Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 2 hours ago
PoC for CVE-2025-47947
ModSecurity, an open source web application firewall engine utilized with Apache, IIS, and Nginx, presents a vulnerability that can lead to a denial of service condition under specific circumstances. This occurs in versions up to and including 2.9.8 when processing requests with the content type ...
PoC for CVE-2026-104123
A vulnerability has been identified in the SourceCodester Online Reviewer Management System version 1.0. Specifically, the issue arises from the file located at /reviewer_0/admins/assessments/activities/btn_functions.php, where manipulation of the 'Title' argument leads to SQL injection. This typ...
Discovered 3 hours ago
PoC for CVE-2026-104120
A security flaw has been identified in ModelContextProtocol's Fetch Tool, affecting versions up to 2026.6.4. The vulnerability resides in the fetch_url function within the server.py file of the mcp-server-fetch and mcp-server-everything components. Attackers can manipulate the url/path argument, ...
PoC for CVE-2026-104054
A vulnerability has been identified in Calcom's Cal.diy product, specifically in versions up to 6.2.0. The flaw resides in the function doesUserIdHaveAccessToBooking within the PBAC Permission Engine, which fails to properly enforce access controls. This oversight allows an attacker to initiate u...
Discovered 4 hours ago
PoC for CVE-2026-104052
A SQL injection vulnerability has been identified in the itsourcecode Pet Shop Management System version 1.0. This issue arises from an unknown function in the file admin_reject_completed.php, where improper handling of the ID argument allows attackers to manipulate SQL queries. As a result, it i...
Discovered 5 hours ago
PoC for CVE-2026-90817
An unauthenticated Remote Code Execution vulnerability affects REDCap, enabling attackers to exploit the survey passthrough routing and Data Import processing. By manipulating HTTP requests, a malicious user can target an unintended controller route from a public survey context and provide a craf...
Discovered 6 hours ago
PoC for CVE-2026-103766
ClipBucket versions 5 through 5.5.3-#197 are susceptible to an SQL injection vulnerability that potentially allows authenticated users with ad_manager_access permission to manipulate SQL queries via the delete parameter in admin_area/ads_manager.php. By leveraging time-based blind payloads, attac...
Discovered 7 hours ago
PoC for CVE-2026-26026
GLPI, an open-source asset and IT management software, is susceptible to template injection through administrator actions, allowing for remote code execution. This vulnerability affects versions 11.0.0 to 11.0.5 and has been resolved in version 11.0.6. Users of affected versions are advised to up...
PoC for CVE-2026-102425
The Balbooa Forms extension for Joomla has a vulnerability that allows unauthenticated remote code execution (RCE) due to improper handling of PHP code submission. This issue arises when the product supports administrator-defined PHP code that executes after a public form submission. By manipulat...
Discovered 9 hours ago
PoC for CVE-2026-88771
An improper input validation vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway, enabling unauthenticated attackers to execute arbitrary commands. This potentially compromises system integrity and security, allowing unauthorized control over the affected product.
Discovered 10 hours ago
PoC for CVE-2026-88789
A vulnerability in the Apache Camel Quarkus XSLT support extension allows attackers to read local files or issue requests to internal network locations through XML external entity declarations. This weakness exists due to the extension's use of an outdated TransformerFactory that does not adhere ...
Discovered 13 hours ago
PoC for CVE-2026-103690
A vulnerability exists in itsourcecode Leave Management System version 1.0 that allows for SQL injection through manipulation of the LEAVEID argument in the controller.php file. Attackers can exploit this flaw remotely, potentially leading to unauthorized access and data manipulation. The exploit...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 15 hours ago
PoC for CVE-2026-103687
A vulnerability exists in the Rhukster DOM-Sanitizer component related to SVG sanitization. The flaw lies in the handling of the function 'url' in the src/DOMSanitizer.php file, which creates an incomplete blacklist for input validation. This allows a potential attacker to exploit the vulnerabili...
PoC for CVE-2024-58388
Sharp and Toshiba Tec multifunction printers are susceptible to an unauthenticated local file inclusion vulnerability. This issue arises from improper validation of user input in the installed_emanual_down.html endpoint. By manipulating the path parameter, attackers can execute directory traversa...
PoC for CVE-2026-103686
A security flaw exists in rhukster's dom-sanitizer component, specifically in the URL validation functionality. The issue lies within the DOMSanitizer::isDangerousUrl method, which can be exploited for cross-site scripting attacks. This vulnerability can allow attackers to initiate remote exploit...
Discovered 16 hours ago
PoC for CVE-2024-55591
A vulnerability exists in FortiOS and FortiProxy that allows a remote attacker to exploit an authentication bypass through crafted requests targeting the Node.js websocket module. This weakness could enable unauthorized users to attain super-admin privileges, compromising system security. Users o...
Discovered 18 hours ago
PoC for CVE-2026-88771
An improper input validation vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway, enabling unauthenticated attackers to execute arbitrary commands. This potentially compromises system integrity and security, allowing unauthorized control over the affected product.
Discovered 19 hours ago
PoC for CVE-2026-59310
VMware vCenter features a directory traversal vulnerability in its Syslog server component. This flaw allows attackers with network access to exploit the vulnerability, potentially leading to unauthorized execution of arbitrary code. Proper safeguards and patching are essential to mitigate the ri...
PoC for CVE-2026-103585
A Cross-Site Scripting (XSS) vulnerability exists in the MediaWiki MediaSearch extension, allowing attackers to inject malicious scripts through improperly neutralized HTML tags in web pages. This affects versions 1.46, 1.45, and 1.43, posing a risk to users by enabling the execution of harmful s...
PoC for CVE-2026-103584
The Wikimedia Foundation MediaWiki CommonsMetadata extension is susceptible to a Cross-Site Scripting vulnerability due to improper neutralization of script-related HTML tags. This flaw permits attackers to inject malicious scripts into web pages viewed by users, which can lead to unauthorized ac...
Discovered 23 hours ago
PoC for CVE-2026-103544
A significant vulnerability affects the OpenConstructionERP software, specifically in the Al Provider Configuration Handler. An unknown function within the ai_client.py file can lead to improper access control, allowing data elements to be exposed to unauthorized sessions. This vulnerability is r...
PoC for CVE-2026-92412
The Five Star Restaurant Reviews plugin for WordPress, prior to version 2.3.14, is vulnerable to Cross-Site Scripting (XSS). This vulnerability arises from improper escaping of user-supplied input, allowing unauthenticated attackers to inject malicious scripts. As a result, any user, including lo...
PoC for CVE-2026-90972
The WP Fusion Lite plugin for WordPress prior to version 3.48.0 has a significant security flaw where it fails to conduct proper capability checks on two of its admin AJAX handlers. This oversight enables any authenticated subscriber to access other users' email addresses, leading to unauthorized...
PoC for CVE-2026-96255
The Payments for Hubtel WordPress plugin prior to version 1.0.2 has a serious flaw that permits unauthorized public access to a debug log. This log stores sensitive information, including the API credentials for the payment gateway, in an unsecured plain text format. As a result, unauthenticated ...
PoC for CVE-2026-96200
The Payments for Hubtel WordPress plugin prior to version 1.0.2 is susceptible to a vulnerability that lacks verification of payment notifications received through its payment callback mechanism. This oversight permits unauthenticated attackers to falsely mark arbitrary orders as paid, leading to...
PoC for CVE-2026-90974
The WP Fusion Lite plugin for WordPress, prior to version 3.48.0, is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated users to access critical settings within the WordPress admin area. By exploiting this weakness, attackers can manipulate the site's CRM inte...
PoC for CVE-2026-96173
The Payments for Hubtel WordPress plugin, prior to version 1.0.2, is susceptible to an authorization flaw that fails to validate whether the requester is authorized to access order information. This vulnerability permits unauthenticated attackers to redirect public payment-callback requests, ther...
PoC for CVE-2026-89296
The Pro Like Button plugin for WordPress prior to version 2.0 contains a vulnerability that fails to properly sanitize and escape input parameters used in SQL queries. This flaw allows unauthenticated attackers to manipulate the queries, potentially executing arbitrary SQL commands. As a result, ...
PoC for CVE-2026-81809
The Paytm Payment Gateway WordPress plugin versions before 2.8.9 is susceptible to SQL injection due to improper data escaping from payment callbacks. Malicious users can exploit this vulnerability, particularly when the gateway operates without the required credentials, enabling them to manipula...
PoC for CVE-2026-87973
The If-So Dynamic Content plugin for WordPress prior to version 1.10.2 is susceptible to a JavaScript injection vulnerability. This issue arises because the plugin fails to properly sanitize conversion names before saving them and does not escape content during the rendering of the analytics page...
PoC for CVE-2026-86610
The Download Manager plugin for WordPress prior to version 3.3.71 has a vulnerability that arises from inadequate sanitization of user inputs. This allows users with the Author role or higher to exploit the system by injecting malicious scripts into the package settings. When a visitor accesses t...
PoC for CVE-2026-87970
The If-So Dynamic Content plugin for WordPress prior to version 1.10.2 is susceptible to an improper input validation vulnerability. This flaw arises from the plugin's failure to adequately escape user-supplied values in AJAX responses. As a consequence, unauthenticated attackers can inject and e...
PoC for CVE-2026-101148
The BackupSheep WordPress Backup Plugin, prior to version 1.8, fails to impose adequate validation checks on its integration key, mistakenly allowing an unset or blank key to be treated as valid. This loophole enables unauthenticated users to access sensitive functionalities, such as creating and...
PoC for CVE-2026-19253
The Cache Enabler WordPress plugin, prior to version 1.8.17, contains a vulnerability that allows unauthenticated users to exploit the URL handling in its cache purge process. By failing to validate a user-supplied URL, the plugin can generate a filesystem path that extends beyond its intended ca...
PoC for CVE-2026-81739
The Paytm Payment Gateway plugin for WordPress prior to version 2.8.9 is vulnerable due to the lack of proper sanitization and escaping of payment callback data. This allows unauthenticated users to manipulate the data stored on admin pages, potentially injecting malicious scripts. Furthermore, t...
PoC for CVE-2026-101147
The Featured Image from URL (FIFU) plugin for WordPress is susceptible to Cross-Site Request Forgery due to improper enforcement of the REST API nonce in versions prior to 6.0.8 and 8.2.8 for the Premium variant. This security flaw enables attackers to exploit the vulnerability through crafted UR...
PoC for CVE-2026-103543
A vulnerability exists in the itsourcecode Leave Management System 1.0 that allows attackers to exploit an unknown function within the /module/leavetype/controller.php file. By manipulating the LEAVTID argument, an attacker can execute SQL injection attacks remotely. This vulnerability has been d...
PoC for CVE-2026-103542
A security flaw has been identified in Form Tools, specifically within the smart_fill function located in the AJAX Endpoint's actions.php file. This vulnerability allows attackers to manipulate the 'url' argument, leading to server-side request forgery (SSRF). It poses a significant risk as the a...
Discovered 1 day ago
PoC for CVE-2026-103541
A vulnerability was discovered in Form Tools that allows for unrestricted file uploads due to a flaw in the uploadFile function within the Ajax Handler component. This issue is present in versions up to 3.1.1. The flaw enables remote attackers to exploit the vulnerability and upload arbitrary fil...
PoC for CVE-2026-103540
A security vulnerability has been identified in the Form Tools application, specifically impacting versions up to 3.1.1. This flaw affects the function 'Clients::updateClientSettingsTab' within the Client Settings component, located in 'global/code/Clients.class.php'. The issue arises from the im...
PoC for CVE-2026-103539
A vulnerability has been identified in the ZongXR SuperMarket version 1.0.0.0, specifically within the Instant Buy component. This weakness allows for a manipulation of the 'Username' argument during the execution of the 'startBuy' function located in the InstantBuyController.java file. As a resu...
PoC for CVE-2026-103538
A significant security vulnerability has been identified in the ZongXR SuperMarket version 1.0.0.0, specifically within the Order Deletion Endpoint function. This flaw arises from improper handling of the orderId parameter in the OrderController.deleteOrder method, leading to a situation where au...
PoC for CVE-2026-103536
A significant security flaw has been identified in the ZongXR Supermarket application, specifically within the OrderController component. The issue lies in the addOrder function, located in the order/src/main/java/com/supermarket/order/controller/OrderController.java file. This vulnerability allo...
PoC for CVE-2026-103446
An authorization bypass vulnerability exists in the WikiLambda extension of MediaWiki, allowing unauthorized users to bypass authentication mechanisms. This flaw is triggered by user-controlled keys, enabling potentially malicious actions. The vulnerability affects the MediaWiki WikiLambda extens...
PoC for CVE-2026-103445
The MediaWiki Page_Forms extension from Wikimedia Foundation contains a vulnerability that allows for stored cross-site scripting (XSS). This issue arises from the improper neutralization of script-related HTML tags within web pages, potentially enabling attackers to inject malicious scripts that...
PoC for CVE-2026-103442
A vulnerability exists in the MediaWiki CentralAuth extension that allows external entities to manipulate system or configuration settings, leading to potential code injection. This issue impacts versions 1.46, 1.45, and 1.43. Users of affected versions are encouraged to update their installation...
PoC for CVE-2026-103441
A deserialization of untrusted data vulnerability exists in the Wikimedia Foundation MediaWiki Wikibase extension, potentially enabling the execution of executable code in files that are not typically executable. This issue raises significant security concerns as it affects multiple versions of t...
PoC for CVE-2026-103440
A vulnerability in the MediaWiki PageTriage extension enables the exposure of sensitive information through improper data queries. Attackers can potentially elicit data that should be protected, impacting user privacy and system integrity. This issue affects specific versions of the PageTriage ex...
PoC for CVE-2026-103437
A reflected XSS vulnerability exists in the MediaWiki ReadingLists extension developed by Wikimedia Foundation. This vulnerability stems from improper neutralization of script-related HTML tags in web pages, allowing attackers to execute malicious scripts in the context of a user's browser. Users...