Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 2 hours ago

PoC for CVE-2026-86166

TendaHg108.7HIGH
Buffer Overflow Vulnerability in Tenda HG10's Boa Web Server

A vulnerability exists in the Tenda HG10 device due to improper handling of arguments in the Boa Web Server component. Specifically, the function formWanRedirect can be manipulated, leading to a buffer overflow condition. This exploit could be executed remotely, allowing an attacker to potentiall...

Discovered 3 hours ago

PoC for CVE-2026-86165

TendaHg109.3CRITICAL
Buffer Overflow Vulnerability in Tenda HG10 Router

A critical buffer overflow vulnerability exists in the Tenda HG10 router, specifically within the formURL function of the /boaform/admin/formURL file. By manipulating the Keywd/urlFQDN argument, an attacker can trigger a buffer overflow remotely. This exploit has been disclosed publicly, raising ...

PoC for CVE-2026-86164

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A security vulnerability exists in the itsourcecode Sales and Inventory System 1.0, located in the 'trans_view.php' file. By manipulating the argument ID, an attacker can execute SQL injection attacks, potentially gaining unauthorized access to sensitive data. This flaw can be exploited remotely,...

PoC for CVE-2026-86163

ItsourcecodeSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Sales and Inventory System

A SQL injection vulnerability has been identified in the itsourcecode Sales and Inventory System version 1.0. This vulnerability primarily affects the processing of requests in the '/pages/pro_del.php' file. Attackers can exploit this vulnerability remotely by manipulating the 'ID' argument, pote...

Discovered 4 hours ago

PoC for CVE-2026-86162

SourcecodesterOnline Voting System6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Online Voting System

A vulnerability has been identified in the SourceCodester Online Voting System version 1.0, specifically within the /ajax.php file's login function. This flaw allows remote attackers to manipulate the Username argument, potentially leading to SQL injection. The exploitation of this vulnerability ...

PoC for CVE-2026-86161

SourcecodesterOnline Voting System6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Online Voting System

A SQL injection vulnerability exists in the SourceCodester Online Voting System version 1.0, specifically in the ajax.php file during the delete_category action. This vulnerability allows an attacker to manipulate the ID argument, leading to unauthorized database access and potential data comprom...

PoC for CVE-2026-86160

SourcecodesterOnline Voting System6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Online Voting System

A vulnerability exists in the SourceCodester Online Voting System 1.0, specifically within the /ajax.php file's delete_voting function. This flaw allows remote attackers to manipulate the ID parameter, potentially leading to SQL injection. The exploit has been publicly disclosed, raising signific...

PoC for CVE-2026-86159

SourcecodesterOnline Voting System6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Online Voting System 1.0

A security flaw was identified in the SourceCodester Online Voting System 1.0, specifically in the handling of user input via the /ajax.php?action=save_user endpoint. This vulnerability permits remote attackers to manipulate the ID parameter, leading to SQL injection. Exploiting this weakness all...

Discovered 5 hours ago

PoC for CVE-2026-0920

WordPressLa-studio Element Kit ...9.8CRITICAL
Administrative User Creation Vulnerability in LA-Studio Element Kit...

The LA-Studio Element Kit for Elementor plugin suffers from a serious vulnerability that allows unauthenticated attackers to create administrative user accounts. The flaw arises from the 'ajax_register_handle' function, which fails to enforce restrictions on user roles during the registration pro...

Discovered 6 hours ago

PoC for CVE-2026-84645

JenkinsJenkins8.8HIGH
Remote Code Execution Vulnerability in Jenkins by CloudBees

In Jenkins versions 2.579 and earlier, including LTS version 2.568.2, a significant vulnerability exists where certain objects are improperly handled as nested field values in user-submitted 'config.xml' documents. This allows for potential remote code execution via HTTP requests processed throug...

Discovered 10 hours ago

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 99%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...

PoC for CVE-2026-64560

LinuxLinux7.8HIGH
Use-After-Free Vulnerability in Linux Kernel Affecting Timer Manage...

A vulnerability in the Linux kernel related to posix CPU timers can lead to a use-after-free condition due to a race in non-leader exec() scenarios. When a timer associated with a process is deleted while concurrently executing an exec() command, it can cause access to freed memory. Specifically,...

PoC for CVE-2026-86060

MikrotikRouteros9.2CRITICAL
Argument-handling Flaw in RouterOS by MikroTik

MikroTik's RouterOS is vulnerable due to an argument-handling flaw in the SSH login process, specifically affecting usernames that start with a prohibited character. This flaw allows an attacker to manipulate the trusted RouterOS policy mask, facilitating privilege escalation. The exploitation of...

PoC for CVE-2026-86060

MikrotikRouteros9.2CRITICAL
Argument-handling Flaw in RouterOS by MikroTik

MikroTik's RouterOS is vulnerable due to an argument-handling flaw in the SSH login process, specifically affecting usernames that start with a prohibited character. This flaw allows an attacker to manipulate the trusted RouterOS policy mask, facilitating privilege escalation. The exploitation of...

Discovered 15 hours ago

PoC for CVE-2026-32475

WordPressElementor Pro9CRITICAL
Unrestricted File Upload Vulnerability in Elementor Pro by Elementor

Elementor Pro has a vulnerability that allows attackers to upload files of dangerous types without restriction. This can lead to potential exploits where malicious files are executed on the server. It is essential for users of Elementor Pro, particularly versions from n/a to 4.2.1, to patch this ...

PoC for CVE-2026-32475

WordPressElementor Pro9CRITICAL
Unrestricted File Upload Vulnerability in Elementor Pro by Elementor

Elementor Pro has a vulnerability that allows attackers to upload files of dangerous types without restriction. This can lead to potential exploits where malicious files are executed on the server. It is essential for users of Elementor Pro, particularly versions from n/a to 4.2.1, to patch this ...

Discovered 17 hours ago

PoC for CVE-2025-4255

PcmanFtp Server6.9MEDIUM
Buffer Overflow Vulnerability in PCMan FTP Server 2.0.7

A buffer overflow vulnerability exists in the RMD Command Handler of PCMan FTP Server 2.0.7, potentially allowing remote attackers to execute arbitrary code. Once the vulnerability is exploited, it could lead to unauthorized access or compromise of the system. The exploit is publicly known, under...

Discovered 19 hours ago

PoC for CVE-2026-86177

PterodactylPanel8.7HIGH
Privilege Escalation in Pterodactyl Panel by Pterodactyl

The Pterodactyl Panel prior to version 1.14.1 has a vulnerability that arises from improper validation of action-specific permissions during the creation of scheduled tasks. This oversight allows subusers with merely the 'schedule.update' permission to execute arbitrary console commands. As a res...

PoC for CVE-2026-86178

PixelfedPixelfed5.3MEDIUM
Unauthorized Access in Pixelfed by Geo-Chen

Pixelfed, up to version 0.12.9, contains a flaw in its StoryComposeController, where it does not validate follower status for its react and comment endpoints. This oversight allows authenticated users to access follower-only stories without necessary permissions. By exploiting this vulnerability,...

PoC for CVE-2026-86176

Netbox-communityNetbox5.3MEDIUM
Information Disclosure in NetBox Release by NetBox Community

NetBox versions through 4.7.0 contain a vulnerability where authenticated users can exploit unscoped querysets in REST and GraphQL API endpoints. This flaw allows unauthorized access to private user records, specifically in Notifications, Subscriptions, and Bookmarks. As a result, an authenticate...

PoC for CVE-2026-86175

Netbox-communityNetbox7.1HIGH
Sensitive Data Exposure in NetBox API by Network-to-Cloud Solutions

NetBox version 4.7.0 exposes sensitive backend credentials, including Git and Amazon S3 plaintext passwords, through REST and GraphQL API responses. This vulnerability enables authenticated users with view-only permissions to access sensitive credentials, potentially leading to unauthorized acces...

Discovered 22 hours ago

PoC for CVE-2026-85649

ChewkeanhoSoftware-actualizer7.9HIGH
Password Validation Flaw in Actualizer by Chew, Kean Ho

The Actualizer software by Chew, Kean Ho prior to version 1.2.1 exhibits a significant fail-open vulnerability in its password validation processes. Specifically, the installer script Shell/debian-minbase-install.sh fails to validate the success of the mkpasswd command when generating yescrypt pa...

Discovered 1 day ago

PoC for CVE-2026-84934

WordPressJch Optimize
Unauthorized Action Execution Risk in JCH Optimize WordPress Plugin

The JCH Optimize plugin for WordPress prior to version 6.0.1 contains a vulnerability that fails to adequately verify user capabilities during certain authenticated AJAX actions. This oversight permits any logged-in user, such as Subscribers, to import arbitrary settings from the plugin. As a con...

PoC for CVE-2026-84935

WordPressHt Menu
Cross-Site Scripting Vulnerability in HT Menu WordPress Plugin

The HT Menu plugin for WordPress, prior to version 1.2.7, fails to validate user capabilities or object ownership when saving navigation menu-item settings. This oversight allows users with minimal permissions, such as Subscribers, to inject malicious JavaScript code. When this code is executed i...

PoC for CVE-2026-84936

WordPressEmbedpress
Unauthorized Access Flaw in EmbedPress Plugin for WordPress

The EmbedPress plugin for WordPress, prior to version 4.6.4, suffers from an authorization flaw in its public review-loading action. This vulnerability allows unauthenticated users to execute repeated, unauthorized requests to billable third-party APIs using the site's API key. This can lead to c...

PoC for CVE-2026-84937

WordPressVideo Player For Youtube
SQL Injection Risk in Video Player for YouTube Plugin by WordPress

The Video Player for YouTube plugin for WordPress, prior to version 2.1.0, fails to adequately sanitize and escape user-supplied input utilized in SQL statements. This oversight permits users with Contributor roles and above to conduct SQL injection attacks, thereby gaining unauthorized access to...

PoC for CVE-2026-84927

WordPressEmbedpress
Authorization Flaw in EmbedPress Plugin by WordPress

The EmbedPress plugin for WordPress prior to version 4.6.4 lacks adequate authorization checks on its Google Reviews REST API routes. This deficiency permits users with Contributor roles and above to alter site-wide store configurations, including the ability to delete pre-existing entries set by...

PoC for CVE-2026-84901

WordPressEventin
Authorization Flaw in Eventin WordPress Plugin Allows Unauthorized ...

The Eventin WordPress plugin is affected by a vulnerability that compromises authorization checks on several REST routes related to event management. Users with contributor-level access and higher can exploit this flaw to manipulate the site's front-page settings, changing them to events they do ...

PoC for CVE-2026-84930

WordPressCatfolders Document Ga...
HTML Injection Vulnerability in CatFolders Document Gallery & PDF L...

The CatFolders Document Gallery & PDF Library plugin for WordPress prior to version 2.0.7 contains a vulnerability due to improper validation of block attributes. This flaw permits users with Author roles or higher to inject arbitrary web scripts, which can execute in the browsers of visitors vie...

PoC for CVE-2026-84926

WordPressEmbedpress
Access Control Flaw in EmbedPress WordPress Plugin Exposing Admin E...

The EmbedPress WordPress plugin prior to version 4.6.4 contains a flaw that allows authenticated users with contributor-level access or higher to access restricted Google Reviews REST routes. This vulnerability permits such users to view the site administrator's email address, a sensitive piece o...

PoC for CVE-2026-84899

WordPressVikwidgetsloader
Inline Script Exposure in VikWidgetsLoader Plugin for WordPress

The VikWidgetsLoader plugin for WordPress prior to version 1.12.0 contains a significant code injection vulnerability. It fails to properly sanitize or escape a block attribute before including it in an inline script. This oversight allows users with Contributor permissions to insert arbitrary Ja...

PoC for CVE-2026-84931

WordPressJoli Table Of Contents
HTML Injection Vulnerability in Joli Table Of Contents Plugin for W...

The Joli Table Of Contents plugin for WordPress, prior to version 3.0.3, fails to properly sanitize or escape shortcode attribute values. This vulnerability allows users with author privileges or higher to inject arbitrary HTML attributes and JavaScript into posts. As a result, code executed in t...

PoC for CVE-2026-84898

WordPressEventin
Local File Inclusion in Eventin WordPress Plugin

The Eventin WordPress plugin allows users with contributor-level access and above to exploit a vulnerability in the template path validation mechanism. This flaw permits the inclusion and execution of arbitrary local PHP files, potentially compromising the security of the website. Users should up...

PoC for CVE-2026-84896

WordPressKing Addons For Elementor
Cross-Site Scripting in King Addons for Elementor Plugin by WordPress

The King Addons for Elementor WordPress plugin versions prior to 51.1.77 is susceptible to a Cross-Site Scripting (XSS) vulnerability. This issue arises due to inadequate escaping of widget display-style settings before rendering them in HTML attributes. As a result, users with Contributor-level ...

PoC for CVE-2026-84221

WordPressKirki
SQL Injection Vulnerability in Kirki WordPress Plugin by Langerhans

The Kirki WordPress plugin prior to version 6.3.0 is susceptible to an SQL injection vulnerability. This flaw occurs because the plugin does not properly sanitize user-supplied identifiers used in SQL queries. As a result, users with editor-level permissions and higher can manipulate queries to i...

PoC for CVE-2026-84225

WordPressKirki
Insufficient User Permission Validation in Kirki Plugin for WordPress

The Kirki plugin for WordPress prior to version 6.3.0 lacks proper validation of user permissions when modifying comments on the page builder. This oversight allows users with only content-level access to alter comments made by others, even on pages that they do not have access to view. As a resu...

PoC for CVE-2026-84745

WordPressThe Events Calendar
Improper Access Control in The Events Calendar Plugin for WordPress

The Events Calendar plugin for WordPress prior to version 6.17.3.1 has a significant security flaw that allows users with low-privilege roles, such as contributors, to access non-public content through public REST archives. This weakness results in unauthorized disclosure of unpublished records, ...

PoC for CVE-2026-83543

WordPressGreenshift
Arbitrary URL Fetching Vulnerability in Greenshift WordPress Plugin

The Greenshift WordPress plugin prior to version 13.2.0 contains a vulnerability that permits users with contributor-level access or higher to provide unvalidated URLs for server-side fetching. This flaw enables these users to create unrestricted requests to arbitrary external hosts, which may ex...

PoC for CVE-2026-84022

WordPressBold Page Builder
Cross-Site Scripting Flaw in Bold Page Builder Plugin by WordPress

The Bold Page Builder WordPress plugin prior to version 5.9.8 allows users with Contributor roles and higher to exploit a lack of sanitization and escaping of shortcode attributes. This oversight permits the injection of arbitrary web scripts into HTML attributes, leading to potential execution o...

PoC for CVE-2026-84021

WordPressBold Page Builder
Cross-Site Scripting Vulnerability in Bold Page Builder Plugin by W...

The Bold Page Builder plugin for WordPress, prior to version 5.9.8, contains a vulnerability that allows attackers to inject arbitrary web scripts. This occurs due to improper validation of link URLs, enabling users with roles as low as Contributor to execute malicious scripts when an affected li...

PoC for CVE-2026-83544

WordPressGreenshift
Cross-Site Scripting Vulnerability in Greenshift WordPress Plugin

The Greenshift plugin for WordPress prior to version 13.2.0 contains a vulnerability that arises from inadequate escaping of block animation attributes output within HTML. This flaw allows users with contributor-level access or higher to inject arbitrary web scripts into the content, which get ex...

PoC for CVE-2026-81424

WordPressAccept Stripe Payments
Payment Verification Flaw in Accept Stripe Payments Plugin by WordP...

The Accept Stripe Payments plugin for WordPress prior to version 2.1.4 lacks proper verification during the checkout process. Specifically, it does not ensure that the product fulfilled matches the actual purchase. Instead, it only checks if the amount paid meets or exceeds the product's price, w...

PoC for CVE-2026-81348

WordPressMy Private Site
Access Control Flaw in My Private Site Plugin for WordPress

The My Private Site plugin for WordPress, prior to version 4.2.3, fails to enforce proper access control on specific front-end elements. This oversight permits unauthenticated users to access restricted content, including posts, comments, and URLs, from sites that are intended to be private. Admi...

PoC for CVE-2026-82846

WordPressMasteriyo Lms
Stored Cross-Site Scripting Vulnerability in Masteriyo LMS Plugin f...

The Masteriyo LMS WordPress plugin prior to version 3.4.0 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper sanitization and escaping of certain course settings. This flaw allows users with a course-author role to inject malicious scripts into the output, which c...

PoC for CVE-2026-81423

WordPressAccept Stripe Payments
Unvalidated Redirect Vulnerability in Accept Stripe Payments Plugin...

The Accept Stripe Payments plugin for WordPress prior to version 2.1.4 contains a serious vulnerability where it fails to validate user-supplied URLs during redirection. This allows unauthenticated attackers to redirect visitors to arbitrary external websites, creating opportunities for phishing ...

PoC for CVE-2026-82304

WordPressMusic Store
SQL Injection Vulnerability in Music Store Plugin for WordPress

The Music Store plugin for WordPress, prior to version 1.4.5, is vulnerable to a SQL injection attack due to insufficient sanitization and escaping of user input. This security flaw allows unauthenticated users to manipulate SQL statements, potentially compromising the database integrity and expo...

PoC for CVE-2026-81404

WordPressIpgp Visitors Origin
Reflected Cross-Site Scripting Vulnerability in IPGP Visitors Origi...

The IPGP Visitors Origin plugin for WordPress fails to properly sanitize and escape user input before including it in the HTTP response. This oversight allows unauthenticated attackers to execute malicious scripts by tricking users into submitting crafted requests. As a result, an attacker could ...

PoC for CVE-2026-78362

WordPressSeo Flow By Lupsonline
API Credential Validation Flaw in SEO Flow by LupsOnline Plugin for...

The SEO Flow by LupsOnline WordPress plugin has a security weakness in its API credential validation process. This flaw allows unauthenticated users to impersonate the site administrator, provided that the plugin is set up in a typical manner. It poses a risk of unauthorized access and potential ...

PoC for CVE-2026-78150

WordPressSmart Post
Post Duplication Flaw in Smart Post Plugin for WordPress

The Smart Post WordPress plugin before version 4.0.8 suffers from an improper access control vulnerability, allowing users with contributor privileges and higher to duplicate any private or password-protected posts. This unauthorized access can lead to exposure of sensitive content and metadata, ...

PoC for CVE-2026-78149

WordPressSmart Post
Information Disclosure Vulnerability in Smart Post Plugin by WordPress

The Smart Post WordPress plugin prior to version 4.0.8 is susceptible to an information disclosure vulnerability. This flaw allows unauthenticated users to access the content of password-protected posts and retrieve their associated passwords through an unauthenticated AJAX request. This poses si...