Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 2 hours ago

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

Discovered 3 hours ago

PoC for CVE-2026-67620

FlowiseaiFlowise6.3MEDIUM
Server-Side Request Forgery Vulnerability in Flowise by Flowise AI

The Flowise application version 3.1.4 is susceptible to a server-side request forgery (SSRF) vulnerability due to an inadequate deny-list configuration in its SSRF guard found in httpSecurity.ts. Specifically, the default configuration omits critical endpoints associated with Oracle Cloud Infrast...

Discovered 7 hours ago

PoC for CVE-2026-18953

AwsAws-transform-mcp-server6.3MEDIUM
Improper Directory Limitation in Amazon awslabs.aws-transform-mcp-s...

The awslabs.aws-transform-mcp-server tool from Amazon contains a vulnerability due to improper validation of the savePath parameter, which could allow an attacker to write files outside the designated working directory. This issue affects versions 0.1.0 through 0.1.4. Users are encouraged to upgr...

Discovered 9 hours ago

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

PoC for CVE-2017-9757

IpfireIpfire🟣 EPSS 38%8.8HIGH
Remote Command Injection Vulnerability in IPFire by IPFire Team

IPFire version 2.19 is susceptible to a Remote Command Injection vulnerability through its ids.cgi component. The issue arises from improper handling of the OINKCODE parameter allowing authenticated users to execute arbitrary shell commands. This vulnerability can be exploited directly or via Cro...

Discovered 10 hours ago

PoC for CVE-2026-63077

JetbrainsTeamcity9.8CRITICAL
Unauthenticated Remote Code Execution in JetBrains TeamCity by JetB...

An unauthenticated remote code execution vulnerability has been identified in JetBrains TeamCity prior to version 2026.1.3 and 2025.11.7. This weakness is exposed through the agent polling protocol, allowing attackers to execute arbitrary code without authentication, posing significant risks to t...

Discovered 11 hours ago

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

Discovered 12 hours ago

PoC for CVE-2026-19268

Abdullah1854Mcpgateway5.3MEDIUM
Command Injection Vulnerability in MCPGateway by Abdullah1854

A command injection vulnerability has been identified in the MCPGateway by Abdullah1854, specifically within the 'getUsageByDateRange' function located in the file 'src/services/claude-usage.ts'. This vulnerability arises due to improper handling of input parameters, allowing an attacker to manip...

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

Discovered 13 hours ago

PoC for CVE-2026-71554

Python-hyperH25.3MEDIUM
Request Smuggling Vulnerability in h2 by Python Hyper

The h2 library, which is a pure-Python implementation of the HTTP/2 protocol stack, has a vulnerability that allows for potential request smuggling. This occurs in versions up to and including 4.4.0, where the library incorrectly handles request header blocks containing multiple Host headers. Sub...

PoC for CVE-2026-71554

Python-hyperH25.3MEDIUM
Request Smuggling Vulnerability in h2 by Python Hyper

The h2 library, which is a pure-Python implementation of the HTTP/2 protocol stack, has a vulnerability that allows for potential request smuggling. This occurs in versions up to and including 4.4.0, where the library incorrectly handles request header blocks containing multiple Host headers. Sub...

PoC for CVE-2026-16955

WordPressAi Engine
File Path Exposure in AI Engine WordPress Plugin by Developer

The AI Engine WordPress plugin prior to version 3.6.6 lacks proper validation of caller-supplied file paths, allowing individuals with subscriber-level access to read arbitrary files from the server. This vulnerability can lead to unauthorized data exfiltration when a specific public API feature ...

PoC for CVE-2026-16953

WordPressAi Engine
Unauthorized File Deletion in AI Engine Plugin for WordPress

The AI Engine WordPress plugin prior to version 3.6.4 suffers from a vulnerability that allows an unauthenticated attacker to delete user-uploaded chatbot files. This security flaw arises due to insufficient verification of the ownership of uploaded files, relying solely on a client-supplied sess...

PoC for CVE-2026-16948

WordPressSolace Extra
Access Control Flaw in Solace Extra WordPress Plugin

The Solace Extra plugin for WordPress suffers from an access control vulnerability due to inadequate capability checks in its AJAX actions. This flaw allows users with minimal privileges (such as Subscribers) to manipulate crucial site-wide settings and delete imported site-builder content, there...

PoC for CVE-2026-16608

WordPressDownload Monitor
Unauthenticated Injection Flaw in Download Monitor Plugin by WordPress

The Download Monitor plugin for WordPress prior to version 5.2.6 contains a vulnerability that allows unauthenticated users to bypass authorization checks on specific AJAX actions. This inadequacy permits unauthorized parties to inject arbitrary download log entries, leading to the potential infl...

PoC for CVE-2026-16595

WordPressWP Directory Kit
Authorization Flaw in WP Directory Kit Plugin Affects WordPress Users

The WP Directory Kit plugin for WordPress versions before 1.5.5 is susceptible to an authorization flaw during one of its authenticated AJAX actions. This vulnerability allows any authenticated user, including those with minimal privileges such as Subscribers, to access sensitive site information...

PoC for CVE-2026-16589

WordPressWP Directory Kit
SQL Injection Vulnerability in WP Directory Kit Plugin Affects Word...

The WP Directory Kit plugin for WordPress suffers from a security flaw that allows SQL injection attacks due to inadequate sanitization and escaping of parameters in authenticated AJAX actions. The vulnerability is particularly concerning because it lacks proper authorization and nonce checks. Th...

PoC for CVE-2026-16594

WordPressWP Directory Kit
Unauthorized Access Risk in WP Directory Kit WordPress Plugin by WP...

The WP Directory Kit plugin for WordPress, prior to version 1.5.5, contains a significant security flaw that lacks proper authorization and nonce validation on an authenticated AJAX action. This oversight enables any authenticated user, such as a Subscriber, to access and potentially disclose sen...

PoC for CVE-2026-16590

WordPressWP Directory Kit
Authorization Bypass in WP Directory Kit Plugin by WordPress

The WP Directory Kit plugin for WordPress is subject to an authorization bypass vulnerability due to improper checks on an authenticated AJAX action. This flaw enables any authenticated user, including those with minimal roles such as Subscriber, to access and retrieve stored contact messages and...

PoC for CVE-2026-16558

WordPressYmc Filter
Access Control Flaw in YMC Filter Plugin by WordPress

The YMC Filter plugin for WordPress, prior to version 3.12.8, contains a significant access control flaw. The plugin fails to properly sanitize and escape a layout builder setting when it is outputted on a public endpoint. Additionally, it lacks verification of object ownership during the saving ...

PoC for CVE-2026-16559

WordPressYmc Filter
Remote Code Execution Vulnerability in YMC Filter Plugin for WordPress

The YMC Filter plugin for WordPress prior to version 3.12.9 is susceptible to an improper input validation vulnerability that fails to sanitize SVG files uploaded via icon upload features. This oversight allows low-privileged users, including those with an Author role, to upload malicious files c...

PoC for CVE-2026-16578

WordPressAdmin Safety Guard — L...
Unauthorized Data Exposure in Admin Safety Guard WordPress Plugin

The Admin Safety Guard plugin for WordPress, specifically in versions prior to 1.4.0, suffers from a critical vulnerability due to a lack of capability checks on its REST API endpoint. This oversight permits unauthenticated attackers to access sensitive information, including a comprehensive list...

PoC for CVE-2026-16574

WordPressDokan: Ai Powered WooC...
Access Control Flaw in Dokan WooCommerce Marketplace Solution

The Dokan plugin for WooCommerce, version prior to 5.0.11, has a significant access control vulnerability. It fails to adequately verify that a downloadable product is associated with the requesting vendor, exposing a risk where an authenticated vendor could inadvertently grant their customers un...

PoC for CVE-2026-16562

WordPressWP Statistics
Insufficient Access Control in WP Statistics by WordPress

The WP Statistics plugin for WordPress, prior to version 14.16.10, is susceptible to a security flaw due to inadequate capability checks on certain AJAX handlers for dashboard analytics. This vulnerability allows users with Subscriber-level access or higher to access and potentially disclose sens...

PoC for CVE-2026-16535

WordPressLink Library
Reflected Cross-Site Scripting Vulnerability in Link Library Plugin

The Link Library plugin for WordPress versions prior to 7.9.4 is susceptible to reflected cross-site scripting (XSS). The plugin fails to properly sanitize and escape a specific parameter that is echoed back in HTTP responses. This oversight allows unauthenticated attackers to exploit the vulnera...

PoC for CVE-2026-16282

WordPressAppointment Hour Booking
Arbitrary Pricing Vulnerability in Appointment Hour Booking Plugin ...

The Appointment Hour Booking plugin for WordPress contains a flaw that allows unauthenticated users to submit a booking price that is not validated against the server-side configured service price. This lack of validation means users can set any final price, including zero or negative values, whi...

PoC for CVE-2026-16269

WordPressNewsletters
API Authentication Flaw in Newsletters Plugin for WordPress

The Newsletters plugin for WordPress is susceptible to an API authentication bypass due to inadequate type comparison of its API authentication key. This flaw enables unauthenticated attackers to exploit the plugin, particularly when the optional API feature is enabled. By leveraging type jugglin...

PoC for CVE-2026-16267

WordPressNewsletters
PHP Object Injection Vulnerability in Newsletters Plugin for WordPress

The Newsletters plugin for WordPress, prior to version 4.16, is susceptible to a PHP Object Injection vulnerability. This flaw occurs due to improper handling of unserialised data retrieved from public form submissions. Attackers, without authentication, can exploit this weakness to inject malici...

PoC for CVE-2026-19259

Mz AutomationLibiec618504.8MEDIUM
Heap-Based Buffer Overflow in MZ Automation libiec61850 Product

A heap-based buffer overflow vulnerability exists in MZ Automation's libiec61850 product, specifically within the MmsMapping_varAccessSpecToObjectReference function found in the src/iec61850/common/iec61850_common.c file. This vulnerability is triggered by improper handling of the GetNamedVariabl...

Discovered 14 hours ago

PoC for CVE-2026-55957

ApacheApache Tomcat7.3HIGH
Missing Authentication Step in Apache Tomcat Affects Multiple Versions

An authentication vulnerability has been identified in Apache Tomcat, specifically relating to the configuration of JNDIRealm when using GSSAPI for authentication purposes. This flaw enables unauthorized attackers to authenticate without providing the correct password, thereby compromising the se...

Discovered 15 hours ago

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

Discovered 17 hours ago

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 100%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

Discovered 19 hours ago

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 100%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

Discovered 20 hours ago

PoC for CVE-2026-64638

WordPressWordPress8.9HIGH
Pre-auth Reflected XSS Vulnerability in WordPress

WordPress is susceptible to a pre-auth reflected cross-site scripting (XSS) vulnerability on the login interface. This security issue allows attackers to exploit a specially crafted malicious webpage designed to lure users into interaction. Although this gateway typically leads to XSS, it represe...

Discovered 22 hours ago

PoC for CVE-2026-19246

HkudsNanobot5.3MEDIUM
Server-Side Request Forgery in HKUDS Nanobot Product

A server-side request forgery vulnerability exists in the HKUDS Nanobot up to version 0.2.1, specifically in the undocumented function _download_image_data_url within the image_generation.py module. This vulnerability allows remote attackers to exploit the function to execute unauthorized server ...

Discovered 23 hours ago

PoC for CVE-2026-19245

HkudsNanobot4.8MEDIUM
Information Disclosure Flaw in HKUDS Nanobot by HKUDS

A vulnerability has been identified in the HKUDS Nanobot's Login-shell Environment Handler, specifically in the ExecTool._prepare_command function within the shell.py file. This flaw can lead to the unintentional disclosure of sensitive information when local access is exploited. It arises from t...

PoC for CVE-2026-19244

HkudsNanobot5.1MEDIUM
Improper Access Control Vulnerability in HKUDS Nanobot Software

A significant vulnerability has been identified in HKUDS Nanobot prior to version 0.2.1, specifically within the connect_mcp_servers function of the mcp.py file. This issue involves improper access controls allowing potential unauthorized registration of MCP resources and prompt wrappers outside ...

Discovered 1 day ago

PoC for CVE-2026-19243

HkudsNanobot5.3MEDIUM
OS Command Injection Vulnerability in HKUDS Nanobot by HKUDS

A security vulnerability exists in HKUDS Nanobot versions prior to 0.3.0, affecting the Shell Allowlist Handler. Specifically, the issue arises from inadequate validation of shell commands, leading to potential remote command injection. Attackers can exploit this vulnerability by manipulating the...

PoC for CVE-2026-64640

ApacheApache Polaris5.3MEDIUM
Improper Storage Validation in Apache Polaris Affects Data Security

An issue has been identified in Apache Polaris where it fails to consistently validate storage locations during table and view registration. Authenticated users with the necessary permissions can leverage this vulnerability to allow Polaris to access Iceberg metadata files from user-defined locat...

PoC for CVE-2026-19231

SourcecodesterSimple Doctors Appoint...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Doctors Appoin...

A security flaw in SourceCodester's Simple Doctors Appointment System version 1.0 allows an attacker to exploit the /admin/ajax.php?action=delete_appointment endpoint. By manipulating the ID parameter, the attacker can execute SQL injection attacks remotely, compromising the integrity and confide...

PoC for CVE-2026-19230

SourcecodesterPhoto Share Website5.1MEDIUM
Cross-Site Scripting in SourceCodester Photo Share Website by Sourc...

A vulnerability has been identified in the SourceCodester Photo Share Website version 1.0, specifically within the Comment Input Box component. This issue arises from improper handling of the 'content' argument in the file '/social/ajax.php?action=save_upload', leading to a cross-site scripting (...

PoC for CVE-2026-63077

JetbrainsTeamcity9.8CRITICAL
Unauthenticated Remote Code Execution in JetBrains TeamCity by JetB...

An unauthenticated remote code execution vulnerability has been identified in JetBrains TeamCity prior to version 2026.1.3 and 2025.11.7. This weakness is exposed through the agent polling protocol, allowing attackers to execute arbitrary code without authentication, posing significant risks to t...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-19213

WonderTraderWondertrader5.3MEDIUM
Remote Command Injection in WonderTrader by Vendor

A vulnerability exists in WonderTrader versions up to 0.9.9 affecting the _undone_qty function in the Pending Order Handler. This security flaw allows remote manipulation of the getUndoneQty argument, leading to unauthorized alterations in behavioral workflows. The exploit is publicly accessible,...

PoC for CVE-2026-19212

WonderTraderWondertrader5.3MEDIUM
Vulnerability in TraderATP Cash Trade Conversion impacts WonderTrad...

A vulnerability exists in the TraderATP Cash Trade Conversion component of WonderTrader, specifically affecting the function within the file src/Includes/WTSTradeDef.hpp. This issue arises from the manipulation of the m_offsetType argument, leading to the use of an uninitialized variable, which c...

PoC for CVE-2026-19211

SourcecodesterPhoto Share Website6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Photo Share Website

A SQL injection vulnerability has been identified in the SourceCodester Photo Share Website version 1.0. This issue is triggered when manipulating the email parameter in the /social/ajax.php?action=signup file. Unsanctioned input can lead to unauthorized access, allowing attackers to execute remo...

PoC for CVE-2026-39987

Marimo-teamMarimo🟣 EPSS 97%9.3CRITICAL
Pre-Authentication Remote Code Execution in Marimo Python Notebook

Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...