Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2025-40019

LinuxLinux
Decryption Vulnerability in Linux Kernel Crypto Module

A vulnerability has been identified in the Linux kernel's crypto module that potentially affects the integrity of encryption methods. The issue arises from the handling of the ssize parameter during decryption and in-place encryption processes. Specifically, the ssize check was not conducted earl...

Discovered 4 hours ago

PoC for CVE-2025-14847

MongoDBMongodb Server🟣 EPSS 58%8.7HIGH
Heap Memory Exposure in MongoDB Server Versions by MongoDB

The vulnerability arises from mismatched length fields in Zlib compressed protocol headers within MongoDB Server, potentially allowing an unauthenticated client to access uninitialized heap memory. This could lead to unauthorized information exposure, affecting versions of MongoDB Server across m...

Discovered 5 hours ago

PoC for CVE-2022-40471

Clinic\'s Patient...Clinic\'s Patient Mana...🟣 EPSS 88%9.8CRITICAL
Remote Code Execution Vulnerability in Clinic's Patient Management ...

The vulnerability in Clinic's Patient Management System version 1.0 allows an attacker to execute arbitrary code remotely. This is achieved through a flaw in the profile picture upload feature located in users.php, which does not adequately validate file uploads. As a result, an attacker can uplo...

Discovered 6 hours ago

PoC for CVE-2022-50802

Etap Lighting Int...Etap Safety Manager5.1MEDIUM
Cross-Site Scripting Vulnerability in ETAP Safety Manager by ETAP

The ETAP Safety Manager version 1.0.0.32 is vulnerable to a cross-site scripting (XSS) attack via the 'action' GET parameter. This vulnerability allows unauthenticated attackers to inject and execute malicious HTML and JavaScript in the browsers of users accessing the affected system. By crafting...

PoC for CVE-2025-15112

Ksenia Security S...Ksenia Security Lares ...5.1MEDIUM
URL Redirection Vulnerability in Ksenia Security Lares Home Automat...

Ksenia Security's Lares 4.0 version 1.6 is susceptible to a URL redirection flaw within the 'cmdOk.xml' script. This vulnerability enables attackers to exploit the 'redirectPage' GET parameter, allowing them to generate malicious links. When a user, who is authenticated, clicks on such a link fro...

PoC for CVE-2025-15113

Ksenia Security S...Ksenia Security Lares ...8.5HIGH
Unprotected Endpoint Vulnerability in Ksenia Security Lares 4.0 Hom...

An unprotected endpoint vulnerability exists in the Ksenia Security Lares 4.0 Home Automation version 1.6. This flaw enables authenticated attackers to upload MPFS File System binary images, which can lead to the overwriting of flash program memory. By exploiting this weakness, attackers may exec...

PoC for CVE-2024-58338

AtemeFlamingo Xl8.6HIGH
Restricted Shell Vulnerability in Anevia Flamingo XL 3.2.9

Anevia Flamingo XL version 3.2.9 contains a vulnerability that exposes users to severe security risks by allowing remote attackers to escape the sandboxed environment via the traceroute command. This flaw can be exploited to inject malicious shell commands, potentially granting attackers full roo...

PoC for CVE-2025-15111

Ksenia Security S...Ksenia Security Lares ...9.3CRITICAL
Default Credentials Vulnerability in Ksenia Security Lares Home Aut...

The Ksenia Security Lares Home Automation version 1.6 is susceptible to a vulnerability that involves default administrative credentials. This weakness permits unauthorized individuals to gain administrative control over the home automation system, potentially leading to significant security brea...

PoC for CVE-2024-58337

The Akuvox CompanyAkuvox Smart Doorphone8.7HIGH
Improper Access Control in Akuvox Smart Intercom S539

The Akuvox Smart Intercom S539 is affected by an improper access control vulnerability that grants users with 'User' privileges the ability to modify API access settings and configurations. This flaw could enable attackers to escalate their privileges, allowing unauthorized manipulation of the de...

PoC for CVE-2024-58336

The Akuvox CompanyAkuvox Smart Doorphone8.7HIGH
Unauthenticated Remote Access Vulnerability in Akuvox Smart Interco...

The Akuvox Smart Intercom S539 is exposed to a serious vulnerability that permits unauthorized users to access live video feeds. By sending a request to the video.cgi endpoint on port 8080, attackers can obtain sensitive video stream data without any form of authentication. This flaw compromises ...

PoC for CVE-2024-58315

Tosibox OyTosibox Key Service8.5HIGH
Unquoted Service Path Vulnerability in Tosibox Key Service 3.3.0

Tosibox Key Service version 3.3.0 exhibits an unquoted service path vulnerability, where local users without administrative privileges may exploit this weakness to execute arbitrary code with elevated permissions. This flaw arises from the improper handling of the service startup process, allowin...

PoC for CVE-2023-54163

Nlb Banka Ad SkopjeNlb Mklik Makedonija8.8HIGH
SQL Injection Vulnerability in NLB mKlik Product from NLB

The NLB mKlik Macedonia mobile application version 3.3.12 is vulnerable to SQL injection through the international transfer parameters. This flaw allows malicious actors to inject arbitrary SQL commands via unsanitized input, which may lead to unauthorized access and disclosure of sensitive infor...

PoC for CVE-2023-54327

TinycontrolLan Controller9.3CRITICAL
Authentication Bypass in Tinycontrol LAN Controller by Tinycontrol

The Tinycontrol LAN Controller 1.58a is susceptible to an authentication bypass vulnerability that enables unauthorized attackers to change administrative passwords through specially crafted API requests. By exploiting the /stm.cgi endpoint with a malicious authentication parameter, attackers can...

PoC for CVE-2022-50804

Jm-data OnuJf511-tv5.1MEDIUM
Cross-Site Request Forgery Vulnerability in JM-DATA ONU JF511-TV

The JM-DATA ONU JF511-TV version 1.0.67 is susceptible to cross-site request forgery (CSRF) attacks. This vulnerability enables malicious actors to execute administrative tasks on behalf of authenticated users without their awareness or approval. Exploitation of this flaw may involve sending craf...

PoC for CVE-2023-53983

AtemeAnevia Flamingo Xl/xs9.3CRITICAL
Weak Default Administrative Credentials in Anevia Flamingo XL/XS Pr...

The Anevia Flamingo XL/XS 3.6.20 is susceptible to an authentication bypass vulnerability stemming from the use of weak default administrative credentials. These hard-coded credentials can be easily guessed by attackers, allowing them to gain unauthorized access to the system and exert full contr...

PoC for CVE-2022-50800

Hangzhou H3c Tech...H3c Ssl Vpn6.9MEDIUM
User Enumeration Vulnerability in H3C SSL VPN

The H3C SSL VPN is susceptible to a user enumeration vulnerability that enables malicious actors to discern valid usernames. By exploiting the 'txtUsrName' parameter in the login_submit.cgi endpoint, attackers can submit various username inputs and analyze the responses returned by the server. Th...

PoC for CVE-2022-50799

Fetch SoftworksFetch Softworks Fetch ...7.1HIGH
Denial of Service Vulnerability in Fetch FTP Client by Fetch Softworks

The Fetch FTP Client version 5.8.2 is susceptible to a denial of service vulnerability that enables attackers to cause complete CPU usage by sending lengthy server responses. This can be exploited by delivering specially designed FTP server responses that exceed 2K bytes in size, leading to exces...

PoC for CVE-2022-50798

Chris BagwellSox6.7MEDIUM
Denial of Service Vulnerability in SoX 14.4.2 Affecting Audio Proce...

SoX version 14.4.2 is susceptible to a denial of service vulnerability triggered by its handling of WAV files. When a specially crafted WAV file is processed, it can lead to a division by zero error, resulting in a floating point exception that crashes the program. This vulnerability highlights t...

PoC for CVE-2022-50795

Sound4 Ltd.Impact/pulse/first8.5HIGH
Conditional Command Injection in SOUND4 IMPACT/FIRST/PULSE/Eco Prod...

The SOUND4 IMPACT/FIRST/PULSE/Eco products version 2.x and below have a vulnerability that allows local authenticated users to exploit a conditional command injection. By leveraging this flaw, attackers can create malicious files in the /tmp directory. Additionally, unauthenticated users can exec...

PoC for CVE-2022-50796

Sound4 Ltd.Impact/pulse/first9.3CRITICAL
Remote Code Execution Vulnerability in SOUND4 IMPACT/FIRST/PULSE/Ec...

The SOUND4 IMPACT/FIRST/PULSE/Eco firmware version 2.x and below is vulnerable to a remote code execution attack due to a flaw in its firmware upload functionality. Specifically, the upload.cgi script allows attackers to perform path traversal attacks, enabling potentially malicious files to be u...

PoC for CVE-2022-50793

Sound4 Ltd.Impact/pulse/first8.7HIGH
Authenticated Command Injection in SOUND4 IMPACT/FIRST/PULSE/Eco Pr...

The SOUND4 IMPACT/FIRST/PULSE/Eco products including versions up to 2.x are susceptible to an authenticated command injection vulnerability found in the www-data-handler.php script. This flaw allows an attacker to manipulate the 'services' POST parameter to introduce arbitrary system commands, ex...

PoC for CVE-2022-50794

Sound4 Ltd.Impact/pulse/first9.3CRITICAL
Unauthenticated Command Injection in SOUND4 IMPACT/FIRST/PULSE/Eco

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and earlier are susceptible to an unauthenticated command injection vulnerability through the 'username' parameter. This weakness allows attackers to exploit the index.php and login.php scripts by injecting arbitrary shell commands via HTTP POST requests...

PoC for CVE-2022-50791

Sound4 Ltd.Impact/pulse/first8.5HIGH
Command Injection Vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco

The SOUND4 IMPACT/FIRST/PULSE/Eco product line, version 2.x and below, is susceptible to a conditional command injection vulnerability. This flaw allows local authenticated users to manipulate the system by creating malicious files within the /tmp directory. Additionally, unauthenticated attacker...

PoC for CVE-2022-50792

Sound4 Ltd.Impact/pulse/first8.7HIGH
Unauthenticated File Disclosure in SOUND4 IMPACT/FIRST/PULSE/Eco Sy...

The SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below are susceptible to an unauthenticated file disclosure vulnerability. This flaw allows remote attackers to manipulate the 'file' GET parameter, potentially granting access to sensitive system files on the affected devices. Exploiting this vu...

PoC for CVE-2022-50790

Sound4 Ltd.Impact/pulse/first6.9MEDIUM
Unauthenticated Access Vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco

The SOUND4 IMPACT, FIRST, PULSE, and Eco products, versions 2.x and lower, are susceptible to an unauthenticated vulnerability that allows remote attackers to access sensitive live radio stream information through specific web scripts. This vulnerability enables attackers to exploit webplay or ff...

PoC for CVE-2022-50789

Sound4 Ltd.Impact/pulse/first8.5HIGH
Command Injection Vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco

The SOUND4 IMPACT/FIRST/PULSE/Eco versions up to and including 2.x are vulnerable to a command injection flaw. This allows local authenticated users to execute malicious commands by creating files with a .dns.pid extension in the /tmp directory. By exploiting this vulnerability through an HTTP PO...

PoC for CVE-2022-50788

Sound4 Ltd.Impact/pulse/first6.9MEDIUM
Information Disclosure in SOUND4 IMPACT/FIRST/PULSE/Eco

The SOUND4 IMPACT/FIRST/PULSE/Eco software versions up to 2.x feature an information disclosure vulnerability that permits unauthorized users to access sensitive log files. This vulnerability occurs when attackers exploit the lack of authentication, enabling them to browse directly to the /log di...

PoC for CVE-2022-50787

Sound4 Ltd.Impact/pulse/first5.3MEDIUM
Unauthenticated Stored XSS in SOUND4 IMPACT/FIRST/PULSE/Eco

The SOUND4 IMPACT, FIRST, PULSE, and Eco applications, specifically versions 2.x, are susceptible to an unauthenticated stored cross-site scripting vulnerability. This security flaw arises when the username parameter processes unvalidated input, permitting attackers to inject malicious scripts. O...

PoC for CVE-2022-50696

Sound4 Ltd.Impact/pulse/first9.3CRITICAL
Hardcoded Credentials in SOUND4 IMPACT/FIRST/PULSE/Eco Devices

The SOUND4 IMPACT/FIRST/PULSE/Eco devices in version 2.x and below contain hardcoded credentials embedded within server binaries. These credentials cannot be altered through standard operations on the device. This vulnerability allows attackers to exploit these static credentials to gain unauthor...

PoC for CVE-2022-50694

Sound4 Ltd.Impact/pulse/first8.8HIGH
SQL Injection Flaw in SOUND4 IMPACT/FIRST/PULSE/Eco Products

The SOUND4 IMPACT, FIRST, PULSE, and Eco products prior to version 2.x exhibit an SQL injection vulnerability in the 'username' POST parameter of index.php. This flaw enables attackers to manipulate the database queries by injecting arbitrary SQL code through the username parameter. Successful ex...

PoC for CVE-2022-50695

Sound4 Ltd.Impact/pulse/first8.7HIGH
Network Vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco Products

The SOUND4 IMPACT/FIRST/PULSE/Eco products, specifically version 2.x, contain a significant network vulnerability. This flaw allows unauthenticated attackers to exploit scripts such as ping.php, traceroute.php, and dns.php, enabling them to send ICMP signals to arbitrary hosts. As a result, attac...

PoC for CVE-2022-50691

MinidvblinuxMinidvblinux9.3CRITICAL
Remote Command Execution Vulnerability in MiniDVBLinux 5.4 by Zero ...

MiniDVBLinux version 5.4 contains a significant remote command execution vulnerability that enables unauthenticated attackers to execute arbitrary commands with root privileges. By exploiting the vulnerable '/tpl/commands.sh' endpoint, attackers can manipulate the 'command' GET parameter, allowin...

PoC for CVE-2022-50692

Sound4 Ltd.Impact/pulse/first6.9MEDIUM
Insufficient Session Expiration Vulnerability in SOUND4's IMPACT/FI...

The SOUND4 IMPACT, FIRST, PULSE, and Eco products up to and including version 2.x expose a weakness in session management. An insufficient session expiration issue allows attackers to take advantage of stale session credentials. This vulnerability can lead to unauthorized access, where attackers ...

Discovered 7 hours ago

PoC for CVE-2025-15360

Newbee LtdNewbee-mall-plus5.1MEDIUM
Unrestricted File Upload in Newbee Mall Plus by Newbee Ltd

A vulnerability has been identified in the Newbee Mall Plus version 2.0.0, where the Upload function in the UploadController.java file allows for unrestricted file uploads through manipulation of the File argument. This flaw poses a significant risk as it can be exploited remotely, permitting una...

PoC for CVE-2025-15357

D-linkDi-7400g+5.3MEDIUM
Command Injection Vulnerability in D-Link DI-7400G+ Router

A security flaw has been identified in the D-Link DI-7400G+ router, specifically affecting the handling of commands through the /msp_info.htm?flag=cmd interface. This vulnerability allows an attacker to exploit the affected function by injecting malicious commands, potentially compromising the de...

Discovered 8 hours ago

PoC for CVE-2025-15356

TendaAc208.7HIGH
Buffer Overflow Vulnerability in Tenda AC20 Router

A buffer overflow vulnerability exists in the Tenda AC20 router, specifically within the sscanf function of the /goform/PowerSaveSet interface. The flaw arises from improper handling of user-supplied input, particularly the 'powerSavingEn', 'time', 'powerSaveDelay', and 'ledCloseType' parameters....

PoC for CVE-2025-15356

TendaAc208.7HIGH
Buffer Overflow Vulnerability in Tenda AC20 Router

A buffer overflow vulnerability exists in the Tenda AC20 router, specifically within the sscanf function of the /goform/PowerSaveSet interface. The flaw arises from improper handling of user-supplied input, particularly the 'powerSavingEn', 'time', 'powerSaveDelay', and 'ledCloseType' parameters....

PoC for CVE-2025-15354

ItsourcecodeSociety Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Society Management System

A SQL injection vulnerability has been identified in the itsourcecode Society Management System version 1.0. The flaw resides in an unrecognized function within the /admin/add_admin.php file, allowing attackers to manipulate the Username argument. This manipulation can lead to unauthorized SQL co...

Discovered 9 hours ago

PoC for CVE-2025-15353

ItsourcecodeSociety Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Society Management System

A vulnerability exists in the itsourcecode Society Management System version 1.0, specifically within the edit_admin_query function located in /admin/edit_admin_query.php. This security flaw allows for SQL injection attacks through improper handling of the Username argument. Attackers can exploit...

Discovered 10 hours ago

PoC for CVE-2025-15263

BiggidroidSimple PHP Cms6.9MEDIUM
SQL Injection Vulnerability in BiggiDroid Simple PHP CMS by BiggiDroid

A vulnerability has been discovered in BiggiDroid Simple PHP CMS 1.0, specifically affecting the admin login functionality located in /admin/login.php. An attacker can manipulate the Username argument to execute SQL injection attacks, potentially compromising the database. This exploit is capable...

PoC for CVE-2025-15262

BiggidroidSimple PHP Cms5.1MEDIUM
Unrestricted File Upload Vulnerability in BiggiDroid Simple PHP CMS...

A vulnerability has been identified in the BiggiDroid Simple PHP CMS version 1.0, specifically within the Site Logo Handler found in the /admin/edit.php file. This flaw permits an attacker to manipulate image arguments, resulting in unrestricted file uploads. Such exploitation could allow remote ...

Discovered 11 hours ago

PoC for CVE-2025-15258

EdimaxBr-6208ac5.1MEDIUM
Open Redirect Vulnerability in Edimax BR-6208AC Web-based Configura...

A significant vulnerability has been discovered in the Edimax BR-6208AC device, specifically within the web-based configuration interface. The flaw, located in the formALGSetup function, allows the manipulation of the wlan-url argument, leading to open redirection attacks. This vulnerability can ...

PoC for CVE-2025-15257

EdimaxBr-6208ac6.9MEDIUM
Command Injection Vulnerability in Edimax BR-6208AC Web Interface

A command injection vulnerability has been identified in the web-based configuration interface of the Edimax BR-6208AC router. The flaw resides in the 'formRoute' function of the '/gogorm/formRoute' file, where manipulation of the input parameters (strIp/strMask/strGateway) can allow attackers to...

Discovered 12 hours ago

PoC for CVE-2025-15256

EdimaxBr-6208ac6.9MEDIUM
Command Injection Vulnerability in Edimax BR-6208AC Router

A command injection vulnerability has been identified in the Edimax BR-6208AC router which affects its web-based configuration interface. The flaw resides in the function formStaDrvSetup, where manipulation of the 'rootAPmac' argument can lead to unauthorized command execution. This vulnerability...

PoC for CVE-2025-15255

TendaW6-s9.3CRITICAL
Stack-Based Buffer Overflow in Tenda W6-S by Tenda

A vulnerability has been identified in the Tenda W6-S model 1.0.0.4(510), specifically in the R7websSsecurityHandler component of the /bin/httpd file. This issue arises due to improper handling of the Cookie argument, which can be exploited to trigger a stack-based buffer overflow. Attackers can ...

Discovered 13 hours ago

PoC for CVE-2025-54236

AdobeAdobe Commerce🟣 EPSS 59%9.1CRITICAL
Improper Input Validation in Adobe Commerce Products

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier face a significant risk due to an Improper Input Validation flaw. This vulnerability allows attackers to bypass security features, potentially leading to session takeover without requiring any us...

PoC for CVE-2025-15254

TendaW6-s5.3MEDIUM
OS Command Injection in Tenda W6-S ATE Service by Tenda

A security flaw exists within the ATE Service of the Tenda W6-S device, specifically affecting the TendaAte function in the /goform/ate file. This vulnerability allows for remote OS command injection, enabling an unauthorized party to execute arbitrary commands on the device. As the exploit has b...

PoC for CVE-2025-15253

TendaM38.7HIGH
Stack-based Buffer Overflow in Tenda M3 Affected by Remote Exploit

A stack-based buffer overflow vulnerability exists in the Tenda M3 device with firmware version 1.0.0.13(4903). This vulnerability is triggered through the manipulation of the 'cmdinput' argument in the /goform/exeCommand file, allowing an attacker to execute remote exploits. Due to its remote ex...

Discovered 14 hours ago

PoC for CVE-2025-15252

TendaM38.7HIGH
Stack-based Buffer Overflow in Tenda M3 Router

A critical flaw exists in the Tenda M3 Router version 1.0.0.13, specifically in the function formSetRemoteDhcpForAp located in the /goform/setDhcpAP file. This vulnerability can be exploited remotely, allowing attackers to manipulate parameters such as startip, endip, leasetime, gateway, dns1, an...

Discovered 15 hours ago

PoC for CVE-2025-15250

08cmsNovel System5.1MEDIUM
Code Injection Vulnerability in 08CMS Novel System by 08CMS

A security flaw has been identified in the 08CMS Novel System, where certain processing within the admina/mtpls.inc.php file of the Template Handler component allows for code injection. This vulnerability enables attackers to execute code remotely, potentially compromising the system. The details...

Latest Cyber Security Exploit PoCs