Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 1 hour ago

PoC for CVE-2025-68645

ZimbraZimbra Collaboration8.8HIGH
Local File Inclusion Vulnerability in Zimbra Collaboration by Zimbra

A Local File Inclusion (LFI) vulnerability has been identified in the Webmail Classic UI of Zimbra Collaboration (ZCS) versions 10.0 and 10.1. This flaw stems from the improper handling of user-supplied request parameters within the RestFilter servlet. An unauthenticated remote attacker can explo...

Discovered 2 hours ago

PoC for CVE-2025-15409

Code-projectsOnline Guitar Store6.9MEDIUM
SQL Injection Vulnerability in Online Guitar Store by Code-Projects

A vulnerability has been identified in the Online Guitar Store application version 1.0, affecting the deletion functionality located in /admin/Delete_product.php. By manipulating the 'del_pro' argument, attackers can execute SQL injection attacks, allowing unauthorized access to the underlying da...

Discovered 3 hours ago

PoC for CVE-2025-15408

Code-projectsOnline Guitar Store6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Online Guitar Store 1.0

A vulnerability exists in the Online Guitar Store 1.0 due to improper handling of input in the Create_product.php file. By manipulating the 'dre_title' argument, an attacker can execute SQL injection attacks remotely. This flaw exposes the application to unauthorized data access and integrity thr...

PoC for CVE-2022-26711

AppleWatch OS9.8CRITICAL
Integer Overflow Vulnerability in Apple Products

An integer overflow vulnerability was identified in Apple’s operating systems, where improper input validation could allow a remote attacker to disrupt the application or potentially execute arbitrary code. This flaw affects several versions of tvOS, iTunes, iOS, iPadOS, watchOS, and macOS, neces...

PoC for CVE-2025-15407

Code-projectsOnline Guitar Store6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Online Guitar Store 1.0

A vulnerability exists in the Code-Projects Online Guitar Store version 1.0, specifically within the /admin/Create_category.php file. This security flaw allows for SQL injection through improper handling of user-input parameters in the dre_Ctitle argument. As the vulnerability is publicly disclos...

Discovered 4 hours ago

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 49%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

PoC for CVE-2025-15406

PHPgurukulOnline Course Registra...5.3MEDIUM
Authorization Flaw in PHPGurukul Online Course Registration System

A vulnerability in the PHPGurukul Online Course Registration system up to version 3.1 has been identified, which allows an attacker to bypass authorization mechanisms. This flaw can potentially lead to unauthorized access, enabling remote exploitation by malicious actors. As the exploit has been ...

PoC for CVE-2024-21413

MicrosoftMicrosoft Office 2019🟣 EPSS 93%9.8CRITICAL
Remote Code Execution Vulnerability Affects Microsoft Outlook

A remote code execution vulnerability in Microsoft Outlook allows an attacker to run arbitrary code on a user's system. This can occur when the vulnerable version processes specially crafted email messages, which can result in unauthorized access or control over the affected system. Attackers can...

Discovered 6 hours ago

PoC for CVE-2025-15405

PHPEMSPHPms5.3MEDIUM
Cross-Site Request Forgery Vulnerability in PHPEMS by PHPEMS

A cross-site request forgery (CSRF) vulnerability has been identified in PHPEMS versions up to 11.0, associated with an unspecified function. This flaw allows malicious actors to execute unauthorized commands on behalf of authenticated users, potentially compromising sensitive data and the integr...

Discovered 7 hours ago

PoC for CVE-2024-41997

WarpWarp Terminal
Command Injection Vulnerability in Warp Terminal Docker Integration

A command injection vulnerability has been identified in Warp Terminal's Docker integration, affecting versions prior to 2024.07.18. This issue allows an attacker to craft a malicious hyperlink capable of executing arbitrary commands on the victim's machine if clicked. Users are urged to update t...

PoC for CVE-2025-67730

FrappeLms5.1MEDIUM
XSS Vulnerability in Frappe Learning Management System Prior to Ver...

The Frappe Learning Management System (LMS) prior to version 2.42.0 is susceptible to a Cross-Site Scripting (XSS) vulnerability. This allows authenticated users to exploit the system by injecting malicious HTML and JavaScript into the description fields found in Job, Course, and Batch forms. Suc...

PoC for CVE-2025-15404

CampcodesSchool File Management...5.3MEDIUM
Unrestricted File Upload Vulnerability in Campcodes School File Man...

A security vulnerability in Campcodes School File Management System version 1.0 exposes an unknown function within the /save_file.php file, allowing attackers to manipulate the File argument. This can lead to unrestricted file uploads, potentially enabling remote exploitation. This issue has been...

Discovered 15 hours ago

PoC for CVE-2025-13820

WordPressComments
User Authentication Weakness in WordPress Comments Plugin by Disqus

The Comments plugin for WordPress, prior to version 7.6.40, exposes a critical vulnerability involving improper validation of user identities when integrating with the disqus.com provider. This issue allows attackers to bypass authentication mechanisms and log in as any user, simply by having kno...

Discovered 23 hours ago

PoC for CVE-2025-15398

UasoftBadaso6.3MEDIUM
Remote Manipulation Vulnerability in Uasoft Badaso Token Handler

A security vulnerability exists in the Uasoft Badaso platform, specifically within the Token Handler's forgetPassword function located in the BadasoAuthController.php file. This flaw can lead to inadequate password recovery processes, potentially allowing unauthorized access to user accounts. Att...

Discovered 1 day ago

PoC for CVE-2015-10145

GargoyleGargoyle Router Manage...8.7HIGH
Authenticated OS Command Execution Vulnerability in Gargoyle Router...

The Gargoyle router management utility versions 1.5.x contains an authenticated OS command execution vulnerability. The flaw resides in the /utility/run_commands.sh script, where the application does not properly validate or restrict inputs supplied via the 'commands' parameter. This oversight al...

PoC for CVE-2025-15394

iCMS DevIcms5.1MEDIUM
Code Injection Vulnerability in iCMS Software by iCMS Dev

A vulnerability identified in iCMS, impacting versions up to 8.0.0, arises from a flaw in the Save function of the app/config/ConfigAdmincp.php file. This issue permits attackers to manipulate the configuration settings through POST requests, leading to potential code injection. As a result, an a...

PoC for CVE-2021-47743

Commax Co., Ltd.Commax Biometric Acces...5.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in COMMAX Biometric Ac...

The COMMAX Biometric Access Control System 1.0.0 is susceptible to an unauthenticated reflected cross-site scripting vulnerability. Exploitation occurs through manipulation of the 'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM' cookie parameters, allowing malicious actors to inject and execute arbitrary HTML...

PoC for CVE-2021-47740

Kz Broadband Tech...Jt3500v6.9MEDIUM
Session Management Vulnerability in KZTech JT3500V 4G LTE CPE

The KZTech JT3500V 4G LTE CPE (version 2.0.1) is affected by a vulnerability that allows attackers to exploit inadequate session expiration controls. This flaw permits the reuse of old session credentials, enabling unauthorized users to maintain access and potentially compromise the authenticatio...

PoC for CVE-2021-47725

Stvs SaStvs Provision4.8MEDIUM
Cross-Site Scripting Vulnerability in STVS ProVision by STVS

STVS ProVision version 5.9.10 is susceptible to a cross-site scripting (XSS) vulnerability allowing authenticated attackers to manipulate the 'files' POST parameter. This weakness enables the injection of arbitrary HTML code, resulting in the execution of malicious scripts in the user's browser s...

PoC for CVE-2021-47747

MeternMetern8.6HIGH
Authenticated Remote Code Execution in MeterN by MeterN.org

MeterN version 1.2.3 has a significant vulnerability that allows attackers to perform authenticated remote code execution via the 'COMMANDx' and 'LIVECOMMANDx' POST parameters in the admin_meter2.php and admin_indicator2.php scripts. This flaw enables an attacker with administrative access to exe...

PoC for CVE-2021-47745

Cypress2008.6HIGH
Authenticated Command Injection Vulnerability in Cypress Solutions ...

Cypress Solutions CTM-200 version 2.7.1 is vulnerable to an authenticated command injection attack through its firmware upgrade script. The vulnerability exists within the 'fw_url' parameter of the ctm-config-upgrade.sh script, allowing remote attackers to inject and execute arbitrary shell comma...

PoC for CVE-2021-47744

CypressOne9.3CRITICAL
Hard-Coded Credentials Vulnerability in Cypress Solutions CTM-200/C...

The CTM-200 and CTM-ONE devices by Cypress Solutions include a security flaw identified by hard-coded credentials, specifically a static 'Chameleon' password. This vulnerability allows attackers to exploit the affected Linux distribution, providing them with unauthorized remote root access throug...

PoC for CVE-2021-47742

Epic Games Inc.Epic Games Psyonix Roc...8.5HIGH
Insecure Permissions in Epic Games Psyonix Rocket League

Epic Games' Psyonix Rocket League before version 1.95 contains a vulnerability related to insecure permissions. This issue permits authenticated users to alter executable files, leveraging full access permissions assigned to the 'Authenticated Users' group. This could lead to unauthorized modific...

PoC for CVE-2021-47741

ZblchinaZbl Epon Onu Broadband...8.7HIGH
Privilege Escalation Vulnerability in ZBL EPON ONU Broadband Router...

The ZBL EPON ONU Broadband Router V100R001 possesses a vulnerability that allows limited administrative users to escalate their privileges. This is achieved by sending specially crafted requests to the router's configuration endpoints, enabling attackers to potentially access sensitive configurat...

PoC for CVE-2021-47726

NucomNucom 11n Wireless Router8.7HIGH
Privilege Escalation Vulnerability in NuCom 11N Wireless Router

The NuCom 11N Wireless Router version 5.07.90 is vulnerable to privilege escalation due to improper handling of requests to the configuration backup endpoint. Non-privileged users can exploit this flaw by sending a specially crafted HTTP GET request. This allows attackers to access and decode sen...

PoC for CVE-2020-36904

SeleaSelea Carplateserver (...9.3CRITICAL
Remote Program Execution in Selea CarPlateServer by Selea

Selea CarPlateServer version 4.0.1.6 has a vulnerability that permits remote program execution via a misconfigured NO_LIST_EXE_PATH parameter. By exploiting this flaw, attackers can bypass authentication through the /cps/ endpoint, gaining the ability to alter server configurations. This can lead...

PoC for CVE-2020-36903

SeleaSelea Carplateserver (...8.5HIGH
Local Privilege Escalation in Selea CarPlateServer by Unquoted Serv...

The Selea CarPlateServer 4.0.1.6 features a vulnerability related to an unquoted service path in its Windows service configuration. This flaw enables local users to potentially execute arbitrary code with elevated privileges. By exploiting the unquoted binary path associated with the service, an ...

PoC for CVE-2025-15391

D-linkDir-806a5.3MEDIUM
Command Injection Vulnerability in D-Link DIR-806A Router

A command injection vulnerability has been discovered in the D-Link DIR-806A router within the SSDP Request Handler's ssdpcgi_main function. This flaw allows remote attackers to manipulate inputs and execute arbitrary commands on the device, potentially compromising its security. The risk is part...

PoC for CVE-2025-15390

PHPgurukulSmall Crm5.3MEDIUM
Authorization Flaw in PHPGurukul Small CRM 4.0

A security vulnerability has been identified in PHPGurukul Small CRM version 4.0, specifically within the /admin/edit-user.php file. This issue involves a lack of proper authorization checks, allowing unauthorized users to manipulate the system remotely. The flaw has been made publicly known, and...

PoC for CVE-2025-7771

TecHPowerupThrottlestop8.7HIGH
Privilege Escalation Vulnerability in ThrottleStop Driver by TechPo...

The ThrottleStop driver, a legitimate component from TechPowerUp, presents a vulnerability due to insecure IOCTL interfaces that permit arbitrary read and write access to the physical memory through the MmMapIoSpace function. This flaw can be exploited by malicious applications running in user mo...

PoC for CVE-2025-58360

GeoserverGeoserver🟣 EPSS 84%8.2HIGH
XML External Entity Flaw in GeoServer by OSGeo

GeoServer, an open-source server used for sharing and editing geospatial data, has been found to contain an XML External Entity (XXE) vulnerability. The issue emerges in versions 2.26.0 to just before 2.26.2 and prior to 2.25.6, where unsanitized XML input can be processed through the specific en...

Discovered 2 days ago

PoC for CVE-2025-14847

MongoDBMongodb Server🟣 EPSS 77%8.7HIGH
Heap Memory Exposure in MongoDB Server Versions by MongoDB

The vulnerability arises from mismatched length fields in Zlib compressed protocol headers within MongoDB Server, potentially allowing an unauthenticated client to access uninitialized heap memory. This could lead to unauthorized information exposure, affecting versions of MongoDB Server across m...

PoC for CVE-2025-14434

WordPressUltimate Post Kit Addo...
Unsecured AJAX Endpoints in Ultimate Post Kit Addons for Elementor ...

The Ultimate Post Kit Addons for Elementor plugin versions prior to 4.0.16 suffer from an improper access control vulnerability. Specifically, multiple AJAX endpoints, such as upk_alex_grid_loadmore_posts, are exposed without proper authentication checks. This oversight allows unauthenticated att...

PoC for CVE-2025-13029

WordPressKnowband Mobile App Bu...
User Deletion Vulnerability in Knowband Mobile App Builder by Knowband

The Knowband Mobile App Builder WordPress plugin prior to version 3.0.0 contains a security flaw that permits unauthenticated users to delete any user account through its REST API. This vulnerability arises from missing authorization checks, allowing attackers to exploit the system and remove use...

PoC for CVE-2025-15375

Eyou TechnologyEyoucms5.3MEDIUM
Deserialization Vulnerability in EyouCMS 1.7.7 by Eyou Technology

A deserialization vulnerability has been identified in EyouCMS up to version 1.7.7, affecting the application/api/controller/Ajax.php component. This flaw exists in the unserialize function, which can be exploited through manipulation of the attstr argument, allowing remote attackers to potential...

PoC for CVE-2025-15374

EyouCMSEyoucms5.1MEDIUM
Cross Site Scripting Vulnerability in EyouCMS Up to Version 1.7.7

A vulnerability exists in EyouCMS, specifically in the Ask Module's Ask.php file, allowing malicious actors to perform cross site scripting (XSS) attacks. This can be triggered by manipulating the 'content' argument within the application. Remote attackers can exploit this weakness, potentially c...

PoC for CVE-2025-15373

EyouEyoucms5.3MEDIUM
Server-Side Request Forgery in EyouCMS by Eyou

A security vulnerability has been identified in EyouCMS versions up to 1.7.7, specifically within the saveRemote function in application/function.php. This flaw allows for server-side request forgery (SSRF), enabling attackers to manipulate requests and potentially expose sensitive server-side re...

PoC for CVE-2025-52691

SmartertoolsSmartermail10CRITICAL
Remote Code Execution Vulnerability in Mail Server Product by Vendor

A vulnerability allows unauthenticated attackers to exploit the mail server product, facilitating the upload of arbitrary files to any location on the server. This could lead to unauthorized actions, including the potential for remote code execution, thereby compromising the integrity and securit...

PoC for CVE-2025-15223

PhilipinhoSimple-PHP-blog5.3MEDIUM
Cross Site Scripting Vulnerability in Philipinho Simple-PHP-Blog

A Cross Site Scripting vulnerability exists in Philipinho Simple-PHP-Blog, specifically in the /login.php file. The vulnerability arises when an attacker manipulates the Username parameter, enabling remote execution of malicious scripts. This issue affects the product's integrity, making user dat...

PoC for CVE-2025-40019

LinuxLinux
Decryption Vulnerability in Linux Kernel Crypto Module

A vulnerability has been identified in the Linux kernel's crypto module that potentially affects the integrity of encryption methods. The issue arises from the handling of the ssize parameter during decryption and in-place encryption processes. Specifically, the ssize check was not conducted earl...

PoC for CVE-2025-15372

YoulaitechVue3-element-admin4.8MEDIUM
Cross-Site Scripting Vulnerability in youlaitech Vue3-Element-Admin

A cross-site scripting vulnerability has been identified in the youlaitech Vue3-Element-Admin component, specifically within the file src/views/system/notice/index.vue. This flaw permits remote attackers to inject malicious scripts into the application, which can be executed in the context of the...

PoC for CVE-2025-15371

TendaI248.5HIGH
Shadow File Vulnerability in Tenda Networking Products

A serious vulnerability affecting Tenda networking products has been identified in the Shadow File component. This flaw allows local attackers to gain unauthorized access due to the presence of hard-coded credentials. Disclosed publicly, the vulnerability highlights the need for immediate action ...

PoC for CVE-2025-14847

MongoDBMongodb Server🟣 EPSS 77%8.7HIGH
Heap Memory Exposure in MongoDB Server Versions by MongoDB

The vulnerability arises from mismatched length fields in Zlib compressed protocol headers within MongoDB Server, potentially allowing an unauthenticated client to access uninitialized heap memory. This could lead to unauthorized information exposure, affecting versions of MongoDB Server across m...

PoC for CVE-2022-40471

Clinic\'s Patient...Clinic\'s Patient Mana...🟣 EPSS 88%9.8CRITICAL
Remote Code Execution Vulnerability in Clinic's Patient Management ...

The vulnerability in Clinic's Patient Management System version 1.0 allows an attacker to execute arbitrary code remotely. This is achieved through a flaw in the profile picture upload feature located in users.php, which does not adequately validate file uploads. As a result, an attacker can uplo...

PoC for CVE-2022-50802

Etap Lighting Int...Etap Safety Manager5.1MEDIUM
Cross-Site Scripting Vulnerability in ETAP Safety Manager by ETAP

The ETAP Safety Manager version 1.0.0.32 is vulnerable to a cross-site scripting (XSS) attack via the 'action' GET parameter. This vulnerability allows unauthenticated attackers to inject and execute malicious HTML and JavaScript in the browsers of users accessing the affected system. By crafting...

PoC for CVE-2025-15112

Ksenia Security S...Ksenia Security Lares ...5.1MEDIUM
URL Redirection Vulnerability in Ksenia Security Lares Home Automat...

Ksenia Security's Lares 4.0 version 1.6 is susceptible to a URL redirection flaw within the 'cmdOk.xml' script. This vulnerability enables attackers to exploit the 'redirectPage' GET parameter, allowing them to generate malicious links. When a user, who is authenticated, clicks on such a link fro...

PoC for CVE-2025-15113

Ksenia Security S...Ksenia Security Lares ...8.5HIGH
Unprotected Endpoint Vulnerability in Ksenia Security Lares 4.0 Hom...

An unprotected endpoint vulnerability exists in the Ksenia Security Lares 4.0 Home Automation version 1.6. This flaw enables authenticated attackers to upload MPFS File System binary images, which can lead to the overwriting of flash program memory. By exploiting this weakness, attackers may exec...

PoC for CVE-2025-15111

Ksenia Security S...Ksenia Security Lares ...9.3CRITICAL
Default Credentials Vulnerability in Ksenia Security Lares Home Aut...

The Ksenia Security Lares Home Automation version 1.6 is susceptible to a vulnerability that involves default administrative credentials. This weakness permits unauthorized individuals to gain administrative control over the home automation system, potentially leading to significant security brea...

PoC for CVE-2024-58338

AtemeFlamingo Xl8.6HIGH
Restricted Shell Vulnerability in Anevia Flamingo XL 3.2.9

Anevia Flamingo XL version 3.2.9 contains a vulnerability that exposes users to severe security risks by allowing remote attackers to escape the sandboxed environment via the traceroute command. This flaw can be exploited to inject malicious shell commands, potentially granting attackers full roo...

PoC for CVE-2024-58336

The Akuvox CompanyAkuvox Smart Doorphone8.7HIGH
Unauthenticated Remote Access Vulnerability in Akuvox Smart Interco...

The Akuvox Smart Intercom S539 is exposed to a serious vulnerability that permits unauthorized users to access live video feeds. By sending a request to the video.cgi endpoint on port 8080, attackers can obtain sensitive video stream data without any form of authentication. This flaw compromises ...

Latest Cyber Security Exploit PoCs