Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2024-1086

LinuxKernel🟣 EPSS 28%7.8HIGH
Linux kernel netfilter use-after-free vulnerability can lead to loc...

A use-after-free vulnerability exists in the nf_tables component of the Linux kernel, specifically within the nft_verdict_init() function. This vulnerability can be exploited when a drop error is incorrectly handled, resulting in a potential double free situation during packet verdict processing....

Discovered 1 hour ago

PoC for CVE-2026-19193

JiangminAntivirus8.5HIGH
Access Control Vulnerability in Jiangmin Antivirus 21

A vulnerability has been identified in Jiangmin Antivirus 21 that affects the MessageNotifyCallback function within the kvcore.sys library of the Minifilter Port. This flaw allows for improper access controls, enabling local attackers to potentially exploit the system through unauthorized manipul...

Discovered 2 hours ago

PoC for CVE-2026-19192

DeepcoolDisplayservice8.5HIGH
Access Control Weakness in DeepCool DisplayService Affects User Sec...

A vulnerability exists in DeepCool DisplayService version 1.2.12 that allows for improper access controls related to the handling of the executable file DeepCoolDisplayService.exe. This flaw can be exploited locally, potentially enabling an attacker to manipulate the service and gain unauthorized...

PoC for CVE-2026-19191

StablebitDrivepool8.5HIGH
Local Privilege Escalation in StableBit DrivePool by StableBit

A security flaw has been identified in StableBit DrivePool version 2.3.13.1687, affecting the DrivePoolService component. This vulnerability enables local users to manipulate permissions within the application, potentially leading to unauthorized access and control over sensitive operations. The ...

Discovered 3 hours ago

PoC for CVE-2026-19190

StablebitScanner8.5HIGH
Local Privilege Escalation in StableBit Scanner by StableBit

A local execution vulnerability has been discovered in StableBit Scanner version 2.6.13.4088, which affects the ScannerService component located in C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe. This issue can lead to permission manipulation, allowing unauthorized access to...

PoC for CVE-2026-18649

Red HatRed Hat Enterprise Lin...7.5HIGH
Denial of Service Vulnerability in GStreamer's RTP Depayloader Elem...

A vulnerability exists in the GStreamer gst-plugins-good package where the rtph264depay and rtph265depay RTP depayloader elements fail to enforce a limit on the size of the reassembly buffer utilized during the processing of fragmented RTP packets. This flaw permits a remote, unauthenticated atta...

Discovered 4 hours ago

PoC for CVE-2026-19189

Power SofwarePoweriso8.5HIGH
Local Privilege Escalation in Power Software PowerISO by Power Soft...

A security vulnerability has been identified in Power Software's PowerISO version 9.3.0.0, which affects the kernel driver component found at C:\Windows\System32\drivers\scdemu.sys. This flaw enables improper privilege management, allowing attackers with local access to exploit the issue. The pot...

Discovered 7 hours ago

PoC for CVE-2026-56164

MicrosoftMicrosoft Sharepoint E...🟣 EPSS 22%5.3MEDIUM
Authentication Bypass in Microsoft Office SharePoint by Microsoft

A vulnerability exists in Microsoft Office SharePoint where a critical function lacks proper authentication. This flaw allows unauthorized attackers to gain elevated privileges over a network, potentially leading to unauthorized actions and data exposure. Microsoft has released guidance for mitig...

Discovered 8 hours ago

PoC for CVE-2026-0300

Palo Alto NetworksCloud Ngfw🟣 EPSS 32%8.7HIGH
Buffer Overflow Vulnerability in Palo Alto Networks User-ID™ Authen...

A buffer overflow vulnerability exists within the User-ID™ Authentication Portal of Palo Alto Networks PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by manipulating specially crafted packets. To miti...

PoC for CVE-2026-70636

FlowiseaiFlowise8.7HIGH
Authentication Bypass Vulnerability in Flowise by Caycon

Flowise versions up to 3.1.4 have a significant security vulnerability that allows unauthenticated attackers to exploit the OAuth2 credential refresh endpoint. This is achieved through a flaw in the prefix-based whitelist matching within the authentication middleware. By sending a specifically cr...

PoC for CVE-2026-67622

FlowiseaiFlowise8.5HIGH
Insecure Direct Object Reference in Flowise OpenAI Integration

The Flowise OpenAI Assistants integration, particularly in version 3.1.4, is susceptible to an insecure direct object reference vulnerability. This flaw enables authenticated attackers to gain unauthorized access to sensitive credentials linked to other workspaces. By exploiting this vulnerabilit...

PoC for CVE-2026-67621

FlowiseaiFlowise7.2HIGH
Authorization Flaw in Flowise Affects Document Store Operations

The Flowise product versions up to 3.1.4 exhibit a significant vulnerability due to missing authorization checks. This flaw enables authenticated users with mere view-level permissions to carry out unauthorized actions on the document store. By exploiting unprotected mutation endpoints, an attack...

Discovered 9 hours ago

PoC for CVE-2026-19110

DataGearDatagear4.8MEDIUM
Cross Site Scripting Vulnerability in DataGear Product by DataGear

A cross site scripting vulnerability exists in DataGear products prior to version 5.0.0, specifically in the function HtmlTplDashboardWidgetHtmlRenderer located in HtmlTplDashboardWidgetHtmlRenderer.java. This flaw allows attackers to manipulate the Title argument, which can lead to unauthorized ...

PoC for CVE-2026-0163

GoogleAndroid9.8CRITICAL
Use After Free Vulnerability in Android Products by Google

A significant vulnerability exists in the Android operating system, specifically within the vpu_ioctl.c file, where multiple functions permit a use after free scenario. This flaw could allow an attacker to escalate privileges remotely without requiring any interaction from users, making it partic...

PoC for CVE-2026-19108

Mz AutomationLibiec618504.8MEDIUM
Use After Free Vulnerability in MZ Automation libiec61850 Version 1...

A use after free vulnerability was identified in MZ Automation's libiec61850 version 1.6.1 impacting the deleteDataSetValuesShadowBuffer function within the URCB Revalidation component. This flaw enables local attackers to manipulate memory allocation, potentially leading to application crashes o...

PoC for CVE-2026-19071

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability has been identified in the itsourcecode Hospital Management System 1.0, specifically within the /viewappointment.php file. An unvalidated input in the function handling 'delid' parameters exposes the application to SQL injection attacks. This flaw allows an attacker to manipulate ...

Discovered 10 hours ago

PoC for CVE-2026-19070

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A SQL injection vulnerability has been identified in the itsourcecode Hospital Management System version 1.0. This flaw affects the file /viewadmin.php, where manipulation of the 'delid' argument allows attackers to execute arbitrary SQL queries on the database. The exploit can be executed remote...

PoC for CVE-2026-19069

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management Sys...

A SQL injection vulnerability exists in the itsourcecode Hospital Management System 1.0, specifically affecting the /treatmentrecord.php file. This vulnerability allows remote attackers to manipulate the 'editid' parameter, leading to unauthorized database access and potential exposure of sensiti...

PoC for CVE-2026-67598

EmlogEmlog9.1CRITICAL
TLS Certificate Validation Flaw in Emlog Pro by Emlog

Emlog Pro, as of version 2.6.23, is susceptible to a TLS certificate validation vulnerability that allows attackers in the same network vicinity to intercept HTTPS requests. This exploitation arises from the unconditional disabling of the CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST options ...

PoC for CVE-2026-19068

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Weakness in itsourcecode Hospital Management System

A vulnerability exists in the itsourcecode Hospital Management System version 1.0, specifically in the treatmentdetail.php file. An attacker can exploit this weakness by manipulating the 'patientid' argument, which may lead to unauthorized access to the database. The attack can be executed remote...

Discovered 11 hours ago

PoC for CVE-2026-19067

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability has been identified in the itsourcecode Hospital Management System 1.0 that allows an attacker to perform SQL injection through the manipulation of the 'editid' argument in the '/treatment.php' file. This flaw can be exploited remotely, posing a significant risk as the exploit has...

Discovered 12 hours ago

PoC for CVE-2025-15674

WordPressPassster2.7LOW
Unauthorized Access Vulnerability in Passster Plugin for WordPress

The Passster WordPress plugin prior to version 4.3.7 contains a vulnerability that allows users with low privileges, specifically those holding the edit_posts capability, to bypass password protection on globally protected content. When global protection is enabled, this flaw allows contributors ...

PoC for CVE-2026-16620

WordPressWPc Name Your Price Fo...7.5HIGH
Server-Side Price Enforcement Flaw in WPC Name Your Price for WooCo...

The WPC Name Your Price for WooCommerce WordPress plugin, prior to version 2.2.5, is vulnerable due to inadequate server-side enforcement of price allowlists for products set to 'Select' price mode. This oversight allows unauthenticated users to manipulate product prices below the merchant's appr...

PoC for CVE-2026-16619

WordPressMiniorange 2fa7.5HIGH
Weakness in miniOrange 2FA Plugin for WordPress Allows Account Take...

The miniOrange 2FA WordPress plugin versions prior to 6.2.8 contain a flaw that permits unlimited second-factor verification attempts. The plugin tracks these attempts using a client-supplied identifier, which is changed on every login. This design oversight allows an attacker who is aware of a u...

PoC for CVE-2026-19062

ChiuwingyanHouse6.9MEDIUM
SQL Injection Vulnerability in Chiuwingyan House Product

A vulnerability has been identified in Chiuwingyan House, specifically affecting the file /paid/selectall.action. This flaw arises from improper handling of the argument 'zuname', leading to SQL injection, which can be exploited remotely. The vendor has been notified of the issue but has not resp...

PoC for CVE-2026-16067

WordPressEvent Booking Manager ...5.3MEDIUM
Ticket Booking Vulnerability in Event Booking Manager for WooCommer...

The Event Booking Manager for WooCommerce (Pro) plugin versions prior to 5.0.3 inadequately validates ticket pricing during native checkout. Instead of re-confirming the configured ticket price on the server, it relies on the client-supplied price. This flaw permits unauthorized users to register...

PoC for CVE-2026-15256

WordPressNinja Forms4.8MEDIUM
Shortcode Injection Flaw in Ninja Forms Plugin by WordPress

The Ninja Forms plugin for WordPress allows unauthenticated adversaries to exploit a vulnerability that arises when user-supplied query-string input is not adequately sanitized. This flaw enables attackers to input data into a form field that bypasses validation, processing it as a shortcode. Whe...

PoC for CVE-2026-17032

SupsysticGoogle-maps-easy-pro9.8CRITICAL
Malicious Code Vulnerability in Supsystic Pro Plugins by Supsystic

Multiple Supsystic Pro plugins were found to contain malicious code due to a compromise of the vendor's update server. This vulnerability permits unauthenticated attackers to execute a second-stage payload, which can lead to the exfiltration of sensitive credentials and data. Furthermore, this ex...

PoC for CVE-2026-13342

WordPressSecurity Optimizer5.3MEDIUM
Security Optimizer Plugin Security Flaw Exposes Login Interface

The Security Optimizer WordPress plugin, versions 1.5.8 through 1.6.4, has a critical security flaw that allows bypassing the IP-based login restriction feature. This vulnerability occurs due to improper validation of requests, enabling unauthenticated users from non-allowlisted IPs to access the...

PoC for CVE-2026-15208

WordPressRegistrationmagic5.3MEDIUM
Improper Payment Verification in RegistrationMagic WordPress Plugin

The RegistrationMagic plugin for WordPress, prior to version 6.0.9.5, has a significant security flaw that undermines its payment verification process. The plugin fails to verify critical payment details—such as the amount, currency, payee, and prior usage—against the registration it is finalizin...

PoC for CVE-2026-15149

WordPressWP Hotel Booking5.3MEDIUM
Unauthenticated Reservation Exploit in WP Hotel Booking Plugin by W...

The WP Hotel Booking plugin prior to version 2.3.3 includes a critical input validation flaw, where it fails to ensure that room quantities and order totals are non-negative. This oversight permits unauthenticated users to manipulate cart data, potentially allowing them to secure confirmed reserv...

PoC for CVE-2026-15147

WordPressFive Star Restaurant R...5.3MEDIUM
Payment Notification Vulnerability in Five Star Restaurant Reservat...

The Five Star Restaurant Reservations plugin for WordPress prior to version 2.7.23 contains a flaw in its handling of payment notifications. It does not properly authenticate incoming payment messages, allowing unauthorized actors to manipulate existing reservations. Attackers can mark any pendin...

PoC for CVE-2026-10524

WordPressCocart7.5HIGH
Price Manipulation Vulnerability in CoCart WordPress Plugin

The CoCart WordPress plugin, especially in versions prior to 4.9.0, has a significant flaw where it does not properly validate user-supplied price values against the actual prices of products. This weakness allows unauthenticated users to bypass typical security measures, enabling them to set arb...

Discovered 13 hours ago

PoC for CVE-2026-14831

WordPressEasy Booking5.3MEDIUM
Insecure Booking Duration in Easy Booking WordPress Plugin

The Easy Booking WordPress plugin prior to version 3.5.0 lacks proper server-side enforcement of the minimum booking duration for products. This vulnerability enables unauthorized users to bypass the configured settings, facilitating the placement of bookings that do not meet the minimum duration...

PoC for CVE-2026-14936

WordPressSimple Membership5.3MEDIUM
Membership Activation Flaw in Simple Membership Plugin by WordPress

The Simple Membership plugin for WordPress, prior to version 4.7.7, exposes a vulnerability that allows unauthenticated individuals to activate or extend memberships. This occurs because the plugin fails to verify that a PayPal payment notification is directed to the configured merchant account o...

PoC for CVE-2026-12901

WordPressGetpaid5.9MEDIUM
Payment Notification Forgery in GetPaid WordPress Plugin

The GetPaid WordPress plugin prior to version 2.8.55 contains a critical flaw that permits unauthenticated attackers to manipulate incoming Worldpay payment notifications. This vulnerability can be exploited to falsely mark pending invoices as paid, effectively allowing the attacker to bypass pay...

PoC for CVE-2026-12501

WordPressWP Travel Engine5.3MEDIUM
Insecure Payment Notification Handling in WP Travel Engine Plugin b...

The WP Travel Engine plugin in WordPress fails to verify incoming PayPal payment notifications against the site's configured merchant account and the order total. This lax verification process allows unauthorized attackers to mark bookings as fully paid by using tokens from a compromised payment ...

PoC for CVE-2026-15152

WordPressWP Hotel Booking5.3MEDIUM
Payment Notification Vulnerability in WP Hotel Booking Plugin by Wo...

The WP Hotel Booking plugin for WordPress has a vulnerability where it fails to verify the authenticity of payment notifications. An attacker can exploit this by submitting false payment notifications, allowing them to mark bookings as fully paid without actual payment being made. This could lead...

PoC for CVE-2026-14842

WordPressEvents Made Easy5.3MEDIUM
Payment Processing Flaw in Events Made Easy Plugin by WordPress

The Events Made Easy WordPress plugin, prior to version 3.1.2, exhibits a critical flaw in its payment processing mechanism. This vulnerability allows unauthenticated users to exploit the system by binding payment authorization tokens incorrectly. Consequently, an attacker can pay a minimal fee f...

PoC for CVE-2026-14225

WordPressEasy Appointments2.7LOW
Shortcode Execution Vulnerability in Easy Appointments Plugin by Wo...

The Easy Appointments WordPress plugin, up to version 3.12.26, is affected by a flaw in its handling of shortcode input. This vulnerability arises from insufficient validation during a block-rendering process, where the plugin only checks the first tag of a supplied string against a predefined al...

PoC for CVE-2026-14812

WordPressPremium Seo10CRITICAL
Unauthenticated Backdoor in Premium SEO WordPress Plugin by Unknown...

The Premium SEO WordPress plugin contains a serious vulnerability that allows unauthorized access through an unauthenticated backdoor. This flaw creates a hidden administrator account, enabling potential attackers to gain full control over the affected WordPress site. In certain builds, it also f...

PoC for CVE-2026-13399

WordPressPayment Plugins For Pa...7.5HIGH
Authorization Bypass in Payment Plugins for PayPal WooCommerce by W...

The Payment Plugins for PayPal WooCommerce before version 2.0.20 lacks necessary authorization checks on a critical REST endpoint. This vulnerability enables unauthorized users to bypass the payment process, potentially leading to unauthorized transactions or exposure to sensitive payment data. P...

PoC for CVE-2026-14306

WordPressTutor Lms4.3MEDIUM
Improper Access Control in Tutor LMS Plugin by WordPress

The Tutor LMS WordPress plugin prior to version 3.9.14 contains a flaw in its access control mechanism. The vulnerability allows authenticated users who have subscriber-level access or higher and are enrolled in at least one course to bypass restrictions on protected content. This misconfiguratio...

PoC for CVE-2026-12584

WordPressPayment Gateway For Re...7.5HIGH
Payment Gateway Vulnerability in Redsys & WooCommerce Lite Plugin b...

The Payment Gateway for Redsys & WooCommerce Lite plugin, prior to version 7.0.2, contains a flaw where it fails to validate the authenticity of payment notifications from providers. This oversight allows attackers to impersonate legitimate payment confirmations, thus marking orders as paid witho...

PoC for CVE-2026-11361

WordPressFormidable Forms5.9MEDIUM
Vulnerability in Formidable Forms Plugin Allows Unauthorized Access

The Formidable Forms plugin for WordPress prior to version 6.32.1 contains a flaw that allows unauthenticated users to bypass the necessary validation for PayPal subscription payments. As a result, these users can improperly trigger actions typically reserved for paying customers, including acces...

PoC for CVE-2026-10599

WordPressIntegrate Phonepe With...7.5HIGH
Unauthenticated Payment Processing Flaw in WooCommerce Plugin from ...

The Integrate PhonePe with WooCommerce WordPress plugin prior to version 1.2.1 is susceptible to an improper authorization vulnerability. This issue allows an attacker to bypass payment verification processes by reusing a valid payment transaction. Consequently, an attacker can manipulate the sta...

PoC for CVE-2026-19060

FoundationagentsMetagpt4.8MEDIUM
Code Injection Vulnerability in FoundationAgents MetaGPT Product by...

A vulnerability has been identified in FoundationAgents' MetaGPT product, affecting versions up to 0.8.2, which enables local manipulation leading to code injection. This vulnerability occurs through an unknown function within the application, allowing attackers to execute malicious code if they ...

PoC for CVE-2026-11976

MonsterInsightsMonsterinsights Pro10CRITICAL
Compromised Update Distribution for MonsterInsights Pro by MonsterI...

The update distribution for MonsterInsights Pro was compromised, involving the presence of a malicious file named 'class-system-check.php' in both version 10.2.2 and the rolled-back version 10.2.0. This breach occurred through the official update bucket hosted on an Amazon S3 server. A single att...

PoC for CVE-2026-5336

WordPressDatapress (dataverse I...6.8MEDIUM
Access Control Flaw in DataPress Plugin Exposes User Data

The DataPress (Dataverse Integration) plugin for WordPress prior to version 2.91 contains an access control vulnerability that inadequately restricts access to its template rendering feature. This oversight allows users with low-level roles, such as Contributor, to access sensitive data. Specific...

PoC for CVE-2026-19059

FoundationagentsMetagpt4.8MEDIUM
Path Traversal Vulnerability in FoundationAgents MetaGPT for Local ...

A path traversal vulnerability exists in FoundationAgents MetaGPT up to version 0.8.2, particularly affecting the read function in metagpt/tools/libs/editor.py. This vulnerability allows attackers with local access to manipulate file paths, potentially enabling unauthorized file access. The explo...