Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 4 hours ago
PoC for CVE-2026-90495
A SQL injection vulnerability exists in Fengoffice's Legacy API within the method Contacts::instance->findAll, located in the file application/models/CompanyWebsite.class.php. This weakness arises from improper argument handling during authentication processes, allowing attackers to manipulate th...
PoC for CVE-2026-90493
A local access control vulnerability exists in the Tonec Internet Download Manager for Windows, specifically within the idmwfp.sys file of the kernel driver component. This vulnerability allows an attacker with local access to manipulate permissions improperly. The issue has been made public, hig...
Discovered 6 hours ago
PoC for CVE-2026-90491
A code injection vulnerability exists in the sanjevirau gsubs product, specifically in the function showQuerySuccessPage within the renderer/index.js file. By manipulating the argument 'filename', an attacker can execute arbitrary code remotely. The potential exploit has been publicly disclosed, ...
Discovered 8 hours ago
PoC for CVE-2026-90489
A cross-site scripting vulnerability affects the Xuxueli XXL-Job application versions up to 3.5.0. The vulnerability exists in the /jobinfo/insert file, where improper handling of the 'name' and 'author' parameters allows attackers to inject malicious scripts. This can be exploited remotely, risk...
PoC for CVE-2026-75650
Adobe Commerce has a vulnerability that allows for improper neutralization of special elements used in a template engine, potentially leading to arbitrary code execution in the context of the current user. An attacker can exploit this issue without requiring any user interaction, posing significa...
PoC for CVE-2026-90648
The vulnerability in wasm2c of WABT allows for a sandbox escape through a flaw in memory allocation handling on certain platforms, particularly 32-bit systems. When the allocation of the funcref table fails, the internal state leads to a scenario where bounds checks pass, permitting unauthorized ...
PoC for CVE-2026-90488
A code injection vulnerability exists in Xuxueli XXL-JOB versions up to 3.4.2. This issue arises in the GroovyClassLoader.parseClass function within the GlueFactory.java file. An attacker can exploit this vulnerability remotely to inject malicious code, potentially leading to unauthorized access ...
PoC for CVE-2026-90487
A vulnerability has been identified in Xuxueli XXL-JOB versions up to 3.4.2, specifically related to the JobGroupController.java file. This flaw allows for improper privilege management, which could potentially be exploited by an attacker remotely. Despite early notifications, the vendor has yet ...
Discovered 11 hours ago
PoC for CVE-2026-78006
The Events Calendar plugin for WordPress has a vulnerability that allows unauthenticated attackers to execute arbitrary code on the server. This is made possible due to inadequate protection in the is_safe_widget_instance function. The exploitation occurs when PHP's magic methods are triggered, a...
Discovered 16 hours ago
PoC for CVE-2026-86547
The mrubyc environment, in versions prior to 4.0.0, has a vulnerability that allows attackers to exploit a null pointer dereference in the op_enter() handler located in src/vm.c. By crafting malicious .mrb bytecode files with OP_ENTER instructions at the top level, an attacker could cause the emb...
PoC for CVE-2023-1326
A vulnerability has been identified in apport-cli versions 2.26.0 and earlier, which may allow a local attacker to escalate privileges under specific conditions. If a system is misconfigured to allow unprivileged users to execute sudo with apport-cli as the command, and if appropriate settings fo...
Discovered 18 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 19 hours ago
PoC for CVE-2021-28664
The Arm Mali GPU kernel driver exhibits a significant vulnerability allowing unprivileged users to obtain read/write access to restricted pages. This flaw can result in privilege escalation or cause a denial of service through memory corruption. The affected versions include various releases of t...
Discovered 1 day ago
PoC for CVE-2026-89013
Dolibarr versions prior to 24.0.1 are susceptible to an authorization bypass vulnerability that enables unauthenticated attackers to read sensitive files. By exploiting a flaw in the document storage endpoints, attackers can leverage a crafted 'hashp' parameter to bypass token validation in criti...
PoC for CVE-2026-89012
Dolibarr versions prior to 24.0.1 exhibit a vulnerability tied to the sqlfilters API query parameter, resulting in a case-sensitive denylist bypass. Authenticated attackers can exploit this flaw by entering uppercase variants of denylist-protected field names, thus circumventing the protective ch...
PoC for CVE-2026-85706
A vulnerability in GitLab CE/EE allows unauthenticated users to read arbitrary files due to inadequate path confinement and a lack of proper authentication checks in the repository commits API. This issue affects GitLab versions 18.7 prior to 19.1.8, 19.2 prior to 19.2.6, and 19.3 prior to 19.3.2...
PoC for CVE-2022-38181
The Arm Mali GPU kernel driver is vulnerable due to mishandled GPU memory operations, which allows unprivileged users to access freed memory. This issue affects multiple versions across the Bifrost, Valhall, and Midgard architectures, posing potential risks for system integrity and data security.
PoC for CVE-2026-87918
The WPBot plugin for WordPress prior to version 8.5.7 is vulnerable to unauthorized access due to the lack of authorization and nonce checks on several AJAX actions. This flaw allows unauthenticated attackers to exploit these actions to relay requests to configured third-party AI providers, effec...
PoC for CVE-2026-87916
The WPBot plugin for WordPress prior to version 8.6.0 is susceptible to an information disclosure vulnerability. This issue arises from the lack of proper capability and nonce checks on the AJAX action responsible for listing stored chat sessions. As a result, unauthenticated attackers can exploi...
PoC for CVE-2026-87919
The XML Feed Manager for WooCommerce plugin, prior to version 3.1.1, suffers from improper access control issues. Specifically, it fails to limit which object methods can be invoked by the product shortcode. This oversight allows users with contributor-level access to delete any WooCommerce produ...
PoC for CVE-2026-87892
The Rox Appointment Booking plugin for WordPress, prior to version 1.2.0, contains a vulnerability that fails to adequately verify the order total and the chosen payment method against its internal server-side pricing. This oversight enables unauthenticated attackers to create confirmed bookings ...
PoC for CVE-2026-87894
The Rox Appointment Booking plugin for WordPress prior to version 1.2.3 lacks proper authorization checks on its endpoint that retrieves booking confirmation details. This oversight permits unauthenticated users to enumerate sequential booking identifiers, thereby gaining access to sensitive cust...
PoC for CVE-2026-87759
The Add User Autocomplete plugin for WordPress versions prior to 1.2 is susceptible to improper access control. It fails to verify capabilities or nonce checks before allowing the creation of a pending site-membership invitation with a role provided by the user. This vulnerability enables any aut...
PoC for CVE-2026-87842
The Zonify WordPress plugin prior to version 1.0.5 has a significant security flaw that lacks the required capability or authentication checks. This vulnerability enables attackers to access the stored account login token without proper authentication. As a result, unauthorized users can exploit ...
PoC for CVE-2026-87888
The YayPricing WordPress plugin prior to version 3.5.7 is susceptible to an authorization bypass vulnerability that affects its REST API. It fails to adequately check user permissions for a specific REST route responsible for storing pricing rules. As a result, unauthorized users with subscriber-...
PoC for CVE-2026-87797
The Sprout Invoices WordPress plugin before version 20.8.16 is vulnerable to an authorization bypass flaw in its AJAX actions. This vulnerability allows authenticated users, including those with lower privileges such as subscribers, to overwrite private notes on records that do not belong to them...
PoC for CVE-2026-87891
The Rox Appointment Booking plugin for WordPress is susceptible to an authorization bypass, which allows unauthorized users to modify the holiday schedule settings. Specifically, the plugin does not enforce capability or authorization checks when saving its holiday schedule. This flaw can enable ...
PoC for CVE-2026-85681
The WP Component WordPress plugin prior to version 2.2.4 has a severe security flaw that permits unauthenticated users to execute actions without proper capability or nonce checks. Attackers can manipulate the option name and value from the incoming requests, making it possible to overwrite criti...
PoC for CVE-2026-84171
The piclect WordPress plugin version 1.0 has a critical file upload vulnerability that allows unauthenticated attackers to upload arbitrary files. Due to a lack of validation for the name and type of uploaded files, attackers can exploit this weakness to write files to a publicly accessible direc...
PoC for CVE-2026-84047
The Album Cover Finder plugin for WordPress, up to version 0.7.0, contains a security flaw that fails to adequately sanitize and escape user input within SQL queries. This oversight allows unauthenticated attackers to execute arbitrary SQL commands, potentially exposing sensitive database informa...
PoC for CVE-2026-84099
The wpstorecart plugin for WordPress, up to version 5.0.7, is susceptible to a vulnerability that allows direct, unauthenticated access to a bundled add-on. This add-on fails to adequately restrict deserialized user-supplied input, which can enable unauthenticated attackers to inject arbitrary PH...
PoC for CVE-2026-86790
The WP Highlight Box plugin allows for the integration of reusable content blocks through shortcodes. However, versions up to and including 1.0 lack proper escaping for certain shortcode attributes prior to rendering on a page. This oversight can lead to stored cross-site scripting vulnerabilitie...
PoC for CVE-2026-84023
A vulnerability in the BEAR WordPress plugin, prior to version 1.2.2, allows attackers to exploit a lack of CSRF nonce verification and user capability checks. This can enable unauthorized modifications of taxonomy terms when a privileged user is tricked into visiting a malicious page, potentiall...
PoC for CVE-2026-84024
The BEAR WordPress plugin versions earlier than 1.2.2 suffers from a CSRF vulnerability due to improper nonce verification when saving meta field configurations. This flaw permits attackers to manipulate settings by duping an authenticated administrator into visiting a malicious link, potentially...
PoC for CVE-2026-82847
The Masteriyo LMS plugin for WordPress versions prior to 3.4.1 is vulnerable due to a failure to properly sanitize and escape course field inputs in the course editor. This flaw permits users assigned the instructor role to carry out Stored Cross-Site Scripting (XSS) attacks, potentially affectin...
PoC for CVE-2026-82851
The Masteriyo LMS plugin for WordPress, prior to version 3.4.1, inherently lacks mechanisms to verify whether a user has the rightful ownership of requested records. This flaw permits users assigned the instructor role to download unrestricted content and metadata associated with any posts, inclu...
PoC for CVE-2026-84025
The BEAR WordPress plugin prior to version 1.2.2 lacks adequate ownership validation on several handlers. This oversight allows users with restrictions to leverage user-supplied identifiers to access confidential product data. Consequently, users can inadvertently view product information belongi...
PoC for CVE-2026-81742
The BE REST Endpoints Plugin for WordPress prior to version 1.0.0 is susceptible to an authorization bypass vulnerability. This flaw permits unauthorized users to read, create, update, and delete widgets without any authentication checks. Furthermore, the plugin fails to sanitize input values, ma...
PoC for CVE-2026-81429
The WPBakery Page Builder plugin for WordPress lacks proper Cross-Site Request Forgery (CSRF) protection in its template import functionality. This oversight allows an attacker to exploit this vulnerability by crafting a malicious request, enabling an authenticated administrator to unintentionall...
PoC for CVE-2026-81402
The DS Ad Rotator plugin for WordPress versions up to 0.8 is susceptible to a serious vulnerability due to the lack of capability checks, nonce validation, and file-type restrictions in its image upload handler. This oversight allows unauthenticated attackers to upload arbitrary files, including ...
PoC for CVE-2026-82845
The Masteriyo LMS WordPress plugin versions prior to 3.4.1 contain a deserialization vulnerability that permits unauthorized execution of arbitrary PHP objects. This security flaw allows users with minimal access to insert user-supplied metadata into the application, which can be exploited to exe...
PoC for CVE-2026-80491
The SAMO Forms plugin for WordPress, prior to version 1.0.0, contains a vulnerability that fails to properly sanitize and escape user input in SQL queries during various unauthenticated actions. This flaw enables attackers to potentially execute SQL injection attacks, compromising the integrity a...
PoC for CVE-2026-81090
The Gpx2Graphics WordPress plugin, up to version 0.3, is susceptible to a cross-site request forgery (CSRF) vulnerability that allows attackers to bypass file upload restrictions. This exploitation occurs because the plugin lacks necessary CSRF checks and type validation for uploaded files. As a ...
PoC for CVE-2026-80494
The Yogeta WP Cloud WordPress plugin prior to version 1.0 is susceptible to a file retrieval vulnerability. This flaw arises from the plugin's failure to properly validate user-supplied file paths before using them in file-read functions on a public endpoint, which does not implement any form of ...
PoC for CVE-2026-78152
The SureRank SEO WordPress plugin, prior to version 1.10.1, inadvertently exposes users' registered email addresses through structured data on public pages. This vulnerability enables unauthenticated visitors to retrieve email addresses of any user who has published content, compromising their pr...
PoC for CVE-2026-77752
The Temporary Login Without Password plugin for WordPress, prior to version 1.9.9, lacks robust verification for user permissions. This deficiency enables an administrator of a single site within a multisite network to unwittingly grant super admin rights to an unauthorized user. Additionally, it...
PoC for CVE-2026-77753
The Temporary Login Without Password plugin for WordPress versions prior to 1.9.9 allows temporary users to create and retain Application Passwords. This vulnerability permits such users to maintain access via REST and XML-RPC even after temporary credentials should have expired or been revoked b...
PoC for CVE-2026-77005
The CODE MONKEYS PROPOSALS WordPress plugin versions up to 1.0.1 suffers from a critical security issue due to its failure to properly validate user-supplied file paths when deleting files. This flaw allows authenticated users, including those with limited permissions such as subscribers, to dele...
PoC for CVE-2026-75800
The Frontegg SAML SSO plugin for WordPress, up to version 1.0.1, contains a significant vulnerability that fails to properly validate the signature and issuer of SAML authentication responses. This oversight permits malicious actors to gain unauthorized access to user accounts, including those wi...
PoC for CVE-2026-77006
The WebTotem Backups plugin for WordPress prior to version 1.0.1 contains a vulnerability where it fails to validate user-supplied file paths and does not adequately check the permissions of users making requests. This oversight allows authenticated users, even those with the lowest privileges (l...