Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 1 hour ago

PoC for CVE-2026-18963

Red HatRed Hat Build Of Keycl...9.1CRITICAL
Authorization Flaw in Keycloak Services by Red Hat

A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...

Discovered 2 hours ago

PoC for CVE-2026-82669

KlaussilveiraGitlist6.9MEDIUM
Denial of Service Vulnerability in GitList by klaussilveira

A vulnerability has been identified in GitList 2.0.0, specifically within the XML Parsing component. The issue lies in the SimpleXMLElement function within the src/SCM/System/Git/CommandLine.php file. An attacker can manipulate this function, leading to a denial of service scenario. This vulnerab...

PoC for CVE-2026-82668

KlaussilveiraGitlist6.9MEDIUM
OS Command Injection Vulnerability in GitList by klaussilveira

A vulnerability exists in GitList version 2.0.0 that allows for OS command injection through the 'getDefaultBranch' function found in the Git Command Line component. This issue can be exploited remotely, potentially leading to unauthorized system commands being executed. Users are strongly advise...

Discovered 3 hours ago

PoC for CVE-2026-82667

YaojingangGeoflow5.1MEDIUM
Server-Side Request Forgery Vulnerability in yaojingang GEOFlow

A vulnerability has been identified in yaojingang GEOFlow prior to version 2.1.1, located in the DistributionController.isValidHttpEndpoint function. This flaw can be exploited through manipulated input for the endpoint_url argument, potentially leading to server-side request forgery (SSRF). The ...

Discovered 4 hours ago

PoC for CVE-2026-82631

Valkey-ioValkey2.1LOW
Use After Free Vulnerability in valkey-io's Valkey Product

A security flaw has been identified in the Valkey product by valkey-io, specifically within the Blocked-on-keys Subsystem. The vulnerability arises from the function handleClientsBlockedOnKey located in the file src/blocked.c, leading to a use after free condition. This flaw allows attackers to e...

PoC for CVE-2026-82630

Tech PowerJobPowerjob6.9MEDIUM
Server-Side Request Forgery in PowerJob Transport Endpoint by Tech ...

A security vulnerability has been detected in PowerJob, specifically within the Transport Endpoint component. The issue exists in the MuConnectionManager.getOrCreateConnection function of the TestController.java file. This flaw enables attackers to execute server-side request forgery (SSRF) attac...

PoC for CVE-2026-82629

JeecgbootJeewx-boot5.1MEDIUM
Unrestricted File Upload Vulnerability in Jeecgboot Jeewx-Boot

An unrestricted file upload vulnerability exists in the Jeecgboot Jeewx-Boot component, specifically within the doUpload function of the MyJwWebJwid3Controller.java file. This flaw allows remote attackers to manipulate file upload arguments, potentially leading to malicious file uploads on the se...

Discovered 5 hours ago

PoC for CVE-2026-82625

Code-projectsSimple Inventory System5.3MEDIUM
Cross-Site Scripting Vulnerability in Code-Projects Simple Inventor...

A cross-site scripting vulnerability has been identified in the Simple Inventory System 1.0 that affects the /register.php file associated with user registration. By manipulating the 'last_name' parameter, an attacker could execute arbitrary JavaScript in a victim's browser. This exploit can be e...

PoC for CVE-2026-82624

Code-projectsSimple Inventory System6.9MEDIUM
Information Disclosure Vulnerability in Simple Inventory System by ...

A vulnerability has been identified in the Simple Inventory System version 1.0 that affects the database backup functionalities through the file 'inventorymanagement.sql'. This flaw could potentially allow an attacker to access sensitive information remotely, putting the security of the system at...

PoC for CVE-2026-82623

open62541Open625416.9MEDIUM
Use After Free Vulnerability in open62541 History Backend

A vulnerability was identified in the open62541 library, specifically in the History Backend component. This issue arises from the UA_DataValue_backend_copyRange function located in the plugins/historydata/ua_history_data_backend_memory.c file. When exploited, it leads to a use after free conditi...

PoC for CVE-2026-77013

WordPress爱采集数据采集和发布插件
Unauthorized Access in Love Collection Data Collection and Publishi...

The Love Collection Data Collection and Publishing plugin for WordPress, version 1.0.0, has a security flaw that permits unauthenticated users to invoke handler methods without appropriate checks. This oversight allows attackers to create user accounts and taxonomy terms within WordPress, potenti...

PoC for CVE-2026-82622

Code-projectsEmployee Leave Managin...5.1MEDIUM
Cross Site Scripting Vulnerability in Employee Leave Managing Syste...

A security vulnerability has been identified in the Employee Leave Managing System, specifically within the Employee Profile Update function located in editaction.php. This flaw allows remote attackers to exploit the application by manipulating the 'Name' argument, resulting in cross site scripti...

Discovered 6 hours ago

PoC for CVE-2026-82621

SoarkeyStudentmanagement6.9MEDIUM
Authorization Bypass in Soarkey StudentManagement by Soarkey

A vulnerability has been discovered in Soarkey StudentManagement and 学生信息管理系统 that could allow an attacker to bypass authorization controls. This weakness is present in the AdminDao.doGet function within the Administrative Servlet component. By manipulating the action argument, remote exploitatio...

PoC for CVE-2026-60004

GiteaGitea🟣 EPSS 85%9.8CRITICAL
Remote Code Execution Vulnerability in Gitea by Gitea

A serious vulnerability exists in Gitea prior to version 1.27.1, allowing attackers to perform remote code execution via manipulation of the diffpatch API. Exploiting this vulnerability can enable unauthorized users to install malicious Git hooks. It is crucial for users of Gitea to update to ver...

PoC for CVE-2026-60004

GiteaGitea🟣 EPSS 85%9.8CRITICAL
Remote Code Execution Vulnerability in Gitea by Gitea

A serious vulnerability exists in Gitea prior to version 1.27.1, allowing attackers to perform remote code execution via manipulation of the diffpatch API. Exploiting this vulnerability can enable unauthorized users to install malicious Git hooks. It is crucial for users of Gitea to update to ver...

PoC for CVE-2026-82620

SoarkeyStudentmanagement5.3MEDIUM
SQL Injection Vulnerability in Soarkey StudentManagement and 学生信息管理系统

A security flaw has been identified in Soarkey StudentManagement and 学生信息管理系统, specifically affecting the function CourseDao.course_ranking located in code/src/dao/CourseDao.java. This vulnerability allows an attacker to manipulate the argument 'cno', thereby executing SQL injection attacks remot...

PoC for CVE-2026-82619

SysterelS2opc5.3MEDIUM
Use After Free Vulnerability in Systerel S2OPC Affected by Remote E...

A vulnerability exists in Systerel S2OPC prior to version 1.7.4, specifically in the function monitored_item_event_filter_treatment_bs__init_event_filter_ctx_and_result within the source file subscription_mgr.c. This issue arises from improper handling of the EventFilter argument, leading to a us...

Discovered 7 hours ago

PoC for CVE-2026-82616

TotolinkNr1800x9.4CRITICAL
Stack-Based Buffer Overflow Vulnerability in TOTOLINK NR1800X Router

A critical vulnerability has been identified in the TOTOLINK NR1800X router, specifically affecting the function setUploadSetting located in the file /cgi-bin/cstecgi.cgi. An exploitable stack-based buffer overflow occurs due to improper handling of the FileName argument, enabling an attacker to ...

PoC for CVE-2026-82615

ItsourcecodeOnline Medicine Delive...6.9MEDIUM
SQL Injection Flaw in itsourcecode Online Medicine Delivery System

A security flaw exists in the itsourcecode Online Medicine Delivery System version 1.0, specifically within the Password Recovery Interface. The issue arises in the function Customer::find_phone located in the /passwordrecover.php file. This vulnerability allows an attacker to manipulate the phon...

PoC for CVE-2026-82614

ItsourcecodeOnline Medicine Delive...6.9MEDIUM
SQL Injection Flaw in itsourcecode Online Medicine Delivery System

A SQL Injection vulnerability has been identified in the itsourcecode Online Medicine Delivery System, specifically within the Product Category Filter interface. This issue arises in the function loadResultList located in the /index.php?q=product file. An attacker can exploit this flaw by manipul...

PoC for CVE-2026-82613

ItsourcecodeOnline Medicine Delive...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Medicine Deliver...

The itsourcecode Online Medicine Delivery System 1.0 is impacted by a SQL injection vulnerability found in the Product Search Interface. Specifically, unauthorized manipulation of the search query parameter in the loadResultList function of the /index.php?q=product file allows attackers to execut...

Discovered 8 hours ago

PoC for CVE-2026-67363

Balbooa.comBalbooa Forms Extensio...7.7HIGH
Pre-auth Payment Amount Manipulation in Balbooa Forms by Joomla Ext...

The Balbooa Forms extension for Joomla is susceptible to a significant vulnerability where the stripeCharges and payAuthorize endpoints accept payment amounts from user-controlled parameters. This flaw allows unattended attackers to manipulate payment amounts, potentially allowing them to purchas...

PoC for CVE-2026-82612

ItsourcecodeOnline Medicine Delive...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Medicine Deliver...

A vulnerability exists in the itsourcecode Online Medicine Delivery System 1.0, specifically in the loadResultList function of the Product Detail Page located at /index.php?q=single-item. An attacker can manipulate the ID argument, leading to remote SQL injection. This manipulation allows unautho...

PoC for CVE-2026-82611

ItsourcecodeOnline Medicine Delive...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Medicine Deliver...

A vulnerability has been discovered in itsourcecode's Online Medicine Delivery System version 1.0. This weakness is located in the Customer Login Interface, specifically within the cusAuthentication function in the login.php file. The vulnerability allows for SQL injection through improper handli...

PoC for CVE-2026-82610

ItsourcecodeOnline Medicine Delive...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Online Medicine Deliver...

A security flaw has been identified in itsourcecode's Online Medicine Delivery System version 1.0. The issue resides in the employee authentication function within the login interface, specifically in the employee::employeeAuthentication method in the /rider/login.php file. This vulnerability all...

PoC for CVE-2026-82609

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0. This vulnerability affects the function located in the file /pages/inv_edit.php, specifically due to improper handling of the argument ID. Attackers can exploit this vulnerability remotel...

Discovered 9 hours ago

PoC for CVE-2026-82608

Kamailio SolutionsKamailio5.3MEDIUM
Out-of-Bounds Read Vulnerability in Kamailio by Kamailio Solutions

A vulnerability affecting Kamailio versions up to 5.5.0 and 6.0.7 has been reported where an out-of-bounds read can occur due to improper handling in the get_4bytes function of the AVP Handler component. This vulnerability allows attackers to exploit the flaw remotely, potentially leading to unau...

PoC for CVE-2026-82607

WordPressProfile Builder Plugin6.9MEDIUM
Unrestricted File Upload Vulnerability in Cozmoslabs Profile Builde...

A vulnerability exists in the Cozmoslabs Profile Builder Plugin up to version 3.16.1 that allows for unrestricted file uploads through the function wppb_ajax_simple_avatar in the admin-ajax.php file. This flaw can be exploited remotely, enabling attackers to upload malicious files without proper ...

Discovered 10 hours ago

PoC for CVE-2026-82603

SeaCMSSeacms5.3MEDIUM
Path Traversal Vulnerability in SeaCMS Affects Comment Cache Proces...

A path traversal vulnerability has been identified in SeaCMS versions up to 13.6, specifically within the member.php file when handling the del_pl action. This vulnerability allows attackers to manipulate the itype/vid argument, potentially enabling unauthorized access to sensitive files on the s...

PoC for CVE-2026-82602

SeaCMSSeacms6.9MEDIUM
Authorization Bypass in SeaCMS Affected by Vulnerability

A security vulnerability has been identified in SeaCMS versions up to 13.6, specifically in the unknown code located in the file /ass.php. This vulnerability allows attackers to bypass authorization controls, potentially giving them unauthorized access to certain functionalities. The flaw can be ...

PoC for CVE-2026-82601

SeaCMSSeacms5.3MEDIUM
Cross Site Scripting Vulnerability in SeaCMS by SeaCMS

A vulnerability has been discovered in SeaCMS versions up to 13.6 that may permit remote attackers to execute cross site scripting (XSS) attacks. The issue resides in the handling of specific input within the '/err.php' file, where manipulation of the 'errtxt' argument can lead to the execution o...

PoC for CVE-2026-82600

SeaCMSSeacms6.9MEDIUM
SQL Injection Vulnerability in SeaCMS Affects Remote Operations

A vulnerability exists in SeaCMS up to version 13.6, allowing for SQL injection through manipulated parameters in the /zyapi.php?ac=videolist endpoint. This exploit can be executed remotely, posing significant risks to data integrity and application security. Attackers can leverage this flaw to e...

Discovered 11 hours ago

PoC for CVE-2026-82599

SeaCMSSeacms5.3MEDIUM
Path Traversal Vulnerability in SeaCMS Avatar Upload Affects File M...

A path traversal vulnerability has been identified in SeaCMS, specifically within the Avatar Upload feature of the /member.php?action=chgpwdsubmit component. By manipulating the oldpic parameter, an attacker can navigate the file system, potentially accessing sensitive files and executing unautho...

PoC for CVE-2026-48611

PHPbbPHPbb9.8CRITICAL
Improper Authentication in OAuth Implementation Affects phpBB Software

The OAuth implementation in phpBB has a critical flaw where improper authentication checks can lead to account hijacking. This vulnerability is particularly concerning as it may allow unauthorized users to gain access to accounts even if OAuth is not configured or enabled. Default installations a...

PoC for CVE-2026-82598

SeaCMSSeacms6.9MEDIUM
Code Injection Vulnerability in SeaCMS Template Engine

A vulnerability exists in SeaCMS, specifically affecting the Template Engine's search.php file within the parseIf function. This flaw allows an attacker to manipulate the searchtype argument, potentially leading to code injection. The exploit can be executed remotely, and its details have been pu...

PoC for CVE-2026-82597

TotolinkNr1800x5.3MEDIUM
Remote Command Injection in TOTOLINK NR1800X Device

A remote command injection vulnerability exists in the TOTOLINK NR1800X that affects the setUssd function within the cgi-bin/cstecgi.cgi file. By manipulating the ussd argument, an attacker can execute unauthorized commands on the device, potentially compromising network security. As the exploit ...

Discovered 12 hours ago

PoC for CVE-2026-82595

D-linkDir-825m5.3MEDIUM
Command Injection in D-Link DIR-825M Router Firmware

A command injection vulnerability has been identified in the D-Link DIR-825M router firmware version 1.1.8. This flaw lies within the system command execution function, specifically in '/boafrm/formSysCmd', where improper validation of the 'sysCmd' argument allows attackers to inject malicious co...

PoC for CVE-2026-82594

LognetGrpc-spring-boot-starter2.3LOW
Improper Authorization in LogNet grpc-spring-boot-starter Affects M...

A vulnerability has been identified within the LogNet grpc-spring-boot-starter framework, specifically in its Annotation Processing functionality. This issue allows for improper authorization, potentially enabling malicious actors to exploit the system via remote execution. The complexity of the ...

PoC for CVE-2026-82593

D-linkDir-825m9.4CRITICAL
Buffer Overflow Vulnerability in D-Link DIR-825M LTE Module Firmware

A vulnerability has been identified in the D-Link DIR-825M router, specifically within the LTE Module Firmware Upgrade functionality. The issue lies in the manipulation of the fota_url parameter in the formLtefotaUpgradeFibocom, which can lead to a stack-based buffer overflow. This flaw allows fo...

PoC for CVE-2026-82592

D-linkDir-825m9.4CRITICAL
Stack-Based Buffer Overflow in D-Link DIR-825M Disk Formatting Handler

A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-825M router within the Disk Formatting Handler Endpoint. This issue arises from improper handling of the 'partition' argument, allowing for remote exploitation. Attackers can leverage this vulnerability to execute a...

Discovered 13 hours ago

PoC for CVE-2026-82589

Open5GSOpen5gs5.3MEDIUM
Denial of Service Vulnerability in Open5GS N1-N2 Message Handler

A security vulnerability exists in Open5GS up to version 2.7.7, specifically in the N1-N2 Message Handler's function amf_namf_comm_handle_n1_n2_message_transfer. This flaw can be exploited remotely by manipulating the N1N2MessageTransferReqData.n2InfoContainer.smInfo.n2InfoContent.ngapIeType argu...

Discovered 14 hours ago

PoC for CVE-2026-76581

WordPressWPmu Dev Dashboard9.8CRITICAL
Authentication Bypass Vulnerability in WPMU DEV Dashboard for WordP...

The WPMU DEV Dashboard plugin for WordPress is prone to an authentication bypass vulnerability due to inconsistent handling of HMAC message construction between the `wdpsso_step1` and `wdpsso_step2` AJAX actions. The first step improperly exposes a concatenation of sensitive tokens, while the sec...

PoC for CVE-2018-7600

DrupalDrupal Before 7.58, 8....🟣 EPSS 100%9.8CRITICAL
Remote Code Execution Vulnerability in Drupal by Acquia

Multiple versions of Drupal, including those prior to 7.58 and various 8.x releases, are susceptible to a vulnerability that permits remote attackers to execute arbitrary code. This exploit takes advantage of configuration flaws in several subsystems, particularly those using default or common mo...

PoC for CVE-2014-6271

GnuBash🟣 EPSS 100%9.8CRITICAL
Code Injection Vulnerability in GNU Bash by The GNU Project

GNU Bash versions up to 4.3 are vulnerable to a code injection flaw due to the mishandling of trailing strings after function definitions in environment variables. This vulnerability enables remote attackers to execute arbitrary code by crafting specific environment variables under various condit...

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 100%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

Discovered 16 hours ago

PoC for CVE-2026-18741

FroidenWorksuite Saas4.6MEDIUM
Stored Cross-Site Scripting in Worksuite SaaS Asset Management Module

The Worksuite SaaS platform, in versions prior to 6.0.14, is affected by a stored cross-site scripting vulnerability within its Asset Management module. This allows authenticated administrators to submit malicious JavaScript payloads in the Location and Description fields when adding new assets. ...

PoC for CVE-2026-82587

Open5GSOpen5gs5.3MEDIUM
Memory Corruption Vulnerability in Open5GS AMF Component

A vulnerability has been identified in Open5GS versions up to 2.7.7, specifically within the AMF component. The issue arises from the amf_namf_comm_decode_ue_mm_context_list function, where improper handling of the ueContext.mmContextList[*].allowedNssai parameter may lead to memory corruption, a...

Discovered 18 hours ago

PoC for CVE-2026-82556

ForgejoForgejo5.3MEDIUM
Server-Side Request Forgery Vulnerability in Forgejo Repository Mig...

A vulnerability exists in the Repository Migration Handler of Forgejo, specifically in the function net.LookupIP located in the file services/migrations/allowlist/is_migrate_allowed.go. This issue can be exploited remotely, allowing attackers to perform server-side request forgery. The public dis...

PoC for CVE-2026-82555

TotolinkN600r6.3MEDIUM
Authentication Vulnerability in TOTOLINK N600R Router

A significant vulnerability exists within the TOTOLINK N600R Router, specifically in the loginAuth function of the Authentication Handler component. This flaw arises from the use of insufficiently random values, making the system susceptible to remote exploitation. Attackers could leverage this v...