Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 8 hours ago

PoC for CVE-2026-81847

Maa-aiMaamcp5.1MEDIUM
Path Traversal Vulnerability in MAA-AI MaaMCP Software

A vulnerability has been discovered in the MAA-AI MaaMCP software, specifically in the save_pipeline/load_pipeline functions within the pipeline_tools.py file. This flaw allows remote attackers to manipulate the system through path traversal, enabling unauthorized access to sensitive files. The a...

PoC for CVE-2026-81845

Arben-admMcp-sequential-thinking5.3MEDIUM
Path Traversal Vulnerability in arben-adm mcp-sequential-thinking

A path traversal vulnerability exists in the mcp-sequential-thinking component's import_session/export_session functionality. This issue is due to improper validation of the 'file_path' argument in server.py, allowing attackers to access unintended files on the server. This vulnerability can be e...

PoC for CVE-2021-27876

VeritasBackup Exec🟣 EPSS 14%8.1HIGH
Unauthorized Access Vulnerability in Veritas Backup Exec

A vulnerability has been identified in Veritas Backup Exec versions prior to 21.2 that compromises secure communication between clients and agents. This flaw arises from weaknesses in the SHA Authentication scheme, allowing an unauthorized attacker to bypass authentication. Once exploited, the at...

PoC for CVE-2026-81837

RoocodeincRoo-code5.3MEDIUM
Path Traversal Vulnerability in RooCodeInc Roo-Code Software

A security flaw within RooCodeInc's Roo-Code software allows for path traversal through the ApplyPatchTool component. Specifically, this issue affects the path.resolve function in the src/core/tools/ApplyPatchTool.ts file, enabling remote attackers to manipulate file paths. This vulnerability is ...

Discovered 9 hours ago

PoC for CVE-2026-81836

RoocodeincRoo-code6.3MEDIUM
Cleartext Transmission Vulnerability in Roo-Code OAuth Callback by ...

A security issue in RooCodeInc's Roo-Code software allows for the cleartext transmission of sensitive information through the OAuth Callback component. Specifically, the vulnerability is found in the file src/integrations/claude-code/oauth.ts, leading to potential exposure of critical data during...

PoC for CVE-2026-81835

RoocodeincRoo-code5.1MEDIUM
Code Injection Vulnerability in RooCodeInc Roo-Code Up to 3.51.1

A code injection vulnerability has been identified in the RooCodeInc Roo-Code application, specifically within the fetch_instructions function of the malicious_mcp_server.py file. This issue arises within the MCP Integration Trust Model and enables attackers to manipulate functions remotely, lead...

Discovered 10 hours ago

PoC for CVE-2026-81834

RoocodeincRoo-code5.3MEDIUM
Code Injection Vulnerability in Roo-Code by RooCodeInc

A code injection vulnerability exists in Roo-Code by RooCodeInc, specifically in the ExecaTerminalProcess function of the README File Handler component. This flaw allows an attacker to remotely execute malicious code by manipulating the affected feature. With the product no longer actively suppor...

PoC for CVE-2026-81833

RoocodeincRoo-code5.1MEDIUM
Code Injection Vulnerability in RooCodeInc Roo-Code Product

A security flaw has been found in RooCodeInc's Roo-Code product up to version 3.51.1. The vulnerability resides in the 'optimizeQuery' function of the 'src/utils/helpers.ts' file within the CodeIndexManager component. This weakness allows for code injection via manipulation, resulting in a potent...

PoC for CVE-2026-81934

RedisRedis9.2CRITICAL
Use-After-Free Vulnerability in Redis with TLS Support

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which processes incoming TLS data. When configured for TLS support, this vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands with the privileges of the Redis server. This cou...

PoC for CVE-2004-2687

SambaSamba🟣 EPSS 88%
Remote Command Execution Vulnerability in distcc for XCode and Others

distcc 2.x, often utilized in XCode 1.5 and other software, is prone to vulnerabilities when improperly configured. This flaw enables remote attackers to execute arbitrary commands through compilation jobs processed by the server without proper authorization checks. If access to the server port i...

Discovered 12 hours ago

PoC for CVE-2026-76640

Unitree RoboticsG1 Edu7.7HIGH
Multiple Vulnerabilities in Unitree G1 EDU Firmware Impact BLE GATT...

The Unitree G1 EDU firmware exposes critical flaws through its BLE GATT server and WiFi provisioning stack, allowing proximity-based attackers to execute arbitrary code without authentication. By exploiting an unquoted heredoc variable in the WiFi provisioning script alongside a buffer overflow i...

PoC for CVE-2015-3246

RedhatLibuser5.1MEDIUM
Local User Vulnerability Affecting Usermode Package in libuser

The vulnerability in the libuser library affects the userhelper program, allowing for a local user to directly modify the /etc/passwd file. If this modification fails, it may result in an inconsistent file state, leading to a denial of service. Additionally, this issue can potentially be exploite...

Discovered 13 hours ago

PoC for CVE-2015-5287

RedhatAutomatic Bug Reportin...7.8HIGH
Local Privilege Escalation Vulnerability in Automatic Bug Reporting...

The Automatic Bug Reporting Tool (ABRT) prior to version 2.7.1 is susceptible to a local privilege escalation vulnerability. This flaw allows local users with specific permissions to execute a symlink attack on files with predictable names, such as '/var/tmp/abrt/abrt-hax-coredump' or '/var/spool...

PoC for CVE-2026-19092

WordPressTutor Lms9.8CRITICAL
Remote Code Execution Vulnerability in Tutor LMS Plugin by WordPress

The Tutor LMS WordPress plugin, prior to version 4.0.6, contains a significant security flaw that permits unauthenticated users to manipulate request data, leading to the overwriting of internal variables during template rendering. This vulnerability enables attackers to invoke arbitrary zero-arg...

Discovered 14 hours ago

PoC for CVE-2026-72898

MetabaseMetabase🟣 EPSS 79%10CRITICAL
SQL Injection Vulnerability in Metabase by Metabase, Inc.

Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...

PoC for CVE-2026-38526

WebkulKrayin CRM9.9CRITICAL
Arbitrary File Upload Vulnerability in Webkul Krayin CRM

An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...

PoC for CVE-2026-19478

GitlabGitlab9.4CRITICAL
Remote Code Modification Vulnerability in GitLab CE/EE

A flaw in GitLab CE/EE allows unauthenticated users to exploit specific GraphQL directives, potentially resulting in unauthorized modification or deletion of public projects and user data. This vulnerability impacts various versions, necessitating immediate user awareness and prompt application o...

Discovered 16 hours ago

PoC for CVE-2026-20303

CiscoCisco Catalyst Sd-wan ...9.9CRITICAL
Improper Input Validation in Cisco Catalyst SD-WAN

Cisco's Catalyst SD-WAN product has been identified with vulnerabilities stemming from improper input validation, as revealed during an internal security review. These issues can potentially expose the system to various security risks, underscoring the importance of implementing software hardenin...

Discovered 17 hours ago

PoC for CVE-2026-77542

Ubiquiti IncUid Enterprise Agent9.1CRITICAL
Improper Input Validation in UID Enterprise Agent by Ubiquiti

A security flaw has been identified in the UID Enterprise Agent developed by Ubiquiti, where improper input validation can be exploited by malicious actors with network access and elevated privileges. This vulnerability enables the execution of command injection on the host device, potentially al...

PoC for CVE-2026-18431

WordPressAvada (fusion) Builder9.8CRITICAL
Avada Theme for WordPress Vulnerable to Arbitrary File Write

The Avada theme for WordPress presents a significant security risk due to an arbitrary file write vulnerability that affects all versions up to 7.16 when paired with an active Fusion Builder plugin (up to version 3.16). This flaw stems from a combination of authorization issues and inadequate inp...

Discovered 18 hours ago

PoC for CVE-2026-81562

AlexgladkovClaude-in-mobile4.8MEDIUM
OS Command Injection Vulnerability in AlexGladkov claude-in-mobile

A security flaw has been identified in AlexGladkov's claude-in-mobile, specifically affecting the execSync function in src/adb/client.ts. This vulnerability allows for OS command injection, requiring local access to the system for exploitation. An upgrade to version 3.10.3 is necessary to mitigat...

Discovered 19 hours ago

PoC for CVE-2026-8467

PhenixdigitalPhoenix Storybook9.5CRITICAL
Code Injection Vulnerability in Phoenix Storybook by Phenix Digital

A vulnerability exists in Phenix Digital's Phoenix Storybook that allows unauthenticated remote code execution due to unsanitized attribute value interpolation during HEEx template generation. The psb-assign WebSocket event handler permits arbitrary attribute names and values from unauthenticated...

PoC for CVE-2026-74233

ZbtlinkWe13269.3CRITICAL
Command Injection Vulnerability in Zbtlink Firmware Products

A security flaw in the Zbtlink firmware for multiple wireless devices allows remote attackers to exploit the infosrvd service via crafted UDP packets. This vulnerability bypasses authentication mechanisms, as it employs a hardcoded salt, enabling unprivileged users to execute arbitrary commands a...

PoC for CVE-2026-81560

BlackmsAistack6.9MEDIUM
Path Traversal in blackms aistack Affecting Static File Handler Fun...

A vulnerability exists in blackms aistack up to version 1.6.1, impacting the Static File Handler component located in src/web/server.ts. This flaw allows for path traversal due to improper handling of the req.url argument, which can be exploited remotely. The exploit code is publicly accessible, ...

Discovered 1 day ago

PoC for CVE-2026-78333

WordPress12 Step Meeting List8.8HIGH
Stored Cross-Site Scripting Vulnerability in 12 Step Meeting List P...

The 12 Step Meeting List WordPress plugin prior to version 3.19.17 allows unauthenticated users to submit unsanitized input, which is stored in the activity log. This input is later displayed back to users in the admin area without adequate escaping, making it possible for an attacker to execute ...

PoC for CVE-2026-78138

WordPressFinale Lite4.3MEDIUM
Unauthorized Access Vulnerability in Finale Lite Plugin by WordPress

The Finale Lite plugin for WordPress prior to version 2.21.0 contains a security flaw that allows authenticated users, including those with Subscriber roles and above, to access sensitive campaign configuration data through an unprotected AJAX action. This oversight enables users to retrieve conf...

PoC for CVE-2026-78139

WordPressNotifima4.3MEDIUM
Authorization Bypass Vulnerability in Notifima WordPress Plugin

The Notifima WordPress plugin before version 3.1.4 lacks proper validation of subscription ownership on its REST endpoints. This oversight allows authenticated users with Subscriber-level access to manipulate subscription settings, specifically the ability to unsubscribe any customer from receivi...

PoC for CVE-2026-77018

WordPressWorkeera8.8HIGH
Arbitrary File Upload Vulnerability in Workeera Plugin for WordPress

The Workeera plugin for WordPress prior to version 1.0.6 lacks adequate restrictions on profile value submissions by candidates. It fails to validate the file types uploaded, allowing users with minimal privileges, such as subscribers, to upload arbitrary files. Consequently, this can lead to rem...

PoC for CVE-2026-78137

WordPressStoregrowth7.5HIGH
Price Manipulation Vulnerability in StoreGrowth Plugin for WordPress

The StoreGrowth WordPress plugin prior to version 2.1.2 is vulnerable due to insufficient validation of browser-supplied product prices on certain unauthenticated actions. This flaw permits attackers to specify arbitrary prices when adding products to the shopping cart, especially when the 'Buy O...

PoC for CVE-2026-78125

WordPressLearnpress5.3MEDIUM
REST API Vulnerability in LearnPress Plugin by WordPress

A critical vulnerability in the LearnPress WordPress plugin allows unauthorized attackers to access sensitive information. This flaw exists in the plugin's REST API, where no authorization checks are performed on certain endpoints. As a result, attackers can exploit this weakness to disclose the ...

PoC for CVE-2026-77017

WordPressWorkeera7.7HIGH
File Access Vulnerability in Workeera WordPress Plugin

The Workeera WordPress plugin versions prior to 1.0.6 allows users with minimal permissions, such as a subscriber, to submit any profile values without restrictions. This lack of input validation leads to unauthorized access where these users can read arbitrary files stored on the server. This in...

PoC for CVE-2026-19715

WordPressWP Oauth Server ( Logi...7.5HIGH
Unauthorized Access to Debug Log in WP OAuth Server Plugin by WordP...

The WP OAuth Server plugin for WordPress, prior to version 6.3.1, contains a flaw that allows unauthenticated users to access the debug log. This log, stored in a publicly accessible location, may contain sensitive information including OAuth tokens, authorization codes, and user records, such as...

PoC for CVE-2026-77016

WordPressWorkeera9.6CRITICAL
File Deletion Vulnerability in Workeera WordPress Plugin Affects Users

The Workeera WordPress plugin prior to version 1.0.6 allows users with minimal permissions, such as subscribers, to delete arbitrary files from the server. This vulnerability arises due to the lack of restrictions on the values that can be written to a user's candidate profile, coupled with inade...

PoC for CVE-2026-76549

WordPressUpdraftplus: WP Backup...5.9MEDIUM
CSRF Vulnerability in UpdraftPlus Backup Plugin for WordPress

The UpdraftPlus: WP Backup & Migration Plugin for WordPress, prior to version 1.26.7, lacks proper CSRF checks in a critical backup management operation. This vulnerability can potentially allow an attacker to trick an authenticated admin into restoring a backup without their consent, effectively...

PoC for CVE-2026-19225

WordPressDefender Security6.6MEDIUM
Arbitrary Code Execution Vulnerability in Defender Security Plugin ...

The Defender Security plugin for WordPress before version 6.2.0 contains a vulnerability that permits an administrator of any single site within a multisite network to execute arbitrary code across the entire network. This flaw arises from the failure to restrict a critical network-wide setting e...

PoC for CVE-2026-19454

WordPressJetbackup4.4MEDIUM
Security Flaw in JetBackup Plugin for WordPress Exposes Sensitive N...

The JetBackup plugin for WordPress prior to version 3.1.23.5 fails to properly enforce multisite authorization checks when serving backup archives and job logs. This oversight enables a network administrator—who does not possess Super Admin privileges—to download complete backups of the entire mu...

PoC for CVE-2026-19223

WordPressSmush7.2HIGH
Arbitrary Code Execution Vulnerability in Smush Plugin for WordPress

The Smush plugin for WordPress, prior to version 4.3.2, is susceptible to a security flaw that enables an administrator of any individual site within a multisite network to execute arbitrary code across the entire network. This flaw arises from insufficient restrictions placed on network-wide set...

PoC for CVE-2026-16569

WordPressMobile App For WooComm...4.3MEDIUM
Insufficient User Capability Check in WooCommerce Mobile App Builde...

The ShopApper Mobile App Builder Service for WooCommerce up to version 0.4.62 has a significant security issue where it does not properly verify user capabilities for stock-update operations. This oversight allows any authenticated user, including customers and subscribers, to alter the stock qua...

PoC for CVE-2026-16567

WordPressDocument Embedder5.3MEDIUM
Unauthorized Document Download Vulnerability in Document Embedder P...

The Document Embedder plugin for WordPress prior to version 2.3.1 has a significant security flaw that allows unauthenticated users to exploit the file download feature. This vulnerability arises because the plugin fails to validate the status of documents before generating a download token. As a...

PoC for CVE-2026-16568

WordPressMobile App For WooComm...4.3MEDIUM
Access Control Vulnerability in ShopApper Mobile App Builder for Wo...

The ShopApper Mobile App Builder Service for WooCommerce has a vulnerability where the plugin does not correctly verify user ownership of customer profiles accessed via its REST API endpoints. This oversight enables authenticated users, such as customers or subscribers, to potentially gain unauth...

PoC for CVE-2026-13415

WordPressCmp7.2HIGH
Privilege Escalation Vulnerability in CMP WordPress Plugin by CMP

The CMP WordPress plugin prior to version 4.1.18 lacks robust checks on setting imports, specifically failing to enforce an option-name allow-list when settings are imported via AJAX actions. This oversight can enable users with Editor permissions, if granted access by an administrator, to modify...

PoC for CVE-2026-13416

WordPressCmp3.5LOW
Arbitrary Web Script Injection Vulnerability in CMP Plugin for Word...

The CMP WordPress plugin prior to version 4.1.18 lacks adequate sanitization and escaping of settings values. This flaw permits users assigned the Editor role, if granted access to the admin-bar controls of the plugin, to inject malicious web scripts. These scripts can execute when a visitor view...

PoC for CVE-2026-13414

WordPressCmp4.8MEDIUM
Authorization Bypass Vulnerability in CMP WordPress Plugin

The CMP WordPress plugin prior to version 4.1.18 is susceptible to an authorization bypass vulnerability due to inadequate checks on several AJAX actions. This flaw allows unauthenticated attackers to bypass intended restrictions and disable the maintenance or coming-soon mode. Notably, some acti...

PoC for CVE-2026-45585

MicrosoftWindows 11 Version 24h26.8MEDIUM
Security Feature Bypass in Windows by Microsoft

A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...

PoC for CVE-2026-81491

BoxpositronWith-context-mcp6.9MEDIUM
Path Traversal Vulnerability in Boxpositron's With-Context-MCP Product

A flaw in Boxpositron's With-Context-MCP (version up to 3.0.7) exposes a path traversal vulnerability through the ingest_notes, teleport_notes, sync_notes, and project_folder functions contained in the src/index.ts file. This allows remote attackers to manipulate the file paths, potentially leadi...

PoC for CVE-2026-18080

WordPressErp: Complete Hr, Acco...9.8CRITICAL
Unrestricted File Upload Vulnerability in ERP: Complete HR, Account...

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is susceptible to an unrestricted file type upload due to insufficient validation of file extensions and improper path normalization in its save_attachments() function. This vulnerability allows unauthenticate...

PoC for CVE-2026-63520

MicrosoftMicrosoft Sharepoint E...8.1HIGH
Remote Code Execution Vulnerability in Microsoft Office SharePoint

A vulnerability exists in Microsoft Office SharePoint due to improper input validation, which could allow an unauthorized attacker to execute arbitrary code over a network. This can lead to significant security breaches if exploited, making it essential for affected users to apply security patche...

PoC for CVE-2026-81486

Bsmi021Mcp-file-context-server6.9MEDIUM
Path Traversal Vulnerability in bsmi021 mcp-file-context-server

A vulnerability has been identified in bsmi021's mcp-file-context-server version 1.0.0, specifically in the read_context function located in src/index.ts. This flaw allows attackers to manipulate the argument path, leading to potential path traversal attacks. This vulnerability can be exploited r...

PoC for CVE-2026-81485

DanielpopamdLinkedin-ads-mcp6.9MEDIUM
Path Traversal Vulnerability in danielpopamd Linkedin Ads MCP Media...

A security vulnerability has been identified in the danielpopamd Linkedin Ads MCP version 1.0.0. This vulnerability arises from an unsafe implementation in the function fs.readFileSync located in the file src/tools/campaign-management.ts, which handles media uploads. An attacker can manipulate th...

PoC for CVE-2026-19912

KalturaKaltura Html5 Video Pl...
Remote Code Execution Vulnerability in Kaltura HTML5 Player

The Kaltura HTML5 player is susceptible to a remote code execution vulnerability due to the unsafe handling of user-supplied data. Specifically, when the mwEmbedLoader.php script processes the ServiceUrl provided by an attacker, it performs deserialization without adequate validation. This exploi...