Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 4 hours ago
PoC for CVE-2015-3306
The mod_copy module in ProFTPD 1.3.5 is vulnerable to exploitation, allowing attackers to perform unauthorized read and write operations on arbitrary files. This is executed through the use of the site cpfr and site cpto commands, enabling remote users to manipulate file contents without permissi...
PoC for CVE-2026-39987
Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...
PoC for CVE-2014-9222
AllegroSoft RomPager versions 4.34 and earlier, employed in various home gateway products, including those from Huawei, have a vulnerability that enables remote attackers to escalate privileges through a specially crafted cookie. This exploitation leverages memory corruption, giving unauthorized ...
Discovered 5 hours ago
PoC for CVE-2026-86519
A security vulnerability has been identified in the Student Crud Operation version 1.0 by Code-Projects, affecting the Backup File Handler component. This vulnerability resides in the /card_activation.sql file, leading to potential information disclosure. Remote attackers can exploit this loophol...
PoC for CVE-2026-86518
A vulnerability has been identified in the Student Crud Operation 1.0, specifically in the /edit.php file. This security flaw allows an attacker to manipulate the ID parameter, enabling SQL injection attacks that can be initiated from a remote location. The risk associated with this vulnerability...
Discovered 6 hours ago
PoC for CVE-2026-86517
A significant SQL injection vulnerability exists in version 1.0 of the itsourcecode Sales and Inventory System. The flaw is located in the mysqli_query function within the /pages/us_searchfrm.php file. An attacker can manipulate the ID argument, facilitating remote SQL injection attacks, which ma...
PoC for CVE-2026-86515
A security vulnerability in vgmstream has been identified, specifically within the add_entry function in the txtp_parser.c file. This weakness allows manipulations of the range_start and range_end parameters, potentially leading to excessive resource consumption. The threat can be executed remote...
PoC for CVE-2026-86514
A vulnerability has been detected in vgmstream, specifically in versions up to r2117, affecting the sscanf function within the txth.c component. This weakness may allow attackers to manipulate data and initiate a stack-based buffer overflow remotely. The potential exploitation of this vulnerabili...
Discovered 7 hours ago
PoC for CVE-2026-86513
A security flaw has been identified in the JSON Pointer parser of jackson-coreutils version 2.0, specifically within the TreePointer.tokensFromInput function. This vulnerability allows for remote execution of attacks that exploit improper resource allocation. The issue was reported to the project...
PoC for CVE-2026-86512
A security vulnerability has been discovered in the java-json-tools json-patch component, specifically in the Copy Move Operations feature. This flaw, found in the methods CopyOperation.apply and MoveOperation.apply, allows for improper access controls, potentially enabling unauthorized actions b...
PoC for CVE-2026-86511
A resource consumption vulnerability has been identified in the Jackson-CoreUtils library version 2.0, found in the BigDecimal.toPlainString function within the JacksonUtils.java file. This vulnerability allows an attacker to manipulate resources, leading to potential denial of service. The explo...
Discovered 8 hours ago
PoC for CVE-2026-86510
A critical vulnerability has been identified in the D-Link DIR-822A A_101 router, specifically within the tunnel_set_params function of the L2TP Control Message Parser. This vulnerability allows for an out-of-bounds write condition that can be exploited remotely. The public disclosure of this exp...
PoC for CVE-2026-86509
A vulnerability exists in the D-Link DIR-895L A1_102b07 router due to a flaw in the sendOffer/sendACK functions within the udhcpcd/serverpacket.c file. This flaw can lead to a stack-based buffer overflow, potentially allowing an attacker to execute arbitrary code. The attack requires access to th...
Discovered 9 hours ago
PoC for CVE-2020-0609
This vulnerability allows an unauthenticated attacker to execute arbitrary code on a target system by sending specially crafted requests to the Windows Remote Desktop Gateway. Successful exploitation could enable the attacker to install programs, view, change or delete data, or create new account...
Discovered 13 hours ago
PoC for CVE-2026-33234
The AutoGPT platform allows users to specify an SMTP server and port, which can lead to potential internal network scanning. This vulnerability arises from the absence of validation checks on user inputs in the SendEmailBlock component. When an authenticated user provides these inputs, AutoGPT by...
Discovered 15 hours ago
PoC for CVE-2026-28576
In the Contacts Provider, a vulnerability exists that allows unauthorized access to the contacts database through an SQL injection attack. Attackers can exploit this flaw without needing any user interaction or elevated privileges, potentially leading to the disclosure of sensitive information st...
PoC for CVE-2025-48384
A vulnerability exists in Git that affects how configuration values are read and written, particularly regarding trailing carriage returns. When a submodule path includes a trailing carriage return, it is altered when read back, which can cause the submodule to be checked out to an incorrect loca...
PoC for CVE-2026-86218
N-central by N-able is susceptible to a critical pre-authentication remote code execution vulnerability, which allows unauthorized parties to execute arbitrary code on vulnerable systems. This issue impacts all versions of N-central prior to 2026.3.1.14, making it essential for users to upgrade t...
Discovered 16 hours ago
PoC for CVE-2026-13181
A vulnerability in Telerik UI for AJAX versions earlier than v2026.2.708 allows an attacker to influence AsyncUploadTypeName processing through forged upload metadata. This manipulation can lead to unsafe type resolution, potentially enabling remote code execution in affected environments. It is ...
Discovered 18 hours ago
PoC for CVE-2026-86321
A vulnerability has been identified in the URL Validation functionality of the java-json-tools jackson-coreutils library, specifically within the 'JsonLoader.fromURL' method. This flaw could allow an attacker to perform server-side request forgery (SSRF), which enables the attacker to exploit the...
PoC for CVE-2026-86319
A vulnerability exists within the json-patch component from java-json-tools, specifically in the JsonPatch.apply function located at src/main/java/com/github/fge/jsonpatch/JsonPatch.java. This vulnerability allows for excessive resource consumption, enabling remote attacks that could lead to Deni...
Discovered 19 hours ago
PoC for CVE-2026-86318
A vulnerability exists in the json-patch component of java-json-tools up to version 1.13, specifically in the JsonMergePatch.fromJson function located in JsonMergePatchDeserializer.java. This flaw can lead to a stack-based buffer overflow, which may be exploited remotely, allowing an attacker to ...
PoC for CVE-2026-86310
A significant SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System 1.0, specifically within an unknown function of the 'cust_edit1.php' file. This flaw allows attackers to manipulate the argument ID, enabling remote exploitation. Such vulnerabilities pose...
PoC for CVE-2026-86309
An SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0 within an unvalidated function in the file /pages/pro_searchfrm.php. This weakness allows attackers to manipulate the ID argument, potentially leading to unauthorized database access and exposure of s...
Discovered 20 hours ago
PoC for CVE-2026-86308
A vulnerability exists in light0011 CMS that allows for remote exploitation through manipulation of the DB_DEBUG argument within the App/Common/Conf/config.php file. This security flaw leads to the unintentional exposure of sensitive information, potentially compromising system security. The issu...
PoC for CVE-2026-86307
A security vulnerability in light0011 CMS has been identified, allowing for potential cross-site request forgery attacks. This flaw enables attackers to initiate unauthorized actions on behalf of authenticated users, posing a significant risk to users' data and system integrity. The issue has bee...
PoC for CVE-2026-86306
A vulnerability has been discovered in the light0011 CMS, specifically within the Cookie Helper component. An issue in the UserModel.class.php file allows attackers to manipulate the Username argument, leading to improper authentication. This issue can potentially be exploited remotely. The affec...
PoC for CVE-2026-86305
A significant vulnerability has been identified in the light0011 CMS, specifically within the Upload::upload function of the ThinkPHP library. This weakness permits unauthorized users to upload files without proper restrictions, potentially leading to unauthorized code execution. The flaw can be ...
Discovered 21 hours ago
PoC for CVE-2026-86302
A security flaw has been identified in the Hospital Information System 1.0 developed by code-projects. This vulnerability is linked to the SQL Database Backup File Handler, specifically in the his.sql file. By manipulating this functionality, unauthorized users may gain access to sensitive inform...
PoC for CVE-2026-86301
A cross-site scripting vulnerability exists in the Hospital Information System (HIS) 1.0, particularly within the Patient Management component found at /HIS/src/patients/editPatient.php. The vulnerability allows attackers to manipulate the 'ID' argument, potentially enabling remote exploitation t...
Discovered 22 hours ago
PoC for CVE-2026-86300
A security flaw has been identified in the Tenda AC9 version 15.03.05.14, specifically in the R7WebsSecurityHandler component of its web management interface. This flaw allows for improper authentication, potentially enabling remote attackers to manipulate access controls. It is essential for use...
PoC for CVE-2026-86299
A vulnerability in the Linksys RE7000 version 2.0.15 allows for OS command injection through the PingTest Handler. Specifically, the manipulation of the pingTestIp, pingTestPktSize, and pingTestTimes parameters in the /cgi-bin/json.cgi?PingTest endpoint can enable an attacker to execute arbitrary...
PoC for CVE-2025-54136
In Cursor Code Editor versions prior to 1.3, a significant vulnerability exists allowing attackers to execute arbitrary code remotely. This occurs through manipulation of a trusted MCP configuration file either within a shared GitHub repository or on the target machine. If an attacker can alter t...
PoC for CVE-2026-86298
A security flaw has been identified in the Class and Exam Timetabling System developed by SourceCodester. Specifically, an SQL injection vulnerability exists within the /delete_subject.php file, where manipulation of the argument ID allows attackers to execute unauthorized database commands. This...
PoC for CVE-2026-86297
A vulnerability has been identified in the D-Link DIR-605 router, specifically within the L2TP Control Message Parser's tunnel_set_params function. This issue arises from improper manipulation of the peer_hostname argument, leading to an off-by-one condition that can allow remote attackers to exp...
Discovered 23 hours ago
PoC for CVE-2026-86296
A vulnerability exists in the D-Link DIR-822A A_101 router related to the strcpy function within the udhcpcd/serverpacket.c file. This weakness can lead to a stack-based buffer overflow, allowing attackers to exploit the vulnerability remotely. The potential risks include unauthorized access and ...
PoC for CVE-2026-86295
A command injection vulnerability has been identified in the D-Link DIR-895L router, specifically in the udhcpcd component's sendACK function within the serverpacket.c file. This flaw allows an attacker to manipulate the Hostname argument to inject and execute arbitrary commands remotely. Given t...
PoC for CVE-2026-86294
A cross-site scripting (XSS) vulnerability exists in the SourceCodester Simple Traffic Offense System 1.0. The issue arises from improper handling of input in the save-settings.php file of the Settings Update Endpoint. By manipulating the parameters site_name or site_desc, an attacker could injec...
PoC for CVE-2026-86293
A vulnerability exists in SourceCodester's Simple Traffic Offense System version 1.0, specifically in the delete-user.php file of the Deletion Endpoint. An attacker can manipulate the argument ID, allowing for unauthorized access and actions due to missing authentication checks. This flaw can be ...
Discovered 1 day ago
PoC for CVE-2026-86292
A vulnerability in the SourceCodester Simple Traffic Offense System 1.0 was discovered, specifically within the user creation functionality located in the saveuser.php file. This vulnerability arises when the argument position is manipulated, leading to a situation where proper user authenticatio...
PoC for CVE-2026-86291
A vulnerability has been uncovered in the itsourcecode Sales and Inventory System, specifically in the file /pages/us_edit1.php. This flaw allows attackers to exploit an insecure function which processes the 'ID' argument, resulting in SQL injection. Such an exploit enables unauthorized access to...
PoC for CVE-2026-86290
A vulnerability has been discovered in the SourceCodester Online Voting System 1.0, specifically affecting the /voting/ajax.php file when the action 'save_category' is invoked. This flaw allows for SQL injection through the manipulation of the 'Category' argument. Attackers can exploit this vulne...
PoC for CVE-2026-86289
A vulnerability has been identified in the Ollama GGUF Decoder, affecting versions up to 0.31.1. This issue arises from the function readGGUFV1String located in the file fs/ggml/gguf.go. An integer overflow can be triggered through remote manipulation. The exploit details have been made public, h...
PoC for CVE-2026-86288
A significant vulnerability exists in ModelCloud's GPTQModel software, specifically within the Triton dequantization kernel located in the gptqmodel/nn_modules/qlinear/tritonv2.py file. This flaw allows for out-of-bounds read due to improper handling of the argument g_idx, potentially enabling re...
PoC for CVE-2026-86285
A vulnerability has been identified in BookStack impacting versions up to 26.05.2, specifically within the Attachment Edit Endpoint's AttachmentController.php file. The flaw resides in the function AttachmentController::getUpdateForm, where improper access control mechanisms are in place. This vu...
PoC for CVE-2026-86284
A security vulnerability has been identified in the getOption function of the jaychouchannel Tourism-Management-System, specifically in the file travel/src/main/java/com/controller/CommonController.java. This flaw arises from improper handling of the tableName/columnName arguments, potentially le...
PoC for CVE-2026-86282
A vulnerability exists in the jaychouchannel Tourism-Management-System, specifically in the `CommonController.java` file, allowing remote attackers to perform SQL injection attacks through manipulated table and column arguments. This flaw, which does not have public versioning details, poses a se...
PoC for CVE-2026-42559
A vulnerability exists in the RMCP Rust SDK that allows for improper validation of the incoming Host header in its Streamable HTTP server transport. This flaw can be exploited through a DNS rebinding attack, enabling a malicious public website to send authenticated requests to an MCP server runni...
PoC for CVE-2026-86281
A security flaw exists in the SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0, allowing for cross-site request forgery (CSRF) attacks. This vulnerability impacts an unspecified function, enabling unauthorized actions on behalf of authenticated users. The explo...
PoC for CVE-2024-7804
A deserialization vulnerability exists in Pytorch's RPC framework, specifically in the `torch.distributed.rpc` module. The flaw stems from inadequate security verifications during the deserialization of PythonUDF objects, potentially enabling malicious actors to execute arbitrary code remotely. B...