Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 4 hours ago
PoC for CVE-2026-86217
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit...
Discovered 5 hours ago
PoC for CVE-2026-86216
A cross-site scripting vulnerability has been identified in the Hotel and Tourism Reservation system (PHP version 1.0) by Code-Projects. This security flaw exists within the /ht/details.php file, where improper handling of the 'room' parameter allows attackers to inject malicious scripts. The exp...
PoC for CVE-2026-86215
A flaw has been detected in the Logout Handler component of the Mstfakts College-Management-System, specifically within the function located in the server.php file. This vulnerability allows an attacker to manipulate the 'log_out' argument, resulting in premature session expiration. The attack ca...
PoC for CVE-2026-86214
A vulnerability exists in the Mstfakts College-Management-System, particularly within the login.php file, where the manipulation of the email argument can lead to improper authentication. This issue allows attackers to perform remote exploitation, potentially compromising user accounts. While the...
Discovered 6 hours ago
PoC for CVE-2026-86213
A SQL injection vulnerability exists in the Mstfakts College-Management-System, specifically in the Search Handler component found in the Front-end/university.php file. An attacker can exploit this vulnerability through the manipulated input parameters 'book_name' and 'book_author', allowing unau...
Discovered 7 hours ago
PoC for CVE-2026-86212
A vulnerability has been identified in Open5GS versions 2.7.7 and 2.8.0 that affects the AMF/MME component. This weakness allows for improper authorization, which can be exploited remotely by attackers. As a result, unauthorized actions may be executed, posing significant risks to application int...
Discovered 8 hours ago
PoC for CVE-2026-86211
A vulnerability exists in the login functionality of the rabindralamsal inventory-management-system version 1.0.0, specifically within the index.php file. This flaw allows for remote exploitation through SQL injection, where improper handling of the username and password inputs can enable attacke...
Discovered 9 hours ago
PoC for CVE-2026-86210
A vulnerability has been found in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the file /delete_user_account.php. This vulnerability allows for remote SQL injection through the manipulation of the argument ID. Attackers can leverage this exploit to execute...
PoC for CVE-2026-80437
The Ninja Forms plugin for WordPress, specifically versions prior to 3.15.2, contains a vulnerability where it fails to prevent shortcodes in request-derived values from executing. This flaw allows unauthenticated users to run any shortcode available on the site, potentially leading to unauthoriz...
PoC for CVE-2026-80439
The Contact Form 7 plugin for WordPress prior to version 3.2.11 is prone to a vulnerability that allows unauthenticated users to exploit form submissions. By injecting shortcodes into form fields, these users can execute any registered shortcode on the site, gaining access to its output. This cou...
PoC for CVE-2026-19859
The JetFormBuilder plugin for WordPress versions prior to 3.6.5.2 is susceptible to an arbitrary code execution vulnerability. This issue stems from the failure to properly sanitize a request parameter before it is utilized in rendering message content. Consequently, unauthenticated users may exp...
PoC for CVE-2026-19862
The JetFormBuilder plugin for WordPress, prior to version 3.6.5.2, contains a vulnerability allowing unauthenticated users to manipulate email headers through unvalidated address values sourced from form submissions. This flaw permits the injection of arbitrary email headers, facilitating hidden ...
PoC for CVE-2026-86209
A vulnerability has been detected in the SourceCodester Class and Exam Timetabling System 1.0. This issue involves an inadequately protected function within the /delete_user.php file, which can be exploited through remote SQL injection via manipulated argument IDs. Attackers can potentially execu...
PoC for CVE-2026-86208
A security vulnerability has been identified in the Class and Exam Timetabling System version 1.0 that allows remote attackers to manipulate the ID parameter within the /delete_teacher.php file, leading to SQL injection. This flaw can let unauthorized users execute arbitrary SQL commands, potenti...
PoC for CVE-2026-86183
A vulnerability exists in the Diem Project's dmWidget component, specifically within the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php. This flaw enables unauthorized users to bypass security measures by manipulating the 'widget_id' argument. As a result, remote attackers ...
Discovered 10 hours ago
PoC for CVE-2026-86182
A vulnerability has been identified in the dmConsole component of diem-project, specifically in the executeCommand function of actions.class.php. This issue allows an attacker to manipulate the dm_command argument, potentially leading to cross-site request forgery (CSRF). Given that the attack ca...
PoC for CVE-2026-27876
This vulnerability arises from a feature in Grafana that allows users to execute arbitrary SQL Expressions through a Grafana Enterprise plugin. If the sqlExpressions feature toggle is enabled, an attacker could exploit this to carry out remote arbitrary code execution. Users are strongly advised ...
PoC for CVE-2026-86181
A vulnerability in the User Profile Update component of the Code-Projects Task Management System 1.0 allows for cross site scripting (XSS) attacks through improper handling of the 'lname' parameter in the /user/UpdateUserProfile.php file. This weakness can be exploited remotely, potentially allow...
PoC for CVE-2026-86180
A vulnerability has been identified in the Task Management System in PHP version 1.0, specifically in the login component located at /index.php. This flaw allows remote attackers to exploit the email parameter, leading to SQL injection. Successful exploitation can compromise the integrity of the ...
Discovered 11 hours ago
PoC for CVE-2026-73570
A remote code execution vulnerability affects Zimbra Collaboration Suite prior to version 10.1.20 when the zimbra-snmp package is active with SNMP notifications enabled. The vulnerability arises from improper sanitization of untrusted input during the SNMP notification processing. This flaw permi...
PoC for CVE-2026-86179
A significant vulnerability exists in the Daily Expense Manager version 1.0, revealing sensitive information through an inadequate security mechanism in the Database Backup Handler. Specifically, manipulation of the /Daily-Expense-Manager/exp_ak.sql file allows an attacker to remotely access and ...
PoC for CVE-2026-86172
A vulnerability exists in DefaultFuction CRM version 1.0.0 that allows an attacker to exploit the 'delete.php' file located in the '/modules/customers/' directory. This is accomplished by manipulating the argument ID, enabling the remote execution of SQL injection attacks. With the exploit now pu...
Discovered 12 hours ago
PoC for CVE-2026-86171
A security vulnerability has been identified within DefaultFuction CRM 1.0.0, specifically affecting the /modules/orders/delete.php file. This vulnerability allows an attacker to manipulate the ID argument, leading to SQL injection attacks from remote locations. The exploit has been publicly disc...
PoC for CVE-2026-84028
The Bold Page Builder WordPress plugin versions prior to 5.9.9 contains a vulnerability that fails to properly sanitize and escape shortcode attributes before rendering them in HTML. This oversight permits users with Contributor role or higher to inject arbitrary web scripts, which could execute ...
PoC for CVE-2026-75793
The SureCart plugin for WordPress prior to version 4.7.0 introduces a significant security risk by failing to respect the site's user registration settings. This oversight allows unauthenticated users to create new accounts on the WordPress site, bypassing registration restrictions. As a result, ...
PoC for CVE-2026-85038
The B2BKing plugin for WooCommerce, prior to version 5.2.40, contains a security flaw where it fails to verify if a selected user role during registration matches the roles provided on the registration form. This oversight allows unauthenticated users to assign themselves to restricted B2B custom...
PoC for CVE-2026-84219
The Kirki WordPress plugin prior to version 6.3.0 is vulnerable to a cross-site scripting security flaw. This vulnerability allows unauthenticated users to store malicious JavaScript code in comments. When a page displaying these comments is viewed, the code executes in the context of any user vi...
PoC for CVE-2026-18480
The SureCart WordPress plugin prior to version 4.6.3 contains a critical flaw enabling users with a subscriber-level account to alter another user's email address, including that of an administrator. This vulnerability permits unauthorized account access through password resets. Additionally, it ...
PoC for CVE-2026-13159
The Real Estate Papi WordPress theme, up to version 1.0.5, lacks essential capability and CSRF checks for certain AJAX actions. This oversight permits any authenticated user, such as a subscriber, to trigger functions that install companion plugins directly from the WordPress.org repository. Once...
PoC for CVE-2020-10770
A vulnerability in Keycloak prior to version 13.0.0 allows an attacker to manipulate the OIDC parameter 'request_uri' to create a Server-side Request Forgery (SSRF) condition. This could enable the attacker to send unauthorized requests from the server, potentially exposing sensitive internal res...
Discovered 13 hours ago
PoC for CVE-2026-1529
A security flaw in Keycloak allows an attacker to exploit a weakness in the invitation token's JSON Web Token (JWT) payload. By modifying the organization ID and target email without proper cryptographic signature verification, an attacker can self-register into an unauthorized organization. This...
PoC for CVE-2026-18963
A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...
PoC for CVE-2026-86170
A vulnerability exists in DefaultFunction CRM version 1.0.0, specifically in the file /modules/orders/edit.php, where improper handling of the argument ID can lead to SQL injection attacks. This flaw allows attackers to manipulate database queries via crafted inputs. With the potential for remote...
PoC for CVE-2026-64747
A buffer overflow vulnerability has been identified across multiple Apple platforms, potentially allowing malicious applications to execute arbitrary code with elevated kernel privileges. Apple has implemented enhanced size validation measures to address this issue in the latest versions of iOS, ...
PoC for CVE-2026-64705
A buffer overflow vulnerability in macOS Sequoia and Sonoma can lead to potential unexpected system termination or unauthorized memory access. This issue was addressed with improved bounds checking in the software. Users are encouraged to update their systems to the latest versions to mitigate ri...
Discovered 14 hours ago
PoC for CVE-2026-86168
A security flaw has been identified in version 1.0 of the Code-Projects Content Management System. The vulnerability is located in an unknown function within the file '/login.php', where improper validation of the 'user_name' parameter allows an attacker to execute SQL injection attacks remotely....
PoC for CVE-2026-86167
A significant OS command injection vulnerability exists in the Tenda HG10 router, specifically in the function formgponConf of the Boa component located within the /boaform/admin/formgponConf file. This vulnerability arises from improper handling of user input in the fmgpon_loid argument, enablin...
PoC for CVE-2026-86166
A vulnerability exists in the Tenda HG10 device due to improper handling of arguments in the Boa Web Server component. Specifically, the function formWanRedirect can be manipulated, leading to a buffer overflow condition. This exploit could be executed remotely, allowing an attacker to potentiall...
Discovered 15 hours ago
PoC for CVE-2026-86165
A critical buffer overflow vulnerability exists in the Tenda HG10 router, specifically within the formURL function of the /boaform/admin/formURL file. By manipulating the Keywd/urlFQDN argument, an attacker can trigger a buffer overflow remotely. This exploit has been disclosed publicly, raising ...
PoC for CVE-2026-86164
A security vulnerability exists in the itsourcecode Sales and Inventory System 1.0, located in the 'trans_view.php' file. By manipulating the argument ID, an attacker can execute SQL injection attacks, potentially gaining unauthorized access to sensitive data. This flaw can be exploited remotely,...
PoC for CVE-2026-86163
A SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0. This vulnerability primarily affects the processing of requests in the '/pages/pro_del.php' file. Attackers can exploit this vulnerability remotely by manipulating the 'ID' argument, pote...
Discovered 16 hours ago
PoC for CVE-2026-86162
A vulnerability has been identified in the SourceCodester Online Voting System version 1.0, specifically within the /ajax.php file's login function. This flaw allows remote attackers to manipulate the Username argument, potentially leading to SQL injection. The exploitation of this vulnerability ...
PoC for CVE-2026-86161
A SQL injection vulnerability exists in the SourceCodester Online Voting System version 1.0, specifically in the ajax.php file during the delete_category action. This vulnerability allows an attacker to manipulate the ID argument, leading to unauthorized database access and potential data comprom...
PoC for CVE-2026-86160
A vulnerability exists in the SourceCodester Online Voting System 1.0, specifically within the /ajax.php file's delete_voting function. This flaw allows remote attackers to manipulate the ID parameter, potentially leading to SQL injection. The exploit has been publicly disclosed, raising signific...
PoC for CVE-2026-86159
A security flaw was identified in the SourceCodester Online Voting System 1.0, specifically in the handling of user input via the /ajax.php?action=save_user endpoint. This vulnerability permits remote attackers to manipulate the ID parameter, leading to SQL injection. Exploiting this weakness all...
Discovered 17 hours ago
PoC for CVE-2026-0920
The LA-Studio Element Kit for Elementor plugin suffers from a serious vulnerability that allows unauthenticated attackers to create administrative user accounts. The flaw arises from the 'ajax_register_handle' function, which fails to enforce restrictions on user roles during the registration pro...
Discovered 18 hours ago
PoC for CVE-2026-84645
In Jenkins versions 2.579 and earlier, including LTS version 2.568.2, a significant vulnerability exists where certain objects are improperly handled as nested field values in user-submitted 'config.xml' documents. This allows for potential remote code execution via HTTP requests processed throug...
Discovered 22 hours ago
PoC for CVE-2026-41940
The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...
PoC for CVE-2026-64560
A vulnerability in the Linux kernel related to posix CPU timers can lead to a use-after-free condition due to a race in non-leader exec() scenarios. When a timer associated with a process is deleted while concurrently executing an exec() command, it can cause access to freed memory. Specifically,...
PoC for CVE-2026-86060
MikroTik's RouterOS is vulnerable due to an argument-handling flaw in the SSH login process, specifically affecting usernames that start with a prohibited character. This flaw allows an attacker to manipulate the trusted RouterOS policy mask, facilitating privilege escalation. The exploitation of...