Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-101081

D-linkDi-84009.4CRITICAL
Buffer Overflow Vulnerability in D-Link DI-8400 Web Administration ...

A vulnerability has been identified in the D-Link DI-8400's Web Administration Service, specifically affecting the menu_nat_more_asp function. This security flaw arises from a stack-based buffer overflow triggered by the manipulation of the 'opt' argument in the menu_nat_more.asp file. Attackers ...

PoC for CVE-2026-101080

TencentAi-infra-guard2.4LOW
Path Traversal Vulnerability in Tencent AI-Infra-Guard File Access ...

A vulnerability exists in Tencent AI-Infra-Guard affecting its File Access component. Specifically, the 'startsWith' function in the 'skill_scan/tools/dir/dir_actions.py' file is susceptible to path traversal attacks. This flaw allows attackers with local access to manipulate file paths, potentia...

PoC for CVE-2026-101079

AgentverusAgentverus-scanner2.4LOW
Improper Input Validation in AgentVerus Scanner from AgentVerus

A vulnerability exists in the AgentVerus Scanner affecting versions up to 0.8.1, primarily in the isSecurityDefenseSkill function within context.js. This flaw allows an attacker to manipulate security decisions by relying on untrusted inputs, potentially leading to unauthorized actions. The attac...

Discovered 4 hours ago

PoC for CVE-2026-101078

Deepseek-aiDeepseek-harness4.8MEDIUM
Improper Isolation in Deepseek-AI's Deepseek-Harness Component

A vulnerability exists in Deepseek-AI's Deepseek-Harness component, specifically within the Landlock Backend located in the profiles.ts file. This vulnerability allows for improper isolation or compartmentalization, which can be exploited locally. An attacker can manipulate the affected function ...

PoC for CVE-2026-101077

NetcoreNr289-ge10CRITICAL
Missing Authentication Flaw in Netcore NR289-GE Router

A vulnerability exists in the Netcore NR289-GE router where the boa_temp Handler's process_request function lacks adequate authentication. This flaw allows a remote attacker to exploit the system without authorization. The potential for exploitation has been made public, and despite early notific...

PoC for CVE-2026-101076

NetcoreNr289-ge10CRITICAL
OS Command Injection Vulnerability in Netcore NR289-GE by Netcore

A critical security vulnerability has been identified in the Netcore NR289-GE version 1.4.5102, affecting its CGI Handler component. This flaw allows an attacker to manipulate the 'ntp_ip' argument in the '/set_ntp_server_ip.cgi' file, leading to potential remote command injection. Without adequa...

PoC for CVE-2026-101075

NetcoreNr289-ge10CRITICAL
OS Command Injection Vulnerability in Netcore NR289-GE Router

A significant security vulnerability exists within the Netcore NR289-GE router, specifically in the 'Location Time Handler' component. By manipulating the 'mac' argument in the '/location_time.cgi' file, an attacker could execute arbitrary operating system commands. This flaw allows for potential...

Discovered 5 hours ago

PoC for CVE-2026-101074

NetcoreNr289-ge9.3CRITICAL
Stack-Based Buffer Overflow in Netcore NR289-GE Routers

A vulnerability has been discovered in the Netcore NR289-GE router, specifically within the password-check function of the Authentication component located in the /bin/boa file. This issue arises due to improper handling of the Username argument, potentially allowing remote attackers to exploit t...

PoC for CVE-2026-101073

NetcoreNr289-ge6.9MEDIUM
Improper Authentication in Netcore NR289-GE Router by Netcore

A security flaw in the Netcore NR289-GE router version 1.4.5102 has been identified in the CGI Dispatcher component, specifically within the /bin/boa file. This vulnerability allows an attacker to exploit improper authentication mechanisms, facilitating unauthorized access. The attack can be exec...

PoC for CVE-2026-88771

Citrix NetscalerAdc9.5CRITICAL
Improper Input Validation in Citrix NetScaler ADC and Gateway

An improper input validation vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway, enabling unauthenticated attackers to execute arbitrary commands. This potentially compromises system integrity and security, allowing unauthorized control over the affected product.

PoC for CVE-2026-85706

GitlabGitlab🟣 EPSS 91%10CRITICAL
Improper Path Confinement in GitLab CE/EE Affecting User Access

A vulnerability in GitLab CE/EE allows unauthenticated users to read arbitrary files due to inadequate path confinement and a lack of proper authentication checks in the repository commits API. This issue affects GitLab versions 18.7 prior to 19.1.8, 19.2 prior to 19.2.6, and 19.3 prior to 19.3.2...

PoC for CVE-2026-101072

NetcoreNr289-ge10CRITICAL
OS Command Injection Vulnerability in Netcore NR289-GE Router

A vulnerability has been detected in the Netcore NR289-GE router, specifically within the CGI Handler component of the firmware version 1.4.5102. The flaw allows an attacker to inject operating system commands through manipulation of the 'ip' parameter in the /ap_ip.cgi file. This can be executed...

Discovered 6 hours ago

PoC for CVE-2026-101071

Acrel ElectricUnet Web Service5.3MEDIUM
Unrestricted File Upload in Acrel Electric Unet Web Service

Acrel Electric Unet Web Service up to version 20260814 contains a vulnerability in the Upload Endpoint that allows for unrestricted file uploads through the manipulation of file arguments in the /exchange/attachment/upload path. This security flaw can be exploited by remote attackers, exposing th...

PoC for CVE-2026-101070

dbgateDbgate6.9MEDIUM
Path Traversal Vulnerability in dbgate Files Endpoint

A security vulnerability exists in dbgate's Files Endpoint, found in the runners.js file within the api/src/controllers directory. This flaw allows an attacker to manipulate the runid argument, resulting in a path traversal condition. Such exploitation can be executed remotely, potentially exposi...

PoC for CVE-2026-101069

dbgateDbgate6.9MEDIUM
Path Traversal Vulnerability in dbgate Export Handler

A security vulnerability exists in dbgate versions up to 7.3.1 within the Export Handler's exportModelSql function, located in the file packages/api/src/controllers/databaseConnections.js. This flaw allows an attacker to manipulate the argument outputFile, potentially leading to unauthorized acce...

PoC for CVE-2026-101068

GenesiDbgate6.9MEDIUM
Path Traversal Vulnerability in dbgate by Genesi

A security flaw has been identified in dbgate, impacting versions up to 7.3.1. The vulnerability resides in the zipJsonLinesData function, specifically within the Create Connection Endpoint. An attacker may manipulate the argument filePath to execute a path traversal attack, which could allow una...

Discovered 7 hours ago

PoC for CVE-2026-101067

VDBDbgate6.9MEDIUM
Path Traversal Vulnerability in DbGate by VDB

An identified vulnerability in DbGate allows for path traversal through the manipulation of the filePath and fileName parameters in the saveUploadedFile function of files.js. This weakness enables attackers to potentially access files outside of the intended directories, thus compromising the app...

PoC for CVE-2026-34990

OpenprintingCups5MEDIUM
Local Privilege Escalation in OpenPrinting CUPS by Unprivileged Users

OpenPrinting's CUPS, an open source printing system for Linux and other Unix-like operating systems, is susceptible to a local privilege escalation vulnerability. An unprivileged user can exploit this flaw to trick the cupsd service into authenticating with an attacker-controlled IPP service on l...

PoC for CVE-2026-101066

dbgateDbgate6.9MEDIUM
Path Traversal Vulnerability in dbgate Affects Archive Link Creatio...

A vulnerability has been identified in dbgate versions up to 7.3.1. The flaw resides in the createLink function of the Archive Link Creation component, specifically within the packages/api/src/controllers/archive.js file. This vulnerability allows attackers to manipulate the linkedFolder argument...

PoC for CVE-2026-101055

ThinkwareU30006.9MEDIUM
Information Disclosure Vulnerability in Thinkware U3000 TCP Service

A significant security flaw has been identified in the Thinkware U3000, specifically in the TCP Service's GET_STATUS function. This vulnerability stems from improper handling of the 'wifi_info' argument, which allows for remote information disclosure to unauthorized users. Exploitation of this vu...

PoC for CVE-2026-101054

ThinkwareU30006.9MEDIUM
Improper Access Controls in Thinkware U3000's TCP Service

A security flaw has been detected in the Thinkware U3000's TCP Service that affects the function get_file in the /tmp/wpa_supplicant.conf file. This vulnerability allows attackers to manipulate access controls, potentially enabling unauthorized remote access. Public exploits are available, and th...

Discovered 8 hours ago

PoC for CVE-2026-34990

OpenprintingCups5MEDIUM
Local Privilege Escalation in OpenPrinting CUPS by Unprivileged Users

OpenPrinting's CUPS, an open source printing system for Linux and other Unix-like operating systems, is susceptible to a local privilege escalation vulnerability. An unprivileged user can exploit this flaw to trick the cupsd service into authenticating with an attacker-controlled IPP service on l...

PoC for CVE-2026-101052

Refly-aiRefly6.9MEDIUM
Security Flaw in Refly AI's JWT Token Handler Affects Refly Product

A security vulnerability exists in Refly AI's product affecting the JWT Token Handler component in versions up to 1.1.0. This vulnerability stems from improper handling of inputs within the 'apps/api/src/modules/config/app.config.ts' file, which leads to hard-coded credentials being present in th...

PoC for CVE-2026-101040

RicohSp 330dn7.1HIGH
Denial of Service Vulnerability in Ricoh Printers by Ricoh

A security flaw in Ricoh printers including models SP 330DN, SP 221, SP C252SF, and Aficio SP 3500SF allows for a Denial of Service attack through manipulation of the HTTP Multipart Form-Data Parser. This vulnerability can be exploited remotely, posing significant risks to networked environments....

PoC for CVE-2026-101039

FastFac1900r10CRITICAL
Stack-Based Buffer Overflow in FAST FAC1900R by FAST

A security flaw has been discovered in the FAST FAC1900R 20190827_2.0.2, specifically in the copy_msg_element function of the devdiscover Service. This issue allows for a stack-based buffer overflow, which could be exploited remotely by attackers. Given that the exploit code is publicly accessibl...

Discovered 9 hours ago

PoC for CVE-2026-101038

FastFac1200r9.4CRITICAL
Stack-based Buffer Overflow in FAST FAC1200R by FAST

A vulnerability exists in the FAST FAC1200R version 5.0_20201119_1.0.2, specifically within the MmtAtePrase function of the MmtAtePrase Parser. This issue involves a stack-based buffer overflow that may be remotely exploited, potentially leading to unauthorized access and system compromise. The e...

PoC for CVE-2026-101037

FastFac1200r9.4CRITICAL
Stack-based Buffer Overflow in FAST FAC1200R Device by FAST

A stack-based buffer overflow has been identified in the FAST FAC1200R 5.0_20201119_1.0.2, specifically within the parse_advertisement_frame function of the devdiscover Service. This vulnerability allows attackers to manipulate the system remotely, posing significant risks to the integrity and av...

PoC for CVE-2026-101036

Flb-musicFlb-music-player4.8MEDIUM
Path Traversal Vulnerability in FLB-Music Player by FLB-Music

A security vulnerability has been identified in FLB-Music-Player versions 1.1.8, 1.1.9, 1.2.0, and 1.2.1, specifically impacting the function path.join within the file /src/main/core/createParsedTrack.ts. This vulnerability allows local attackers to manipulate file paths, potentially leading to u...

Discovered 10 hours ago

PoC for CVE-2026-101035

AligungrUeransim6.9MEDIUM
Uncaught Exception Vulnerability in UERANSIM by aligungr

A vulnerability has been identified in UERANSIM versions up to 3.3.0, particularly impacting the DecodePlainMmMessage function in the source file src/lib/nas/encode.cpp. This flaw can lead to an uncaught exception, which may be exploited remotely, allowing attackers to manipulate the system. Imme...

PoC for CVE-2026-101018

DayruiXunruicms5.1MEDIUM
SQL Injection in XunruiCMS Affecting Dayrui Software

A security flaw exists in Dayrui's XunruiCMS, specifically affecting versions up to 4.7.2. The vulnerability occurs within the 'group_all_edit' function of the 'Home.php' file in the Group Editing component. A manipulation of the 'groupid' argument enables attackers to execute SQL injection attac...

PoC for CVE-2026-101017

Trusted Domain Pr...Opendmarc6.9MEDIUM
Improper Handling of Exceptional Conditions in Trusted Domain Proje...

A vulnerability in Trusted Domain Project OpenDMARC versions up to 1.4.2 involves improper handling of exceptional conditions within the strcasecmp function in the library libopendmarc/opendmarc_policy.c. This flaw allows for potential remote exploitation, as the exploit has been made public. The...

PoC for CVE-2026-101016

Trusted Domain Pr...Opendmarc6.9MEDIUM
Improper Authentication Vulnerability in Trusted Domain Project Ope...

A security flaw has been identified in OpenDMARC, specifically in the opendmarc_policy_parse_dmarc function within the library libopendmarc/opendmarc_policy.c. This issue stems from the manipulation of parameters such as fo, rf, ri, pct, sp, adkim, aspf, rua, and ruf, leading to improper handling...

Discovered 11 hours ago

PoC for CVE-2026-101015

Trusted Domain Pr...Opendmarc6.9MEDIUM
Improper Input Validation in Trusted Domain Project OpenDMARC 1.4.2

A vulnerability has been identified in the Trusted Domain Project OpenDMARC up to version 1.4.2, where improper validation of unsafe equivalence in input is present in the file policy.c of the Domain Handler component. This flaw may allow remote attackers to exploit this issue by executing a mani...

PoC for CVE-2026-101014

Trusted Domain Pr...Opendmarc6.9MEDIUM
Off-by-One Vulnerability in Trusted Domain Project OpenDMARC Product

A vulnerability has been identified in the Trusted Domain Project OpenDMARC software, specifically in the opendmarc_util_cleanup function within the DMARC Record Parser. This off-by-one flaw allows for potential manipulation leading to unauthorized actions. The issue can be triggered remotely, ma...

PoC for CVE-2025-56005

PythonPLY (Python Lex-Yacc)🟣 EPSS 19%9.8CRITICAL
Remote Code Execution Vulnerability in PLY Library by Python

An undocumented and unsafe feature in the PLY library version 3.11 presents a significant security risk, allowing remote code execution via the `picklefile` parameter in the `yacc()` function. This parameter accepts `.pkl` files, which are deserialized using `pickle.load()` without any form of va...

Discovered 12 hours ago

PoC for CVE-2026-101011

AapanelBaota5.1MEDIUM
SQL Injection Vulnerability in aaPanel BaoTa by aaPanel

A security flaw has been identified in aaPanel BaoTa, specifically in the domainMod.py file's get_domain_status function. This vulnerability allows remote attackers to manipulate input arguments, leading to potential SQL injection attacks. The vulnerability affects all versions of aaPanel BaoTa u...

PoC for CVE-2025-56005

PythonPLY (Python Lex-Yacc)🟣 EPSS 19%9.8CRITICAL
Remote Code Execution Vulnerability in PLY Library by Python

An undocumented and unsafe feature in the PLY library version 3.11 presents a significant security risk, allowing remote code execution via the `picklefile` parameter in the `yacc()` function. This parameter accepts `.pkl` files, which are deserialized using `pickle.load()` without any form of va...

PoC for CVE-2026-101010

AapanelBaota5.1MEDIUM
SQL Injection Vulnerability in aaPanel BaoTa Remote Management Tool

A SQL injection vulnerability exists in the getData function of the data.py file in aaPanel BaoTa versions up to 11.8.0. This flaw allows an attacker to manipulate the log_type argument, potentially leading to unauthorized access and exposure of sensitive data. Given that the exploit is publicly ...

PoC for CVE-2026-101009

AapanelBaota9.3CRITICAL
OS Command Injection Vulnerability in aaPanel BaoTa Unzip Handler

The aaPanel BaoTa software, specifically versions up to 11.8.0, contains a vulnerability in the Unzip Handler component. This flaw is found within the function panelTask.bt_task._unzip located in the file /www/server/panel/class/panelTask.py. A remote attacker can exploit this vulnerability by ma...

PoC for CVE-2026-101008

AapanelBaota9.4CRITICAL
Command Injection Vulnerability in aaPanel BaoTa

A critical command injection vulnerability exists in the merge_split_file function within the File Merge Handler of aaPanel BaoTa up to version 11.8.0. By manipulating the argument split_file_path, an attacker can execute arbitrary commands on the server remotely. This vulnerability has been publ...

Discovered 13 hours ago

PoC for CVE-2026-101007

AapanelBaota9.3CRITICAL
OS Command Injection Vulnerability in aaPanel BaoTa Database Backup...

A critical vulnerability has been discovered in aaPanel BaoTa affecting versions up to 11.8.0. This flaw resides in the InputSql function of the Database Backup Handler found in the file class/database.py. It allows an attacker to manipulate the Password argument, potentially leading to unauthori...

PoC for CVE-2026-92996

WordPressVerge3d Publishing And...5.3MEDIUM
Authentication Bypass in Verge3D WordPress Plugin

The Verge3D WordPress plugin versions 4.1.0 to 4.13.0 contains a serious flaw in its payment handling process. It fails to properly verify payments with the payment provider or check for order ownership, enabling unauthenticated users to manipulate the order status by marking any order as paid. T...

PoC for CVE-2026-89411

WordPressPaymattic5.3MEDIUM
Improper Payment Verification in Paymattic Plugin by WordPress

The Paymattic WordPress plugin versions prior to 4.6.26 are affected by a flaw that fails to properly verify that a confirmed Stripe payment corresponds to the intended order. This vulnerability allows unauthenticated users to mark any pending order as paid by creating a smaller payment of their ...

PoC for CVE-2026-88828

WordPressBlacklist Manager5.4MEDIUM
User Authentication Bypass in Blacklist Manager for WooCommerce Plugin

The Blacklist Manager for WooCommerce plugin allows users whose accounts are supposed to be blocked to bypass these restrictions through various authentication methods. This flaw means that previously blocked users can still gain access with their existing privileges, thereby undermining the inte...

PoC for CVE-2026-86838

WordPressBookly5.3MEDIUM
Server-Side Validation Flaw in Bookly Plugin for WordPress

The Bookly plugin for WordPress prior to version 28.3 contains a vulnerability where it fails to properly validate the booking quantity input from clients on the server side. This oversight enables unauthenticated users to manipulate the booking process, allowing them to set the total appointment...

PoC for CVE-2026-84744

WordPressWPforms6.5MEDIUM
Shortcode Injection Vulnerability in WPForms Lite Plugin by WordPress

The WPForms Lite plugin for WordPress, versions 1.5.0.1 to 2.0.2, contains a flaw that fails to properly strip shortcode delimiters from user-submitted field values. This oversight enables unauthenticated individuals to execute arbitrary shortcodes registered on the website, potentially revealing...

PoC for CVE-2026-89300

WordPressWP Verify Api5.3MEDIUM
Unauthorized Data Insertion in WP Verify API Plugin Affects WordPress

The WP Verify API plugin for WordPress, up to version 1.0.0, is susceptible to a serious authorization bypass vulnerability. This flaw allows unauthenticated users to access specific REST API routes, which lack proper security checks. As a result, malicious actors can insert arbitrary data direct...

PoC for CVE-2026-93000

WordPressSps-suite6.8MEDIUM
SQL Injection Vulnerability in SPS-Suite WordPress Plugin by WPScan

The SPS-Suite plugin for WordPress, up to version 1.4.0, has a significant vulnerability where it fails to properly sanitize the search query when utilizing the static-page search feature. This oversight allows unauthorized attackers to craft malicious SQL queries, potentially leading to unauthor...

PoC for CVE-2026-89303

WordPressPost Voting System6.4MEDIUM
SQL Injection Vulnerability in Post Voting System WordPress Plugin

The Post Voting System plugin for WordPress versions up to 1.0 is vulnerable due to improper sanitization and escaping of parameters in SQL queries. This flaw allows any authenticated user to exploit the plugin, potentially leading to unauthorized database access and manipulation through SQL inje...

PoC for CVE-2026-101005

October CMSOctober Cms6.9MEDIUM
Server-Side Request Forgery in October CMS Affects Image Processing

A vulnerability in the October CMS up to version 4.3.4 exists in the validateExternalImageHost function, located in System/Classes/ResizeImages.php. This flaw allows attackers to exploit server-side request forgery (SSRF) vulnerabilities, potentially enabling remote access and manipulation of ser...