Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-2865

ItsourcecodeAgri-trading Online Sh...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Agri-Trading Online Sho...

A vulnerability exists in the itsourcecode Agri-Trading Online Shopping System 1.0, specifically within the HTTP POST Request Handler's productcontroller.php file. This vulnerability allows for SQL injection via manipulation of the Product argument, enabling attackers to execute remote exploits. ...

PoC for CVE-2026-2864

Feng Ha HaSsm-erp5.3MEDIUM
Path Traversal Vulnerability in Megagao ERP Solution by Feng Ha Ha

A path traversal vulnerability has been identified in the Megagao ERP and Production SSM solutions, specifically within the pictureDelete function of the PictureController.java file. This vulnerability can be exploited remotely through manipulation of the picName argument, allowing unauthorized a...

Discovered 5 hours ago

PoC for CVE-2026-2863

Feng Ha HaSsm-erp5.3MEDIUM
Path Traversal Flaw in Feng_Ha_Ha/Megagao SSM-ERP and Production_SSM

A path traversal vulnerability exists in the deleteFile function of FileServiceImpl.java within both Megagao SSM-ERP and Production_SSM products. This flaw allows attackers to manipulate file paths, potentially enabling them to access unauthorized files on the server. The attack can be initiated ...

PoC for CVE-2025-2304

Owen2345Camaleon-cms9.4CRITICAL
Privilege Escalation Flaw in Camaleon CMS

A critical issue in Camaleon CMS's UsersController, specifically in the 'updated_ajax' method, enables privilege escalation due to the improper handling of parameters. The vulnerability arises from the use of the permit! method, which fails to filter input, allowing all parameters to be processed...

Discovered 6 hours ago

PoC for CVE-2026-2860

Feng Ha HaSsm-erp5.3MEDIUM
Improper Authorization Flaw in SSM ERP by Feng_Ha_Ha

A security vulnerability has been identified in the SSM ERP and Production SSM systems from Feng_Ha_Ha, specifically within the EmployeeController.java file. This flaw allows for improper authorization, which may be exploited remotely, potentially leading to unauthorized access. The issue has bee...

Discovered 12 hours ago

PoC for CVE-2019-25454

PHPmoadminPHPmoadmin5.3MEDIUM
Stored Cross-Site Scripting in phpMoAdmin by phpMoAdmin

phpMoAdmin version 1.1.5 is affected by a stored cross-site scripting vulnerability, enabling unauthorized users to inject harmful scripts into the application. By exploiting this vulnerability, attackers can manipulate the collection parameter in GET requests to moadmin.php, allowing them to exe...

PoC for CVE-2019-25449

OrientdbOrientdb5.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in OrientDB by OrientDB

OrientDB 3.0.17 is susceptible to a reflected cross-site scripting vulnerability that can be exploited by attackers to inject malicious scripts into web applications. By crafting specific JSON payloads and submitting them via POST requests to the document endpoint, attackers can execute arbitrary...

PoC for CVE-2019-25441

KostasmitroglouThesystem9.3CRITICAL
Command Injection Vulnerability in thesystem 1.0 from kostasmitroglou

The thesystem 1.0 is vulnerable to command injection through its run_command endpoint, which permits unauthenticated attackers to execute arbitrary system commands. By sending crafted POST requests containing shell commands in the command parameter, attackers can gain unauthorized access and exec...

PoC for CVE-2019-25438

LabcollectorLabcollector8.8HIGH
SQL Injection Vulnerability in LabCollector by LabCollector

LabCollector version 5.423 is susceptible to multiple SQL injection vulnerabilities that can be exploited by unauthenticated attackers. By manipulating POST parameters, such as those found in login.php and retrieve_password.php, attackers can inject malicious SQL queries. This could lead to unaut...

PoC for CVE-2019-25437

FoscamFoscam Video Managemen...6.7MEDIUM
Buffer Overflow Vulnerability in Foscam Video Management System

The Foscam Video Management System version 1.1.6.6 is susceptible to a buffer overflow vulnerability in the UID field. This allows local attackers to exploit the system by submitting an excessively long string (up to 5000 characters) into the UID parameter while attempting to add a device. When t...

PoC for CVE-2019-25436

SricamDeviceviewer5.1MEDIUM
Password Change Bypass Vulnerability in Sricam DeviceViewer by Sricam

The Sricam DeviceViewer 3.12.0.1 is vulnerable to a password change security bypass. This issue enables authenticated users to change passwords without validating the original password. Attackers can exploit this vulnerability by injecting a malicious payload into the old password field during th...

PoC for CVE-2019-25435

SricamSricam Deviceviewer8.4HIGH
Local Buffer Overflow in Sricam DeviceViewer Affects User Management

Sricam DeviceViewer 3.12.0.1 is vulnerable to a local buffer overflow in the user management section, specifically when adding a new user. This flaw allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. By injecting a malicious payload into the Username ...

PoC for CVE-2019-25434

NsasoftNsauditor Spotauditor6.7MEDIUM
Denial of Service Vulnerability in SpotAuditor by NSA

SpotAuditor version 5.3.1.0 has a denial of service vulnerability that can be exploited by unauthenticated attackers. By submitting excessively large strings (5000 bytes or more) in the registration name field, attackers can cause the application to crash due to unhandled exceptions. This vulnera...

PoC for CVE-2019-25432

Part-dbPart-db8.8HIGH
Authentication Bypass Vulnerability in Part-DB by Part-DB

Part-DB 0.4 is susceptible to an authentication bypass vulnerability that enables unauthenticated attackers to gain access by exploiting SQL injection flaws in the login mechanism. By injecting malicious SQL syntax, specifically a single quote followed by 'or', into the authentication parameters,...

PoC for CVE-2019-25431

Delpino73Blue-smiley-organizer8.8HIGH
SQL Injection Vulnerability in Blue-Smiley-Organizer by delpino73

The Blue-Smiley-Organizer 1.32 application by delpino73 contains a vulnerability that allows unauthenticated attackers to exploit SQL injection through the datetime parameter. By crafting specific POST requests, attackers can manipulate database queries to extract sensitive information using vari...

PoC for CVE-2018-25158

ChamiloChamillo Lms8.7HIGH
Arbitrary File Upload Vulnerability in Chamilo LMS by Chamilo

Chamilo LMS version 1.11.8 has a vulnerability that allows authenticated users to upload files through the elfinder filemanager module. By taking advantage of this flaw, attackers can upload files disguised as images, rename them to PHP extensions, and execute arbitrary code by accessing these fi...

PoC for CVE-2025-31161

CrushftpCrushftp🟣 EPSS 88%9.8CRITICAL
Authentication Bypass Vulnerability in CrushFTP by CrushFTP

A significant vulnerability exists in CrushFTP versions prior to 10.8.4 and 11.3.1, enabling attackers to exploit an authentication bypass flaw. This vulnerability allows unauthorized users to gain access to the crushadmin account through a race condition in the AWS4-HMAC authorization method, pa...

Discovered 13 hours ago

PoC for CVE-2026-2858

Wren-langWren4.8MEDIUM
Out-of-Bounds Read Vulnerability in Wren Programming Language by Wr...

A local vulnerability has been identified in the Wren programming language's source file parser component, specifically in the peekChar function of src/vm/wren_compiler.c. This flaw allows attackers to perform out-of-bounds reads, potentially leading to unauthorized access to sensitive data or cr...

Discovered 14 hours ago

PoC for CVE-2026-2857

D-linkDwr-m9608.7HIGH
Stack-Based Buffer Overflow in D-Link DWR-M960 Router

A vulnerability exists in the D-Link DWR-M960 router's Port Forwarding Configuration Endpoint that allows for stack-based buffer overflow via the manipulation of the submit-url argument in the function sub_423E00 of the /boafrm/formPortFw file. This weakness potentially enables remote attackers t...

PoC for CVE-2026-2856

D-linkDwr-m9608.7HIGH
Stack-Based Buffer Overflow in D-Link DWR-M960 Products

A stack-based buffer overflow vulnerability exists in the D-Link DWR-M960 1.01.07 specifically in the Filter Configuration Endpoint. The flaw lies within the function sub_424AFC located in the file /boafrm/formFilter. An attacker can manipulate the 'submit-url' argument, potentially allowing for ...

Discovered 15 hours ago

PoC for CVE-2026-2855

D-linkDwr-m9608.7HIGH
Stack-Based Buffer Overflow Vulnerability in D-Link DWR-M960 Router

A stack-based buffer overflow vulnerability exists in the D-Link DWR-M960 router, specifically within the DDNS Settings Handler, triggered by improper handling of user input in the submit-url argument. This vulnerability can be exploited remotely, allowing attackers to manipulate the router's fun...

Discovered 16 hours ago

PoC for CVE-2026-2854

D-linkDwr-m9608.7HIGH
Stack-Based Buffer Overflow in D-Link DWR-M960 Router

A stack-based buffer overflow vulnerability exists in the D-Link DWR-M960 due to improper handling of the argument submit-url within the NTP Configuration Endpoint. This flaw can be exploited remotely, potentially allowing an attacker to manipulate memory and execute arbitrary code. Security upda...

PoC for CVE-2026-2853

D-linkDwr-m9608.7HIGH
Buffer Overflow Vulnerability in D-Link DWR-M960 Router

A stack-based buffer overflow vulnerability has been identified in the D-Link DWR-M960 router's system log configuration endpoint, specifically in the function sub_462E14 of the /boafrm/formSysLog file. By manipulating the argument submit-url, an attacker can exploit this vulnerability remotely, ...

PoC for CVE-2026-2852

YeqifuWarehouse5.3MEDIUM
Improper Access Controls in Yeqifu Warehouse Product

A vulnerability has been identified in Yeqifu Warehouse, specifically within the Sales Endpoint's SalesController.java file, affecting the addSales, updateSales, and deleteSales functions. This issue allows for improper access controls, which may lead to unauthorized operations on sales data. The...

PoC for CVE-2019-25445

PHPscriptsmallFiverr Clone Script5.1MEDIUM
Cross-Site Scripting in Fiverr Clone Script by Fiverr

The Fiverr Clone Script version 1.2.2 has a cross-site scripting (XSS) vulnerability allowing unauthenticated attackers to inject malicious scripts. By manipulating the 'keyword' parameter in the search-results.php file, attackers can craft URLs containing script tags, which enables execution of ...

Discovered 18 hours ago

PoC for CVE-2026-2851

YeqifuWarehouse5.3MEDIUM
Improper Access Control in yeqifu Warehouse Affects Inport Endpoint

A vulnerability exists in the yeqifu warehouse affecting the Inport Endpoint, specifically within the addInport, updateInport, and deleteInport functions of the InportController.java file. This issue, tied to inadequate access controls, allows unauthorized access and manipulation remotely. Althou...

PoC for CVE-2026-2850

YeqifuWarehouse5.3MEDIUM
Improper Access Controls in Customer Endpoint of yeqifu Warehouse

A vulnerability was identified in the yeqifu warehouse affecting the Customer Endpoint's addCustomer, updateCustomer, and deleteCustomer functions. This flaw leads to improper access controls, allowing for potential remote exploitation. The vulnerability was made public, and while it has been ack...

PoC for CVE-2025-15583

DetronetdipE-commerce5.1MEDIUM
Cross-Site Scripting Vulnerability in Detronetdip E-commerce by Det...

A cross-site scripting vulnerability has been detected in the Detronetdip E-commerce platform version 1.0.0, specifically within the get_safe_value function located in utility/function.php. This weakness allows remote attackers to execute crafted scripts, potentially compromising user interaction...

PoC for CVE-2025-15582

DetronetdipE-commerce5.3MEDIUM
Authorization Bypass in detronetdip E-commerce by detronetdip

A security flaw in the detronetdip E-commerce version 1.0.0 has been identified, specifically in the Product Management Module's Delete/Update function. This vulnerability allows for an authorization bypass through manipulation of the argument ID, enabling potential unauthorized access to sensiti...

Discovered 19 hours ago

PoC for CVE-2026-2849

YeqifuWarehouse5.3MEDIUM
Improper Access Controls in Yeqifu Warehouse Cache Sync Handler

A vulnerability exists in the Cache Sync Handler of the Yeqifu Warehouse that allows attackers to manipulate access controls improperly. The issue lies within the deleteCache/removeAllCache/syncCache functions of the CacheController.java file. Since this vulnerability can be exploited remotely, i...

PoC for CVE-2026-2848

SourcecodesterSimple Responsive Tour...6.9MEDIUM
SQL Injection Flaw in SourceCodester Simple Responsive Tourism Website

A vulnerability has been identified in SourceCodester's Simple Responsive Tourism Website version 1.0, specifically within the Registration component's functionality in the Master.php file. The flaw results from improper handling of user input for the Username argument, which can lead to SQL inje...

PoC for CVE-2026-2847

UttHiper 5208.6HIGH
OS Command Injection Vulnerability in UTT HiPER 520 Web Management ...

In the UTT HiPER 520 (version 1.7.7-160105), a vulnerability has been identified in the web management interface located in the function sub_44EFB4 of the file /goform/formReleaseConnect. This flaw allows attackers to manipulate the Isp_Name parameter, leading to OS command injection. The vulnera...

PoC for CVE-2026-2846

UttHiper 5208.6HIGH
OS Command Injection in UTT HiPER 520 Web Management Interface

A security vulnerability exists in the UTT HiPER 520 product, particularly in the Web Management Interface. This vulnerability allows remote attackers to manipulate the 'policyNames' argument in the sub_44D264 function of the formPdbUpConfig file. Successful exploitation can lead to OS command in...

Discovered 1 day ago

PoC for CVE-2025-4517

Python Software F...Cpython9.4CRITICAL
Arbitrary Filesystem Write Vulnerability in Python Tarfile Module

The vulnerability in the Python tarfile module allows for arbitrary filesystem writes when extracting untrusted tar archives with the filter parameter set to 'data' or 'tar'. This issue arises specifically in Python 3.12 or later. Users who employ the TarFile.extractall() or TarFile.extract() met...

PoC for CVE-2023-30533

SheetjsSheetjs7.8HIGH
Prototype Pollution Vulnerability in SheetJS Community Edition

The SheetJS Community Edition software prior to version 0.19.3 is susceptible to a Prototype Pollution vulnerability, which can be exploited through specially crafted files. This issue allows an attacker to manipulate the properties of JavaScript objects, potentially leading to unauthorized acces...

PoC for CVE-2025-47812

WftpserverWing Ftp Server🟣 EPSS 93%10CRITICAL
Remote Code Execution Vulnerability in Wing FTP Server

In Wing FTP Server prior to version 7.4.4, both user and admin web interfaces improperly handle null ('\0') bytes, which can lead to the injection of arbitrary Lua code into user session files. This vulnerability enables attackers to execute arbitrary system commands with the privileges of the FT...

PoC for CVE-2026-2825

RachelosWerss We-mp-rss5.1MEDIUM
Cross-Site Scripting in rachelos WeRSS Article Module for WordPress

A vulnerability exists in rachelos WeRSS we-mp-rss up to version 1.4.8, specifically in the Article Module's fix_html function located in tools/fix.py. This vulnerability permits attackers to execute remote cross-site scripting attacks, compromising the security of affected installations. The exp...

PoC for CVE-2026-2824

ComfastCf-e75.3MEDIUM
Command Injection Vulnerability in Comfast CF-E7 by Comfast

A command injection vulnerability has been identified in the Comfast CF-E7 router, specifically in the web management component 'webmggnt'. This flaw resides in the function sub_441CF4 located within the configuration file accessed via the endpoint /cgi-bin/mbox-config?method=SET&section=ping_con...

PoC for CVE-2026-2823

ComfastCf-e75.3MEDIUM
Command Injection Vulnerability in Comfast CF-E7 Device

A command injection vulnerability has been identified in the Comfast CF-E7 device, specifically in version 2.6.0.9. The vulnerability exists within the function sub_41ACCC found in the /cgi-bin/mbox-config?method=SET&section=ntp_timezone component of webmggnt. By manipulating the 'timestr' argume...

PoC for CVE-2026-2822

Beijing Guoju Inf...Jeecgboot5.3MEDIUM
SQL Injection Vulnerability in JeecgBoot Backend Interface

A SQL injection vulnerability exists in the Backend Interface of JeecgBoot up to version 3.9.1, specifically within the function handling /jeecgboot/sys/dict/loadDict/airag_app,1,create_by. This flaw allows attackers to manipulate the 'keyword' argument, enabling remote execution of SQL commands....

PoC for CVE-2026-2821

FujianSmart Integrated Manag...6.9MEDIUM
SQL Injection Vulnerability in Fujian Smart Integrated Management P...

A vulnerability has been discovered within the Fujian Smart Integrated Management Platform System prior to version 7.5, specifically affecting the functionality of /Module/CRXT/Controller/XCamera.ashx. This issue arises from improper handling of the ChannelName argument, allowing attackers to per...

PoC for CVE-2026-2820

FujianSmart Integrated Manag...6.9MEDIUM
SQL Injection Vulnerability in Fujian Smart Integrated Management P...

A security flaw exists in the Fujian Smart Integrated Management Platform System prior to version 7.5, specifically affecting the file /Module/CRXT/Controller/XAccessPermissionPlus.ashx. This flaw allows for SQL injection through improper handling of the DeviceIDS argument. Remote attackers can l...

PoC for CVE-2025-71243

SpipSaisies Pour Formulaire9.3CRITICAL
Remote Code Execution Vulnerability in SPIP Saisies Plugin

The Saisies plugin for SPIP has a significant vulnerability that allows attackers to execute arbitrary code on the server. This critical issue affects SPIP versions from 5.4.0 to 5.11.0. It is crucial for users to update to version 5.11.1 or later to secure their applications and protect against ...

Discovered 2 days ago

PoC for CVE-2025-65717

Ritwick DeyVisual Studio Code Ext...4.3MEDIUM
File Exfiltration Vulnerability in Visual Studio Code Extensions by...

A vulnerability exists in Visual Studio Code Extensions Live Server v5.7.9 that enables malicious actors to exfiltrate sensitive files from users' systems through crafted HTML pages. User interaction is required to initiate the attack, exposing them to potential data breaches. It is crucial for u...

PoC for CVE-2026-27476

BixatRustfly9.3CRITICAL
Command Injection Vulnerability in RustFly Remote UI Control

RustFly 2.0.0 is susceptible to a command injection flaw within its remote user interface control mechanism. This vulnerability allows attackers to send specially crafted hex-encoded instructions over UDP port 5005, lacking appropriate input validation. By exploiting this weakness, attackers can ...

PoC for CVE-2022-41840

WordPressWelcart E-commerce (Wo...🟣 EPSS 82%9.8CRITICAL
WordPress Welcart eCommerce plugin <= 2.7.7 - Unauth. Directory Tra...

Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

PoC for CVE-2019-25430

CdomeComodo Dome Firewall5.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in Comodo Dome Firewal...

Comodo Dome Firewall version 2.7.0 is vulnerable to a reflected cross-site scripting attack. This issue allows unauthenticated attackers to inject harmful scripts into the application by manipulating the 'username' parameter. By sending crafted POST requests to the 'vpn_users' endpoint, an attack...

PoC for CVE-2026-23829

AxllentMailpit5.3MEDIUM
Header Injection Vulnerability in Mailpit Email Testing Tool by Axl...

Mailpit, an email testing tool developed by Axllent, has a vulnerability in its SMTP server that allows attackers to exploit insufficient validation in the regular expression used for validating `RCPT TO` and `MAIL FROM` addresses. This flaw enables attackers to inject arbitrary SMTP headers, pot...

PoC for CVE-2026-2711

ZhutoutoutousanWorldquant-miner6.3MEDIUM
Server-Side Request Forgery in zhutoutoutousan Worldquant Miner

A vulnerability identified in zhutoutoutousan's Worldquant Miner up to version 1.0.9 resides in an obscure function of the 'ssrf_proxy.py' file. This flaw enables attackers to execute a server-side request forgery (SSRF) attack by manipulating the 'make_request' argument. The remote nature of thi...

PoC for CVE-2026-2709

BusyOrgBusy5.1MEDIUM
Open Redirect Vulnerability in Busy Application by BusyOrg

A vulnerability exists in the Busy application up to version 2.5.5, specifically in the Callback Handler component within the source code file app.js. This flaw allows an attacker to manipulate the state argument, leading to an open redirect. This issue can be exploited remotely, posing a signifi...