Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 4 hours ago

PoC for CVE-2026-100373

Open-metadataOpenmetadata5.1MEDIUM
Server-Side Request Forgery in OpenMetadata by OpenMetadata

OpenMetadata versions up to 2.0.2 exhibit a server-side request forgery vulnerability in the URLValidator.validateURL function. This flaw arises from improper DNS hostname resolution and inadequate validation of internal addresses. Users with permissions to create or update EventSubscription can ...

PoC for CVE-2026-100372

MacwarriorClipbucket-v58.6HIGH
Path Traversal Vulnerability in ClipBucket Admin Template Editor by...

ClipBucket versions prior to 5.5.3-#197 contain a vulnerability in the admin template editor that allows authenticated administrators with manage_template_access permission to exploit directory traversal sequences. This flaw enables the modification of executable PHP files by traversing outside o...

PoC for CVE-2026-100310

GnuLibextractor7.3HIGH
Privilege Escalation Vulnerability in GNU libextractor by GNU

GNU libextractor prior to version 1.16 is susceptible to a privilege escalation vulnerability due to the improper handling of the LIBEXTRACTOR_PREFIX environment variable. This flaw allows a local attacker to exploit the system by loading plugins from an untrusted search path, potentially executi...

Discovered 5 hours ago

PoC for CVE-2026-100306

TduckcloudTduck-survey-form6.9MEDIUM
Write Password Bypass in TDuck Survey Form by TDuck Cloud

The TDuck Survey Form version 6.0 has a vulnerability that allows remote unauthenticated attackers to submit form entries without providing valid passwords. The application relies solely on client-side validation for write password enforcement, which can be bypassed through direct API access usin...

PoC for CVE-2026-100304

TduckcloudTduck-survey-form6MEDIUM
Information Disclosure Vulnerability in TDuck Survey Form by TDuckC...

The TDuck Survey Form 6.0 has a significant information disclosure issue wherein the FormAuthUtils.hasPermission method operates in a fail-open mode. This flaw allows authenticated users to access submissions from forms that are no longer valid. Specifically, when a user provides a dataId for a p...

PoC for CVE-2026-100303

TduckcloudTduck-survey-form5.3MEDIUM
Authorization Checks Bypass in TDuck Survey Form by TDuckCloud

The TDuck Survey Form, up to version 6.0, is susceptible to an authorization bypass vulnerability. Non-admin authenticated users can exploit the FormThemeController endpoints to manipulate global form themes and categories. This allows them to add, modify, or delete themes and theme categories, w...

PoC for CVE-2026-97896

KrayinLaravel-crm5.1MEDIUM
Cross Site Scripting Vulnerability in Krayin Laravel-CRM by Webkul

A cross site scripting vulnerability exists in Krayin Laravel-CRM versions up to 2.2.5, specifically in the Upload Functionality's ConfigurationForm::rules method. This issue can be exploited remotely, allowing attackers to inject scripts into web pages viewed by users. The vulnerability has been...

PoC for CVE-2026-97895

KrayinLaravel-crm5.3MEDIUM
Privilege Mismanagement in Krayin Laravel-CRM User Management

A vulnerability was identified in the Krayin Laravel-CRM framework affecting the User Management component. This issue arises from improper handling of the role_id argument in the UserController.php file, allowing unauthorized users to gain elevated privileges. The flaw can be exploited remotely,...

PoC for CVE-2026-97064

Yzcheng90X-springboot9.3CRITICAL
Authentication Bypass in X-SpringBoot Due to Hardcoded Static Maste...

X-SpringBoot versions up to 6.0 include a hardcoded static master login verification code (172839) that is enabled by default in the database seed. This vulnerability enables unauthenticated attackers to authenticate as any user by simply providing the public master code along with a known email ...

PoC for CVE-2026-97060

Yzcheng90X-springboot8.6HIGH
Object-Level Authorization Bypass in X-SpringBoot User Management

The X-SpringBoot framework through version 6.0 is susceptible to an object-level authorization bypass in its user management functionality. This vulnerability allows sub-administrators to manage users without proper ownership verification. Attackers with user-management permissions can exploit th...

PoC for CVE-2026-100192

Yzcheng90X-springboot6.9MEDIUM
Credential Exposure Vulnerability in X-SpringBoot by YZ Cheng

X-SpringBoot up to version 6.0 has a vulnerability in its application manager functionality that exposes sensitive appKey and appSecret credentials via an unauthenticated GET request. The flaw allows unauthorized attackers to access these credentials through the /application/manager/select endpoi...

Discovered 6 hours ago

PoC for CVE-2026-97886

MathurvishalCloudclassroom-PHP-pro...5.3MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom-PHP-Project

A SQL injection vulnerability has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically within the managevideos2.php file. This issue arises from the manipulation of the argument 'editassid', allowing remote attackers to execute unauthorized SQL commands. The software follo...

PoC for CVE-2026-97885

MathurvishalCloudclassroom-PHP-pro...6.9MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom Project

A vulnerability has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically in the updatefaculty.php file. This flaw arises from improper validation of the 'fid' argument, allowing for SQL injection attacks that can be executed remotely. As the project employs a rolling relea...

PoC for CVE-2026-97884

MathurvishalCloudclassroom-PHP-pro...5.3MEDIUM
SQL Injection Vulnerability in Student Update Functionality of math...

A vulnerability has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically in the Student Update Functionality located in the updatestudent.php file. This weakness, stemming from improper validation of user input, allows for SQL injection attacks through the manipulation of ...

PoC for CVE-2026-97883

MathurvishalCloudclassroom-PHP-pro...6.9MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom-PHP-Project

A security vulnerability exists in the mathurvishal CloudClassroom-PHP-Project prior to version 5dadec098bfbbf3300d60c3494db3fb95b66e7be, specifically in the 'updatequery.php' file. This issue allows an attacker to manipulate the 'gid' argument, resulting in SQL injection that can be initiated re...

Discovered 7 hours ago

PoC for CVE-2026-97882

MathurvishalCloudclassroom-PHP-pro...6.9MEDIUM
SQL Injection Vulnerability in mathurvishal CloudClassroom Faculty ...

A vulnerability exists in the mathurvishal CloudClassroom-PHP-Project that allows for SQL injection through the Faculty Authentication component. This vulnerability specifically resides in the 'loginlinkfaculty.php' file, where improper handling of user input in the form of arguments 'fid/pass' c...

PoC for CVE-2026-97879

ZhistareduStartraining6.9MEDIUM
Missing Authentication in zhistaredu StarTraining Component API-Doc...

A significant security flaw has been found in the zhistaredu StarTraining product, specifically within the API-Docs Endpoint at the SecurityConfig.java file. This vulnerability allows for missing authentication, enabling remote attackers to exploit the system. The vulnerability pertains to an unk...

PoC for CVE-2026-97878

ZhistareduStartraining6.9MEDIUM
Missing Authentication Vulnerability in zhistaredu StarTraining Dru...

A significant vulnerability has been identified in the zhistaredu StarTraining product affecting the Druid Console component. The flaw exists in the 'anonymous' function located in the '/druid/index.html' file, where inadequate authentication controls can be exploited. Attackers may leverage this...

PoC for CVE-2026-97877

ZhistareduStartraining6.9MEDIUM
JWT Token Handler Vulnerability in zhistaredu StarTraining Software

A vulnerability has been identified in the zhistaredu StarTraining software, specifically in the JWT Token Handler component. The issue arises from the UserLoginService.createToken function in application.yml, which leads to the use of hard-coded passwords due to improper handling of user_id and ...

Discovered 8 hours ago

PoC for CVE-2026-97871

ZhonglunCloudpos6.9MEDIUM
Code Injection Vulnerability in Zhonglun CloudPos Product

A vulnerability exists in Zhonglun CloudPos, specifically in the OpenLocalBrowser function located in the JSBridge component. This vulnerability arises when an attacker manipulates the 'url' argument, leading to potential code injection, which can be executed remotely. The disclosure of this expl...

PoC for CVE-2026-61732

BittersecurityDecepticon10CRITICAL
Autonomous Hacking Agent Vulnerability in Decepticon by BitterSecurity

The Decepticon hacking agent from BitterSecurity is susceptible to a vulnerability due to improper handling of special-token literals in LLM messages generated during web crawls. In versions before 1.1.17, the system wraps results of agent reconnaissance without filtering these literals, allowing...

PoC for CVE-2026-97869

LangChain4jLangchain4j2.1LOW
Deserialization Flaw in LangChain4j Agentic Component Impacting Mul...

A deserialization flaw in the LangChain4j-agentic component impacts multiple pre-release versions, allowing remote exploitation if AgenticScope persistence is enabled. This issue was identified in the AgenticScopeSerializer.fromJson method and poses a risk where an attacker with write access to t...

Discovered 9 hours ago

PoC for CVE-2026-97868

SheshbabuZen5.1MEDIUM
Cross-Site Scripting Vulnerability in sheshbabu zen Note Editor

A vulnerability has been identified in the Note Editor component of the sheshbabu zen product, specifically related to the use of the dangerouslySetInnerHTML function in NotesEditor.jsx. This issue allows an attacker to inject malicious scripts into a web page, leading to cross-site scripting (XS...

PoC for CVE-2026-97866

ZhonglunCloudpos6.3MEDIUM
Remote Code Execution in Zhonglun CloudPOS 3.0 Automatic Update Fea...

A vulnerability exists in the Automatic Update feature of Zhonglun CloudPOS 3.0, stemming from an inadequate implementation of the Program.cs file. Manipulating certain parameters—such as the version, URL, package key, or package name—can grant unauthorized access to channels that should be restr...

Discovered 10 hours ago

PoC for CVE-2025-9974

NokiaNokia Ont8HIGH
Input Handling Flaw in ONT/Beacon Device from Nokia

The ONT/Beacon device by Nokia features a critical input handling flaw in its unified WEBUI application. This vulnerability allows low-privileged authenticated users to exploit insufficient validation of user-supplied data, enabling them to execute arbitrary commands on the device's operating sys...

Discovered 11 hours ago

PoC for CVE-2026-65660

MicrosoftMicrosoft Sharepoint E...8.8HIGH
Code Injection Vulnerability in Microsoft Office SharePoint

A vulnerability in Microsoft Office SharePoint permits an authorized attacker to execute code injection, enabling them to perform spoofing attacks over a network. This weakness poses significant risks as it can lead to unauthorized access and manipulation of sensitive information. Organizations u...

Discovered 13 hours ago

PoC for CVE-2014-6271

GnuBash🟣 EPSS 100%9.8CRITICAL
Code Injection Vulnerability in GNU Bash by The GNU Project

GNU Bash versions up to 4.3 are vulnerable to a code injection flaw due to the mishandling of trailing strings after function definitions in environment variables. This vulnerability enables remote attackers to execute arbitrary code by crafting specific environment variables under various condit...

PoC for CVE-2026-87902

WordPressWordPress8.1HIGH
Local File Inclusion in WordPress Leading to Remote Code Execution

An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...

Discovered 14 hours ago

PoC for CVE-2026-87902

WordPressWordPress8.1HIGH
Local File Inclusion in WordPress Leading to Remote Code Execution

An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...

PoC for CVE-2026-93485

WordPressWordPress7.1HIGH
Cross-Site Scripting in Automattic WordPress Core

An improper neutralization of input during web page generation vulnerability in Automattic WordPress core can lead to a DOM-Based XSS attack. This issue arises from the default configuration of WordPress, which allows unauthenticated users to exploit cross-site scripting by bypassing comment mode...

Discovered 15 hours ago

PoC for CVE-2026-88848

WordPressMasterstudy Lms4.2MEDIUM
Membership Bypass Vulnerability in MasterStudy LMS WordPress Plugin

The MasterStudy LMS plugin for WordPress, specifically versions 1.9 through 3.7.50, is susceptible to a serious vulnerability that allows unauthorized course enrollment. The flaw arises because the plugin fails to verify whether a member's requested course aligns with their membership plan. As a ...

PoC for CVE-2026-80514

WordPressWPforo Forum5.3MEDIUM
IP Spoofing Vulnerability in wpForo Forum Plugin for WordPress

The wpForo Forum plugin for WordPress versions 3.0.0 to 3.1.5 has a vulnerability that fails to adequately verify client-supplied IP address headers. This flaw enables unauthenticated attackers to manipulate these headers, thereby bypassing established rate limits on paid AI requests. As a result...

PoC for CVE-2026-86837

WordPressBookly5.3MEDIUM
Identity Verification Flaw in Bookly Plugin by WordPress

The Bookly WordPress plugin prior to version 28.3 is susceptible to a vulnerability where it fails to adequately verify the identity of customers when they attempt to update their stored details. This oversight allows unauthorized attackers who have knowledge of a customer's primary identifier to...

PoC for CVE-2026-8461

FfmpegFfmpeg8.8HIGH
Out-of-bounds Write Vulnerability in FFmpeg's Libavcodec Library

An out-of-bounds write vulnerability has been identified in the libavcodec library of FFmpeg, particularly within the MagicYUV decoder. This flaw may lead to denial-of-service conditions and has the potential to be exploited for remote code execution. The issue arises from improper handling of ce...

Discovered 18 hours ago

PoC for CVE-2026-78397

WordPressLink Library4MEDIUM
Unvalidated URL Handling in Link Library Plugin by WordPress

The Link Library plugin for WordPress prior to version 7.9.6 suffers from a security flaw due to improper URL validation. When a user submits a URL, the plugin may revert to making requests to potentially unsafe internal network resources if the input is deemed unsafe. This lack of validation ena...

PoC for CVE-2026-78394

WordPressLink Library4.1MEDIUM
Directory Write Vulnerability in Link Library Plugin for WordPress

The Link Library WordPress plugin prior to version 7.9.6 contains a flaw that permits unauthorized users with the Contributor role and higher to create directories and manipulate image files on the server. This vulnerability arises due to a lack of proper sanitation of user-supplied input, allowi...

PoC for CVE-2026-78393

WordPressLink Library6.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in Link Library WordPr...

The Link Library WordPress plugin prior to version 7.9.6 is vulnerable due to inadequate escaping of certain parameters when generating links for its front-end directory pages. This oversight allows for the exploitation of Reflected Cross-Site Scripting attacks, affecting any visitor to the site,...

PoC for CVE-2026-97721

SanluanPubliccms5.1MEDIUM
Authorization Bypass Vulnerability in Sanluan PublicCMS

A significant vulnerability exists in Sanluan PublicCMS, affecting versions up to 6.202506.e. This flaw is found in the CmsContentAdminController, specifically in the exportExcel/exportData functionality. An attacker can exploit this vulnerability to bypass authorization controls by manipulating ...

Discovered 19 hours ago

PoC for CVE-2026-72001

PangolinPangolin8.6HIGH
Authentication Bypass in Pangolin by Fosrl

Pangolin versions prior to 1.22.0 have a security flaw that permits unauthorized users to bypass authentication mechanisms. This vulnerability arises when an attacker manipulates URL parameters for the share-link authentication endpoint, leading to unauthorized access to various protected resourc...

Discovered 21 hours ago

PoC for CVE-2026-12227

WordPressVisual Composer Websit...9.8CRITICAL
Local File Inclusion Vulnerability in Visual Composer Website Build...

The Visual Composer Website Builder plugin for WordPress allows local file inclusion through the `vcv-template` parameter in all versions up to and including 45.16.0. This vulnerability enables unauthenticated attackers to include and execute arbitrary files on the server, potentially leading to ...

PoC for CVE-2026-94609

GoauthentikAuthentik8.8HIGH
Privilege Escalation Vulnerability in Authentik Identity Provider

Prior to the versions 2026.2.7, 2026.5.7, and 2026.8.2, Authentik had a privilege escalation vulnerability whereby accounts with delegated group management permissions could grant superuser status without proper authorization. This issue affected only deployments where non-administrators were giv...

PoC for CVE-2026-97650

NingzichunStudent-management-system5.3MEDIUM
Cross Site Scripting Vulnerability in ningzichun Student Management...

A cross site scripting vulnerability exists in the ningzichun student-management-system due to improper handling of user input in the echo function of admin/fun/addLog.php. This flaw allows an attacker to manipulate the 'reason' and 'detail' arguments, potentially leading to the execution of mali...

PoC for CVE-2026-12227

WordPressVisual Composer Websit...9.8CRITICAL
Local File Inclusion Vulnerability in Visual Composer Website Build...

The Visual Composer Website Builder plugin for WordPress allows local file inclusion through the `vcv-template` parameter in all versions up to and including 45.16.0. This vulnerability enables unauthenticated attackers to include and execute arbitrary files on the server, potentially leading to ...

Discovered 22 hours ago

PoC for CVE-2026-97649

NingzichunStudent-management-system5.1MEDIUM
Default Credentials Vulnerability in ningzichun Student Management ...

A significant vulnerability exists within the ningzichun student-management-system, specifically in the file example_lite.sql, allowing attackers to exploit an unknown functionality. This flaw facilitates the use of default credentials, enabling unauthorized remote access. Although the issue has ...

PoC for CVE-2026-97648

NingzichunStudent-management-system5.3MEDIUM
Cross-Site Request Forgery in Ningzichun Student Management System

A cross-site request forgery vulnerability has been identified in the Ningzichun Student Management System, affecting versions up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This flaw allows attackers to execute unauthorized commands on behalf of users without their consent, enabling remote expl...

PoC for CVE-2023-49070

ApacheApache Ofbiz🟣 EPSS 95%9.8CRITICAL
Pre-auth RCE in Apache Ofbiz Prior to 18.12.10 Due to XML-RPC No Lo...

The vulnerability in Apache OFBiz arises from an outdated XML-RPC component, which has not been maintained and poses a risk of pre-authentication remote code execution. This issue specifically affects Apache OFBiz versions before 18.12.10, highlighting the necessity for users to upgrade to the la...

PoC for CVE-2026-97647

NingzichunStudent-management-system6.9MEDIUM
Authorization Bypass in ningzichun Student Management System

A security vulnerability has been identified in the ningzichun Student Management System, specifically affecting versions up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. The issue resides in an undisclosed function within editLog.php, which allows for the manipulation of parameters such as sid, a...

Discovered 23 hours ago

PoC for CVE-2026-97646

NingzichunStudent-management-system6.9MEDIUM
Authorization Bypass in ningzichun Student Management System

A vulnerability has been identified in the ningzichun Student Management System, specifically affecting the file admin/fun/getStudent.php. This weakness allows attackers to bypass authorization by manipulating the 'sid' argument. The vulnerability can be exploited remotely, allowing unauthorized ...

Discovered 1 day ago

PoC for CVE-2026-97368

ChillzhuangSpringblade5.3MEDIUM
Authorization Bypass in chillzhuang SpringBlade UserAuthInfo Service

A vulnerability in the chillzhuang SpringBlade framework has been identified, affecting the UserServiceImpl.userInfo function. This weakness allows an attacker to manipulate userId arguments, leading to unauthorized access to user information. The exploitable endpoint can be accessed remotely, ra...

PoC for CVE-2026-93353

9001Copyparty6MEDIUM
Volume Restriction Bypass in Copyparty's SFTP Front End

Copyparty's SFTP front end is vulnerable to a volume restriction bypass, allowing authenticated users to create, delete, or modify files outside their permitted volume boundaries. By exploiting specific handlers (_mkdir, _rmdir, and _chattr), attackers can craft destination paths without proper a...