Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2019-6250

ZeroMQLibzMQ🟣 EPSS 29%8.8HIGH
Pointer Overflow in ZeroMQ Library Leading to Code Execution

A pointer overflow vulnerability exists in the ZeroMQ library (libzmq) that can allow an authenticated attacker to execute arbitrary code. The flaw arises from an integer overflow in the v2_decoder.cpp component, specifically within the zmq::v2_decoder_t::size_ready function. This vulnerability e...

Discovered 2 hours ago

PoC for CVE-2020-11022

JqueryJquery6.9MEDIUM
Potential XSS vulnerability in jQuery

In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.

Discovered 4 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-7704

Av StumpflPixera Two Media Server5.3MEDIUM
Path Traversal Vulnerability in AV Stumpfl Pixera Two Media Server

A path traversal vulnerability has been identified in AV Stumpfl Pixera Two Media Server versions up to 25.1 R2. This vulnerability affects an undisclosed function in the Service Port 1338 component, allowing attackers to manipulate the system and potentially read arbitrary files. The exploit has...

PoC for CVE-2026-29000

Pac4jPac4j-jwt9.3CRITICAL
Authentication Bypass in JwtAuthenticator of pac4j-jwt by pac4j

The pac4j-jwt library's JwtAuthenticator prior to versions 4.5.9, 5.7.9, and 6.3.3 is susceptible to an authentication bypass that could allow remote adversaries to create forged authentication tokens. By leveraging the server's RSA public key, attackers are able to craft a JWE-wrapped PlainJWT w...

Discovered 5 hours ago

PoC for CVE-2026-7702

ToeverythingAffine6.9MEDIUM
Authorization Bypass Vulnerability in AFFiNE by toeverything

A vulnerability has been identified in toeverything AFFiNE versions up to 0.26.3, specifically within the 'allowDocPreview' function of the Public Markdown Preview Endpoint. This flaw enables an unauthorized actor to bypass authorization controls, potentially exposing sensitive documents to unaut...

PoC for CVE-2026-3494

Mariadb FoundationMariadb Server5.3MEDIUM
Vulnerability in MariaDB Server Affects Audit Logging Mechanisms

In versions of the MariaDB server up to 11.8.5, a significant issue arises when the server audit plugin is activated with specific filtering settings for DCL, DDL, or DML queries. Authenticated database users can execute SQL statements that bypass the intended audit logs by using comments prefixe...

Discovered 6 hours ago

PoC for CVE-2026-7700

Langflow-aiLangflow5.3MEDIUM
Code Injection Vulnerability in langflow-ai's Langflow Product

A security weakness has been identified in langflow-ai's Langflow product versions up to 1.8.4, specifically within the eval function in the LambdaFilterComponent. This vulnerability allows an attacker to execute malicious code by manipulating inputs, which can be done remotely. The potential for...

PoC for CVE-2026-7699

DromaraMaxkey5.3MEDIUM
SQL Injection Vulnerability in Dromara MaxKey Software

A notable security flaw has been detected in Dromara MaxKey versions up to 3.5.13, specifically within the StrUtils.checkSqlInjection function of StrUtils.java. This vulnerability allows attackers to execute SQL injection via manipulated arguments in the filtersfields parameter. The attack can be...

Discovered 7 hours ago

PoC for CVE-2026-7698

TiandyEasy7 Integrated Manag...6.9MEDIUM
OS Command Injection Vulnerability in Tiandy Easy7 Integrated Manag...

A critical vulnerability has been detected within the Tiandy Easy7 Integrated Management Platform version 7.17.0. This vulnerability arises from an inappropriate handling of the argument 'week' in the file /Easy7/rest/systemInfo/updateDbBackupInfo, which could potentially allow an attacker to exe...

PoC for CVE-2026-7697

AmttHotel Broadband Operat...5.1MEDIUM
SQL Injection Vulnerability in AMTT Hotel Broadband Operation Syste...

The AMTT Hotel Broadband Operation System version 1.0 contains a vulnerability located within the /manager/card/cardhand_submit.php file. This issue arises from improper handling of the ID argument, which can lead to SQL injection attacks. An attacker may exploit this vulnerability remotely to ex...

Discovered 8 hours ago

PoC for CVE-2026-7696

Acrel ElectricalEems Enterprise Power ...5.3MEDIUM
Unrestricted File Upload Vulnerability in Acrel Electrical EEMS Pla...

Acrel Electrical's EEMS Enterprise Power Operation and Maintenance Cloud Platform version 1.3.0 has a vulnerability that allows an unrestricted file upload through a specific function of the file /SubstationWEBV2/main/uploadH5Files. This weakness may facilitate remote attacks, enabling unauthoriz...

PoC for CVE-2026-7695

Acrel ElectricalEems Enterprise Power ...6.9MEDIUM
SQL Injection Vulnerability in Acrel Electrical EEMS Power Platform

A critical SQL injection vulnerability has been identified in the Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform version 1.3.0. This vulnerability arises from improper handling of the 'fCircuitids' argument in the file '/SubstationWEBV2/main/elecMaxMinAvgValue', a...

Discovered 9 hours ago

PoC for CVE-2026-7694

Acrel ElectricalEcems Enterprise Micro...6.9MEDIUM
SQL Injection Vulnerability in Acrel Electrical ECEMS Enterprise Mi...

A vulnerability exists in the Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System version 1.3.0, specifically within an unspecified function of the file '/SubstationWEBV2/main/elecMaxMinAvgValue'. This flaw allows attackers to manipulate the argument 'fCircuitids', pot...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-7692

WavlinkWl-wn570ha15.3MEDIUM
Command Injection Vulnerability in Wavlink WL-WN570HA1 Router

A command injection vulnerability exists in the Wavlink WL-WN570HA1 router, specifically within the ping_ddns function located in the /cgi-bin/adm.cgi file. An attacker can exploit this vulnerability by manipulating the DDNS argument, allowing remote code execution. The issue affects firmware ver...

Discovered 10 hours ago

PoC for CVE-2026-7691

WavlinkWl-wn570ha15.3MEDIUM
Command Injection Vulnerability in Wavlink Wireless Router

A security vulnerability has been identified in the Wavlink WL-WN570HA1 router, particularly in the function set_sys_cmd located in the /cgi-bin/adm.cgi file. This flaw allows attackers to manipulate command arguments for command injection, enabling remote exploits. The issue has been publicly di...

Discovered 11 hours ago

PoC for CVE-2026-7690

WavlinkWl-wn570ha15.3MEDIUM
Command Injection Vulnerability in Wavlink WL-WN570HA1 Router

A command injection vulnerability exists in the Wavlink WL-WN570HA1 router's set_sys_adm function within the /cgi-bin/adm.cgi file. This flaw arises from improper handling of the Username argument, making the device susceptible to remote attacks. The exploit has been publicly disclosed, and users...

PoC for CVE-2026-7689

DolibarrErp Crm6.3MEDIUM
Security Flaw in Dolibarr ERP CRM Affecting Online Signature Module

A significant security flaw has been identified in Dolibarr ERP CRM, specifically within the Online Signature Module. The issue resides in the function dol_verifyHash located in the library htdocs/core/lib/security.lib.php. This flaw leads to inadequate verification of cryptographic signatures, w...

Discovered 12 hours ago

PoC for CVE-2026-7687

Langflow-aiLangflow5.3MEDIUM
Command Injection Vulnerability in Langflow by Langflow-ai

A command injection vulnerability exists in the Langflow product by Langflow-ai, specifically within the CodeParser.parse_callable_details function in the code_parser.py file. This vulnerability affects versions up to 1.8.4, allowing remote attackers to execute arbitrary commands through crafted ...

Discovered 13 hours ago

PoC for CVE-2026-7686

EyeoAdblock Plus6.9MEDIUM
Improper Access Control in Eyeo Adblock Plus Chrome Extension

A vulnerability exists in the Eyeo Adblock Plus Chrome extension, specifically within the postMessage function of the premium.preload.js file related to the Legacy Premium Activation component. This flaw allows for improper access control, potentially enabling remote exploitation. Although the ex...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-7685

EdimaxBr-6208ac8.7HIGH
Buffer Overflow Vulnerability in Edimax BR-6208AC Router

A vulnerability exists in the Edimax BR-6208AC router affecting versions up to 1.02, specifically within the /goform/setWAN function. Manipulation of the pptpDfGateway argument can trigger a buffer overflow, which may be exploited remotely. This exploit is publicly known and poses a significant t...

Discovered 14 hours ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 28%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-7683

EdimaxBr-6428nc5.3MEDIUM
Command Injection Vulnerability in Edimax BR-6428nC Web Interface

A security weakness is present in the Edimax BR-6428nC, affecting the web interface component. This vulnerability arises due to improper handling of user input in the /goform/setWAN function, specifically with the parameters pppUserName and pptpUserName. An attacker can exploit this flaw remotely...

PoC for CVE-2026-7682

EdimaxBr-6208ac5.3MEDIUM
Command Injection Vulnerability in Edimax BR-6208AC Router

A security flaw exists in the Edimax BR-6208AC version 1.02, specifically within the setWAN function used in L2TP Mode. The vulnerability arises from improper handling of the L2TPUserName argument, allowing attackers to inject commands remotely. As this flaw can be exploited from outside the netw...

PoC for CVE-2026-5337

WordPressFrontend File Manager ...
Insecure Direct Object Reference Vulnerability in Frontend File Man...

Authenticated attackers with Subscriber-level access or higher can exploit an Insecure Direct Object Reference in the Frontend File Manager Plugin for WordPress. This vulnerability arises from inadequate user authorization validation for file download requests. By manipulating the 'file_id' param...

Discovered 16 hours ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 28%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-7679

YunaivYudao-cloud6.9MEDIUM
Improper Authentication Vulnerability in YunaiV yudao-cloud

A security flaw has been discovered in YunaiV's yudao-cloud that affects the getAccessToken function within the OAuth2TokenServiceImpl.java located at yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/service/impl. This vulnerability allows for improper authentication, which can...

PoC for CVE-2026-7678

YunaivYudao-cloud5.3MEDIUM
SQL Injection Vulnerability in YunaiV yudao-cloud

A SQL injection vulnerability exists in the YunaiV yudao-cloud product, particularly within the getDataBySQL function located in 'yudao-module-report-biz/src/main/java/io/github/ruoyi/report/service/impl/GoViewDataServiceImpl.java'. This vulnerability allows an attacker to manipulate SQL queries,...

Discovered 17 hours ago

PoC for CVE-2026-7677

KerwincuiFastbee5.1MEDIUM
Cross-Site Scripting Vulnerability in FastBee by kerwincui

A cross-site scripting (XSS) vulnerability exists in the FastBee application from kerwincui affecting versions up to 1.2.1. The issue is found in the System Notice Handler, specifically in the 'Add' function of SysNoticeController.java. An attacker can manipulate the 'noticeContent' argument, ena...

PoC for CVE-2026-7676

KerwincuiFastbee5.3MEDIUM
Path Traversal Vulnerability in kerwincui FastBee Tool Download End...

A path traversal vulnerability was identified in the Tool Download Endpoint of kerwincui's FastBee, affecting versions up to 1.2.1. This flaw arises from the improper handling of the 'fileName' argument in the ToolController.download function. Attackers can exploit this vulnerability remotely to ...

Discovered 18 hours ago

PoC for CVE-2026-7675

Shenzhen Libituo ...Lbt-t300-hw18.7HIGH
Buffer Overflow Vulnerability in Shenzhen Libituo Technology Product

A buffer overflow vulnerability has been identified in the Shenzhen Libituo Technology LBT-T300-HW1 router, specifically within the start_lan function of the /apply.cgi file. This issue arises when user-controlled input is mishandled, allowing remote attackers to manipulate the Channel/ApCliSsid ...

PoC for CVE-2024-53677

ApacheApache Struts🟣 EPSS 93%9.8CRITICAL
Flawed File Upload Logic in Apache Struts Exposes Vulnerability

A security flaw in the file upload mechanism of Apache Struts could allow an attacker to exploit file upload parameters. This vulnerability enables path traversal, leading to the possibility of uploading a malicious file that can facilitate remote code execution. To mitigate risks, users should u...

Discovered 19 hours ago

PoC for CVE-2026-7673

ZBJKCrmeb Java5.1MEDIUM
Unrestricted File Upload Vulnerability in crmeb_java by ZBJK

A vulnerability in the crmeb_java product version up to 1.3.4 has been identified that allows for unrestricted file uploads through the Admin Upload component. Specifically, the issue resides in the UploadServiceImpl.java file, where manipulation of the model argument can lead to unauthorized fil...

Discovered 20 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-7671

CodewiseTornet Scooter Mobile App6.3MEDIUM
Improper Authentication in CodeWise Tornet Scooter Mobile App for i...

The CodeWise Tornet Scooter Mobile App version 4.75 for both iOS and Android is exposed to a vulnerability that allows for improper restriction of excessive authentication attempts through an undisclosed function in the file /TwoFactor. This flaw enables attackers to potentially exploit the syste...

Discovered 21 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-7671

CodewiseTornet Scooter Mobile App6.3MEDIUM
Improper Authentication in CodeWise Tornet Scooter Mobile App for i...

The CodeWise Tornet Scooter Mobile App version 4.75 for both iOS and Android is exposed to a vulnerability that allows for improper restriction of excessive authentication attempts through an undisclosed function in the file /TwoFactor. This flaw enables attackers to potentially exploit the syste...

Discovered 22 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-7670

JinherOa6.9MEDIUM
SQL Injection Vulnerability in Jinher OA by Jinher Technology

A vulnerability exists in Jinher OA version 1.0, specifically within the file /C6/JHSoft.Web.PlanSummarize/UserSel.aspx. This flaw allows attackers to manipulate the DeptIDList argument, enabling SQL injection attacks that can be executed remotely. The exploit has been documented and potentially ...

PoC for CVE-2026-42167

ProftpdProftpd8.1HIGH
Remote Code Execution Vulnerability in ProFTPD's mod_sql

The mod_sql module in ProFTPD prior to version 1.3.10rc1 contains a critical vulnerability that allows remote attackers to execute arbitrary code by sending specially crafted username requests. This occurs in scenarios where USER request logging is enabled with an expansion format like %U, combin...

Discovered 1 day ago

PoC for CVE-2026-7668

MikrotikRouteros6.9MEDIUM
Out-of-Bounds Read Vulnerability in MikroTik RouterOS

An out-of-bounds read vulnerability has been identified in MikroTik RouterOS version 6.49.8, specifically within the ASN1_STRING_data function found in the library nova/lib/www/scep.p, which is part of the SCEP Endpoint component. This flaw arises from improper handling of the transactionID and m...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 28%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-42779

ApacheApache Mina9.8CRITICAL
Arbitrary Code Execution Vulnerability in Apache MINA by Apache

A vulnerability exists in Apache MINA's AbstractIoBuffer.resolveClass() method, where the check for allowed class names has not been properly enforced in specific version branches. This oversight permits arbitrary code execution when certain applications call IoBuffer.getObject(), making it criti...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...