Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-39987
Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...
PoC for CVE-2026-33937
In Handlebars versions 4.0.0 through 4.7.8, a vulnerability exists where `Handlebars.compile()` can accept a pre-parsed AST object directly. This leads to the potential injection of arbitrary JavaScript into the generated code because the `value` field of a `NumberLiteral` AST node is emitted dir...
PoC for CVE-2025-29927
A security flaw exists in the Next.js framework that allows an attacker to bypass authorization checks if such checks are implemented in middleware. This vulnerability arises in versions prior to 14.2.25 and 15.2.3. To mitigate risk, it is recommended to restrict incoming requests that include th...
PoC for CVE-2026-52887
NocoBase, an AI-powered no-code/low-code platform, has a vulnerability in versions prior to 2.0.61 due to an improper handling of input parameters in the notification API. The GET request to /api/myInAppChannels:list allows authenticated users to inject unvalidated input into SQL commands. This o...
PoC for CVE-2026-63223
CodeIgniter, a popular PHP web framework, has a vulnerability that arises from inadequate validation of uploaded files. Before version 4.7.4, the upload validation rules, specifically 'is_image' and 'mime_in', fail to enforce safe client filename extensions independently. This oversight allows re...
PoC for CVE-2026-12940
IBM Langflow OSS versions 1.0.0 through 1.10.1 are exposed to a remote code execution vulnerability due to improper handling of environment variables in the MCP (Model Context Protocol) stdio launcher. Specifically, the vulnerability lies in the failure of the software to include critical variabl...
PoC for CVE-2026-1337
A cross-site scripting (XSS) vulnerability exists in the query log handling of Neo4j Enterprise and Community Editions prior to version 2026.01. Due to insufficient escaping of Unicode characters, users may inadvertently expose themselves to XSS attacks when logs are opened in tools that render t...
Discovered 3 hours ago
PoC for CVE-2026-16572
The LogMyTrip plugin for WordPress, up to version 1.9, is susceptible to SQL injection attacks due to its failure to properly sanitize and escape user input taken from cookies before incorporating it into SQL queries. This vulnerability permits unauthenticated users to manipulate the database thr...
PoC for CVE-2026-16565
The Dokan WooCommerce Multivendor Marketplace Solution plugin prior to version 5.0.9 is susceptible to an authorization bypass vulnerability. This flaw occurs due to the plugin's failure to verify product ownership on its product-attribute REST write endpoints. As a result, users with Dokan vendo...
PoC for CVE-2026-16563
The Academy LMS WordPress plugin versions before 3.8.3 contains a vulnerability where the REST API does not properly verify course enrollment or status of lesson publication. This oversight allows users with a Subscriber-level account to access the content of lessons they are not enrolled in. Thi...
PoC for CVE-2026-16564
The Dokan plugin for WordPress prior to version 5.0.9 contains a significant access control vulnerability. This flaw does not verify the ownership of orders on a REST endpoint responsible for bulk order-status changes, which can permit users holding a Dokan vendor account to alter the status of a...
PoC for CVE-2026-16539
The Page Duplicator plugin for WordPress, up to version 1.0.0, contains an SQL injection vulnerability due to insufficient sanitization and escaping of user inputs during the page duplication process. This flaw allows users with the Editor role and higher to execute malicious SQL queries, potenti...
PoC for CVE-2026-15931
The Simple Membership plugin for WordPress allows unauthenticated users to send a malicious payment approval request, which includes an unsanitized subscriber name. This leads to the potential execution of arbitrary JavaScript in an administrator's session. Because the plugin doesn't properly esc...
PoC for CVE-2026-16300
The ChamaWP WordPress plugin prior to version 1.0.13 is susceptible to a flaw that fails to adequately validate password reset requests. This vulnerability allows unauthorized attackers to reset passwords for any user, including those with administrative privileges. Such exploitation could lead t...
PoC for CVE-2026-16289
The ProfileGrid plugin for WordPress prior to version 6.0.0.0 lacks proper authorization checks when managing pending membership requests. This flaw permits any authenticated user, including those with lower privileges such as Subscribers, to retrieve sensitive information regarding users who are...
PoC for CVE-2026-16060
The Insert or Embed Articulate Content plugin for WordPress, up to version 4.3000000027, has a critical vulnerability that allows Editor-level users to exploit the feature for uploading archives. The plugin fails to adequately validate the contents of these uploads, enabling the upload of executa...
PoC for CVE-2026-16297
The Clearfy Cache plugin for WordPress, prior to version 2.4.3, contains a vulnerability that permits unrestricted classes during the unserialization of settings-import data. This flaw can be exploited by users with administrator privileges to conduct PHP Object Injection attacks. Should a suitab...
PoC for CVE-2026-16250
The Personal QR Message WordPress plugin versions through 1.0 lacks proper restriction on file types that users can upload via an unauthenticated handler. This oversight permits unauthenticated users to upload arbitrary PHP executables, which can be directly accessed. If exploited, this could lea...
PoC for CVE-2026-15930
The Simple Membership WordPress plugin allows unauthenticated attackers to exploit a flaw in user creation processes. When an account is created, the plugin fails to verify if this creation was successful before utilizing the returned user ID to update an account. This can lead to unauthorized mo...
PoC for CVE-2026-15260
The GEO my WP plugin for WordPress versions prior to 4.5.5.3 is vulnerable to an authentication bypass due to inadequate checks on two of its AJAX actions. This oversight allows users with subscriber-level access to manipulate or delete geolocation records for other users and posts by simply prov...
PoC for CVE-2026-15383
The Blog Floating Button WordPress plugin prior to version 1.4.20 suffers from a vulnerability where the visitor User-Agent header is not properly sanitized or escaped. This weakness allows an unauthenticated attacker to inject malicious scripts through a tracking REST endpoint. The exploited scr...
PoC for CVE-2026-14557
The SoftMarket Digital Marketplace WordPress plugin prior to version 1.0.0 suffers from an authentication bypass vulnerability. This occurs due to inadequate validation of authentication tokens within a section of its email verification process. As a result, unauthenticated attackers can compromi...
PoC for CVE-2026-15231
The Tag, Category, and Taxonomy Manager plugin for WordPress versions before 3.51.0 contains a flaw that allows users with contributor privileges to bypass authorization checks. This vulnerability enables them to access and disclose data from private or draft posts that they do not own, posing a ...
PoC for CVE-2025-15672
The ChamaWP plugin for WordPress prior to version 1.0.13 is vulnerable due to insufficient validation of user input. This flaw allows unauthenticated users to supply manipulated data that is passed to a PHP deserialization function. If exploited, this may enable attackers to inject arbitrary PHP ...
PoC for CVE-2026-12965
The Super Store Finder WordPress plugin version 7.8 contains a serious vulnerability where it fails to properly sanitize user-supplied input in an unauthenticated AJAX action. This flaw enables attackers to execute SQL injection attacks, potentially allowing them to manipulate database queries an...
PoC for CVE-2025-15673
The Import and Export Users and Customers plugin for WordPress versions earlier than 2.4.3 contains a vulnerability that allows high-privileged users to leverage insufficient restrictions on file paths during CSV imports. This flaw enables them to read sensitive files from the server, potentially...
PoC for CVE-2026-13340
The SVG Support WordPress plugin prior to version 2.5.17 fails to properly sanitize SVG files with the .svgz extension when uploaded by users who are permitted to do so. This oversight allows for the potential execution of malicious scripts embedded within these files, affecting users who view th...
PoC for CVE-2026-12872
The Webinfos WordPress plugin version 1.2 lacks proper validation mechanisms for uploaded files, allowing unauthenticated attackers to upload arbitrary files, including potentially malicious PHP scripts. This presents a significant security risk as it enables remote code execution in directories ...
PoC for CVE-2026-16274
The Classified Listing plugin for WordPress prior to version 5.4.4 is susceptible to an improper access control vulnerability. This flaw arises from the lack of capability or ownership checks on an AJAX action that retrieves post content. As a result, users with contributor-level access and highe...
PoC for CVE-2026-16534
The Import and Export Users and Customers plugin for WordPress before version 2.4.2 lacks proper enforcement of role-assignment and per-user edit permissions during CSV imports. This oversight allows a user with only basic user-creation rights to not only create a new administrator account but al...
PoC for CVE-2026-16532
The Link Library Plugin for WordPress version 7.9.2 and earlier is susceptible to SQL injection due to inadequate sanitization and escaping of user-supplied input. This flaw enables unauthenticated attackers to exploit the vulnerability, potentially allowing them to manipulate or access sensitive...
PoC for CVE-2026-16276
The Classified Listing WordPress plugin, prior to version 5.4.4, lacks proper capability checks for an AJAX action that presents aggregated store revenue totals. This oversight permits users with contributor-level access and higher privileges to view sensitive daily revenue figures, typically exc...
PoC for CVE-2026-15254
The Simply Schedule Appointments plugin for WordPress contains a significant access control issue. The plugin fails to implement proper capability checks on an administrative appointment-listing shortcode, which allows users with roles of Contributor or higher to access and disclose sensitive app...
PoC for CVE-2026-16057
The Contest Gallery plugin for WordPress contains a vulnerability in its post-deletion mechanism, where it fails to execute proper per-object capability and nonce checks. Instead, it relies on a coarse role-membership test, which allows any user with Author-level permissions or higher to delete p...
PoC for CVE-2026-43284
A vulnerability exists in the Linux kernel that concerns the handling of shared skb fragments during the decryption process in ESP-in-UDP packets. When pages are attached from a pipe directly to an skb using MSG_SPLICE_PAGES, the kernel marked these SKBs with SKBFL_SHARED_FRAG, which plays a cruc...
Discovered 4 hours ago
PoC for CVE-2026-9806
A stored cross-site scripting vulnerability exists in the notification panel of CTI Transmute. This issue arises when notification messages containing user-controlled convert names are displayed using innerHTML without sufficient sanitization measures. An attacker could exploit this by crafting a...
PoC for CVE-2026-18583
A vulnerability has been discovered in mz-automation's libiec61850 component pertaining to the MMS Request Handler. Specifically, the function checkDataSetAccess within the mms_mapping.c file allows for remote manipulation that may lead to an out-of-bounds read condition. This flaw affects versio...
Discovered 6 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 7 hours ago
PoC for CVE-2026-18582
A security flaw has been identified in the libiec61850 library from MZ Automation that affects the Reporting_RCBWriteAccessHandler function. This flaw can lead to improper memory management, specifically the free of memory not occurring on the heap. Due to this vulnerability, attackers can exploi...
Discovered 8 hours ago
PoC for CVE-2026-18581
A vulnerability has been identified in the Jinja Minja Template Parser of the ggml-org llama.cpp project. An attacker with local access can manipulate inputs in such a way that it leads to a reachable assertion, potentially compromising the application's stability. The issue was reported through ...
Discovered 9 hours ago
PoC for CVE-2024-40422
The StitionAI Devika application is vulnerable to a path traversal attack due to the insufficient validation of the snapshot_path parameter in the /api/get-browser-snapshot endpoint. Malicious actors can exploit this vulnerability by crafting requests that traverse the directory structure, allowi...
PoC for CVE-2026-39987
Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...
Discovered 11 hours ago
PoC for CVE-2026-9809
In Mautic 7, a stored Cross-Site Scripting (XSS) vulnerability exists within the Projects component. This flaw arises due to improper sanitization of user-supplied project names displayed in administrative detail views, such as campaigns, emails, or forms. When an authenticated user, who has perm...
Discovered 12 hours ago
PoC for CVE-2026-9811
A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. The application inadequately sanitizes project names retrieved via AJAX, which can lead to malicious scripts being injected into the DOM. An authenticated user capable of creating projects can ...
Discovered 14 hours ago
PoC for CVE-2026-58424
A vulnerability exists in Gitea that allows an unauthorized user to bypass the workflow approval gate, creating a potential security risk. This issue could lead to unauthorized modifications being made without proper oversight, undermining the integrity of project workflows. Users are advised to ...
Discovered 15 hours ago
PoC for CVE-2026-59941
Dompdf, an HTML to PDF converter for PHP, has a vulnerability where it improperly processes BMP images. Versions up to 3.15 can accept BMP images with declared header dimensions that do not correlate with the actual pixel dimensions. This oversight allows attackers to supply an excessively large ...
PoC for CVE-2026-57827
The RSFiles Joomla extension presents a security vulnerability that allows for unauthenticated users to upload arbitrary files, potentially enabling the execution of malicious code remotely. This flaw can lead to significant security risks for affected Joomla installations as it opens pathways fo...
Discovered 23 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2025-31207
A logic issue in iOS and iPadOS may allow a malicious app to enumerate the installed applications on a user's device. This could lead to potential privacy breaches, where sensitive information about user preferences and installations could be exposed. The issue has been addressed with enhanced ch...
Discovered 1 day ago
PoC for CVE-2018-9995
Certain DVR devices, including the TBK DVR4104 and DVR4216 models, as well as various rebranded variants, are susceptible to a remote authentication bypass. By manipulating the 'Cookie: uid=admin' header, attackers can access sensitive functionalities without proper authentication. This vulnerabi...