Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2022-22965
A vulnerability in the Spring Framework could allow unauthorized remote code execution (RCE) when an application is running on JDK 9+ with Spring MVC or Spring WebFlux deployed as a WAR on a Tomcat server. If the application is executed as a Spring Boot executable JAR, it is not susceptible to th...
PoC for CVE-2026-3891
The Pix for WooCommerce plugin for WordPress is susceptible to arbitrary file uploads due to a lack of capability checks and insufficient file type validation within the 'lkn_pix_for_woocommerce_c6_save_settings' function. This vulnerability exists across all versions through 1.5.0. An unauthenti...
PoC for CVE-2026-15409
A Server-side Request Forgery (SSRF) vulnerability has been identified within the Work Place interface of the SMA1000 Appliance. This security flaw allows a remote attacker, without authentication, to exploit the appliance, enabling it to make requests to unintended and potentially malicious loca...
PoC for CVE-2026-26114
In Microsoft Office SharePoint, a vulnerability exists that enables an authorized attacker to manipulate untrusted data, leading to potential remote code execution. This flaw allows the attacker to send serialized data that can be improperly processed by the SharePoint server. If successfully exp...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2023-30547
The vm2 sandbox environment, designed for executing untrusted Node.js code, contains a vulnerability in its exception handling mechanism. Versions up to 3.9.16 are susceptible to an attack that allows an unsanitized host exception to be raised within the `handleException()` function. This flaw ca...
Discovered 14 minutes ago
PoC for CVE-2023-36874
The Windows Error Reporting Service contains a vulnerability that can allow attackers to elevate their privileges. This weakness may enable an unauthorized user to take control of affected systems, potentially leading to further exploits. It is essential for users to apply security updates and pa...
Discovered 28 minutes ago
PoC for CVE-2026-9848
The WP Ticket plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit SQL Injection through the search query parameter. This occurs when the plugin processes search requests without properly sanitizing inputs, leading to potential exposure of sensitive informatio...
Discovered 55 minutes ago
PoC for CVE-2026-43637
The Cornac library prior to version 2.6.0 is susceptible to a path traversal vulnerability, enabling malicious actors to exploit file writing practices. By delivering a specially crafted TAR archive that includes '../' sequences or absolute path definitions, attackers can manipulate the _extract_...
Discovered 2 hours ago
PoC for CVE-2026-63720
The datamodel-code-generator prior to version 0.70.0 is susceptible to a code injection issue that enables attackers with control over input schemas to execute arbitrary Python code. By providing a malicious customBasePath value—which includes embedded newlines and a dot-free Python expression—an...
PoC for CVE-2026-65321
PyAthena prior to version 3.35.4 is susceptible to SQL injection due to improper quote-escaping in the DefaultParameterFormatter.format() function. This flaw enables unauthenticated attackers to inject arbitrary SQL commands, particularly through DELETE and CTAS SQL statements. An exploit can occ...
Discovered 3 hours ago
PoC for CVE-2026-18616
A command injection vulnerability has been discovered in the GL-iNet GL-MT3000, specifically affecting versions up to 4.4.5. The issue arises from improper handling of the 'public_key' argument in the 'server.set_peer' function of the '/cgi-bin/glc' file within the 'wg-server.so' native plugin. T...
PoC for CVE-2026-18615
A command injection vulnerability exists in the GL-iNet GL-MT3000 device, specifically within the wg-server.generate_publickey function found in the /cgi-bin/glc path of the wg-server.so Native Plugin. By manipulating the private_key argument, an attacker could execute arbitrary commands on the s...
PoC for CVE-2026-18614
A command injection vulnerability exists in the GL-iNet GL-MT3000's s2s.so Native Plugin, specifically in the s2s.enable_echo_server function. This vulnerability allows attackers to manipulate the 'port' argument, enabling remote code execution through crafted input. The risk is heightened as the...
PoC for CVE-2026-18613
A security issue has been identified in GL-iNet's GL-MT3000 router affecting versions up to 4.4.5, specifically within the 'plugins.set_config' function located in the '/cgi-bin/glc' file of the 'plugins.so' native plugin. This vulnerability enables attackers to perform remote injection by manipu...
Discovered 4 hours ago
PoC for CVE-2026-18612
A vulnerability in the GL-iNet GL-MT3000 router has been identified that allows for command injection through the plugins.so Native Plugin. The flaw resides in the manipulation of the functions 'plugins.remove_package' and 'plugins.install_package' within the /cgi-bin/glc file. This issue can be ...
PoC for CVE-2026-18607
A security vulnerability has been identified in several Wavlink routers where a stack-based buffer overflow occurs in the upload.cgi file due to improper handling of the HTTP_COOKIE argument in the strcpy function. This flaw allows an attacker to remotely execute an exploit, which could lead to u...
Discovered 5 hours ago
PoC for CVE-2026-18606
A vulnerability in Razer's RzUpdateService version 1.10.14.0 was discovered that affects the Named Pipe Handler component. This security issue involves manipulations of the lpThreadParameter argument, which can lead to improper privilege management. Attackers with local access could exploit this ...
PoC for CVE-2026-67612
OpenEMR versions up to 8.2.0 are susceptible to a stored cross-site scripting (XSS) vulnerability found in the patient portal template system. Authenticated administrators can inadvertently introduce malicious HTML and JavaScript payloads through the template save mode, which inadequately filters...
PoC for CVE-2026-67611
OpenEMR versions until 8.2.0 exhibit a vulnerability that allows attackers with valid user credentials to bypass multi-factor authentication. This is accomplished by exploiting an unauthenticated client registration endpoint as part of the OAuth2 password grant flow. By registering an OAuth2 clie...
PoC for CVE-2026-67610
OpenEMR versions up to 8.2.0 are susceptible to an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint. This flaw allows unauthenticated attackers to register a malicious client by submitting a self-generated RSA keypair through the jwks field. Once an adminis...
PoC for CVE-2026-18605
A security flaw has been identified in CheckMAL AppCheck Pro version 3.1.43.10, stemming from an unknown function within the AppCheckD.sys library, which is part of the Kernel Mini-Filter Driver. This vulnerability allows for an uncontrolled search path that could be exploited through local manip...
PoC for CVE-2026-39932
OpenEMR versions prior to 8.2.0 are susceptible to a remote code execution vulnerability involving the document category tree component. Authenticated administrators can exploit this flaw by injecting malicious PHP payloads into the categories database table. Attackers may manipulate the id colum...
PoC for CVE-2026-39931
OpenEMR versions up to 8.2.0 contain a critical SQL injection vulnerability in the backup configuration import feature. This vulnerability enables attackers with administrative privileges to upload maliciously crafted SQL files, leading to unauthorized execution of arbitrary Data Definition Langu...
PoC for CVE-2026-41453
Krayin CRM versions prior to 2.2.4 are susceptible to a blind SQL injection vulnerability found in the leads DataGrid. This issue arises when authenticated users manipulate the 'rotten_lead[in]' query parameter, allowing them to inject arbitrary SQL into a HAVING clause. The vulnerability stems f...
PoC for CVE-2026-18604
A vulnerability found in the textPlus Text Message and Call App on Android, specifically impacting version 8.3.5, allows for improper export of application components through the DialerActivity. This security flaw necessitates local access to exploit and can lead to unauthorized access to sensiti...
PoC for CVE-2026-41452
Krayin CRM version 2.2.4 is susceptible to a vulnerability in its installer middleware that enables unauthorized remote attackers to compromise the primary administrator account. By crafting a specific HTTP POST request with an X-Requested-With: XMLHttpRequest header, attackers can circumvent the...
Discovered 6 hours ago
PoC for CVE-2026-39987
Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...
PoC for CVE-2026-18602
A command injection vulnerability exists in the GL.iNet GL-MT3000 router's ovpn-client native plugin. This vulnerability is triggered when an attacker manipulates the Hostname argument within the ovpn-client.get_recommend_config function. The flaw allows for remote exploitation, enabling unauthor...
PoC for CVE-2026-33937
In Handlebars versions 4.0.0 through 4.7.8, a vulnerability exists where `Handlebars.compile()` can accept a pre-parsed AST object directly. This leads to the potential injection of arbitrary JavaScript into the generated code because the `value` field of a `NumberLiteral` AST node is emitted dir...
PoC for CVE-2025-29927
A security flaw exists in the Next.js framework that allows an attacker to bypass authorization checks if such checks are implemented in middleware. This vulnerability arises in versions prior to 14.2.25 and 15.2.3. To mitigate risk, it is recommended to restrict incoming requests that include th...
Discovered 8 hours ago
PoC for CVE-2026-67609
An insecure sudoers configuration in Telenia Software TVox versions 26.5.3 and earlier (including 24.9.21 and prior) allows privileged elevation by users with access to the apache account. This loophole enables attackers to execute arbitrary commands as root without a password due to the NOPASSWD...
PoC for CVE-2026-67608
The TVox versions 26.5.3 and earlier, as well as 24.9.21 and prior, contain a significant OS command injection flaw located in the action_audio.php file. This vulnerability allows authenticated attackers to execute arbitrary operating system commands by manipulating the unsanitized 'pid' paramete...
PoC for CVE-2026-64827
An authentication bypass vulnerability exists in Telenia Software TVox versions 26.5.3 and earlier, as well as 24.9.21 and prior. The flaw is located in the set_env.php file, specifically within the redirectToLoginAdminIRequestHaveAccessToken() function. This function improperly derives the curre...
PoC for CVE-2026-18601
A command injection vulnerability has been identified in the GL.iNet GL-MT3000 router, specifically affecting the ovpn-client.check_config function within the /cgi-bin/glc of the ovpn-client.so Native Plugin. By manipulating the argument 'filename', an attacker can exploit this vulnerability to e...
PoC for CVE-2026-18600
A vulnerability has been identified in the GL.iNet GL-MT3000 device, specifically within the Network Lua RPC Plugin. The flaw lies in the handling of the 'switch' argument in the network.switch_info and network.switch_status functions. This weakness may allow an attacker to execute arbitrary comm...
PoC for CVE-2026-52887
NocoBase, an AI-powered no-code/low-code platform, has a vulnerability in versions prior to 2.0.61 due to an improper handling of input parameters in the notification API. The GET request to /api/myInAppChannels:list allows authenticated users to inject unvalidated input into SQL commands. This o...
Discovered 9 hours ago
PoC for CVE-2026-63223
CodeIgniter, a popular PHP web framework, has a vulnerability that arises from inadequate validation of uploaded files. Before version 4.7.4, the upload validation rules, specifically 'is_image' and 'mime_in', fail to enforce safe client filename extensions independently. This oversight allows re...
PoC for CVE-2026-12940
IBM Langflow OSS versions 1.0.0 through 1.10.1 are exposed to a remote code execution vulnerability due to improper handling of environment variables in the MCP (Model Context Protocol) stdio launcher. Specifically, the vulnerability lies in the failure of the software to include critical variabl...
PoC for CVE-2026-18599
A command injection vulnerability has been identified in the GL.iNet GL-MT3000 router, specifically affecting version 4.4.5. This flaw resides within the Logread Lua RPC Plugin, particularly in the logread.set_config function. An attacker can manipulate the record_size argument in a way that allo...
Discovered 10 hours ago
PoC for CVE-2026-18598
A command injection vulnerability exists in the Logread Lua RPC plugin of GL.iNet GL-MT3000 routers, specifically in the logread.get_system_log function. This flaw allows remote attackers to manipulate parameters, leading to unauthorized command execution on the device. The exploit is publicly av...
Discovered 12 hours ago
PoC for CVE-2026-1337
A cross-site scripting (XSS) vulnerability exists in the query log handling of Neo4j Enterprise and Community Editions prior to version 2026.01. Due to insufficient escaping of Unicode characters, users may inadvertently expose themselves to XSS attacks when logs are opened in tools that render t...
Discovered 13 hours ago
PoC for CVE-2026-18593
A vulnerability has been identified in the vxcontrol PentAGI product up to version 2.1.0, specifically affecting the Tool Management Protocol Handler. This vulnerability resides within the file backend/pkg/templates/prompts/pentester.tmpl and can potentially allow for remote exploitation leading ...
Discovered 14 hours ago
PoC for CVE-2026-18592
A security vulnerability has been identified in osCommerce version 4.14.63493, specifically within the EmailController function located in app/lib/backend/controllers/EmailController.php. This flaw allows an attacker to exploit the email_templates_key argument, leading to SQL injection. The attac...
PoC for CVE-2026-18591
A vulnerability in the Meesho Online Shopping App for Android, specifically in the com.meesho.supply component, allows for the unsafe handling of sensitive user data. This weakness results in the cleartext storage of personal information such as user ID, phone number, email address, and name, whi...
Discovered 15 hours ago
PoC for CVE-2026-16565
The Dokan WooCommerce Multivendor Marketplace Solution plugin prior to version 5.0.9 is susceptible to an authorization bypass vulnerability. This flaw occurs due to the plugin's failure to verify product ownership on its product-attribute REST write endpoints. As a result, users with Dokan vendo...
PoC for CVE-2026-16539
The Page Duplicator plugin for WordPress, up to version 1.0.0, contains an SQL injection vulnerability due to insufficient sanitization and escaping of user inputs during the page duplication process. This flaw allows users with the Editor role and higher to execute malicious SQL queries, potenti...
PoC for CVE-2026-16564
The Dokan plugin for WordPress prior to version 5.0.9 contains a significant access control vulnerability. This flaw does not verify the ownership of orders on a REST endpoint responsible for bulk order-status changes, which can permit users holding a Dokan vendor account to alter the status of a...
PoC for CVE-2026-16563
The Academy LMS WordPress plugin versions before 3.8.3 contains a vulnerability where the REST API does not properly verify course enrollment or status of lesson publication. This oversight allows users with a Subscriber-level account to access the content of lessons they are not enrolled in. Thi...
PoC for CVE-2026-16572
The LogMyTrip plugin for WordPress, up to version 1.9, is susceptible to SQL injection attacks due to its failure to properly sanitize and escape user input taken from cookies before incorporating it into SQL queries. This vulnerability permits unauthenticated users to manipulate the database thr...