Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2026-9577

WordPressPost Status Notifier Lite
Reflected Cross-Site Scripting Vulnerability in Post Status Notifie...

The Post Status Notifier Lite WordPress plugin prior to version 1.13.0 is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability. This occurs due to insufficient sanitization of the `mod` URL parameter when reflected on the admin settings page. An attacker can exploit this vulnerabil...

PoC for CVE-2026-9066

WordPressWP Compress
Reflected XSS Vulnerability in WP Compress Plugin for WordPress

The WP Compress plugin for WordPress prior to version 7.10.04 is susceptible to a Reflected XSS vulnerability due to improper validation of a query parameter that directs the asset CDN host. This security flaw allows attackers to manipulate script URLs, injecting malicious JavaScript that execute...

PoC for CVE-2026-14291

WordPressSecurity-ninja-premium
Two-Factor Authentication Bypass in Security Ninja Premium WordPres...

The Security Ninja Premium WordPress plugin versions prior to 5.290 have a significant flaw in their two-factor authentication implementation. An unauthenticated attacker equipped with a user's password can bypass the required one-time code needed for authentication. This vulnerability compromise...

PoC for CVE-2026-12082

WordPressPraison Ai Seo
Authorization Flaw in Praison AI SEO WordPress Plugin Exposes Confi...

The Praison AI SEO WordPress plugin versions prior to 5.0.7 contain an authorization bypass vulnerability that permits unauthorized users to modify permalinks for published posts. Additionally, this flaw enables access to sensitive configuration data within the plugin, which could compromise site...

Discovered 3 hours ago

PoC for CVE-2023-36003

MicrosoftWindows 10 Version 18096.7MEDIUM
Elevation of Privilege Vulnerability Affects XAML Diagnostics

XAML Diagnostics Elevation of Privilege Vulnerability

Discovered 4 hours ago

PoC for CVE-2025-64512

PDFminerPDFminer.six8.6HIGH
Arbitrary Code Execution in Pdfminer.six by Malicious PDF Files

Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...

Discovered 5 hours ago

PoC for CVE-2026-58138

Conductor-ossConductor9.3CRITICAL
Unauthenticated Remote Code Execution in Orkes Conductor by Orkes

An unauthenticated remote code execution vulnerability in Orkes Conductor versions prior to 3.30.2 could allow remote attackers to execute arbitrary operating system commands by submitting malicious JavaScript or Python expressions through workflow definitions to the workflow API endpoint without...

Discovered 6 hours ago

PoC for CVE-2026-63030

WordPressWordPress🟣 EPSS 39%9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2024-9264

GrafanaGrafana🟣 EPSS 98%9.4CRITICAL
Grafana SQL Expressions Vulnerability: Command Injection and Local ...

The experimental SQL Expressions feature in Grafana enables users to evaluate `duckdb` queries which can contain user input. However, the queries are inadequately sanitized prior to being processed by `duckdb`, creating a vulnerability that could lead to command injection and local file inclusion...

Discovered 8 hours ago

PoC for CVE-2026-16632

BoazsegevFacil.io6.9MEDIUM
Improper Input Validation in WebSocket Frame Parser of Facil.io by ...

A vulnerability has been identified in the facil.io library, affecting versions up to 0.7.4. The flaw resides in the websocket_on_protocol_error function located in the websocket_parser.h file. This vulnerability arises from improper input validation when manipulating the argument on_message, all...

PoC for CVE-2026-16631

Node.jsPublint4.8MEDIUM
OS Command Injection Vulnerability in publint Package Manager by No...

A vulnerability has been identified in the publint package manager affecting versions up to 0.1.4. This vulnerability is linked to the child_process.exec function within the src/node/pack.js file. It enables an attacker to execute arbitrary operating system commands through manipulated input. The...

Discovered 9 hours ago

PoC for CVE-2026-16630

SyncfusionEj2-javascript-ui-cont...4.8MEDIUM
OS Command Injection Vulnerability in Syncfusion EJ2 JavaScript UI ...

A security vulnerability has been discovered in Syncfusion's EJ2 JavaScript UI Controls that allows for an OS command injection via the child_process.exec function in package.json. This vulnerability is present in versions up to 33.2.3. Attackers must exploit this vulnerability locally to manipul...

Discovered 10 hours ago

PoC for CVE-2026-63030

WordPressWordPress🟣 EPSS 39%9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

Discovered 11 hours ago

PoC for CVE-2026-16628

HerokuOclif4.8MEDIUM
OS Command Injection Vulnerability in oclif by Heroku

A security vulnerability exists in oclif versions up to 4.23.16, allowing local users to exploit the 'child_process.exec' functionality in the JIT Plugin Entry Handler. By manipulating the 'jitPlugins' argument, an attacker can execute arbitrary operating system commands, potentially leading to u...

PoC for CVE-2024-3094

🟣 EPSS 86%10CRITICAL
Malicious Code Discovered in xz Upstream Tarballs, Affecting liblzm...

The XZ utility has been compromised due to malicious code introduced in the upstream tarballs starting from version 5.6.0. A sophisticated obfuscation technique is employed where the liblzma build process extracts a prebuilt object file hidden within a disguised test file in the source code. This...

PoC for CVE-2026-45729

ThorvgThorvg4.3MEDIUM
Null Pointer Dereference in Thor Vector Graphics Engine

A null pointer dereference vulnerability was identified in the Thor Vector Graphics Engine (ThorVG) prior to version 1.0.5. This vulnerability can cause the engine to crash when untrusted SVG data is processed through the Picture::load() function via the SvgLoader::run(). Attackers can exploit th...

Discovered 12 hours ago

PoC for CVE-2026-63030

WordPressWordPress🟣 EPSS 39%9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2026-56139

ApacheApache Camel Undertow5.3MEDIUM
Sensitive Information Disclosure in Apache Camel Undertow Component

The Apache Camel Undertow Component contains a vulnerability that allows unauthorized clients to receive detailed error messages, including Java stack traces, during route processing failures. This occurs due to a misconfiguration of the muteException option, which defaults to false. This can lea...

Discovered 13 hours ago

PoC for CVE-2026-55994

ApacheApache Camel Iggy7.5HIGH
Server-Side Request Forgery and Information Exposure in Apache Came...

In the Apache Camel framework, the Iggy component has a vulnerability that allows unauthorized actors to exploit improper input validation, resulting in Server-Side Request Forgery (SSRF) and exposure of sensitive information. The issue arises as the Iggy component does not filter Camel-internal ...

PoC for CVE-2026-55993

ApacheApache Camel Atmospher...7.5HIGH
Improper Input Validation and SSRF in Apache Camel's Atmosphere Web...

A vulnerability in the Atmosphere Websocket Component of Apache Camel allows attackers to exploit improper input validation in inbound WebSocket queries. The absence of a HeaderFilterStrategy enables clients to inject control headers into the Camel Exchange. This results in potential server-side ...

PoC for CVE-2025-64512

PDFminerPDFminer.six8.6HIGH
Arbitrary Code Execution in Pdfminer.six by Malicious PDF Files

Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...

Discovered 15 hours ago

PoC for CVE-2026-65013

OnlookRepo8.7HIGH
Broken Object Level Authorization in Onlook Product by Onlook Dev

The Onlook product version 0.2.32 has a broken object level authorization vulnerability, allowing authenticated attackers to exploit tRPC API endpoints. By supplying arbitrary UUID values to procedures such as project.get, member.remove, and chat.conversation.delete, attackers can gain unauthoriz...

PoC for CVE-2026-65012

Invoke-aiInvokeai6.3MEDIUM
Unauthenticated Directory Enumeration in InvokeAI by Stability AI

InvokeAI prior to version 6.13.7 presents a vulnerability in the /api/v2/models/scan_folder endpoint, which allows unauthenticated users to exploit the scan_path parameter. This flaw permits attackers to recursively enumerate server filesystem directories, effectively exposing sensitive informati...

Discovered 16 hours ago

PoC for CVE-2026-64828

FroidenTabletrack5.3MEDIUM
Stored Cross-Site Scripting Vulnerability in Froiden TableTrack

Froiden TableTrack versions up to 1.3.10 are susceptible to a stored cross-site scripting vulnerability through the order notes field. This flaw permits unauthenticated attackers to inject arbitrary HTML and JavaScript into the application, allowing for malicious payloads to execute within the ad...

Discovered 19 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 21 hours ago

PoC for CVE-2026-50522

MicrosoftMicrosoft Sharepoint E...🟣 EPSS 20%9.8CRITICAL
Deserialization Vulnerability in Microsoft SharePoint by Microsoft

The vulnerability allows an attacker to send specially crafted payloads to Microsoft Office SharePoint, potentially resulting in unauthorized remote code execution. This security flaw occurs due to the improper handling of untrusted data. If exploited, it could enable malicious actors to execute ...

Discovered 1 day ago

PoC for CVE-2026-25632

WaterfuturesEpyt-flow10CRITICAL
Remote Code Execution Vulnerability in EPyT-Flow Python Package

The EPyT-Flow Python package, which facilitates the generation of hydraulic and water quality scenario data for water distribution networks, contains a vulnerability that enables remote code execution. Prior to version 0.16.1, the package's REST API incorrectly processes attacker-manipulated JSON...

PoC for CVE-2024-27867

AppleAirpods4.3MEDIUM
Improved State Management Fixes Authentication Issue

The CVE-2024-27867 vulnerability affects a wide range of Apple’s wireless audio devices, including AirPods (2nd generation and later), AirPods Pro (all models), AirPods Max, Powerbeats Pro, and Beats Fit Pro. It allows an attacker within Bluetooth range to spoof the intended source device and gai...

PoC for CVE-2026-12987

WordPressEvents Manager7.5HIGH
PHP Object Injection Vulnerability in Events Manager WordPress Plugin

The Events Manager plugin for WordPress versions prior to 7.3.7 is vulnerable due to improper handling of booking-registration data in No-User-Account Booking Mode. Specifically, a registration field supplied by the booker is stored as booking metadata and later deserialized without restrictions ...

PoC for CVE-2026-14322

WordPressTimetics5.3MEDIUM
WordPress Timetics Plugin Vulnerability Allows Unauthenticated Book...

The Timetics WordPress plugin, prior to version 1.0.57, has a significant vulnerability that allows unauthorized users to create fully-approved bookings for paid appointments. This occurs due to the lack of enforcement of a pending or unpaid status for new bookings made through unsupported paymen...

PoC for CVE-2026-12968

WordPressProduct Addons And Pro...8.8HIGH
Unauthenticated File Upload Vulnerability in Product Addons and Opt...

The Product Addons and Product Options With Custom Fields plugin for WordPress prior to version 1.6.15 is susceptible to an unauthenticated file upload vulnerability. This flaw allows attackers to exploit a file-upload endpoint that fails to properly restrict access, letting an unauthenticated us...

PoC for CVE-2026-57588

TenableNessus1.6LOW
SQL Injection Vulnerability in Nessus by Tenable

A SQL injection vulnerability exists in Nessus that allows attackers to create a harmful scan result file. When a privileged user imports this file, it may result in malicious SQL being injected into the scan results database. This exploitation could lead to unauthorized access and potential data...

PoC for CVE-2026-60137

WordPressWordPress🟣 EPSS 20%5.9MEDIUM
SQL Injection Vulnerability in WordPress Core Affecting Multiple Ve...

A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...

PoC for CVE-2026-60137

WordPressWordPress🟣 EPSS 20%5.9MEDIUM
SQL Injection Vulnerability in WordPress Core Affecting Multiple Ve...

A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...

PoC for CVE-2025-32432

CraftcmsCms🟣 EPSS 100%10CRITICAL
Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic

Craft CMS, a customizable content management system, has a remote code execution vulnerability present in specific versions. Attackers could exploit this flaw to execute arbitrary code on the server, posing a significant security risk. The affected versions span from 3.0.0-RC1 to just before 3.9....

PoC for CVE-2026-16492

UmijsUmi5.1MEDIUM
OS Command Injection Vulnerability in umijs GIT File Helper

A security weakness has been discovered in the GIT File Helper component of umijs. Specifically, the function git.getFileCreateInfo located in packages/utils/src/getFileGitIno.ts is susceptible to OS command injection. This vulnerability could enable attackers to execute arbitrary commands on the...

PoC for CVE-2026-16490

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A security vulnerability has been identified in itsourcecode Hospital Management System 1.0, specifically within an unspecified function of the /prescription.php file. This flaw allows attackers to inject malicious SQL queries through the manipulation of the 'editid' argument, leading to potentia...

PoC for CVE-2026-16489

jsforceJsforce4.8MEDIUM
OS Command Injection Vulnerability in jsforce Library by jsforce

A vulnerability has been discovered in the jsforce library, specifically in the function _execCommand located in lib/registry/sfdx.js. This flaw allows for os command injection, posing a risk to local environments where the code is executed. Exploitation of this vulnerability can lead to unauthor...

PoC for CVE-2026-16488

QusetionsMinicode-python2.3LOW
OS Command Injection Vulnerability in QUSETIONS MiniCode-Python

A security flaw was identified in QUSETIONS MiniCode-Python version 0.1.0, specifically impacting the subprocess.Popen function within the Project File Handler component. This vulnerability allows for potential OS command injection, creating a pathway for attackers to execute arbitrary commands o...

PoC for CVE-2026-16486

SourcecodesterClass And Exam Timetab...5.3MEDIUM
Cross Site Scripting Vulnerability in SourceCodester Class and Exam...

A vulnerability exists in SourceCodester's Class and Exam Timetabling System 1.0 within the /BSIS.php file. This vulnerability enables an attacker to manipulate the 'day' argument, which can lead to Cross Site Scripting (XSS) attacks. Since the exploit can be initiated remotely, it poses a signif...

PoC for CVE-2026-16485

SourcecodesterClass And Exam Timetab...5.3MEDIUM
Cross Site Scripting Vulnerability in SourceCodester Class and Exam...

A cross site scripting vulnerability exists in the SourceCodester Class and Exam Timetabling System 1.0, specifically related to the manipulation of the 'day' argument in the /class.php file. This flaw enables an attacker to execute arbitrary scripts in the user's browser, which can compromise se...

PoC for CVE-2026-53913

ApacheApache Camel Keycloak9.8CRITICAL
Improper Authentication in Apache Camel Keycloak Component

The Apache Camel Keycloak Component contains a vulnerability where improper authentication leads to potential unauthorized access. The KeycloakSecurityPolicy’s default configuration may allow requests with invalid tokens to bypass checks entirely. This means that as long as a request carries a no...

PoC for CVE-2026-16484

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A vulnerability has been identified in the SourceCodester Class and Exam Timetabling System 1.0, specifically within the /edit_subjecta.php file. This vulnerability allows for SQL injection attacks through manipulation of the argument ID, potentially enabling an attacker to execute arbitrary SQL ...

PoC for CVE-2026-8989

AutelMaxicharger Single8.6HIGH
Unrestricted Access to Firmware in Autel Maxi Charger by Autel

The Autel Maxi Charger Single firmware version V1.03.51 contains a significant vulnerability that allows unauthorized access to the NXP i.MX6 recovery mode via exposed hardware recovery pins. This flaw permits attackers with physical access to execute malicious code, enabling them to modify or ex...

PoC for CVE-2026-27654

F5Nginx Open Source🟣 EPSS 22%8.8HIGH
Buffer Overflow Vulnerability in NGINX Open Source and NGINX Plus

A vulnerability exists within the ngx_http_dav_module of NGINX Open Source and NGINX Plus that can be exploited to trigger a buffer overflow in the NGINX worker process. This scenario is possible when configuration files utilize the DAV module's MOVE or COPY methods combined with specific prefix ...

PoC for CVE-2026-63080

AptabaseAptabase7.1HIGH
SQL Injection Vulnerability in Aptabase's ClickHouse Query Backend

A SQL injection vulnerability exists within Aptabase's ClickHouse query backend, stemming from commit 5a89368. This flaw enables authenticated attackers to exploit unsanitized filter parameters in Liquid SQL templates, allowing unauthorized access to event data across multiple tenants. By manipul...

PoC for CVE-2024-3094

🟣 EPSS 86%10CRITICAL
Malicious Code Discovered in xz Upstream Tarballs, Affecting liblzm...

The XZ utility has been compromised due to malicious code introduced in the upstream tarballs starting from version 5.6.0. A sophisticated obfuscation technique is employed where the liblzma build process extracts a prebuilt object file hidden within a disguised test file in the source code. This...

PoC for CVE-2026-64822

ThiagopenaDjangosige6.9MEDIUM
User Enumeration Vulnerability in djangoSIGE Product by Americooo

The djangoSIGE product, up to version 1.10, contains a vulnerability that allows unauthenticated attackers to exploit the ForgotPasswordView functionality. By interacting with the password reset endpoint, attackers can submit arbitrary usernames or email addresses and determine if they correspond...

Discovered 2 days ago

PoC for CVE-2016-20096

Kunshi Network Te...Linknat Vos30009.3CRITICAL
Unauthenticated SQL Injection Risk in Linknat VOS3000 and VOS2009 S...

Linknat VOS3000 and VOS2009 versions up to 2.1.2.0 are susceptible to an unauthenticated SQL injection vulnerability via the login endpoint's name parameter. This flaw allows remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data. By manip...

PoC for CVE-2016-20096

Kunshi Network Te...Linknat Vos30009.3CRITICAL
Unauthenticated SQL Injection Risk in Linknat VOS3000 and VOS2009 S...

Linknat VOS3000 and VOS2009 versions up to 2.1.2.0 are susceptible to an unauthenticated SQL injection vulnerability via the login endpoint's name parameter. This flaw allows remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data. By manip...