Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 2 hours ago

PoC for CVE-2026-97368

ChillzhuangSpringblade5.3MEDIUM
Authorization Bypass in chillzhuang SpringBlade UserAuthInfo Service

A vulnerability in the chillzhuang SpringBlade framework has been identified, affecting the UserServiceImpl.userInfo function. This weakness allows an attacker to manipulate userId arguments, leading to unauthorized access to user information. The exploitable endpoint can be accessed remotely, ra...

PoC for CVE-2026-93353

9001Copyparty6MEDIUM
Volume Restriction Bypass in Copyparty's SFTP Front End

Copyparty's SFTP front end is vulnerable to a volume restriction bypass, allowing authenticated users to create, delete, or modify files outside their permitted volume boundaries. By exploiting specific handlers (_mkdir, _rmdir, and _chattr), attackers can craft destination paths without proper a...

PoC for CVE-2026-97366

Jhen0409React-native-debugger5.3MEDIUM
OS Command Injection Vulnerability in jhen0409 React Native Debugger

A vulnerability in jhen0409 React Native Debugger versions up to 0.14.0 allows for OS command injection via the openDevTools function in the electron/window.js file. By manipulating the host argument, an attacker can launch commands on the target system remotely. This exploit has been publicly re...

Discovered 3 hours ago

PoC for CVE-2026-15015

WordPressMountdev Ai Mcp Connec...9.8CRITICAL
Authorization Bypass in MountDev AI MCP Connector Plugin for WordPress

The MountDev AI MCP Connector for WordPress allows unauthorized users to exploit a vulnerability that bypasses the necessary authorization checks. Attackers can register arbitrary OAuth clients via a public registration endpoint and gain access to secure functionalities of the plugin. This includ...

PoC for CVE-2026-97326

SongxinjianqweChat6.9MEDIUM
Server-Side Request Forgery in Songxinjianqwe Chat Affected by Vuln...

A vulnerability has been identified in Songxinjianqwe Chat, specifically in the chat-server component located in the ChatServer.java file. This weakness allows for server-side request forgery (SSRF), enabling attackers to potentially initiate remote exploitation. The affected version is up to ac6...

PoC for CVE-2026-78306

DjiNeo8.5HIGH
Bluetooth Vulnerability in DJI Drones Exposes Wi-Fi Settings

DJI drones possess a vulnerability that allows attackers within Bluetooth range to send unauthenticated DUML commands. This flaw enables unauthorized modifications to critical Wi-Fi settings, including SSID and PSK, providing attackers potential access to control interfaces of the drone. Conseque...

Discovered 5 hours ago

PoC for CVE-2026-97233

VolotatAnagnorisis5.1MEDIUM
Cross-Site Scripting Vulnerability in volotat Anagnorisis Media Fil...

A cross-site scripting vulnerability has been discovered in the volotat Anagnorisis application, specifically within the html function of PlaylistManager.js. This issue arises due to the manipulation of the 'file_path' argument, which can lead to unauthorized script execution by an attacker. Sinc...

Discovered 6 hours ago

PoC for CVE-2026-97232

VolotatAnagnorisis5.3MEDIUM
Path Traversal Vulnerability in Volotat Anagnorisis by Volotat

A significant vulnerability exists in the Volotat Anagnorisis product, specifically in the functions responsible for handling file operations, such as get_file_content, save_file_content, and move_files. This flaw allows attackers to manipulate file paths, leading to unauthorized access to sensit...

PoC for CVE-2026-97231

VolotatAnagnorisis6.9MEDIUM
Missing Authentication Vulnerability in volotat Anagnorisis Socket....

A vulnerability has been identified in the Socket.IO Connect Interface of volotat Anagnorisis versions up to 0.4.0, specifically within the 'app.py' file. This flaw allows for missing authentication, enabling unauthorized users to exploit the system remotely. As this exploit has been publicly dis...

Discovered 8 hours ago

PoC for CVE-2026-97362

RejettoHfs28.7HIGH
Denial of Service Vulnerability in HFS2 File Server by HFS2 Vendor

HFS2 versions 2.4.0 and earlier are susceptible to a denial of service vulnerability that allows unauthenticated attackers to disrupt service. By sending a specially crafted request, an attacker can cause a serving thread to enter a busy loop, leading to a complete unresponsiveness of the file se...

Discovered 9 hours ago

PoC for CVE-2026-97360

RejettoHfs210CRITICAL
Unauthenticated Arbitrary File Access Vulnerability in HFS2 by WgetNZ

HFS2 version 2.4.0 and earlier has a vulnerability that allows unauthenticated attackers to gain unauthorized access to files. This weakness is due to the macro dispatcher's insufficient authorization checks and the path resolver's failure to restrict absolute paths. As a result, attackers can re...

PoC for CVE-2026-97359

RejettoHfs210CRITICAL
Template Injection Vulnerability in HFS2 by WgetNZ

HFS2 versions 2.4.0 and earlier are susceptible to a template injection vulnerability located in the multipart upload handler. This issue allows unauthenticated attackers to execute arbitrary commands on the host system by embedding malicious template syntax within a crafted filename. By manipula...

Discovered 10 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 11 hours ago

PoC for CVE-2026-97182

Halo-devHalo6.9MEDIUM
Improper Neutralization in Halo from halo-dev

A security vulnerability has been identified in the halo-dev Halo application, specifically affecting versions up to 2.25.4/2.26.1. The issue resides in the ReplyNotificationSubscriptionHelper.java file, where the component's SpEL Handler fails to properly neutralize certain elements. This flaw c...

Discovered 12 hours ago

PoC for CVE-2026-97179

Zhejiang Landzone...O2oa5.3MEDIUM
Information Disclosure Vulnerability in O2OA Cipher Connection Handler

A security flaw has been identified in the O2OA product that affects its Cipher Connection Handler. This vulnerability arises from improper handling of the 'fileUrl' parameter within the file located at o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnection...

Discovered 13 hours ago

PoC for CVE-2026-84543

AppleMac OS7.5HIGH
Out-of-Bounds Access Vulnerability in macOS Products by Apple

An out-of-bounds access issue in Apple's macOS products could allow a malicious SMB server to exploit the vulnerability, leading to unexpected system terminations or potential corruption of kernel memory. This flaw highlights the importance of proper bounds checking in software designed to handle...

Discovered 15 hours ago

PoC for CVE-2026-87902

WordPressWordPress8.1HIGH
Local File Inclusion in WordPress Leading to Remote Code Execution

An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...

Discovered 17 hours ago

PoC for CVE-2026-93662

WordPressEvents Manager4.3MEDIUM
Improper Access Control in Events Manager Plugin for WordPress

The Events Manager plugin for WordPress prior to version 7.4.5 is vulnerable to improper access control. This vulnerability allows low-privileged users to manipulate owner values in event and location searches. As a result, these users can access unpublished, pending, or trashed content from othe...

PoC for CVE-2026-93661

WordPressEvents Manager2.7LOW
Ticket Management Vulnerability in Events Manager Plugin by WordPress

The Events Manager WordPress plugin, before version 7.4.5, is susceptible to a vulnerability that allows users managing tickets for a single event to execute unauthorized updates. This flaw permits the overwriting and reassignment of tickets to different events, which can lead to unauthorized acc...

PoC for CVE-2026-89004

WordPressWPematico Rss Feed Fet...2.7LOW
Unauthorized Data Exposure in WPeMatico RSS Feed Fetcher WordPress ...

The WPeMatico RSS Feed Fetcher WordPress plugin prior to version 2.8.26 has a security weakness where it fails to authenticate user ownership or authorization before disclosing sensitive campaign configuration and execution logs. This vulnerability allows users with contributor-level access and h...

PoC for CVE-2026-89005

WordPressWPematico Rss Feed Fet...6.8MEDIUM
Stored Cross-Site Scripting in WPeMatico RSS Feed Fetcher Plugin fo...

The WPeMatico RSS Feed Fetcher plugin for WordPress prior to version 2.8.26 allows attackers to exploit a lack of proper sanitization and escaping in a campaign configuration field. This vulnerability permits users with Contributor roles and higher to execute Stored Cross-Site Scripting (XSS) att...

PoC for CVE-2026-89002

WordPressWPematico Rss Feed Fet...6.8MEDIUM
Stored Cross-Site Scripting Vulnerability in WPeMatico RSS Feed Fet...

The WPeMatico RSS Feed Fetcher plugin for WordPress prior to version 2.8.26 fails to adequately sanitize and escape content retrieved from user-supplied sources. This oversight can enable contributors to exploit the vulnerability and execute Stored Cross-Site Scripting attacks, affecting higher-p...

PoC for CVE-2026-88843

WordPressMasterstudy Lms WordPr...7.2HIGH
Arbitrary File Execution in MasterStudy LMS Plugin by Webnus

The MasterStudy LMS WordPress Plugin prior to version 3.7.50 is vulnerable due to improper validation of display-style settings. This flaw permits users with Contributor roles or above to include and execute arbitrary local PHP files on the server. Notably, a similar path issue was addressed in a...

PoC for CVE-2026-88845

WordPressMasterstudy Lms WordPr...4.3MEDIUM
Unauthorized Content Publishing in MasterStudy LMS Plugin

The MasterStudy LMS WordPress plugin prior to version 3.7.50 lacks necessary capability and nonce checks during an administrative maintenance action. This oversight allows any authenticated user, including those with the lowest privilege levels like subscribers, to create published content on the...

PoC for CVE-2026-88847

WordPressMasterstudy Lms WordPr...4.3MEDIUM
Unauthorized Access Vulnerability in MasterStudy LMS Plugin for Wor...

The MasterStudy LMS WordPress plugin, prior to version 3.7.50, contains a vulnerability that compromises the enrollment verification process. It permits any authenticated user, including those with subscriber-level accounts, to inaccurately record lesson completions for courses they are not enrol...

PoC for CVE-2026-88846

WordPressMasterstudy Lms WordPr...5.3MEDIUM
User Account Creation Flaw in MasterStudy LMS WordPress Plugin

The MasterStudy LMS WordPress Plugin prior to version 3.7.50 has a significant vulnerability where it fails to verify if user registration is enabled on the WordPress site. This oversight permits unauthenticated users to create accounts via the plugin's front-end registration processes, even when...

PoC for CVE-2026-82849

WordPressMasteriyo Lms4.3MEDIUM
Improper Access Control Flaw in Masteriyo LMS Plugin for WordPress

The Masteriyo LMS plugin for WordPress prior to version 3.4.2 exhibits an improper access control vulnerability. This flaw permits authenticated users, including self-registered subscribers, to access and read other users' course-progress records. Specifically, the plugin fails to properly verify...

PoC for CVE-2026-82850

WordPressMasteriyo Lms4.3MEDIUM
Unauthorized Access to Quiz Answers in Masteriyo LMS by WordPress

The Masteriyo LMS plugin for WordPress presents a significant access control weakness, allowing authenticated users, including students, to retrieve the correct answers to quizzes. This vulnerability occurs due to improper access restrictions, enabling users to access answer keys for quizzes acro...

PoC for CVE-2026-84151

WordPressThe Post Grid3.5LOW
HTML Injection Vulnerability in Post Grid WordPress Plugin by WordP...

The Post Grid WordPress plugin versions prior to 7.9.5 suffer from an HTML injection vulnerability due to inadequate restrictions on the allowed HTML elements. This flaw permits users with Contributor roles and higher to insert iframe, style, and input elements that are typically removed from con...

PoC for CVE-2026-82195

WordPress10web Booster6.5MEDIUM
Access Control Flaw in 10Web Booster Plugin by 10Web

The 10Web Booster plugin for WordPress prior to version 2.34.0 contains an access control vulnerability that allows unauthenticated users to gain access to the routine responsible for issuing the shared secret for cloud connections. This flaw enables unauthorized users to not only view the shared...

PoC for CVE-2026-80513

WordPressWPforo Forum7.5HIGH
PHP Object Injection Vulnerability in wpForo Forum Plugin by WordPress

The wpForo Forum plugin for WordPress, prior to version 3.1.6, is vulnerable to PHP Object Injection due to inadequate restrictions on deserialized user-supplied profile field values. This loophole enables authenticated users with Subscriber-level access or higher to instantiate arbitrary classes...

PoC for CVE-2026-80338

WordPressCmb26.8MEDIUM
Arbitrary Option Manipulation in CMB2 WordPress Plugin

The CMB2 WordPress plugin before version 2.13.0 lacks necessary capability checks on specific AJAX actions. This flaw permits users with minimal permissions, such as Subscribers, to create or modify arbitrary WordPress options, potentially leading to the corruption of critical site settings. Such...

PoC for CVE-2026-74991

WordPressWPforms6.8MEDIUM
Unauthorized Payment Manipulation in WPForms Plugin by WPForms

The WPForms plugin for WordPress, prior to version 2.0.2, is vulnerable due to a lack of validation on Stripe payment objects during public form submissions. As a result, unauthenticated users can exploit this weakness to initiate full refunds and cancel subscriptions associated with payments mad...

Discovered 19 hours ago

PoC for CVE-2026-96898

Yhx070424Shopxo6.9MEDIUM
Path Traversal Vulnerability in ShopXO Ueditor Upload Interface by ...

A path traversal vulnerability has been identified in the yhx070424 ShopXO application, specifically within the Ueditor Upload Interface located in the file config/ueditor.php up to version 2.2.7. This flaw allows an attacker to manipulate the 'path_type' argument, possibly leading to unauthorize...

PoC for CVE-2026-96892

EdimaxBr-6428nc5.3MEDIUM
Open Redirect Vulnerability in Edimax BR-6428nC Products

A significant flaw has been detected in the Edimax BR-6428nC version 1.16 that affects the functionality of the 'websRedirect' in the 'goform' handler. This vulnerability arises from the manipulation of the 'submit-url' argument, potentially allowing attackers to execute an open redirect attack r...

Discovered 20 hours ago

PoC for CVE-2026-87902

WordPressWordPress8.1HIGH
Local File Inclusion in WordPress Leading to Remote Code Execution

An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...

PoC for CVE-2026-96884

MantisMantiszip5.3MEDIUM
Path Traversal Vulnerability in MantisZip by Mantis

A security flaw has been identified in MantisZip versions up to 0.4.5, specifically within the Path.Combine function of MainWindow.UI.cs in the Preview component. This vulnerability allows attackers to manipulate file paths, leading to unauthorized access to sensitive data through path traversal....

PoC for CVE-2026-96882

TalelinLin-cms-spring-boot6.9MEDIUM
Improper Authorization Vulnerability in TaleLin lin-cms-spring-boot...

A vulnerability exists in the TaleLin lin-cms-spring-boot product, specifically in the searchBook function of the BookController component. This flaw permits unauthorized access to sensitive operations, making it possible for an attacker to exploit the system remotely. The exploit is publicly ava...

PoC for CVE-2026-96881

TalelinLin-cms-spring-boot6.9MEDIUM
Improper Authorization in TaleLin lin-cms-spring-boot Affects Remot...

A vulnerability has been identified in the TaleLin lin-cms-spring-boot framework, specifically within the book Endpoint's getBooks function located in BookController.java. This issue can lead to improper authorization, potentially allowing remote attackers to manipulate access controls. The vulne...

PoC for CVE-2024-37054

MlflowMlflow8.8HIGH
Arbitrary Code Execution Vulnerability in MLflow Platform

A significant security vulnerability exists within the MLflow platform developed by Databricks. This issue arises from the deserialization of untrusted data in versions 0.9.0 and later. Attackers exploit this vulnerability by uploading a malicious PyFunc model that, once interacted with, can exec...

Discovered 21 hours ago

PoC for CVE-2026-96880

TalelinLin-cms-spring-boot6.9MEDIUM
Improper Authorization in TaleLin lin-cms-spring-boot Product

A vulnerability exists in the TaleLin lin-cms-spring-boot application, specifically in the book endpoint located in the BookController.java file. The flaw arises from improper validation of the ID argument in the getBook function, allowing unauthorized access to resources. This vulnerability can ...

PoC for CVE-2026-96810

Huanzi-qchBase-admin5.1MEDIUM
Cross Site Scripting Vulnerability in Huanzi QCH Base Admin Software

A cross site scripting vulnerability exists in the Add User Handler of Huanzi QCH Base Admin, affecting versions up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This vulnerability is triggered through the manipulation of the Username argument in the Save function within the CommonController.java ...

PoC for CVE-2026-96803

Java110Microcommunity6.9MEDIUM
SQL Injection Vulnerability in java110 MicroCommunity by java110

A security vulnerability has been identified in java110 MicroCommunity, specifically within the fallBack API Endpoint in the BusinessApi.java file. An attacker can manipulate the 'fallBackSql' argument, leading to SQL injection vulnerabilities that could be exploited remotely. The affected versio...

PoC for CVE-2026-89274

WordPressWP Recipe Maker9.1CRITICAL
Arbitrary Shortcode Execution in WP Recipe Maker Plugin for WordPress

The WP Recipe Maker plugin for WordPress is vulnerable due to a flaw that allows unauthorized execution of registered shortcodes on recipe pages. This arises from the method 'WPRM_Metadata::sanitize_metadata()' which processes every scalar field of the recipe's metadata, including 'reviewBody', w...

PoC for CVE-2026-96777

FormaLms5.3MEDIUM
SQL Injection Vulnerability in Forma LMS Multi-User-Selector by Forma

A security flaw exists in Forma LMS versions up to 4.1.43, specifically within the Multi-User-Selector AJAX Endpoint. The vulnerability is triggered through the UserselectorAdmController::getDataTask function found in the /appCore/ajax.adm_server.php file. Malicious users can exploit this flaw by...

PoC for CVE-2020-15368

AsrockRgb Driver Firmware5.5MEDIUM
ASRock RGB Driver Vulnerability Exposes System Resources

The ASRock RGB Driver contains a significant access control vulnerability within its AsrDrv103.sys component. This flaw permits unauthorized user space access, enabling attackers to manipulate the driver and potentially execute harmful exploits against the system. In particular, an attacker can t...

PoC for CVE-2026-93349

FrictionlessdataFrictionless-py8.6HIGH
OS Command Injection Vulnerability in Frictionless Data Package by ...

The Frictionless Data Package through version 5.20.0rc1 contains a vulnerability that allows remote attackers to execute arbitrary operating system commands. This exploitation occurs through the 'explore' console command when a user interacts with a crafted Data Package descriptor. Attackers can ...

Discovered 22 hours ago

PoC for CVE-2026-96773

IntelliantsSubrion Cms5.3MEDIUM
Open Redirect Vulnerability in Intelliants Subrion CMS Affecting Lo...

A weakness has been discovered in Intelliants Subrion CMS version 4.2.1 and earlier, specifically within the login functionality found in the 'front/login.php' file. This flaw allows an attacker to manipulate the $_SERVER['HTTP_REFERER'] argument, leading to an open redirect scenario. Such an att...

PoC for CVE-2026-96772

IntelliantsSubrion Cms6.9MEDIUM
Information Disclosure Vulnerability in Intelliants Subrion CMS

A security flaw has been identified in Intelliants Subrion CMS, specifically related to the handling of the /actions.json?action=assign-owner file. An improper manipulation of the argument 'q' can lead to unauthorized information disclosure, potentially exposing sensitive data. The attack can be ...

PoC for CVE-2026-96764

Kvcache-aiMooncake5.3MEDIUM
Resource Allocation Vulnerability in kvcache-ai Mooncake by Kvcache.ai

A vulnerability has been discovered in the kvcache-ai mooncake product, specifically in the MasterService::GetReplicaListByRegex function, part of the Regular Expression Handler component. This weakness allows attackers to manipulate the application to allocate excessive resources, potentially le...