend.ts file. This can lead to potential exploitation by attackers remotely. Users of versions up to 4.4.0 are advised to upgr...

PoC for CVE-2021-30327

QualcommSnapdragon Mobile, Sna...7.5HIGH
Buffer Overflow in Sahara Protocol Affects Qualcomm Snapdragon Prod...

A buffer overflow vulnerability exists in the Sahara protocol utilized within Qualcomm's Snapdragon mobile platforms. This flaw can lead to the unintended overwriting of secure configuration data, potentially compromising system integrity and security across a range of Snapdragon products, includ...

PoC for CVE-2026-78638

PeerigonUnzip-crx4.8MEDIUM
Path Traversal Vulnerability in unzip-crx by Peerigon

A security flaw has been identified in the unzip-crx library developed by Peerigon, specifically impacting versions up to 0.2.0. This vulnerability arises in the 'unzip' function located within the 'dist/index.js' file of the Archive Extraction component. By manipulating the 'destination' argumen...

PoC for CVE-2026-74939

MozillaFirefox8.8HIGH
Privilege Escalation Vulnerability in Mozilla Firefox Navigation Co...

A security flaw in the Mozilla Firefox navigation component allows unauthorized users to escalate their privileges, potentially exposing critical parts of the application. This vulnerability was addressed in multiple versions, including Firefox 154 and various releases of Firefox ESR. Users are s...

Discovered 14 hours ago

PoC for CVE-2019-0708

MicrosoftWindows🟣 EPSS 100%9.8CRITICAL
Remote Code Execution Vulnerability in Microsoft Remote Desktop Ser...

A remote code execution vulnerability in Microsoft Remote Desktop Services allows an unauthenticated attacker to connect to the target system via RDP and execute arbitrary code by sending specially crafted requests. This exploitation can lead to significant security breaches if not mitigated adeq...

PoC for CVE-2025-46359

Alfasado Inc.Powercms8.6HIGH
Path Traversal Vulnerability in PowerCMS by PowerCMS

A path traversal vulnerability has been identified in the backup and restore features of multiple versions of PowerCMS. This flaw allows product administrators to execute arbitrary code by restoring a crafted backup file. This issue emphasizes the importance of securing backup functionalities wit...

Discovered 15 hours ago

PoC for CVE-2026-63039

ApacheApache Inlong9.8CRITICAL
SQL Injection Vulnerability in Apache InLong by Apache

An SQL Injection vulnerability has been identified in Apache InLong, where improper neutralization of special elements in SQL commands allows an attacker to inject malicious strings into SQL statements. This can compromise the integrity and confidentiality of the database. Affected users should u...

PoC for CVE-2026-28672

ApacheApache Ranger9.8CRITICAL
Command Injection Vulnerability in Apache Ranger Software by Apache

A command injection vulnerability exists in Apache Ranger, affecting versions from 0.6 to 2.8. This flaw allows attackers to execute arbitrary commands on the host system. Improper handling of special elements in command inputs can lead to significant security risks, enabling unauthorized access ...

Discovered 16 hours ago

PoC for CVE-2026-78329

ApacheApache Camel
Improper Input Validation in Apache Camel's Undertow Component

An improper input validation vulnerability in the Undertow component of Apache Camel allows unauthorized header manipulation. The default headerFilterStrategy configuration leads to failure in applying specific filtering rules on endpoint-configured routes, resulting in legacy websocket headers b...

PoC for CVE-2026-71300

ApacheApache Camel
Improper Input Validation in Apache Camel's Atmosphere Websocket Co...

An improper input validation vulnerability exists in Apache Camel's Atmosphere Websocket component, affecting several versions. This issue allows external senders to manipulate message delivery by injecting harmful values into specific headers. When bridging an HTTP consumer into an atmosphere-we...

PoC for CVE-2026-60093

ApacheApache Camel
Relative Path Traversal Vulnerability in Apache Camel Azure Storage...

A relative path traversal vulnerability has been identified in the Apache Camel Azure Storage Datalake component. This issue enables unauthorized access, allowing malicious users to manipulate file paths during file downloads. Specifically, the component fails to properly validate file paths, per...

PoC for CVE-2026-66906

ApacheApache Camel
Relative Path Traversal Vulnerability in Apache Camel Azure Storage...

The Apache Camel Azure Storage Blob component is susceptible to a relative path traversal vulnerability, allowing unauthorized access to the local filesystem. Through its downloadBlobToFile operation, an attacker can exploit the lack of proper path validation, potentially overwriting files outsid...

PoC for CVE-2026-66907

ApacheApache Camel
Relative Path Traversal Vulnerability in Apache Camel Google Storag...

A relative path traversal vulnerability exists in the Apache Camel Google Storage component, allowing unauthorized file overwrite on the local filesystem. When the downloadFileName option is set without proper filtering or normalization, it constructs local paths that may lead outside the intende...

PoC for CVE-2026-66908

ApacheApache Camel
Improper Authentication Vulnerability in Apache Camel's HTTP Component

Apache Camel's HTTP component exhibits an improper authentication vulnerability that affects versions 4.8.0 to 4.21.x. When JWT authentication is configured, the server fails to validate the 'iss' and 'aud' claims of incoming tokens if neither the jwtIssuer nor jwtAudience are specified, leading ...

Discovered 17 hours ago

PoC for CVE-2026-68820

MicrosoftWindows 10 Version 16077HIGH
Privilege Elevation Vulnerability in Windows Ancillary Function Dri...

A use after free vulnerability exists in the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to exploit the driver and potentially elevate privileges locally, threatening the integrity of the operating system. To mitigate risk, it is essential to apply the ...

PoC for CVE-2026-63621

ApacheApache Camel
Improper Input Validation in Apache Camel's Knative Component

The Apache Camel Knative component contains a vulnerability that allows unauthenticated attackers to inject Camel-internal headers through structured-mode CloudEvent requests. This occurs when CloudEvent extension fields are read directly from JSON bodies, bypassing essential header filter strate...

PoC for CVE-2026-59230

ApacheApache Camel
Input Validation Flaw in Apache Camel Affects Header Processing

An improper input validation vulnerability in Apache Camel affects the handling of MIME multipart messages within the camel-mail component. When configured with headersInline set to true, the component indiscriminately copies MIME headers from incoming messages to Camel messages, lacking any head...

Discovered 19 hours ago

PoC for CVE-2026-78435

FaveoHelpdesk5.1MEDIUM
Path Traversal Vulnerability in Faveo Helpdesk Logo Handler

A path traversal vulnerability exists in the Faveo Helpdesk, affecting versions up to 2.0.3, specifically in the unlink function of the Logo Handler component. By manipulating the argument data1, attackers can exploit this vulnerability remotely, which poses a significant security risk. This issu...

PoC for CVE-2026-78434

FaveoHelpdesk6.9MEDIUM
Missing Authentication Flaw in Faveo Helpdesk Software

A missing authentication vulnerability exists in the Faveo Helpdesk software up to version 2.0.3. Specifically, the flaw is related to the FormController::post_ticket_reply function in the app/Http/Controllers/Client/helpdesk/FormController.php file. This vulnerability allows attackers to initiat...

Discovered 20 hours ago

PoC for CVE-2026-72714

Rocq-proverRocq6.8MEDIUM
State Desynchronization Vulnerability in Rocq Prover by Rocq

Rocq Prover contains a vulnerability where the universe graph fails to restore the checking flag for universe validation after a module that disables this check is closed. Normally, this local setting should only persist for the lifespan of the module, reverting to a global state upon closure. Ho...

PoC for CVE-2026-72711

LeanproverLean46.8MEDIUM
Lean 4 Kernel Opaque Declaration Vulnerability in Lean Prover

The Lean 4 kernel contains a flaw where it fails to properly check that the body of an opaque declaration is closed. Specifically, the method environment::add_opaque omits the crucial check found in the definition and theorem paths, allowing for a scenario where a value may contain free variables...

PoC for CVE-2026-72705

Rocq-proverRocq6.8MEDIUM
Recursive Call Vulnerability in Rocq Prover by Endrazine

The guard checker in Rocq Prover is susceptible to a type safety violation where recursive calls using fixpoint arguments are inadequately tracked. This could lead to scenarios where a type becomes definitionally equal to its negation. Consequently, self-application can produce false results with...

PoC for CVE-2026-72704

Rocq-proverRocq6.8MEDIUM
Guard Checker Flaw in Rocq Prover Affects Recursive Type Parameter ...

The Rocq Prover's guard checker contains a significant flaw whereby alterations to a recursive type parameter are not validated post-transport. This oversight allows a fixpoint to apply rewrites based on type equality, which may lead to the acceptance of an altered recursive tree that has not und...

PoC for CVE-2026-72703

Rocq-proverRocq6.8MEDIUM
Guard Checker Vulnerability in Rocq Prover by Rocq Technologies

The guard checker in Rocq Prover erroneously classifies a nested mutual fixpoint parameter as uniform without performing a thorough analysis of inter-body calls. The function find_uniform_parameters only evaluates self-recursive calls, leading to the risk of accepting a non-terminating definition...

PoC for CVE-2020-37268

Rocq-proverRocq6.8MEDIUM
Print Assumptions Vulnerability in Rocq Prover by Endrazine

The Print Assumptions feature in Rocq Prover is vulnerable to a flaw arising from the failure to report the disabling of universe checking during specific operations. When a definition is created under these conditions, it can be inlined through parameters without retaining any record of the unsa...

Discovered 21 hours ago

PoC for CVE-2026-78430

SworddutMcp-ffmpeg-helper4.8MEDIUM
OS Command Injection in Sworddut MCP-FFmpeg-Helper by Sworddut

A vulnerability exists in Sworddut's MCP-FFmpeg-Helper affecting versions 0.1.0, 0.1.1, and 0.2.1 that allows for OS command injection. This is due to improper handling of input arguments in the 'handleToolCall' function specifically in the 'src/tools/handlers.ts' file. Exploitation requires loca...

PoC for CVE-2018-5803

LinuxLinux5.5MEDIUM
Kernel Vulnerability in Linux Kernel Affecting Multiple Versions

The vulnerability identified in the Linux Kernel prior to version 4.15.8 involves a flaw within the '_sctp_make_chunk()' function. This flaw is triggered during the processing of SCTP packets, particularly linked to length handling, which can lead to unexpected behavior. Exploiting this flaw can ...

PoC for CVE-2026-71511

DolibarrDolibarr7.1HIGH
Sensitive Data Exposure in Dolibarr's Members REST API

Dolibarr ERP & CRM prior to version 24.0.0 suffers from a sensitive data exposure vulnerability within the Members REST API. This allows authenticated attackers with member-read permissions to access bcrypt password verifiers by querying specific member endpoints. Unfiltered data output from both...

PoC for CVE-2026-71510

DolibarrDolibarr7.1HIGH
SQL Injection Vulnerability in Dolibarr REST API

Dolibarr versions prior to 24.0.0 contain a SQL injection vulnerability in the users REST API. This flaw allows authenticated users with read access to manipulate unfiltered parameters within SQL WHERE clauses, which can lead to unauthorized data extraction. Attackers can exploit this issue to pe...

PoC for CVE-2026-71509

DolibarrDolibarr7.1HIGH
Improper Authorization Vulnerability in Dolibarr Expense Report by ...

Dolibarr before version 24.0.0 is susceptible to an improper authorization vulnerability within its expense report REST API update endpoint. This flaw permits authenticated users with rights to create expenses to override the approval workflow. By manipulating certain fields through the API, atta...

Discovered 22 hours ago

PoC for CVE-2026-71508

DolibarrDolibarr7.1HIGH
Improper Authorization Vulnerability in Dolibarr by Dolibarr S.A.

Dolibarr prior to version 24.0.0 features an improper authorization vulnerability within its user REST API update endpoint. This flaw allows users who possess write permissions to modify sensitive payroll information. By leveraging an incomplete credential denylist that fails to adequately secure...

PoC for CVE-2026-71507

DolibarrDolibarr7.1HIGH
Broken Object-Level Authorization in Dolibarr's REST API

Dolibarr ERP & CRM prior to version 24.0.0 is susceptible to a broken object-level authorization vulnerability within its REST API. This flaw allows authenticated attackers who possess permissions for third-party creation to illicitly create, modify, or remove bank account information for any com...

PoC for CVE-2026-71506

DolibarrDolibarr7.2HIGH
Improper Authorization Vulnerability in Dolibarr Payments API

Dolibarr prior to version 24.0.0 is susceptible to an improper authorization vulnerability within its payments REST API delete endpoint. This flaw enables authenticated users possessing rights to delete invoices to exploit a misconfigured permission check. As a result, attackers can effectively b...

PoC for CVE-2026-71505

DolibarrDolibarr7.1HIGH
Broken Object-Level Authorization Vulnerability in Dolibarr REST API

Dolibarr versions prior to 24.0.0 are susceptible to a broken object-level authorization flaw in their REST API. This vulnerability permits authenticated attackers, who possess third-party creation rights, to manipulate the WebPortal passwords of enterprises by circumventing access checks that ar...

PoC for CVE-2026-71504

DolibarrDolibarr8.6HIGH
Improper Authorization Vulnerability in Dolibarr Members REST API

Dolibarr ERP & CRM prior to version 24.0.0 is susceptible to an improper authorization flaw within the Members REST API. This vulnerability enables attackers who possess member-creation rights to reset the passwords of any user account, including sensitive accounts like that of the system adminis...

PoC for CVE-2026-71503

DolibarrDolibarr5.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in Dolibarr by Dolibarr

Dolibarr versions prior to 24.0.0 introduce a reflected cross-site scripting (XSS) vulnerability in the extra fields administration template. The issue arises because the 'type' request parameter is displayed on the webpage without proper JavaScript-context encoding and lacks a Content-Security-P...

Discovered 1 day ago

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 100%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...