Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-32710

MariadbServer8.6HIGH
Unauthorized Access Vulnerability in MariaDB Server

An issue has been identified in the JSON_SCHEMA_VALID() function of MariaDB Server, which is derived from MySQL. This vulnerability allows authenticated users to crash versions 11.4 prior to 11.4.10 and 11.8 prior to 11.8.6 of MariaDB server. While under specific conditions, it could lead to remo...

PoC for CVE-2025-70149

CodeAstroMembership Management ...9.8CRITICAL
SQL Injection Vulnerability in CodeAstro Membership Management System

The CodeAstro Membership Management System version 1.0 is prone to an SQL Injection vulnerability via the ID parameter in print_membership_card.php. This flaw allows attackers to manipulate database queries by injecting arbitrary SQL code, potentially leading to unauthorized data access and manip...

Discovered 10 minutes ago

PoC for CVE-2011-1249

MicrosoftWindows Server 2008
Privilege Escalation Vulnerability in Microsoft Windows Products

The Ancillary Function Driver (AFD) in various versions of Microsoft Windows does not execute proper validation of user-mode input. This flaw enables local users to escalate their privileges via specially crafted applications, potentially leading to unauthorized access to system resources. Affect...

Discovered 15 minutes ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 2 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 3 hours ago

PoC for CVE-2020-1938

ApacheApache Tomcat🟣 EPSS 94%9.8CRITICAL
Apache Tomcat AJP Connector Insecure Configuration Vulnerability

The Apache JServ Protocol (AJP) Connector in Apache Tomcat allowed for misconfigured connections that could be exploited by attackers. By default, the AJP Connector is enabled, listening on all configured IP addresses. This elevated trust can lead to unauthorized access and manipulation of files ...

Discovered 4 hours ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 27%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

Discovered 5 hours ago

PoC for CVE-2026-8028

FlowiseaiFlowise6.3MEDIUM
Information Disclosure Vulnerability in FlowiseAI Flowise by Flowise

A vulnerability exists in FlowiseAI Flowise versions up to 3.0.12 that impacts the 'verify' function located in the account.service.ts file within the Endpoint component. This flaw enables attackers to manipulate requests, potentially leading to unauthorized access to sensitive information. The c...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 6 hours ago

PoC for CVE-2026-23918

ApacheApache Http Server8.8HIGH
Double Free and Remote Code Execution Vulnerability in Apache HTTP ...

A double free vulnerability has been identified in Apache HTTP Server that may lead to remote code execution, particularly concerning the HTTP/2 protocol. This issue affects version 2.4.66, and it is crucial for users to upgrade to version 2.4.67 to mitigate any potential security risks associate...

PoC for CVE-2026-39363

VitejsVite8.2HIGH
WebSocket Vulnerability in Vite Frontend Framework

A vulnerability in the Vite frontend tooling framework allows unauthorized access to arbitrary files on the server. If an attacker connects to the Vite development server's WebSocket without an Origin header, they can exploit the custom WebSocket event 'vite:invoke' to retrieve file contents as J...

Discovered 8 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 10 hours ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 27%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

Discovered 12 hours ago

PoC for CVE-2026-29000

Pac4jPac4j-jwt9.3CRITICAL
Authentication Bypass in JwtAuthenticator of pac4j-jwt by pac4j

The pac4j-jwt library's JwtAuthenticator prior to versions 4.5.9, 5.7.9, and 6.3.3 is susceptible to an authentication bypass that could allow remote adversaries to create forged authentication tokens. By leveraging the server's RSA public key, attackers are able to craft a JWE-wrapped PlainJWT w...

PoC for CVE-2026-0073

GoogleAndroid8.8HIGH
Logic Error in Wireless ADB Authentication in Android Products

A significant logic error in the adbd_tls_verify_cert function of auth.cpp in various Android versions permits a bypass of the wireless ADB mutual authentication process. This flaw can lead to unauthorized remote code execution by exploiting the vulnerability as the shell user without requiring a...

Discovered 13 hours ago

PoC for CVE-2025-21333

MicrosoftWindows 10 Version 21h2🟣 EPSS 82%7.8HIGH
Elevated Privilege Exposure in Windows Hyper-V by Microsoft

A vulnerability has been identified in Windows Hyper-V, specifically related to the NT Kernel Integration Virtual Service Provider (VSP). This flaw allows an attacker to gain elevated privileges through carefully crafted input, potentially leading to unauthorized access and control over the host ...

PoC for CVE-2026-26128

MicrosoftWindows 10 Version 16077.8HIGH
Improper Authentication in Windows SMB Server by Microsoft

A vulnerability in Windows SMB Server allows authorized attackers to exploit improper authentication mechanisms, enabling them to elevate their privileges locally. This weakness can be leveraged to gain unauthorized access and control over sensitive resources within the affected system, presentin...

Discovered 14 hours ago

PoC for CVE-2026-7482

OllamaOllama8.8HIGH
Heap Out-of-Bounds Read Vulnerability in Ollama by Ollama

The Ollama application is susceptible to a heap out-of-bounds read vulnerability within its GGUF model loader. This issue arises when the /api/create endpoint processes an attacker-defined GGUF file where the tensor offset and size exceed the file’s actual length. During quantization, the server ...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 15 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 17 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 19 hours ago

PoC for CVE-2022-22963

VmwareSpring Cloud Function🟣 EPSS 94%9.8CRITICAL
Remote Code Execution Vulnerability in Spring Cloud Function by VMware

In certain versions of Spring Cloud Function, an attacker can exploit the routing functionality through a specially crafted Spring Expression Language (SpEL) as a routing-expression. This misconfiguration may allow unauthorized access to local resources and the execution of arbitrary code, posing...

Discovered 22 hours ago

PoC for CVE-2026-41950

LanggeniusDify6MEDIUM
Authorization Bypass Vulnerability in Dify by LangGenius

An authorization bypass vulnerability exists in Dify prior to version 1.14.0, enabling authenticated users to read files uploaded by other users within the same tenant. By supplying arbitrary file UUIDs in a chat-messages request, attackers can exploit inadequate permission checks in the chat-mes...

PoC for CVE-2026-23918

ApacheApache Http Server8.8HIGH
Double Free and Remote Code Execution Vulnerability in Apache HTTP ...

A double free vulnerability has been identified in Apache HTTP Server that may lead to remote code execution, particularly concerning the HTTP/2 protocol. This issue affects version 2.4.66, and it is crucial for users to upgrade to version 2.4.67 to mitigate any potential security risks associate...

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 1 day ago

PoC for CVE-2026-7857

D-linkDi-81008.6HIGH
Buffer Overflow Vulnerability in D-Link DI-8100 Router

The D-Link DI-8100 router contains a vulnerability in the sprintf function located within the /user_group.asp file of the CGI Handler component. This vulnerability allows an attacker to execute a buffer overflow, potentially leading to unauthorized actions on the device. The attack can be initiat...

PoC for CVE-2026-7856

D-linkDi-81008.6HIGH
Buffer Overflow Vulnerability in D-Link DI-8100 Web Management Inte...

A flaw in D-Link DI-8100 version 16.07.26A1 has been identified within the web management interface at /url_member.asp. A vulnerability exists that allows remote attackers to manipulate the 'Name' argument, resulting in a buffer overflow. This may enable unauthorized access and exploitation, maki...

PoC for CVE-2026-23918

ApacheApache Http Server8.8HIGH
Double Free and Remote Code Execution Vulnerability in Apache HTTP ...

A double free vulnerability has been identified in Apache HTTP Server that may lead to remote code execution, particularly concerning the HTTP/2 protocol. This issue affects version 2.4.66, and it is crucial for users to upgrade to version 2.4.67 to mitigate any potential security risks associate...

PoC for CVE-2026-7855

D-linkDi-81008.7HIGH
Buffer Overflow Vulnerability in D-Link DI-8100 HTTP Request Handler

A buffer overflow vulnerability exists in the D-Link DI-8100, particularly within the tggl_asp function of the /tggl.asp file in the HTTP Request Handler. Attackers can manipulate the argument 'Name' to trigger this overflow, potentially leading to remote exploitation. The exploit has been made p...

PoC for CVE-2026-7854

D-linkDi-81009.3CRITICAL
Buffer Overflow Vulnerability in D-Link DI-8100 Router

A buffer overflow vulnerability has been identified in the D-Link DI-8100 router, specifically within the url_rule_asp function located in the /url_rule.asp file of the POST Parameter Handler. This vulnerability allows attackers to manipulate input parameters that could potentially lead to unauth...

PoC for CVE-2026-7853

D-linkDi-81009.3CRITICAL
Buffer Overflow in D-Link DI-8100 Affects HTTP Handler Functionality

A vulnerability exists in the D-Link DI-8100 router's HTTP handler, specifically in the 'sprintf' function within the '/auto_reboot.asp' file. The flaw arises from improper handling of input parameters, which can lead to a buffer overflow condition. An attacker can exploit this vulnerability remo...

PoC for CVE-2026-7851

D-linkDi-81008.6HIGH
Stack-based Buffer Overflow in D-Link DI-8100 Router

A stack-based buffer overflow vulnerability has been identified in the D-Link DI-8100 router, specifically in the sprintf function within the yyxz.asp file. This vulnerability arises from improper handling of the ID argument, allowing an attacker to execute arbitrary code remotely. Exploits for t...

PoC for CVE-2026-7847

Chatchat-spaceLangchain-chatchat2.1LOW
Insufficient Randomness in File Upload Handler of Langchain-Chatcha...

A vulnerability exists in the Uploaded File Handler of Langchain-Chatchat, impacting versions up to 0.3.1.3. Specifically, the issue lies within the _get_file_id function in the openai_routes.py file, where manipulation can lead to the use of insufficiently random values. This flaw necessitates a...

PoC for CVE-2026-7846

Chatchat-spaceLangchain-chatchat2.1LOW
Race Condition in Langchain-Chatchat's OpenAI-Compatible File Uploa...

A race condition vulnerability exists in Langchain-Chatchat's OpenAI-Compatible File Upload API, specifically within the function handling file uploads in openai_routes.py. This flaw allows for manipulation of the file.filename parameter, leading to a time-of-check to time-of-use (TOCTOU) issue. ...

PoC for CVE-2026-7845

Chatchat-spaceLangchain-chatchat2.1LOW
Weak Hash Vulnerability in Langchain-Chatchat Product by chatchat-s...

A vulnerability has been identified in Langchain-Chatchat affecting versions up to 0.3.1.3. This issue arises from a flaw in the Vision Chat Paste Image Handler, specifically within the function PIL.Image.tobytes. The vulnerability can be exploited through manipulation of the paste_image.image_da...

PoC for CVE-2026-7844

Chatchat-spaceLangchain-chatchat5.3MEDIUM
Missing Authentication Vulnerability in Langchain-Chatchat by chatc...

A vulnerability has been identified in the Langchain-Chatchat product from chatchat-space, where the Compatible File Service fails to enforce proper authentication controls for specific functions. This oversight, affecting functions such as retrieving and deleting files, allows unauthorized users...

PoC for CVE-2026-7834

EfmIptime Nas1dual9.3CRITICAL
Buffer Overflow Vulnerability in EFM ipTIME NAS1dual by EFM Networks

A vulnerability in the EFM ipTIME NAS1dual 1.5.24 relates to the function get_csrf_whites within the file /cgi/advanced/misc_main.cgi. This flaw can be exploited via remote attacks, leading to stack-based buffer overflow, which can compromise system integrity. The issue was disclosed publicly, an...

PoC for CVE-2026-7833

EfmIptime C2008.6HIGH
Command Injection Vulnerability in EFM ipTIME C200 by EFM Networks

A command injection vulnerability has been discovered in the EFM ipTIME C200 router, specifically affecting the ApplyRestore Endpoint functionality located in the /cgi/iux_set.cgi file. This weakness originates from improper handling of the RestoreFile argument within the sub_408F90 function, all...

PoC for CVE-2026-7832

IobitAdvanced Systemcare7.3HIGH
Symlink Following Vulnerability in IObit Advanced SystemCare 19

A security flaw has been identified in IObit Advanced SystemCare 19, specifically within the ASC.exe component of the Service. This flaw allows for symlink following, enabling potential local attack vectors. The complexity of exploiting this vulnerability is significant, and successful exploitati...

PoC for CVE-2023-54349

SpondonitAmazcart Cms5.1MEDIUM
Reflected Cross-Site Scripting in AmazCart CMS 3.4 by Spondonit

AmazCart CMS version 3.4 is susceptible to a reflected cross-site scripting vulnerability that enables unauthenticated attackers to inject harmful scripts through the search functionality. Malicious users can leverage this flaw by inputting script tags in the search box, which can then execute ar...

PoC for CVE-2023-54348

RajodiyaErpgo Saas8.7HIGH
CSV Injection Vulnerability in ERPGo SaaS by ERPGo

The ERPGo SaaS 3.9 contains a vulnerability that enables authenticated attackers to perform CSV injection by inserting crafted formula payloads into vendor name fields. This loophole allows attackers to execute arbitrary code when the generated CSV file is opened in spreadsheet applications, pote...

PoC for CVE-2023-54346

WordPressWordPress Plugin Backu...8.7HIGH
Information Disclosure in Backup Migration Plugin for WordPress

The Backup Migration Plugin version 1.2.8 for WordPress is vulnerable to information disclosure that enables unauthenticated attackers to access sensitive database backups. By exploiting predictable file paths, attackers can enumerate backup directories using configuration files and logs. This vu...

PoC for CVE-2023-54347

Open-emrOpenemr8.7HIGH
Authentication Bypass in OpenEMR 7.0.1 by OpenEMR

OpenEMR version 7.0.1 is susceptible to a brute force authentication vulnerability, where attackers can exploit the login mechanism to bypass rate limiting controls. By sending multiple login attempts via POST requests with specific parameters, they can test various username and password combinat...

PoC for CVE-2023-54345

ErpnextFrappe Framework (erpn...8.7HIGH
Sandbox Escape in Frappe Framework ERPNext by Frappe

The Frappe Framework ERPNext version 13.4.0 is susceptible to a sandbox escape vulnerability within RestrictedPython. This issue permits authenticated users with the System Manager role to execute arbitrary code by leveraging frame introspection. Specifically, an attacker can craft a server scrip...

PoC for CVE-2023-54342

Equinox[osgi9.3CRITICAL
Remote Code Execution Vulnerability in Eclipse Equinox OSGi Console...

Eclipse Equinox OSGi versions 3.8 through 3.18 are susceptible to a remote code execution vulnerability via the console interface. This flaw enables unauthenticated attackers to exploit the fork command functionality, allowing them to establish a telnet connection to the OSGi console. By performi...

PoC for CVE-2023-54344

Equinox[osgi9.3CRITICAL
Remote Code Execution Vulnerability in Eclipse Equinox OSGi by Ecli...

Eclipse Equinox OSGi versions 3.7.2 and earlier contain a vulnerability that permits attackers to execute arbitrary commands remotely. By connecting to the OSGi console port, unauthenticated users can send crafted payloads encoded in base64, wrapped within fork directives, enabling them to execut...

Discovered 2 days ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

PoC for CVE-2026-7823

TotolinkA8000ru9.3CRITICAL
Command Injection Flaw in Totolink A8000RU Router

A security flaw has been identified in the Totolink A8000RU router, specifically within the setAppFilterCfg function in cgi-bin/cstecgi.cgi. This vulnerability allows for remote command injection via manipulation of the 'enable' argument. An attacker can exploit this flaw to execute arbitrary com...

PoC for CVE-2026-7822

ItsourcecodeCourier Management System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Courier Management Syst...

A vulnerability has been discovered in the itsourcecode Courier Management System 1.0, specifically in the /print_pdets.php file. This vulnerability allows for SQL injection due to improper handling of the 'ids' argument. The flaw can be exploited from a remote location, enabling attackers to man...

PoC for CVE-2026-7812

54yyyuCode-mcp6.9MEDIUM
Command Injection Vulnerability in MCP Tool by 54yyyu

A command injection vulnerability exists in the MCP Tool developed by 54yyyu, specifically within the git_operation function found in src/code_mcp/server.py. This flaw allows an attacker to manipulate the operation argument remotely, leading to unauthorized command execution. Despite the project ...