Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered just now...

PoC for CVE-2026-74251

Phoca.czPhoca Cart Extension F...9.3CRITICAL
SQL Injection Vulnerability in Phoca Cart by Joomla Extension

The Phoca Cart extension for Joomla contains a vulnerability that allows unauthenticated attackers to exploit specific GET parameters ('a[]' and 's[]') on the public shop items page. By manipulating these parameters, attackers can create unfiltered SQL queries, leading to unauthorized access to s...

Discovered 3 hours ago

PoC for CVE-2026-20000

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

An SQL injection vulnerability has been identified in the itsourcecode Hospital Management System version 1.0. The flaw arises from an unspecified function in the file /viewprescriptionrecord.php, where manipulation of the argument 'delid' allows attackers to execute arbitrary SQL queries. This v...

PoC for CVE-2026-19999

Open Asset Import...Assimp5.3MEDIUM
Buffer Overflow Vulnerability in Open Asset Import Library Assimp

A security vulnerability in Open Asset Import Library Assimp's Bone Transformation Key Parser allows for buffer overflow due to improper handling of the transmatrix_count/pcBoneTransforms argument in the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7. This flaw can be exploited remote...

PoC for CVE-2026-19998

Code-projectsOnline Shopping System5.3MEDIUM
Cross-Site Scripting Vulnerability in Code-Projects Online Shopping...

A vulnerability has been discovered in the Code-Projects Online Shopping System, specifically within the 'offersmail.php' file. This issue arises from improper handling of user input in the email argument, which makes it susceptible to cross-site scripting attacks. Remote attackers could exploit ...

PoC for CVE-2026-19997

WebkulBagisto5.1MEDIUM
Authorization Bypass in Webkul Bagisto Affects Backend Sales RMA En...

A security flaw has been identified in Webkul Bagisto that impacts versions up to 2.4.4. This vulnerability arises from improper handling of the /admin/sales/rma/requests endpoint within the Backend Sales RMA component, enabling remote attackers to bypass authorization controls. Although the vend...

Discovered 4 hours ago

PoC for CVE-2026-19996

WebkulBagisto5.3MEDIUM
Improper Privilege Management in Webkul Bagisto Affects Backend Cus...

A vulnerability exists in Webkul Bagisto, specifically impacting versions up to 2.4.4. This flaw is located in the Backend Customer Behavior Data Endpoint, where manipulation of the argument ID can result in improper privilege management. This allows an attacker to potentially exploit the system ...

PoC for CVE-2026-19995

WebkulBagisto5.1MEDIUM
Cross-Site Scripting Vulnerability in Webkul Bagisto by Webkul

A cross-site scripting vulnerability exists in Webkul Bagisto versions up to 2.4.4 in the RMA Message Handler component. This weakness can be exploited by manipulating the 'Message' argument in the /customer/account/rma/send-message file, potentially allowing attackers to execute arbitrary script...

PoC for CVE-2026-19994

WebkulBagisto5.3MEDIUM
Authorization Bypass in Webkul Bagisto Configuration Management

A vulnerability exists in Webkul Bagisto versions up to 2.4.4, specifically affecting the configuration management functionality located at /admin/configuration/cache-management/execute. By manipulating the 'action' argument, an unauthorized party could bypass expected permissions. This flaw enab...

PoC for CVE-2026-14832

WordPressShopsmart Loyalty For ...
Unauthorized Access Vulnerability in ShopSmart Loyalty Plugin for W...

The ShopSmart Loyalty for WooCommerce plugin version 1.0.0 lacks essential authorization checks for phone number lookups. This oversight permits unauthenticated users to access sensitive customer profiles by simply knowing a customer's phone number. Once accessed, an unauthorized individual can v...

PoC for CVE-2026-13700

WordPressWooms
Server-Side Request Forgery Vulnerability in WooMS WordPress Plugin

The WooMS WordPress plugin, up to version 9.14, is susceptible to a vulnerability that allows an attacker to craft a malicious URL. This exploitation occurs due to improper validation of user-supplied URLs before executing them in server-side requests. Consequently, stored third-party integration...

PoC for CVE-2026-19993

WebkulBagisto5.3MEDIUM
Webkul Bagisto RMA State Validation Vulnerability

A vulnerability exists in Webkul Bagisto prior to version 2.4.4 in the RMA State Validation component, specifically concerning the file /customer/account/rma/update-status. This issue enables a potential attacker to enforce behavioral workflows through unauthorized manipulation. The attack can be...

Discovered 5 hours ago

PoC for CVE-2026-19992

Orange View LimitedDualsafe Password Mana...2.3LOW
Information Disclosure Vulnerability in Orange View Limited DualSaf...

A vulnerability has been identified in the Orange View Limited DualSafe Password Manager & Digital Vault Extension for Chrome, specifically within the postMessage-based bridge function. This flaw allows attackers to potentially manipulate the component, leading to unauthorized information disclos...

PoC for CVE-2026-19988

AlaevSeo Tools Extension5.3MEDIUM
Cross Site Scripting Vulnerability in Alaev SEO Tools Extension for...

Alaev SEO Tools Extension for Chrome versions up to 1.0.10 has a vulnerability in its Popup UI component, specifically in the addDiv function within src/popup.html. This vulnerability allows remote attackers to execute scripts in the context of the user’s browser, leading to potential unauthorize...

PoC for CVE-2026-19986

AdBlock Ltd.Adblock For Youtube Ex...5.3MEDIUM
Improper Authorization Vulnerability in Adblock for Youtube Chrome ...

A vulnerability has been detected in the Adblock for Youtube Extension version 7.2.1 for Chrome, originating from a flaw in the updateDynamicRules function within contentscript.js. This vulnerability allows attackers to exploit the argument yt-anti-adblock-detected, which can lead to improper aut...

Discovered 6 hours ago

PoC for CVE-2026-19984

JkawamotoMcp-florence25.3MEDIUM
Server-Side Request Forgery in jkawamoto mcp-florence2 Plugin

A security flaw in the jkawamoto mcp-florence2 plugin, specifically in the get_images function of src/mcp_florence2/__init__.py, allows for server-side request forgery. This vulnerability enables an attacker to manipulate input arguments and potentially exploit server weaknesses from remote locat...

Discovered 7 hours ago

PoC for CVE-2026-19978

Jiantao88Android-mcp-server4.8MEDIUM
Command Execution Vulnerability in jiantao88 Android MCP Server

A flaw exists in the jiantao88 Android MCP Server, specifically in the Command Execution function located in build/index.js. This vulnerability allows for OS command injection by manipulating parameters such as deviceId, packageName, permission, and extras[].key or extras[].value. The exploit is ...

PoC for CVE-2026-19977

EfmIptime A3004t10CRITICAL
Improper Authentication in EFM ipTIME A3004T by EFM Networks

A vulnerability has been identified in the EFM ipTIME A3004T router, specifically within the httpcon_check_session_url function associated with session validation. This flaw enables improper authentication, which could allow attackers to exploit the system remotely. The vulnerability has been mad...

Discovered 8 hours ago

PoC for CVE-2026-19976

ComfastCf-n1-s5.1MEDIUM
Command Injection Vulnerability in COMFAST CF-N1-S by COMFAST

A command injection vulnerability exists in the COMFAST CF-N1-S version 2.6.0.1. The flaw lies in the unvalidated handling of the 'macaddress' parameter in the sub_44A968 function within the /cgi-bin/mbox-config path. An attacker can exploit this to execute arbitrary commands on the device remote...

PoC for CVE-2026-19973

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A security flaw has been identified in the itsourcecode Hospital Management System version 1.0, specifically within the /viewpaymentreport.php file. This vulnerability allows attackers to manipulate the 'delid' argument, leading to SQL injection attacks. The issue can be exploited remotely, makin...

Discovered 9 hours ago

PoC for CVE-2026-19972

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability exists in the itsourcecode Hospital Management System version 1.0 due to improper handling of inputs in the remote file /viewpatient.php. This weakness allows attackers to manipulate the 'delid' argument, resulting in SQL injection. Successful exploitation could enable unauthorize...

PoC for CVE-2026-19970

Open Asset Import...Assimp5.3MEDIUM
Heap-Based Buffer Overflow in Open Asset Import Library Assimp (17c...

A vulnerability was identified within the Open Asset Import Library Assimp, specifically in the function Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 located in the MDLLoader.cpp file. This vulnerability arises from improper handling of the argument bones_num, leading to a potential heap-ba...

PoC for CVE-2026-8508

ZyxelWax650s Firmware6.5MEDIUM
Improper Authentication Vulnerability in Zyxel WAX650S Firmware

An improper authentication flaw exists in the 'social_login.cgi' CGI program within Zyxel WAX650S firmware, allowing attackers connected to the WLAN to bypass captive portal authentication protocols. This vulnerability could enable unauthorized access to network resources, posing a significant ri...

PoC for CVE-2026-6837

ZyxelWax650s Firmware7.2HIGH
Command Injection Vulnerability in Zyxel WAX650S Firmware

A post-authentication command injection vulnerability exists in the 'export-cgi' CGI program of Zyxel WAX650S firmware, allowing authenticated users with administrator privileges to execute arbitrary operating system commands on the device. This vulnerability poses significant risks as it could b...

PoC for CVE-2026-19969

Open Asset Import...Assimp5.3MEDIUM
Buffer Overflow Vulnerability in Open Asset Import Library Assimp's...

A security vulnerability identified in the Open Asset Import Library Assimp version 17c12da affects the function Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 within the MDLLoader.cpp file. This vulnerability allows for a buffer overflow due to improper handling of input data, which could p...

Discovered 10 hours ago

PoC for CVE-2026-19968

Open Asset Import...Assimp5.3MEDIUM
Heap-based Buffer Overflow in Open Asset Import Library Assimp Affe...

A weakness exists within the Open Asset Import Library Assimp specifically related to the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7. This vulnerability can potentially lead to a heap-based buffer overflow, allowing attackers to execute malicious code. The exploit can be initiated remotely...

PoC for CVE-2026-19967

Open Asset Import...Assimp5.3MEDIUM
Heap-Based Buffer Overflow in Open Asset Import Library Assimp

A security flaw has been identified in the Open Asset Import Library Assimp, specifically within the Assimp::Compression::decompressBlock function in the Common/Compression.cpp file. This vulnerability may allow an attacker to exploit a heap-based buffer overflow through manipulation of the input...

PoC for CVE-2026-19966

CodecanyonTimecamp Integration F...5.3MEDIUM
Authorization Bypass in CodeCanyon TimeCamp Integration for CRM

A vulnerability has been discovered in the CodeCanyon TimeCamp Integration for CRM plugin, affecting versions up to 2.8. This issue occurs during the processing of the 'save_contact' file in the Contact Information Update component, specifically through manipulation of the 'contact_id' argument. ...

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 100%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

Discovered 11 hours ago

PoC for CVE-2026-19964

Jij-incJij-mcp-server5.1MEDIUM
Code Injection Vulnerability in Jij-Inc Jij-MCP-Server

A code injection vulnerability exists in the Jij-Inc Jij-MCP-Server 0.1.0, specifically in the PythonREPL.run function within the file jij_mcp/python_repr.py. This issue allows for remote code execution due to improper handling of input arguments, enabling attackers to manipulate the 'code' argum...

PoC for CVE-2026-19963

EdimaxEw-7478apc5.3MEDIUM
Command Injection Vulnerability in Edimax EW-7478APC Firmware

A command injection vulnerability has been identified in the Edimax EW-7478APC at version 1.04. The flaw resides in the 'stainfo' function located in the /goform/stainfo file, where improper handling of the 'interface' argument allows for remote code execution. This vulnerability poses significan...

PoC for CVE-2026-19962

EdimaxEw-7478apc5.3MEDIUM
Command Injection Vulnerability in Edimax EW-7478APC Network Device

A command injection vulnerability exists in the Edimax EW-7478APC network device due to improper validation of user input in the setWAN function located at /goform/setWAN. By manipulating the parameters pppUserName, pptpUserName, or L2TPUserName, an attacker can execute arbitrary commands on the ...

PoC for CVE-2026-19961

EdimaxEw-7478apc9.4CRITICAL
Buffer Overflow Vulnerability in Edimax EW-7478APC by Edimax

A buffer overflow vulnerability has been identified in the Edimax EW-7478APC's formWlSiteSurvey function, specifically in the /goform/formWlSiteSurvey file. Manipulating the 'selSSID' argument could allow remote attackers to execute arbitrary code. This vulnerability is particularly concerning as...

Discovered 12 hours ago

PoC for CVE-2026-19960

EdimaxEw-7478apc5.3MEDIUM
Command Injection Vulnerability in Edimax EW-7478APC by Edimax

A serious command injection vulnerability has been identified in the Edimax EW-7478APC, specifically within the formWlbasic function of the /goform/formWlbasic file. This vulnerability arises from improper handling of the rootAPmac parameter, allowing an attacker to execute arbitrary commands rem...

PoC for CVE-2026-19959

EdimaxEw-7478apc9.4CRITICAL
Buffer Overflow Vulnerability in Edimax EW-7478APC Router

A buffer overflow vulnerability has been identified in the Edimax EW-7478APC routing device, specifically within the function formWanTcpipSetup located at /goform/formWanTcpipSetup. The issue arises from improper handling of the pppUserName argument, allowing for stack-based buffer overflow condi...

PoC for CVE-2026-19958

IatsiukPptr-mcp5.3MEDIUM
Code Injection Vulnerability in iatsiuk pptr-mcp Tool

A vulnerability has been identified in the iatsiuk pptr-mcp execute Tool, specifically within the executeCode function located in the src/vm-executor.ts file. This flaw allows for remote code injection, opening a path for attackers to execute malicious scripts remotely. Despite the discovery of t...

PoC for CVE-2026-19957

GraphlitGraphlit-mcp-server5.3MEDIUM
Server-side Request Forgery Vulnerability in Graphlit MCP Server by...

A vulnerability has been discovered in version 1.0.1 of the Graphlit MCP Server, specifically within the fetch function in the src/tools.ts file associated with the ssrf-test endpoint. This vulnerability allows for potential server-side request forgery, enabling attackers to manipulate URL parame...

Discovered 14 hours ago

PoC for CVE-2026-19955

TrailDBTraildb5.1MEDIUM
Out-of-Bounds Read Vulnerability in TrailDB's TOC Validation Function

A vulnerability in TrailDB version 0.6 affects the TOC Validation component, specifically the tdb_open function located in /src/tdb.c. Exploitation of this issue allows for out-of-bounds read operations, which can be executed remotely. Although early notifications were sent to the project maintai...

Discovered 16 hours ago

PoC for CVE-2025-5781

HitachiHitachi Ops Center Api...5.2MEDIUM
Information Exposure Vulnerability in Hitachi Ops Center API Config...

An information exposure vulnerability exists in Hitachi's Ops Center API Configuration Manager, Configuration Manager, and Device Manager, which could enable unauthorized session hijacking. This flaw affects multiple product versions, potentially exposing sensitive information to attackers. It is...

Discovered 1 day ago

PoC for CVE-2021-42574

UnicodeUnicode🟣 EPSS 12%8.3HIGH
Visual Reordering Vulnerability in Unicode Specification Affecting ...

A vulnerability in the Unicode Specification, particularly in the Bidirectional Algorithm, allows adversaries to manipulate the visual order of characters. This can lead to confusion when analyzing source code, as the logical order of tokens processed by compilers and interpreters may differ from...

PoC for CVE-2026-17544

PHP GroupPHP8.1HIGH
Out-of-Bounds Write Vulnerability in PHP Affects Multiple Versions

A vulnerability exists in PHP that allows an attacker to manipulate input to the bccomp() function, potentially leading to out-of-bounds write conditions. This flaw can cause significant issues, including stack and heap corruption, in various PHP versions, notably impacting those prior to their r...

PoC for CVE-2026-47103

FgmacedoPython-statemachine9.3CRITICAL
Remote Code Execution Vulnerability in Python StateMachine by FG Ma...

A critical security vulnerability exists in Python StateMachine versions prior to 3.2.0, allowing remote code execution through unsafe evaluation of crafted SCXML documents. Attackers can inject malicious expression strings that, when processed by the SCXMLProcessor, are passed to Python's eval()...

PoC for CVE-2026-19726

WordPressVisualizer
Authorization Flaw in Visualizer Plugin Affects WordPress Users

The Visualizer Plugin for WordPress, prior to version 4.0.7, contains an authorization flaw that allows users with Contributor privileges and higher to access sensitive chart configurations. This vulnerability enables these users to read full configurations of charts, including those that should ...

PoC for CVE-2026-19714

WordPressSimple Jwt Login
Unauthenticated Access in Simple JWT Login Plugin for WordPress

The Simple JWT Login plugin for WordPress prior to version 3.6.8 fails to properly validate the audience of Google identity tokens. This flaw enables unauthenticated users to authenticate themselves as any user associated with the email address contained in such tokens. Consequently, this vulnera...

PoC for CVE-2026-19712

WordPressMasteriyo Lms
Stored Cross-Site Scripting Vulnerability in Masteriyo LMS Plugin f...

The Masteriyo LMS WordPress plugin prior to version 2.3.3 lacks proper sanitization and escaping of quiz fields, enabling instructor role users to store unfiltered HTML. This vulnerability could lead to Stored Cross-Site Scripting attacks, affecting all visitors, including administrators, of the ...

PoC for CVE-2026-19728

WordPressExtra Product Options ...
File Disclosure Vulnerability in Extra Product Options Builder for ...

The Extra Product Options Builder for WooCommerce plugin prior to version 1.2.176 lacks sufficient verification for user entitlements when serving customer-uploaded files. This vulnerability allows unauthenticated users to retrieve these files if they are aware of their stored names. The plugin's...

PoC for CVE-2026-19725

WordPressWPvivid — Backup, Migr...
Unauthorized File Creation Vulnerability in WPvivid Backup, Migrati...

The WPvivid — Backup, Migration & Staging WordPress plugin prior to version 0.9.131 contains a vulnerability that allows an unauthenticated attacker, armed with a site-to-site transfer key, to manipulate log file paths. This occurs due to inadequate sanitization of inputs, enabling the attacker t...

PoC for CVE-2026-19717

WordPressCatfolders Document Ga...
Authorization Bypass in CatFolders Document Gallery & PDF Library P...

The CatFolders Document Gallery & PDF Library WordPress plugin before version 2.0.7 contains an authorization flaw in specific REST API endpoints. This vulnerability allows unauthenticated users to access sensitive information such as the title, type, size, and URL of media attachments linked to ...

PoC for CVE-2026-17533

WordPressAll-in-one WP Migratio...
Arbitrary Code Execution in All-in-One WP Migration and Backup Plug...

The All-in-One WP Migration and Backup plugin for WordPress prior to version 7.108 presents a significant security flaw in multisite environments. This vulnerability permits an administrator of a single subsite to access and execute arbitrary PHP code across the entire network. Without sufficient...

PoC for CVE-2026-18653

WordPressWP Directory Kit
SQL Injection Vulnerability in WP Directory Kit Plugin for WordPress

The WP Directory Kit plugin for WordPress, versions prior to 1.5.7, is vulnerable due to improper sanitization and escaping of parameters used in SQL statements. This flaw allows an administrator on a multisite installation to execute SQL injection attacks, potentially granting them unauthorized ...

PoC for CVE-2026-19613

WordPressEcs
Unauthorized Data Access in ECS WordPress Plugin by N3rdish

The ECS WordPress plugin prior to version 4.3.10 features a security flaw where it fails to enforce proper ownership and post-status checks when retrieving custom field values based on user-supplied post identifiers. This oversight permits users with contributor-level access or higher to access a...