Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 4 hours ago

PoC for CVE-2025-40778

IscBind 98.6HIGH
Data Injection Vulnerability in BIND Software by ISC

This vulnerability in BIND software allows attackers to inject malicious data into the cache due to overly lenient acceptance of records from responses. This flaw affects multiple versions of BIND 9, posing a risk of cache poisoning, which could potentially lead to compromised network integrity a...

Discovered 13 hours ago

PoC for CVE-2019-25286

GcafeGcafé8.5HIGH
Unquoted Service Path Vulnerability in GCafé by GCafé

GCafé 3.0 is susceptible to an unquoted service path vulnerability in the gbClientService. This flaw allows local attackers the potential to execute arbitrary code with elevated privileges. By exploiting the incorrect configuration of the service path, attackers can inject malicious executables t...

PoC for CVE-2019-25283

ShrewShrew Soft Vpn Client8.5HIGH
Unquoted Service Path Vulnerability in Shrew Soft VPN Client

The Shrew Soft VPN Client version 2.2.2 has a significant flaw due to the presence of an unquoted service path. This vulnerability permits local users to execute arbitrary code with elevated privileges by placing malicious executables within the unquoted service path. An attacker can exploit this...

PoC for CVE-2019-25288

WacomWacom Wtabletservice8.5HIGH
Unquoted Service Path Vulnerability in Wacom WTabletService

Wacom WTabletService version 6.6.7-3 is susceptible to an unquoted service path vulnerability, which presents a significant risk for local attackers. This flaw allows an attacker to place a malicious executable file within the service path, granting them the ability to execute unauthorized code w...

PoC for CVE-2019-25287

WebcompanionAdaware Web Companion ...8.5HIGH
Unquoted Service Path Vulnerability in Adaware Web Companion by Lav...

Adaware Web Companion version 4.8.2078.3950 is susceptible to an unquoted service path vulnerability within its WCAssistantService. This flaw allows local users to exploit the unquoted path located in 'C:\Program Files (x86)\Lavasoft\Web Companion\Application\', potentially enabling them to execu...

PoC for CVE-2019-25285

AlpsDevice Controller8.5HIGH
Unquoted Service Path Vulnerability in Alps Pointing-device Controller

The Alps Pointing-device Controller version 8.1202.1711.04 contains an unquoted service path vulnerability within the ApHidMonitorService component. This flaw enables local attackers to execute arbitrary code with elevated privileges by placing malicious executables in the service's path. As a re...

PoC for CVE-2019-25281

Ncp-eNcp Secure Entry Client8.5HIGH
Unquoted Service Path Vulnerability in NCP Secure Entry Client 9.2

The NCP Secure Entry Client 9.2 features an unquoted service path vulnerability affecting several Windows services, including ncprwsnt, rwsrsu, ncpclcfg, and NcpSec. This flaw allows local users to execute arbitrary code by injecting malicious commands into these unquoted service paths. During se...

PoC for CVE-2019-25276

RockwellautomationStudio8.5HIGH
Unquoted Service Path Vulnerability in FactoryTalk Activation Servi...

The FactoryTalk Activation Service in Studio 5000 Logix Designer 30.01.00 is vulnerable due to an unquoted service path issue. This flaw permits local users to execute arbitrary code with elevated permissions, potentially compromising system integrity. Attackers can exploit this vulnerability by ...

PoC for CVE-2019-25274

PhotodexProshow Producer8.5HIGH
Unquoted Service Path Vulnerability in ProShow Producer by Photodex

ProShow Producer 9.0.3797 is vulnerable to an unquoted service path issue in the ScsiAccess service. This vulnerability enables local attackers to potentially execute arbitrary code. By exploiting the unquoted binary path, attackers may inject malicious executables that are executed with LocalSys...

PoC for CVE-2019-25275

FilehorseBartvpn8.5HIGH
Unquoted Service Path Vulnerability in BartVPN by BartVPN

BartVPN 1.2.2 is susceptible to an unquoted service path vulnerability within the BartVPNService. This flaw enables local attackers to potentially execute arbitrary code with elevated privileges. By inserting malicious executables into predetermined file system locations, attackers can exploit th...

PoC for CVE-2019-25273

Easy-hide-ipIp8.5HIGH
Unquoted Service Path Vulnerability in Easy-Hide-IP by Easy-Hide-IP

The Easy-Hide-IP application version 5.0.0.3 is vulnerable due to an unquoted service path in the EasyRedirect service. This vulnerability allows local attackers to potentially execute arbitrary code by injecting malicious executables using the unquoted path found in 'C:\Program Files\Easy-Hide-I...

PoC for CVE-2019-25272

TenaxsoftTexassoft Cyberplanet8.5HIGH
Unquoted Service Path Vulnerability in TexasSoft CyberPlanet 6.4.131

TexasSoft CyberPlanet 6.4.131 contains a vulnerability in the CCSrvProxy service due to an unquoted service path. This issue allows local attackers to exploit the executable path at 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious code. As a result, attackers can ob...

PoC for CVE-2019-25271

NetgateData Backup8.5HIGH
Unquoted Service Path Vulnerability in NETGATE Data Backup by NETGATE

The NETGATE Data Backup 3.0.620 version contains a vulnerability in its NGDatBckpSrv Windows service configuration due to an unquoted service path. This misconfiguration allows attackers to potentially exploit the vulnerability by placing malicious executable files in specific directory locations...

PoC for CVE-2019-25269

NetgateAmiti Antivirus8.5HIGH
Unquoted Service Path Vulnerability in Amiti Antivirus by Amiti Sof...

Amiti Antivirus 25.0.640 has a vulnerability related to unquoted service paths in its Windows service configuration. This flaw allows attackers to exploit the unquoted path to insert and execute harmful code with elevated LocalSystem privileges by placing malicious executable files in predetermin...

PoC for CVE-2019-25267

WftpserverWing Ftp Server8.5HIGH
Unquoted Service Path Vulnerability in Wing FTP Server by Wing FTP ...

Wing FTP Server version 6.0.7 is susceptible to an unquoted service path vulnerability, which could enable local attackers to exploit the binary path in the service configuration. By injecting malicious executables, attackers can gain elevated system privileges that allow them to execute arbitrar...

Discovered 15 hours ago

PoC for CVE-2026-1884

ZenTaoZentao5.1MEDIUM
Server-Side Request Forgery in ZenTao Webhook Module

A vulnerability has been found in ZenTao affecting versions up to 21.7.6-85642. The issue lies in the fetchHook function within the Webhook Module's model.php file. This weakness can lead to server-side request forgery, allowing attackers to initiate unauthorized requests remotely. Exploits have ...

Discovered 18 hours ago

PoC for CVE-2024-5243

TP-LinkOmada Er605 Firmware7.5HIGH
Buffer Overflow Remote Code Execution Vulnerability Affects TP-Link...

A remote code execution vulnerability has been identified in the TP-Link Omada ER605 router due to a buffer overflow flaw in its DNS name handling. This weakness stems from inadequate validation of user-supplied data length before copying it to a buffer, enabling network-adjacent attackers to pot...

Discovered 23 hours ago

PoC for CVE-2025-2304

Owen2345Camaleon-cms9.4CRITICAL
Privilege Escalation Flaw in Camaleon CMS

A critical issue in Camaleon CMS's UsersController, specifically in the 'updated_ajax' method, enables privilege escalation due to the improper handling of parameters. The vulnerability arises from the use of the permit! method, which fails to filter input, allowing all parameters to be processed...

Discovered 1 day ago

PoC for CVE-2024-31317

GoogleAndroid7.8HIGH
Unpatched Deserialization Vulnerability in ZygoteProcess.java Could...

A vulnerability has been identified in the Android Framework that allows potential code execution through unsafe deserialization in multiple functions of ZygoteProcess.java. This flaw enables local privilege escalation, requiring user execution privileges but eliminating the need for user interac...

PoC for CVE-2025-68493

ApacheApache Struts8.1HIGH
Missing XML Validation Vulnerability in Apache Struts by Apache

A missing XML validation vulnerability exists in Apache Struts, affecting numerous versions. This flaw could be exploited to compromise the integrity of the applications relying on these frameworks. Users are urged to upgrade to version 6.1.1, which addresses the security concern and enhances ove...

PoC for CVE-2025-7771

TecHPowerupThrottlestop8.7HIGH
Privilege Escalation Vulnerability in ThrottleStop Driver by TechPo...

The ThrottleStop driver, a legitimate component from TechPowerUp, presents a vulnerability due to insecure IOCTL interfaces that permit arbitrary read and write access to the physical memory through the MmMapIoSpace function. This flaw can be exploited by malicious applications running in user mo...

Discovered 2 days ago

PoC for CVE-2026-1835

Lcg0124Bootdo5.3MEDIUM
Cross-Site Request Forgery in lcg0124 BootDo Affected by Security Flaw

A cross-site request forgery vulnerability exists in lcg0124 BootDo that allows an attacker to manipulate user requests without their knowledge. This vulnerability affects versions up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb and enables remote attackers to exploit the flaw, potentially comprom...

PoC for CVE-2024-46987

Owen2345Camaleon-cms7.7HIGH
Camaleon CMS Vulnerability in Download Private File Method

Camaleon CMS, a robust content management system built on Ruby on Rails, has a path traversal vulnerability in the MediaController's download_private_file method. This flaw permits authenticated users to potentially download any file stored on the web server, depending on file permissions configu...

PoC for CVE-2026-1813

Bolo-blogBolo-solo5.3MEDIUM
Remote File Upload Vulnerability in Bolo-Blog Bolo-Solo Product

A vulnerability exists in the Bolo-Solo application affecting versions up to 2.6.4. An issue within the FreeMarker Template Handler's PicUploadProcessor.java file allows remote attackers to upload arbitrary files. This flaw can be exploited without restriction, posing significant risks to the sys...

PoC for CVE-2026-1812

Bolo-blogBolo-solo5.3MEDIUM
Path Traversal Vulnerability in bolo-blog Bolo-Solo by Bolo-Blog

A vulnerability exists in the Bolo-Solo platform, specifically within the importFromCnblogs function of the BackupService.java file. This flaw allows for a path traversal attack, enabling unauthorized access to files on the server. An attacker can exploit this vulnerability remotely, manipulating...

PoC for CVE-2020-37087

Rubikon TeknolojiEasy Transfer5.1MEDIUM
Persistent Cross-Site Scripting Vulnerability in Easy Transfer by E...

The Easy Transfer application version 1.7 for iOS exhibits a persistent cross-site scripting vulnerability that enables remote attackers to inject harmful scripts. By manipulating the parameters such as oldPath, newPath, and path during Create Folder and Move/Edit operations, attackers can levera...

PoC for CVE-2020-37087

Rubikon TeknolojiEasy Transfer5.1MEDIUM
Persistent Cross-Site Scripting Vulnerability in Easy Transfer by E...

The Easy Transfer application version 1.7 for iOS exhibits a persistent cross-site scripting vulnerability that enables remote attackers to inject harmful scripts. By manipulating the parameters such as oldPath, newPath, and path during Create Folder and Move/Edit operations, attackers can levera...

PoC for CVE-2020-37097

Edimax Technology...Ew-7438rpn Mini8.7HIGH
Information Disclosure in Edimax EW-7438RPn WiFi Range Extender

The Edimax EW-7438RPn 1.13 contains a vulnerability that allows unauthorized access to sensitive WiFi network configuration details. Through the wlencrypt_wiz.asp file, attackers can exploit this issue to retrieve critical information, including the WiFi network name and plaintext passwords store...

PoC for CVE-2020-37096

Edimax Technology...Ew-7438rpn Mini5.1MEDIUM
Cross-Site Request Forgery in Edimax EW-7438RPn Wi-Fi Range Extender

The Edimax EW-7438RPn version 1.13 Wi-Fi range extender is susceptible to a cross-site request forgery vulnerability through its MAC filtering configuration interface. This weakness allows attackers to create malicious web pages designed to trick users into unintentionally adding unauthorized MAC...

PoC for CVE-2020-37094

EspocrmEspocrm8.7HIGH
Authentication Vulnerability in EspoCRM by EspoCRM

EspoCRM version 5.8.5 is susceptible to an authentication vulnerability that enables attackers to gain unauthorized access to other user accounts. By manipulating authorization headers, including Basic Authorization and Espo-Authorization tokens, an attacker can decode and alter these tokens, pot...

PoC for CVE-2020-37093

Netis Systems Co....Netis E1+8.7HIGH
Information Disclosure Vulnerability in Netis E1+ by Netis Systems

The Netis E1+ version 1.2.32533 is subject to an information disclosure vulnerability that permits unauthenticated attackers to extract WiFi credentials, including SSID and passwords, via a specific endpoint. By sending a crafted GET request to the netcore_get.cgi endpoint, attackers can gain una...

PoC for CVE-2020-37092

Netis Systems Co....Netis E1+9.3CRITICAL
Hardcoded Root Account Vulnerability in Netis E1+ by Netis Systems

The Netis E1+ version 1.2.32533 is vulnerable due to a hardcoded root account that exposes the device to unauthorized access. This flaw allows attackers to utilize a predefined username and password to gain full administrative privileges on the device. This poses significant risks, as intruders c...

PoC for CVE-2020-37091

Maian MediaMaian Support Helpdesk5.1MEDIUM
Cross-Site Request Forgery in Maian Support Helpdesk from Maian Sup...

Maian Support Helpdesk version 4.3 is vulnerable to cross-site request forgery, allowing attackers to create administrative accounts without authentication. By exploiting this vulnerability, attackers can craft malicious HTML forms that facilitate the addition of admin users and enable unrestrict...

PoC for CVE-2020-37089

AroxSchool Erp Pro7.1HIGH
SQL Injection Vulnerability in School ERP Pro by Arox

School ERP Pro version 1.0 exhibits a SQL injection weakness in the 'es_messagesid' parameter, which is vulnerable to manipulation through GET requests. This flaw allows attackers to inject malicious SQL statements that can lead to unauthorized access to sensitive data, alteration of database ent...

PoC for CVE-2020-37090

AroxSchool Erp Pro8.7HIGH
File Upload Vulnerability in School ERP Pro by Arox

School ERP Pro 1.0 contains a file upload vulnerability that permits unauthorized users to upload arbitrary PHP files through its messaging system. This exposure enables attackers to execute malicious PHP scripts on the server, potentially compromising the security of the entire application and i...

PoC for CVE-2020-37088

AroxSchool Erp Pro8.7HIGH
File Disclosure Vulnerability in School ERP Pro by Arox

School ERP Pro 1.0 has a file disclosure vulnerability that enables unauthorized users to read sensitive files by manipulating the 'document' parameter in download.php. This exploitation can lead to unauthorized access to critical system configuration files and sensitive credentials through direc...

PoC for CVE-2020-37085

SunnysidesoftVirtualtablet Server8.7HIGH
Denial of Service Vulnerability in VirtualTablet Server by Sunny Si...

VirtualTablet Server version 3.0.2 is susceptible to a denial of service vulnerability, which can be exploited by attackers sending oversized string payloads via the Thrift protocol. By invoking the send_say() method with a lengthy string, attackers may render the server unresponsive, disrupting ...

PoC for CVE-2020-37083

ChatelaoPHP Address Book8.8HIGH
SQL Injection Vulnerability in PHP AddressBook by SourceForge

PHP AddressBook version 9.0.0.1 is vulnerable to a time-based blind SQL injection. This vulnerability enables remote attackers to exploit the 'id' parameter, allowing them to craft SQL queries with time delays. By analyzing the response times from the application, attackers can gain unauthorized ...

PoC for CVE-2020-37082

WeberpWeberp8.6HIGH
Unauthenticated File Access in webERP Product by webERP Vendor

webERP version 4.15.1 contains a vulnerability that permits unauthorized access to sensitive database backup files. Remote attackers can exploit this issue by directly requesting backup files located in the companies/weberp/ directory, compromising the confidentiality of the stored data. The vuln...

PoC for CVE-2020-37081

Fishing Reservati...Fishing Reservation Sy...7.1HIGH
Remote SQL Injection Vulnerability in Fishing Reservation System by...

The Fishing Reservation System 7.5 is susceptible to multiple remote SQL injection vulnerabilities prevalent in files such as admin.php, cart.php, and calendar.php. Attackers can exploit vulnerable parameters like uid, pid, type, m, y, and code to execute arbitrary SQL commands, potentially leadi...

PoC for CVE-2020-37081

Fishing Reservati...Fishing Reservation Sy...7.1HIGH
Remote SQL Injection Vulnerability in Fishing Reservation System by...

The Fishing Reservation System 7.5 is susceptible to multiple remote SQL injection vulnerabilities prevalent in files such as admin.php, cart.php, and calendar.php. Attackers can exploit vulnerable parameters like uid, pid, type, m, y, and code to execute arbitrary SQL commands, potentially leadi...

PoC for CVE-2020-37080

LuiswangWebtareas7.2HIGH
Arbitrary File Deletion Vulnerability in webTareas by webTareas Pro...

The webTareas 2.0.p8 application contains a vulnerability in the print_layout.php administration component that allows unauthorized users to delete arbitrary files from the server. This vulnerability is exploited through manipulating the 'atttmp1' parameter, enabling attackers to specify which fi...

PoC for CVE-2020-37077

Twinkle Toes Soft...Booked Scheduler6.9MEDIUM
Directory Traversal Vulnerability in Booked Scheduler by Booked Sch...

The version 2.7.7 of Booked Scheduler is susceptible to a directory traversal vulnerability in the manage_email_templates.php script. This flaw permits authenticated administrators to access files that they should not normally be able to read, exposing sensitive data. Attackers can exploit the vu...

PoC for CVE-2020-37078

I-doit GmbhI-doit Open Source Cmdb7.2HIGH
File Deletion Vulnerability in i-doit Open Source CMDB by i-doit

The i-doit Open Source CMDB version 1.14.1 is susceptible to a file deletion vulnerability within its import module. This security flaw permits authenticated attackers to exploit the 'delete_import' parameter, allowing them to send crafted POST requests to remove files from the server's filesyste...

PoC for CVE-2020-37076

VictoralagwuCmssite8.8HIGH
SQL Injection Vulnerability in Victor CMS by Victor Alagwu

Victor CMS version 1.0 is susceptible to a SQL injection vulnerability that occurs in the 'post' parameter on post.php. This flaw enables remote attackers to craft and send malicious UNION SELECT payloads, thereby compromising the integrity of database queries. Exploitation of this vulnerability ...

PoC for CVE-2020-37075

LizardsystemsLansend8.4HIGH
Buffer Overflow Vulnerability in LanSend 3.2 by LanSend

The LanSend 3.2 application contains a buffer overflow vulnerability in its Add Computers Wizard file import functionality. This vulnerability allows remote attackers to craft malicious payload files that, when imported, can trigger a structured exception handler (SEH) overwrite, enabling the exe...

PoC for CVE-2020-37073

VictoralagwuCmssite8.6HIGH
Authenticated File Upload Vulnerability in Victor CMS by Victor Alagwu

Victor CMS 1.0 contains a vulnerability that enables authenticated users, specifically administrators, to upload PHP files with arbitrary content via the user_image parameter. This flaw allows attackers to upload a malicious PHP shell to the /img/ directory. Once an attacker has successfully uplo...

PoC for CVE-2020-37074

LizardsystemsRemote Desktop Audit8.4HIGH
Buffer Overflow Vulnerability in Remote Desktop Audit by Lizard Sys...

The Remote Desktop Audit version 2.3.0.157 is susceptible to a buffer overflow vulnerability during the Add Computers Wizard file import. By exploiting this flaw, an attacker can craft a specialized payload that triggers a structured exception handler (SEH) bypass. This manipulation allows arbitr...

PoC for CVE-2020-37071

CraftcmsCraftcms9.3CRITICAL
Deserialization Vulnerability in CraftCMS vCard Plugin from CraftCMS

The CraftCMS vCard Plugin version 1.0.0 has a deserialization vulnerability that may allow unauthenticated attackers to execute arbitrary PHP code. This exploit is possible through a specially crafted payload that targets the plugin's vCard download functionality, enabling remote code execution. ...

PoC for CVE-2020-37071

CraftcmsCraftcms9.3CRITICAL
Deserialization Vulnerability in CraftCMS vCard Plugin from CraftCMS

The CraftCMS vCard Plugin version 1.0.0 has a deserialization vulnerability that may allow unauthenticated attackers to execute arbitrary PHP code. This exploit is possible through a specially crafted payload that targets the plugin's vCard download functionality, enabling remote code execution. ...