Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 94%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

Discovered 3 hours ago

PoC for CVE-2026-31802

IsaacsNode-tar8.2HIGH
Symlink Vulnerability in node-tar for Node.js by Isaacs

node-tar, a comprehensive Tar utility for Node.js, is susceptible to a symlink vulnerability that allows an attacker to craft a drive-relative symlink target. This exploitation can lead to the creation of symlinks that point to paths outside the targeted extraction directory. As a result, during ...

PoC for CVE-2026-4170

TopsecTopacm9.3CRITICAL
OS Command Injection Vulnerability in Topsec TopACM 3.0

An OS command injection vulnerability exists in the Topsec TopACM 3.0 product, specifically within the HTTP Request Handler component linked to the file /view/systemConfig/management/nmc_sync.php. By manipulating the 'template_path' argument, an attacker can execute arbitrary OS commands remotely...

Discovered 4 hours ago

PoC for CVE-2026-4168

TecnickTcexam4.8MEDIUM
Cross Site Scripting Vulnerability in Tecnick TCExam by Tecnick

A vulnerability affecting Tecnick TCExam version 16.5.0 has been identified in the Group Handler component, particularly in the file /admin/code/tce_edit_group.php. This vulnerability allows for cross site scripting (XSS) attacks through the manipulation of the 'Name' argument. Remote attackers c...

PoC for CVE-2026-4167

BelkinF9k11228.7HIGH
Stack-Based Buffer Overflow in Belkin F9K1122 Router

A significant vulnerability has been identified in the Belkin F9K1122 router, specifically related to the 'formReboot' function in the /goform/formReboot file. This security flaw can be exploited by manipulating the argument 'webpage,' leading to a stack-based buffer overflow. Attackers may initi...

PoC for CVE-2026-4166

WavlinkWl-nu516u15.1MEDIUM
Cross Site Scripting Vulnerability in Wavlink WL-NU516U1 Product

A cross site scripting vulnerability exists in the Wavlink WL-NU516U1 240425 due to improper handling of user input in the login.cgi script. This flaw allows an attacker to manipulate the homepage or hostname parameters, executing arbitrary JavaScript in the context of the affected user's session...

Discovered 5 hours ago

PoC for CVE-2020-15099

Typo3Typo3 Cms8.1HIGH
Exposure of Sensitive Information to an Unauthorized Actor in TYPO3...

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.20, and greater than or equal to 10.0.0 and less than 10.4.6, in a case where an attacker manages to generate a valid cryptographic message authentication code (HMAC-SHA1) - either by using a different existing vulnerability or in case...

Discovered 7 hours ago

PoC for CVE-2026-4164

WavlinkWl-wn578w29.3CRITICAL
Command Injection Vulnerability in Wavlink WL-WN578W2

A vulnerability has been identified in the Wavlink WL-WN578W2, specifically in the functions Delete_Mac_list, SetName, and GuestWifi within the /cgi-bin/wireless.cgi file. This flaw allows attackers to perform command injection via manipulated POST requests. The issue can be exploited remotely, r...

Discovered 11 hours ago

PoC for CVE-2025-15467

OpenSSLOpenSSL9.8CRITICAL
Stack Buffer Overflow Vulnerability in OpenSSL Parsing CMS Messages

A vulnerability exists in OpenSSL when parsing CMS AuthEnvelopedData structures that employ AEAD ciphers like AES-GCM. This flaw arises from the improper handling of oversized Initialization Vectors (IVs) crafted within ASN.1 parameters, leading to a stack buffer overflow. An attacker can exploit...

PoC for CVE-2025-68926

RustfsRustfs9.8CRITICAL
Authentication Vulnerability in RustFS Object Storage System

The RustFS object storage system, prior to version 1.0.0-alpha.77, suffers from a significant authentication vulnerability due to the use of a hardcoded static token, 'rustfs rpc'. This token is exposed in the source code and is non-configurable, meaning it cannot be altered or rotated. As a resu...

PoC for CVE-2026-4163

WavlinkWl-wn579a39.3CRITICAL
Command Injection Vulnerability in Wavlink WL-WN579A3 Router

A command injection vulnerability has been identified in the Wavlink WL-WN579A3 router, specifically affecting the SetName/GuestWifi function in the /cgi-bin/wireless.cgi component. This vulnerability allows attackers to remotely execute unauthorized commands by manipulating the POST request para...

Discovered 14 hours ago

PoC for CVE-2025-60787

MotionEye ProjectMotionEye🟣 EPSS 66%7.2HIGH
OS Command Injection Vulnerability in MotionEye by MotionEye Project

MotionEye versions up to and including 0.43.1b4 are susceptible to OS Command Injection through improperly sanitized configuration parameters like image_file_name. This vulnerability allows remote authenticated users with administrative privileges to inject malicious commands into Motion configur...

Discovered 22 hours ago

PoC for CVE-2026-27944

0xjackyNginx-ui9.8CRITICAL
Authentication Bypass in Nginx UI Affects Nginx Web Server

Nginx UI, a web interface for the Nginx web server, has a critical security flaw where the /api/backup endpoint is accessible without authentication. This vulnerability allows unauthenticated attackers to retrieve a complete system backup that includes sensitive information such as user credentia...

Discovered 1 day ago

PoC for CVE-2024-23222

AppleiOS And iPad OS8.8HIGH
Safari Fixes Type Confusion Issue, Addresses Arbitrary Code Executi...

A type confusion vulnerability has been identified in Apple's operating systems that could allow attackers to execute arbitrary code by processing specially crafted web content. Improved checks have been implemented in the latest versions of iOS, iPadOS, macOS, and tvOS to address this issue. App...

PoC for CVE-2026-3891

WordPressPix For WooCommerce9.8CRITICAL
Arbitrary File Upload Vulnerability in Pix for WooCommerce Plugin b...

The Pix for WooCommerce plugin for WordPress is susceptible to arbitrary file uploads due to a lack of capability checks and insufficient file type validation within the 'lkn_pix_for_woocommerce_c6_save_settings' function. This vulnerability exists across all versions through 1.5.0. An unauthenti...

PoC for CVE-2024-14027

LinuxLinux
Memory Exhaustion Vulnerability in Linux Kernel Affecting File Hand...

A vulnerability in the Linux kernel's file handling mechanism, specifically in the fremovexattr() syscall, can lead to kernel memory exhaustion. The issue arises when fdget() is called to acquire a file reference, but if strncpy_from_user() fails on the name input, the function exits prematurely ...

PoC for CVE-2024-47176

OpenprintingCups-browsed🟣 EPSS 88%5.3MEDIUM
CUPS 'cups-browsed' Vulnerability Allows Remote Execution of Arbitr...

The CUPS printing system, which is widely used for managing print jobs, has a vulnerability in its cups-browsed component that allows for network printing functionality such as auto-discovery of print services. This component binds to INADDR_ANY:631, which leads to a scenario where it will accept...

Discovered 2 days ago

PoC for CVE-2026-29000

Pac4jPac4j-jwt9.3CRITICAL
Authentication Bypass in JwtAuthenticator of pac4j-jwt by pac4j

The pac4j-jwt library's JwtAuthenticator prior to versions 4.5.9, 5.7.9, and 6.3.3 is susceptible to an authentication bypass that could allow remote adversaries to create forged authentication tokens. By leveraging the server's RSA public key, attackers are able to craft a JWE-wrapped PlainJWT w...

PoC for CVE-2026-21509

MicrosoftMicrosoft 365 Apps For...7.8HIGH
Security Feature Bypass in Microsoft Office

A vulnerability exists in Microsoft Office that allows attackers to manipulate untrusted inputs, enabling them to bypass critical security measures locally. This flaw can expose systems to unauthorized actions, compromising the integrity of sensitive data. It is crucial for users to apply the lat...

Discovered 3 days ago

PoC for CVE-2026-31816

BudibaseBudibase9.1CRITICAL
Unauthorized API Access Vulnerability in Budibase Low Code Platform

Budibase, a low code platform for creating internal tools, exhibits a significant vulnerability in its server's authorization mechanism. In versions 3.31.4 and earlier, the 'authorized()' middleware designed to protect server-side API endpoints can be bypassed entirely by appending a specific web...

PoC for CVE-2018-7600

DrupalDrupal Before 7.58, 8....🟣 EPSS 94%9.8CRITICAL
Remote Code Execution Vulnerability in Drupal by Acquia

Multiple versions of Drupal, including those prior to 7.58 and various 8.x releases, are susceptible to a vulnerability that permits remote attackers to execute arbitrary code. This exploit takes advantage of configuration flaws in several subsystems, particularly those using default or common mo...

PoC for CVE-2026-4045

ProjectSendProjectsend6.3MEDIUM
Remote Code Execution Vulnerability in ProjectSend Auth Component

A security vulnerability exists in ProjectSend affecting versions up to r1945, specifically in the Auth.php file. This flaw allows for the manipulation of the ldap_email argument, which can cause discrepancies in the application's responses. An attacker may exploit this issue remotely, although t...

PoC for CVE-2019-25543

NetartmediaNetartmedia Real Estat...8.8HIGH
SQL Injection Vulnerability in Netartmedia Real Estate Portal Product

The Netartmedia Real Estate Portal 5.0 has an SQL injection vulnerability that can be exploited by attackers to manipulate database queries. By sending specially crafted POST requests to index.php with malicious SQL in the page parameter, unauthorized users can bypass security measures, extract s...

PoC for CVE-2019-25541

NetartmediaNetartmedia PHP Mall8.8HIGH
SQL Injection Vulnerabilities in Netartmedia PHP Mall by Netartmedia

Netartmedia PHP Mall 4.1 has been found to contain multiple SQL injection vulnerabilities that enable unauthenticated attackers to manipulate database queries. By exploiting unvalidated parameters, such as 'id' in index.php and 'Email' in loginaction.php, threat actors can execute time-based blin...

PoC for CVE-2019-25539

Sourceforge202cms8.8HIGH
Blind SQL Injection in 202CMS v10 Beta by sourceforge

202CMS v10 beta is vulnerable to a blind SQL injection flaw, which allows attackers to exploit the log_user parameter. Through carefully crafted POST requests to index.php, attackers can implement time-based blind injection techniques to execute arbitrary SQL commands. This vulnerability can lead...

PoC for CVE-2019-25537

NetartmediaNetartmedia Event Portal8.8HIGH
SQL Injection Vulnerability in Netartmedia Event Portal

Netartmedia Event Portal 2.0 is vulnerable to a time-based blind SQL injection, enabling unauthenticated attackers to insert SQL commands through the Email parameter. By sending manipulated POST requests to loginaction.php, attackers can extract sensitive data from the database, posing severe ris...

PoC for CVE-2019-25536

NetartmediaNetartmedia PHP Real E...8.8HIGH
SQL Injection Vulnerability in Netartmedia PHP Real Estate Agency S...

The Netartmedia PHP Real Estate Agency 4.0 software contains a serious SQL injection vulnerability that allows unauthenticated attackers to craft malicious POST requests. By exploiting the features[] parameter in the index.php file, attackers can execute arbitrary SQL queries that may lead to una...

PoC for CVE-2019-25535

NetartmediaNetartmedia PHP Dating...8.8HIGH
SQL Injection Vulnerability in Netartmedia PHP Dating Site

The Netartmedia PHP Dating Site is vulnerable to SQL injection attacks via the Email parameter in the loginaction.php file. This allows unauthenticated attackers to inject malicious SQL code, potentially enabling them to extract sensitive data from the database. By sending specially crafted POST ...

PoC for CVE-2019-25534

NetartmediaNetartmedia PHP Car De...8.8HIGH
SQL Injection Vulnerability in Netartmedia PHP Car Dealer

The Netartmedia PHP Car Dealer contains a significant SQL injection vulnerability that enables attackers, without authentication, to execute arbitrary SQL queries. This flaw is exploited through the features[] parameter in POST requests to index.php, allowing malicious users to inject SQL payload...

PoC for CVE-2019-25533

PHPbusinessdirectoryNetartmedia PHP Busine...8.8HIGH
SQL Injection Vulnerability in Netartmedia PHP Business Directory

Netartmedia's PHP Business Directory version 4.2 is susceptible to an SQL injection flaw that can be exploited by unauthenticated users. This vulnerability allows attackers to inject malicious SQL statements through the Email parameter when sending POST requests to the loginaction.php endpoint. S...

PoC for CVE-2019-25532

NetartmediaNetartmedia Jobs Portal8.8HIGH
SQL Injection Vulnerability in Netartmedia Jobs Portal 6.1

The Netartmedia Jobs Portal 6.1 is susceptible to an SQL injection vulnerability, which enables unauthenticated attackers to manipulate database queries. By sending carefully crafted POST requests to the loginaction.php file with malicious SQL code injected through the Email parameter, attackers ...

PoC for CVE-2019-25531

NetartmediaNetartmedia Deals Portal8.8HIGH
SQL Injection Vulnerability in Netartmedia Deals Portal

The Netartmedia Deals Portal is susceptible to an SQL injection vulnerability through the Email parameter in loginaction.php. This flaw enables unauthenticated attackers to execute crafted SQL queries via POST requests, providing them the capability to manipulate database operations. As a result,...

PoC for CVE-2019-25530

Hotel-booking-scriptUhotelbooking System8.8HIGH
SQL Injection Vulnerability in uHotelBooking System by uZer

The uHotelBooking System is susceptible to an SQL injection vulnerability, which enables unauthenticated attackers to manipulate database queries. By exploiting the 'system_page' GET parameter, malicious users can inject SQL commands via crafted requests to index.php. This misuse can lead to the ...

PoC for CVE-2019-25529

SourceforgePlaceto Cms7.1HIGH
SQL Injection Vulnerability in Placeto CMS Alpha by Placeto

Placeto CMS Alpha version 4 contains a vulnerability that enables authenticated attackers to exploit SQL injection through the 'page' parameter. By manipulating the parameter, attackers can craft GET requests to the admin/edit.php endpoint, leveraging techniques such as boolean-based blind, time-...

PoC for CVE-2019-25528

InoutscriptsInout Easyrooms Ultima...8.8HIGH
SQL Injection Vulnerability in Inout EasyRooms Ultimate Edition by ...

Inout EasyRooms Ultimate Edition v1.0 contains a security flaw that allows unauthorized users to execute SQL commands through the property1 parameter. By crafting specific POST requests to the search/searchdetailed endpoint, attackers can inject harmful SQL queries, potentially exposing sensitive...

PoC for CVE-2019-25524

XooscriptsXoogallery8.8HIGH
SQL Injection Vulnerability in XooGallery by XooTheme

XooGallery, a product by XooTheme, has a vulnerability that enables unauthorized individuals to execute SQL injection attacks through the 'p' parameter in a GET request to results.php. This means that attackers can pass crafted SQL code, compromising the integrity of the database. Such exploits c...

PoC for CVE-2019-25520

JettwebHazir Haber Sitesi Scr...8.8HIGH
Authentication Bypass Vulnerability in Jettweb PHP Script by Jettweb

The Jettweb PHP Hazir Haber Sitesi Scripti V1 is susceptible to an authentication bypass vulnerability that allows attackers to circumvent authentication protections in the administration panel. Through improper SQL query validation, malicious users can inject SQL payloads into the username and p...

PoC for CVE-2019-25515

JettwebHazir Haber Sitesi Scr...8.7HIGH
Authentication Bypass in Jettweb PHP Hazir Haber Sitesi Scripti V3

The Jettweb PHP Hazir Haber Sitesi Scripti V3 contains a significant security flaw that enables unauthenticated users to gain administrative access to the system. By exploiting the vulnerability present in the login.php administration panel, attackers can craft specific SQL syntax and manipulate ...

PoC for CVE-2019-25510

JettwebHazir Haber Sitesi Scr...8.8HIGH
Authentication Bypass Vulnerability in Jettweb PHP Hazir Haber Site...

The Jettweb PHP Hazir Haber Sitesi Scripti V2 is susceptible to an authentication bypass vulnerability due to improper validation of SQL queries in the administration panel. This flaw allows unauthenticated attackers to exploit SQL injection payloads using the login form at admingiris.php, potent...

PoC for CVE-2019-25509

XooscriptsXoodigital8.8HIGH
SQL Injection Vulnerability in XooDigital Latest Product

The XooDigital Latest product is susceptible to an SQL injection vulnerability via the 'p' parameter in the results.php file. This flaw enables unauthenticated attackers to craft GET requests with malicious 'p' values, allowing them to manipulate database queries and potentially extract sensitive...

PoC for CVE-2019-25508

JettwebHazir Ilan Sitesi Scripti8.8HIGH
SQL Injection Vulnerability in Jettweb PHP Hazir Ilan Sitesi Script...

The Jettweb PHP Hazir Ilan Sitesi Script V2 contains a significant SQL injection vulnerability that permits unauthenticated attackers to manipulate database queries through the 'kat' parameter. By sending specially crafted GET requests to the katgetir.php endpoint with malicious 'kat' values, att...

PoC for CVE-2019-25488

JettwebRent A Car Scripti8.8HIGH
SQL Injection Vulnerability in Jettweb Hazir Rent A Car Script by J...

The Jettweb Hazir Rent A Car Script V4 is plagued by multiple SQL injection vulnerabilities within its admin panel. These flaws allow unauthenticated attackers to execute arbitrary SQL commands by manipulating GET parameters such as 'tur', 'id', and 'ozellikdil' in the admin/index.php endpoint. S...

PoC for CVE-2019-25482

JettwebHazir Rent A Car Sites...8.8HIGH
SQL Injection Vulnerability in Jettweb PHP Hazir Rent A Car Sitesi ...

The Jettweb PHP Hazir Rent A Car Sitesi Scripti V2 is susceptible to an SQL injection flaw that allows attackers to exploit the 'arac_kategori_id' parameter. By crafting POST requests with malicious SQL code, unauthenticated users can manipulate database queries, potentially exposing sensitive in...

PoC for CVE-2019-25479

InoutscriptsInout Realestate8.8HIGH
SQL Injection Vulnerability in Inout RealEstate by Inout

Inout RealEstate is susceptible to SQL injection, primarily affecting the agents/agentlistdetails endpoint. This vulnerability allows unauthenticated attackers to manipulate database queries by injecting malicious SQL code through the city parameter. By sending crafted POST requests, attackers ca...

PoC for CVE-2019-25481

IscriptsIscripts Reservelogic8.8HIGH
SQL Injection in iScripts ReserveLogic

iScripts ReserveLogic is affected by an SQL injection vulnerability that enables unauthenticated attackers to exploit the jqSearchDestination parameter. By sending specially crafted POST requests to the search endpoint, attackers can inject malicious SQL code, allowing them to manipulate database...

PoC for CVE-2019-25473

SoftwebinternationalClinic Pro7.1HIGH
SQL Injection Vulnerability in Clinic Pro by Clinic Pro Vendor

Clinic Pro is exposed to a SQL injection vulnerability due to improper handling of user-supplied input through the month parameter. This flaw allows authenticated attackers to craft malicious POST requests targeting the monthly_expense_overview endpoint. By utilizing techniques such as boolean-ba...

PoC for CVE-2026-4044

ProjectSendProjectsend5.1MEDIUM
Path Traversal Vulnerability in ProjectSend Delete Handler

A vulnerability in ProjectSend, specifically within the Delete Handler component's realpath function in the import-orphans.php file, allows for a path traversal exploit. By manipulating the argument files[], an attacker may gain unauthorized access to files on the server. This issue became public...

PoC for CVE-2026-4043

TendaI128.7HIGH
Stack-based Buffer Overflow in Tenda i12 by Tenda

A security vulnerability has been identified in Tenda i12 firmware version 1.0.0.6(2204). This vulnerability arises from improper handling of the index parameter in the 'formwrlSSIDget' function within the '/goform/wifiSSIDget' file. An attacker can exploit this weakness to achieve a stack-based ...

PoC for CVE-2026-4042

TendaI128.7HIGH
Stack-based Buffer Overflow in Tenda i12 Wireless Router

A vulnerability in the Tenda i12 wireless router allows for a stack-based buffer overflow through the formWifiMacFilterGet function located in the /goform/WifiMacFilterGet file. This weakness could be exploited remotely, enabling potential attackers to manipulate index arguments. The exploit has ...

PoC for CVE-2026-4041

TendaI128.7HIGH
Stack-based Buffer Overflow in Tenda i12 Router

A security vulnerability has been identified in the Tenda i12 router, specifically within the vos_strcpy function located in the /goform/exeCommand file. This flaw allows an attacker to manipulate the cmdinput argument, leading to a stack-based buffer overflow. The vulnerability can be exploited ...