Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-60206
A vulnerability in Oracle WebLogic Server's Core component permits low-privileged attackers with network access to exploit SAML, potentially compromising the server's functionality. This can lead to unauthorized access, impacting not only the WebLogic Server but also additional interconnected pro...
Discovered 3 hours ago
PoC for CVE-2026-12877
The Project Management, Bug and Issue Tracking Plugin for WordPress, prior to version 5.1.0, is susceptible to SQL injection due to inadequate sanitization and escaping of user-supplied input in SQL queries. This vulnerability allows unauthenticated attackers to manipulate database queries, poten...
PoC for CVE-2026-14603
The WowOptin: Next-Gen Popup Maker plugin for WordPress, prior to version 1.4.38, is vulnerable due to insufficient authorization checks on a REST endpoint. This flaw allows unauthenticated users to disable all opt-in forms across the site and to inject new template-based opt-in entries into the ...
PoC for CVE-2026-12981
The CAFEHAUS API WordPress plugin prior to version 1.0.0 is vulnerable to an authentication bypass issue that permits attackers to reset user passwords without any form of authentication or authorization. This flaw enables attackers to gain unauthorized access to any user's account, including tho...
PoC for CVE-2026-12690
The ProfileGrid plugin for WordPress contains a vulnerability related to its license management functionality. This flaw arises from the absence of a proper capability check, as it solely relies on a nonce that is accessible to any logged-in user. Consequently, this allows authenticated users wit...
PoC for CVE-2026-12688
The ProfileGrid WordPress plugin prior to version 5.9.9.7 is susceptible to an improper input validation vulnerability. This flaw allows unauthenticated attackers to exploit the plugin's handling of PayPal Instant Payment Notification (IPN) messages. By forging a valid PayPal notification, an att...
PoC for CVE-2026-12689
The ProfileGrid WordPress plugin prior to version 5.9.9.7 contains a significant authorization flaw that enables authenticated users with Subscriber-level access and higher to interact maliciously with others' private-message threads. This includes the ability to soft-delete threads, alter metada...
PoC for CVE-2026-12497
The Paid Membership Plugin for WordPress prior to version 4.16.18 fails to consistently enforce role restrictions in its front-end registration process. This vulnerability arises because the role options presented to users and the roles accepted by the registration handler are evaluated by differ...
Discovered 4 hours ago
PoC for CVE-2011-2523
A serious backdoor vulnerability was discovered in vsftpd 2.3.4, affecting downloads made between June 30 and July 3, 2011. This vulnerability allows an attacker to exploit the software and open a remote shell on port 6200/tcp, granting unauthorized access to the system. It poses significant risk...
Discovered 5 hours ago
PoC for CVE-2026-54121
A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...
PoC for CVE-2026-59880
Immutable.js exhibits a vulnerability in its data structures, specifically in Immutable.Map and Immutable.Set. Prior to versions 4.3.9 and 5.1.8, these structures use a linear search method in a HashCollisionNode bucket containing keys with the same 32-bit hash. An attacker controlling the input ...
Discovered 6 hours ago
PoC for CVE-2026-58057
Flowise versions prior to 3.1.3 suffer from a vulnerability due to improper validation of Custom MCP standard input/output environment variables against a denylist. The case-sensitive nature of the comparison allows an authenticated user to exploit this flaw on Windows systems where environment v...
PoC for CVE-2020-1472
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a...
Discovered 11 hours ago
PoC for CVE-2026-16767
A vulnerability has been identified in Ne-Lexa's php-zip library versions up to 4.0.2. It occurs within the ZipFile::extractTo function located in src/ZipFile.php, where inadequate validation of the entryName argument allows for malicious path traversal attacks. This vulnerability can be exploite...
PoC for CVE-2026-16765
A SQL injection vulnerability has been identified within the CodeAstro Online Classroom application at the '/OnlineClassroom/loginlinkadmin.php' endpoint. By manipulating the 'aid' parameter, an attacker may execute arbitrary SQL commands, potentially leading to unauthorized access to the databas...
PoC for CVE-2026-65694
Microweber CMS, up to version 2.0.20, has a significant path traversal flaw in its static file controller. This vulnerability allows remote, unauthenticated attackers to exploit the failure of the normalize_path() function. By supplying specially crafted directory traversal sequences in the path ...
Discovered 12 hours ago
PoC for CVE-2026-16763
A vulnerability exists in Localstack Serverless-Localstack versions up to 1.4.0, specifically within the Configuration Handler's index.js file. This security flaw allows an attacker to manipulate the 'custom.localstack.docker.compose_file' argument, potentially leading to OS command injection. Al...
Discovered 14 hours ago
PoC for CVE-2026-42533
A vulnerability in NGINX Plus and NGINX Open Source arises when a map directive improperly utilizes regex matching in conjunction with string expressions referencing the map’s regex capture variables before the map output variable, or when non-cacheable variables are used under specific condition...
PoC for CVE-2021-41773
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default config...
Discovered 15 hours ago
PoC for CVE-2026-65010
Hugging Face Datasets prior to version 5.00 is susceptible to a symlink-following vulnerability. This issue arises within the Extractor.extract() function, whereby local attackers can exploit predictable output paths to pre-plant symbolic links. As a result, these attackers can redirect the extra...
PoC for CVE-2026-63765
Chatwoot, prior to version 4.16.0, is susceptible to an authentication bypass in the direct uploads controller. This flaw allows attackers without authorization to create arbitrary ActiveStorage blobs within any tenant account. By exploiting the absence of proper authentication checks, attackers ...
PoC for CVE-2026-65920
The Diffusers library by Hugging Face encountered a path traversal issue in the _get_checkpoint_shard_files function, allowing attackers to exploit the vulnerability by providing malicious weight_map values in model index JSON. This flaw enables them to utilize ../ sequences or absolute paths, th...
PoC for CVE-2026-65918
The torchvision component of PyTorch is vulnerable to an out-of-bounds heap read in the GIF decoder's read_from_tensor callback. The issue arises when the decoder processes malicious or corrupted GIF files, potentially leading to a denial of service through segmentation faults or the exposure of ...
Discovered 16 hours ago
PoC for CVE-2026-65702
The Vanna application prior to version 2.0.2 has a path traversal flaw within its FileSystemConversationStore persistence integration. This vulnerability permits unauthenticated remote attackers to exploit the conversation_id parameter in the chat API. By injecting path traversal sequences, attac...
PoC for CVE-2026-65701
The SoftVC VITS Singing Voice Conversion product contains a path traversal vulnerability within its full-song inference server. This flaw allows unauthenticated remote attackers to exploit the system by supplying malicious filesystem paths through the 'audio_path' field in an unauthenticated POST...
PoC for CVE-2026-65700
The h2oGPT application, up to version 0.2.1, contains a vulnerability allowing unauthenticated attackers to exploit the OpenAI-compatible files API. By leveraging traversal sequences within the bearer token, attackers can bypass authentication mechanisms, leading to unauthorized file reading, wri...
PoC for CVE-2026-65699
AgentGPT version 1.0.0 has a critical flaw that permits authenticated users to bypass authorization checks by manipulating request parameters. This vulnerability allows users to attach tasks to agent runs belonging to other users without verifying ownership, posing a significant risk of task hist...
PoC for CVE-2026-65698
Void versions up to 1.3.4 exhibit a path traversal vulnerability in their AI agent file-reading tools, which can be exploited by network-adjacent attackers. This flaw enables unauthorized access to arbitrary host files outside the designated workspace by injecting instructions into the content be...
PoC for CVE-2026-65697
Fathom Lite versions up to 1.3.1 are vulnerable to a stored cross-site scripting (XSS) issue that affects the analytics collection functionality. This vulnerability allows unauthenticated attackers to inject malicious JavaScript code via crafted hostname and pathname inputs directed to the /colle...
PoC for CVE-2026-65696
Overseerr version 1.35.0 contains a significant vulnerability within its push subscription API that allows authenticated users to bypass authorization controls. By manipulating the userId in the API path, attackers can illicitly list, view, and delete push subscriptions belonging to other users. ...
PoC for CVE-2026-65695
The Office-Word-MCP-Server, up to version 1.1.11, has a path traversal vulnerability in its document handling tools. This flaw allows unauthenticated attackers to manipulate the filename argument to read or overwrite .docx files beyond the designated working directory. The vulnerability arises fr...
Discovered 17 hours ago
PoC for CVE-2026-65917
CyberPanel, up to version 1.9.1, is susceptible to an insecure direct object reference (IDOR) vulnerability in its IncBackups application. Authenticated users can exploit this flaw to access or manipulate the backup resources of other tenants using a globally sequential IncJob ID that is not rest...
PoC for CVE-2026-65916
CyberPanel versions up to 1.9.1 are susceptible to a missing authorization vulnerability in the cancelBackupCreation handler. This flaw permits authenticated users to manipulate backup processes of other tenants, including terminating backups, deleting archives, and corrupting status files. By cr...
Discovered 19 hours ago
PoC for CVE-2026-16735
A security vulnerability exists in the release-it conventional-changelog component, specifically within the writeChangelog function found in index.js. By manipulating the infile argument, an attacker could execute OS commands, leading to potential exploitation. This vulnerability requires local a...
PoC for CVE-2024-37054
A significant security vulnerability exists within the MLflow platform developed by Databricks. This issue arises from the deserialization of untrusted data in versions 0.9.0 and later. Attackers exploit this vulnerability by uploading a malicious PyFunc model that, once interacted with, can exec...
PoC for CVE-2026-16733
A vulnerability exists in the bahmutov find-cypress-specs package, specifically in the shell.exec function located in src/index.js of the Branch Handler component. By manipulating the --branch argument, an attacker can execute arbitrary operating system commands. This vulnerability is limited to ...
Discovered 1 day ago
PoC for CVE-2026-46331
An issue exists in the Linux Kernel where improper handling of copy-on-write (COW) operations can lead to page cache corruption. This is due to the tcf_pedit_act() function, which computes the COW range without considering runtime header offsets added by typed keys. As a result, portions of the w...
PoC for CVE-2026-9066
The WP Compress plugin for WordPress prior to version 7.10.04 is susceptible to a Reflected XSS vulnerability due to improper validation of a query parameter that directs the asset CDN host. This security flaw allows attackers to manipulate script URLs, injecting malicious JavaScript that execute...
PoC for CVE-2026-9577
The Post Status Notifier Lite WordPress plugin prior to version 1.13.0 is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability. This occurs due to insufficient sanitization of the `mod` URL parameter when reflected on the admin settings page. An attacker can exploit this vulnerabil...
PoC for CVE-2026-12082
The Praison AI SEO WordPress plugin versions prior to 5.0.7 contain an authorization bypass vulnerability that permits unauthorized users to modify permalinks for published posts. Additionally, this flaw enables access to sensitive configuration data within the plugin, which could compromise site...
PoC for CVE-2026-14291
The Security Ninja Premium WordPress plugin versions prior to 5.290 have a significant flaw in their two-factor authentication implementation. An unauthenticated attacker equipped with a user's password can bypass the required one-time code needed for authentication. This vulnerability compromise...
PoC for CVE-2023-36003
XAML Diagnostics Elevation of Privilege Vulnerability
PoC for CVE-2025-64512
Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...
PoC for CVE-2026-58138
An unauthenticated remote code execution vulnerability in Orkes Conductor versions prior to 3.30.2 could allow remote attackers to execute arbitrary operating system commands by submitting malicious JavaScript or Python expressions through workflow definitions to the workflow API endpoint without...
PoC for CVE-2026-6330
A vulnerability in the ML-KEM implementation for ARM64 architecture in wolfSSL is related to improper ciphertext comparison during the encryption process. Specifically, the comparison method only examines half of the re-encrypted ciphertext, which undermines the effective security measures mandat...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
PoC for CVE-2026-16653
A significant security flaw has been identified in the facil.io framework, specifically within the http_sendfile2 function located in the file lib/facil/http/http.c, which serves as a Public Folder Handler. This vulnerability allows for path traversal attacks, enabling unauthorized access to rest...
PoC for CVE-2024-9264
The experimental SQL Expressions feature in Grafana enables users to evaluate `duckdb` queries which can contain user input. However, the queries are inadequately sanitized prior to being processed by `duckdb`, creating a vulnerability that could lead to command injection and local file inclusion...
PoC for CVE-2026-16632
A vulnerability has been identified in the facil.io library, affecting versions up to 0.7.4. The flaw resides in the websocket_on_protocol_error function located in the websocket_parser.h file. This vulnerability arises from improper input validation when manipulating the argument on_message, all...
PoC for CVE-2026-16631
A vulnerability has been identified in the publint package manager affecting versions up to 0.1.4. This vulnerability is linked to the child_process.exec function within the src/node/pack.js file. It enables an attacker to execute arbitrary operating system commands through manipulated input. The...