Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered just now...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2024-8068

CitrixCitrix Session Recording5.1MEDIUM
Privilege Escalation in Citrix Session Recording

Security researchers have discovered critical vulnerabilities in Citrix Virtual Apps and Desktops that could potentially allow remote code execution (RCE) attacks. The vulnerabilities tracked as CVE-2024-8068 and CVE-2024-8069 affect the Session Recording component of Citrix Virtual Apps and Desk...

Discovered 3 hours ago

PoC for CVE-2018-1058

The Postgresql Gl...Postgresql🟣 EPSS 13%8.8HIGH
Query Behavior Modification Flaw in PostgreSQL by PostgreSQL Global...

A vulnerability exists in PostgreSQL that enables a user to manipulate the behavior of database queries for others. An attacker with a valid user account can exploit this flaw to execute code with superuser privileges, potentially compromising the integrity and security of the database system. Th...

PoC for CVE-2026-34486

ApacheApache Tomcat🟣 EPSS 83%7.5HIGH
Missing Encryption of Sensitive Data Vulnerability in Apache Tomcat

A vulnerability has been identified in Apache Tomcat that arises from missing encryption mechanisms for sensitive data, which could lead to data exposure. This issue was introduced as a result of the fix for another vulnerability, allowing the EncryptInterceptor to be bypassed. Users running vers...

Discovered 4 hours ago

PoC for CVE-2026-18504

FastifyFastify5.4MEDIUM
Schema Validation Bypass in Fastify Web Framework by Fastify

A schema validation bypass in the Fastify web framework can allow unvalidated request bodies to reach the application logic. Affected versions prior to 5.12.1 fail to replace the root request body with a coerced value when a request body schema targets a top-level primitive. This allows invalid d...

Discovered 7 hours ago

PoC for CVE-2026-19416

WordPressKivicare
Authentication Bypass in KiviCare Plugin for WordPress

The KiviCare WordPress plugin, prior to version 4.5.4, lacks sufficient checks to ensure that users are authorized to modify appointments. This flaw allows authenticated patients to manipulate other patients' appointments by canceling or rescheduling them without proper permissions. As a result, ...

PoC for CVE-2026-19782

WordPressWPs Bidouille
Authorization Flaw in WPS Bidouille Plugin by WordPress

The WPS Bidouille plugin for WordPress prior to version 1.33.5 lacks adequate authorization checks in an AJAX action, potentially allowing any authenticated user—such as a subscriber—to access and retrieve the email addresses of all registered users. This vulnerability raises significant privacy ...

PoC for CVE-2026-19842

WordPressSaml Single Sign On
Signature Verification Flaw in SAML Single Sign On Plugin for WordP...

The SAML Single Sign On WordPress plugin, prior to version 5.4.7, contains a serious security flaw that fails to adequately verify the signature of SAML responses before storing the accompanying certificate. This oversight allows an admin-level user to inadvertently promote an unverified certific...

PoC for CVE-2026-19709

WordPressMembership For WooComm...
API Security Flaw in Membership for WooCommerce Plugin by WordPress

The Membership for WooCommerce plugin prior to version 3.1.2 lacks adequate validation to ensure an API consumer secret is generated before allowing access to its REST API routes. This oversight permits unauthenticated attackers to exploit the API, potentially revealing sensitive user membership ...

PoC for CVE-2026-19417

WordPressKivicare
Unrestricted File Download Vulnerability in KiviCare WordPress Plugin

The KiviCare WordPress plugin, versions prior to 4.5.4, is susceptible to an unrestricted file download vulnerability. This security flaw arises from the plugin's failure to properly verify if an authenticated user has the right to access specific media files. As a result, patient-level users may...

PoC for CVE-2026-18779

WordPressTruebooker
Unauthorized Access in TrueBooker Plugin for WordPress

The TrueBooker WordPress plugin, prior to version 1.2.7, contains a security flaw that lacks appropriate authorization checks in one of its AJAX actions. This vulnerability enables unauthenticated users to potentially delete any appointment records, along with related booking items and payment da...

PoC for CVE-2026-19406

WordPressEasy Appointments
Insufficient Access Control in Easy Appointments WordPress Plugin b...

The Easy Appointments plugin for WordPress, prior to version 4.0.1, is affected by a vulnerability that permits users with contributor-level access to read and retrieve all appointment records through an unsecured REST endpoint. This oversight exposes sensitive information, including customer nam...

PoC for CVE-2026-19056

WordPressProsolution WP Client
Reflected Cross-Site Scripting Vulnerability in ProSolution WP Clie...

The ProSolution WP Client plugin for WordPress, prior to version 2.0.11, contains a flaw that allows for reflected Cross-Site Scripting (XSS). This weakness arises from the improper sanitization and escaping of a parameter that is reflected in an HTML attribute on one of its administrative pages....

PoC for CVE-2026-19055

WordPressProsolution WP Client
Reflected Cross-Site Scripting Vulnerability in ProSolution WP Clie...

The ProSolution WP Client plugin for WordPress contains a reflected Cross-Site Scripting (XSS) vulnerability that can be exploited by attackers. The issue arises from the plugin's failure to adequately sanitize and escape numerous parameters before incorporating them into HTML attributes on publi...

PoC for CVE-2026-18937

WordPressBroken Link Checker
Arbitrary Code Execution Vulnerability in Broken Link Checker Plugi...

The Broken Link Checker plugin for WordPress, prior to version 2.4.12, is susceptible to a serious security vulnerability. This issue arises from the lack of restrictions on the query variables that the plugin accepts from user input on sites employing plain permalinks. As a result, unauthenticat...

PoC for CVE-2026-18466

WordPressWP Maps
Excessive Database Option Creation in WP Maps Plugin from WordPress

The WP Maps plugin for WordPress, before version 4.9.8, is susceptible to an improper capability check that does not validate user permissions during certain AJAX actions. This flaw permits users with a Subscriber account to create an unlimited number of options within the database, leading to po...

PoC for CVE-2026-18776

WordPressTruebooker
Authorization Flaw in TrueBooker Plugin for WordPress

The TrueBooker plugin for WordPress prior to version 1.2.7 contains a significant vulnerability due to inadequate authorization checks within specific AJAX actions. This flaw enables unauthenticated users to alter the email addresses of any user accounts, including those of administrators. By cha...

PoC for CVE-2026-18777

WordPressTruebooker
Authorisation Failure in TrueBooker Plugin by WordPress

The TrueBooker WordPress plugin, prior to version 1.2.7, is susceptible to an authorization bypass vulnerability in its AJAX actions. This flaw permits unauthenticated users to manipulate the status of any appointment and trigger notification emails to clients involved. Such unauthorized access c...

PoC for CVE-2026-18778

WordPressTruebooker
Improper Authorization in TrueBooker Plugin for WordPress

The TrueBooker WordPress plugin prior to version 1.2.7 lacks essential authorization checks in specific AJAX actions. This vulnerability permits unauthorized users to access sensitive customer information, including names, email addresses, phone numbers, and postal addresses, associated with appo...

PoC for CVE-2026-17565

WordPressAnimation Addons For E...
Server-Side Request Forgery in Animation Addons for Elementor Plugin

The Animation Addons for Elementor WordPress plugin prior to version 2.7.2 is susceptible to a server-side request forgery (SSRF) vulnerability. This occurs when the plugin fails to validate a user-supplied input, enabling unauthorized users to create HTTP requests to internal resources on the se...

PoC for CVE-2026-18202

WordPressJetengine
Stored Cross-Site Scripting Vulnerability in JetEngine WordPress Pl...

The JetEngine WordPress plugin prior to version 3.8.14 permits the inclusion of SVG files in the allowed upload types without proper sanitization of the file contents. This vulnerability enables users, such as Authors with file upload capabilities, to upload files containing malicious JavaScript....

PoC for CVE-2026-18051

WordPressW3 Total Cache
File Write Vulnerability in W3 Total Cache Plugin for WordPress

The W3 Total Cache plugin for WordPress prior to version 2.10.5 contains a vulnerability due to improper validation of request paths. This flaw permits unauthenticated attackers to write files to any directory on the server, potentially overwriting existing files, including critical configuration...

PoC for CVE-2026-18031

WordPressTabapay Gateway
Unauthorized Access in TabaPay Gateway WordPress Plugin

The TabaPay Gateway WordPress plugin, up to version 1.4.0, lacks proper validation of payment callbacks. This failure allows attackers to bypass authentication measures, granting them unauthorized access to the accounts of registered users, including administrative accounts. Such vulnerabilities ...

PoC for CVE-2026-18231

WordPressWP Directory Kit
Authorization Bypass Vulnerability in WP Directory Kit WordPress Pl...

A vulnerability exists in the WP Directory Kit WordPress plugin, prior to version 1.5.7, that lacks proper authorization checks on a public AJAX action. This flaw allows unauthorized attackers to query unfiltered database rows, potentially exposing sensitive user data such as usernames and email ...

PoC for CVE-2026-16950

WordPressProduct Shortlist
SQL Injection Vulnerability in Product Shortlist Plugin by WordPress

The Product Shortlist plugin for WordPress, up to version 1.0.4, is susceptible to SQL injection due to inadequate sanitization and escaping of user input. This vulnerability enables an attacker without authentication to execute malicious SQL queries, potentially compromising the database and exp...

PoC for CVE-2026-16617

WordPressSimple File List
Stored Cross-Site Scripting Vulnerability in Simple File List Plugi...

The Simple File List plugin for WordPress, up to version 6.3.11, is susceptible to a stored cross-site scripting vulnerability. This arises from the plugin's failure to adequately sanitize and escape file descriptions before displaying them on the public file list. When front-end file management ...

PoC for CVE-2026-16979

WordPressSmartcrawl Seo Checker...
Information Disclosure in SmartCrawl SEO Plugin for WordPress

The SmartCrawl SEO plugin for WordPress, prior to version 3.16.3, has a security flaw that allows users with a Subscriber role to bypass capability checks on certain AJAX actions. This vulnerability enables these users to access titles of private and draft posts by their ID, as well as enumerate ...

PoC for CVE-2026-16616

WordPressSimple File List
File Manipulation Vulnerability in Simple File List Plugin by WordP...

The Simple File List WordPress plugin through version 6.3.11 is vulnerable due to its failure to validate the source path during file-move operations. This issue allows unauthenticated users to access arbitrary files on the server. Moreover, it enables them to move critical files out of the web r...

PoC for CVE-2026-16570

WordPressNextscripts: Social Ne...
Reflected Cross-Site Scripting Vulnerability in NextScripts Social ...

The NextScripts Social Networks Auto-Poster WordPress plugin prior to version 4.4.8 is susceptible to reflected Cross-Site Scripting (XSS) due to improper escaping of certain query-string parameters. This vulnerability can be exploited by malicious actors to craft special links that, when clicked...

PoC for CVE-2026-15253

WordPressEasy Media Replace
Cross-Site Scripting Vulnerability in Easy Media Replace Plugin for...

The Easy Media Replace plugin for WordPress, through version 0.2.0, contains a vulnerability that allows arbitrary web scripts to be injected into HTML attributes. This occurs because the plugin fails to adequately sanitize and escape attachment titles before rendering them in the media library l...

PoC for CVE-2026-14861

WordPressUser Verification By P...
User Verification Bypass in PickPlugins WordPress Plugin

The User Verification by PickPlugins plugin for WordPress, specifically versions up to 2.0.47, reveals a significant security flaw. This issue arises from the plugin's failure to authenticate requests for resending verification emails. As a result, unauthorized users can manipulate the email-veri...

PoC for CVE-2026-16058

WordPressYaycurrency
Unauthorized Data Exposure in YayCurrency WordPress Plugin

The YayCurrency WordPress plugin prior to version 3.3.5 fails to implement necessary capability and ownership checks in its multi-vendor integration handlers. This oversight allows unauthenticated users to access sensitive data, including order totals, vendors' earnings, balance ledgers, and with...

PoC for CVE-2026-14826

WordPressQuiz And Survey Master...
Authorization Flaw in Quiz and Survey Master Plugin by WordPress

The Quiz and Survey Master plugin for WordPress prior to version 11.2.4 has a significant authorization issue in its REST routes. Users with contributor-level access and above can access sensitive configuration data for quizzes created by other users, including email notification recipient addres...

PoC for CVE-2026-14287

WordPress10web Booster
Unauthorized Access Vulnerability in 10Web Booster Plugin by WordPress

The 10Web Booster plugin for WordPress prior to version 2.33.5 is susceptible to an unauthorized access vulnerability. This issue arises due to inadequate validation of access tokens on an unauthenticated request handler. Additionally, the plugin fails to properly escape attacker-provided stylesh...

PoC for CVE-2026-14196

WordPressWcfm Marketplace
Review Management Flaw in WCFM Marketplace Plugin for WordPress

The WCFM Marketplace plugin for WordPress contains a serious vulnerability wherein it fails to ensure that a marketplace vendor is the rightful owner of a review before permitting its deletion or unapproval. This oversight allows vendors to inappropriately alter or eliminate reviews linked to oth...

PoC for CVE-2026-14825

WordPressQuiz And Survey Master...
Improper Access Control in Quiz and Survey Master Plugin for WordPress

The Quiz and Survey Master plugin for WordPress prior to version 11.2.4 has a security flaw that fails to perform ownership checks on quiz settings. This allows users with contributor rights or higher to alter frontend text settings for quizzes they did not create, potentially leading to unauthor...

PoC for CVE-2026-14334

WordPressBooking Calendar, Appo...
Improperly Sanitized SVG File Upload in Booking Calendar WordPress ...

The Booking Calendar, Appointment Booking System WordPress plugin, up to version 3.2.36, is affected by a vulnerability that fails to adequately sanitize uploaded SVG files. This oversight allows unauthenticated attackers to upload malicious SVG files which can execute arbitrary JavaScript when o...

PoC for CVE-2026-13173

WordPressEventin
Role Modification Vulnerability in Eventin WordPress Plugin by Eventin

The Eventin WordPress plugin prior to version 4.1.21 suffers from a permissions oversight, allowing users with contributor-level access and higher to alter the roles and metadata of other users during speaker creation. This vulnerability enables unauthorized changes, potentially leading to privil...

PoC for CVE-2026-13175

WordPressEventin
Unauthorized Schedule Modification in Eventin WordPress Plugin by E...

The Eventin WordPress plugin prior to version 4.1.21 lacks proper validation of user ownership when modifying or deleting schedule entries. This oversight permits users with contributor-level access and higher to manipulate schedule records created by other users, potentially leading to unauthori...

PoC for CVE-2026-12983

WordPressDinatur
SQL Injection and Data Loss Vulnerability in Dinatur WordPress Plugin

The Dinatur WordPress plugin version 1.18 is vulnerable due to improper handling of user input, which can lead to SQL injection attacks. This allows unauthenticated users to manipulate SQL queries and gain unauthorized access to sensitive database information. Additionally, the plugin lacks neces...

PoC for CVE-2026-13169

WordPressEventin
Authorization Flaw in Eventin WordPress Plugin by Eventin

The Eventin WordPress plugin prior to version 4.1.21 lacks adequate verification of event ownership, enabling users with contributor-level access or higher to modify, delete, or reassign events created by other users, including those with administrator privileges. This oversight poses significant...

PoC for CVE-2026-13174

WordPressEventin
Unauthorized Account Deletion in Eventin Plugin for WordPress

The Eventin WordPress plugin prior to version 4.1.21 contains an access control vulnerability that does not properly verify user ownership or capabilities. As a result, individuals with contributor-level access and higher are able to delete other users' accounts permanently. This flaw can lead to...

PoC for CVE-2026-11565

WordPressAdvanced File Manager
File Management Flaw in Advanced File Manager Plugin by WordPress

The Advanced File Manager plugin for WordPress, before version 5.4.13, contains a significant security issue due to insufficient capability checks in its file management AJAX actions. This deficiency permits users with any role that has been granted file-manager access—potentially even those with...

Discovered 10 hours ago

PoC for CVE-2026-76050

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A security flaw has been identified in the SourceCodester Simple Online Food Ordering System version 1.0, specifically within the /admin/ajax.php?action=delete_menu endpoint. By manipulating the 'ID' parameter, an attacker can execute SQL injection attacks remotely, potentially compromising the i...

PoC for CVE-2026-76049

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A SQL injection vulnerability exists in the SourceCodester Simple Online Food Ordering System 1.0, specifically in the function handling requests at /admin/ajax.php?action=save_menu. By manipulating the ID parameter, unauthorized parties are able to execute arbitrary SQL queries on the database, ...

PoC for CVE-2026-76048

SourcecodesterSimple Online Food Ord...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Online Food Or...

A vulnerability has been identified in the SourceCodester Simple Online Food Ordering System, specifically within an unknown function in the /admin/ajax.php file during the login process. This flaw allows an attacker to manipulate the Username parameter, resulting in a SQL injection. Such an atta...

PoC for CVE-2026-76014

BusyBoxBusybox4.8MEDIUM
BusyBox Vulnerability in FEATURE_WGET_TIMEOUT Leading to Null Point...

A vulnerability exists in BusyBox affecting the FEATURE_WGET_TIMEOUT handler in networking/wget.c, specifically due to improper handling of the -T argument. This vulnerability can lead to a null pointer dereference, potentially allowing local users to exploit the issue. Due to the public disclosu...

Discovered 11 hours ago

PoC for CVE-2026-76004

UttHiper 1250gw9.4CRITICAL
Buffer Overflow Vulnerability in UTT HiPER 1250GW by UTT

A vulnerability in the UTT HiPER 1250GW's HTTP Handler component enables stack-based buffer overflow through improper handling of pvid in the strcpy function. This security weakness permits remote attackers to exploit the flaw, potentially leading to unauthorized access and system compromise. The...

PoC for CVE-2026-76003

UttHiper 1200gw9.4CRITICAL
Stack-Based Buffer Overflow in UTT HiPER 1200GW - Vulnerability Alert

A stack-based buffer overflow vulnerability has been discovered in the UTT HiPER 1200GW router, specifically in the strcpy function within the formGroupConfig file. By manipulating the argument 'timestart', attackers may exploit this weakness remotely, potentially leading to unauthorized access o...

Discovered 12 hours ago

PoC for CVE-2026-75986

Code-projectsOnline Job Portal System6.9MEDIUM
SQL Injection Exploit in Code-Projects Online Job Portal System's P...

A security flaw exists in the Online Job Portal System version 1.0 affecting the password recovery functionality. An inadequately validated input in the file /ForPass.php allows remote attackers to exploit the system through SQL injection by manipulating the user name argument directly. Given the...