Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2022-24355

Tp-linkTl-wr940n8.8HIGH
Arbitrary Code Execution Vulnerability in TP-Link Router

This vulnerability exists in the TP-Link TL-WR940N router, allowing attackers in the network vicinity to execute arbitrary code due to insufficient validation of user-supplied data lengths when parsing file name extensions. This flaw can be exploited without authentication, enabling attackers to ...

PoC for CVE-2020-7882

HancomwithAnysign4pc7.5HIGH
anySign directory traversal vulnerability

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

PoC for CVE-2024-28000

WordPressLitespeed Cache🟣 EPSS 68%9.8CRITICAL
Incorrect Privilege Assignment vulnerability in LiteSpeed Cache all...

The CVE-2024-28000 vulnerability is found in the widely-used LiteSpeed Cache Plugin for WordPress websites, allowing unauthenticated users to gain administrator-level access and create new user accounts with the administrator role. This critical privilege escalation vulnerability has a high CVSS ...

PoC for CVE-2026-16723

AlibabaFastjson9CRITICAL
Remote Code Execution Vulnerability in fastjson by Alibaba

A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...

Discovered 5 hours ago

PoC for CVE-2026-10702

MozillaFirefox4.3MEDIUM
JIT Miscompilation Vulnerability in Firefox by Mozilla

A JIT (Just-In-Time) miscompilation vulnerability has been identified in the JavaScript Engine of Firefox. This flaw could potentially allow attackers to exploit the JIT component, leading to unexpected behavior or execution of arbitrary code. This issue has been addressed in Firefox version 151....

Discovered 6 hours ago

PoC for CVE-2026-59726

RuvnetRuflo10CRITICAL
Unauthenticated Access in Ruflo Agent Meta-Harness

The Ruflo Agent Meta-Harness prior to version 3.16.3 had a critical security flaw wherein its default Docker deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without any authentication. This oversight potentially allowed an unauthenticated attacker to execute commands, g...

Discovered 10 hours ago

PoC for CVE-2026-45746

Termix-sshTermix9CRITICAL
Broken Access Control in Termix Web Management Platform

The Termix Web Management Platform includes a vulnerability related to Broken Access Control, specifically in its File Manager feature. This issue stems from inadequate validation of the sessionId parameter, allowing attackers to exploit the backend's trust in a client-controlled identifier. As a...

PoC for CVE-2026-14310

WordPressTutor Lms5.4MEDIUM
Inadequate User Access Control in Tutor LMS WordPress Plugin

The Tutor LMS WordPress plugin prior to version 4.0.0 features a significant flaw in its user access control mechanism. This vulnerability permits authenticated users, regardless of their role, to access Q&A threads not associated with courses they are enrolled in. Moreover, it enables such users...

PoC for CVE-2026-14305

WordPressWP Delicious5.3MEDIUM
Authorization Bypass in WP Delicious Plugin Affecting WordPress Users

The WP Delicious plugin for WordPress prior to version 1.10.2 is susceptible to an authorization bypass vulnerability. This flaw allows unauthenticated users to exploit AJAX actions without proper authorization. As a result, users can modify certain post metadata, specifically the like counter an...

PoC for CVE-2026-14239

WordPressTourmaster
Stored Cross-Site Scripting in Tourmaster WordPress Plugin

The Tourmaster WordPress plugin prior to version 5.4.8 is vulnerable due to inadequate nonce checks when saving a custom-filter label from user input. This weakness allows unauthenticated attackers to exploit it and potentially inject malicious JavaScript. If a logged-in administrator is tricked ...

PoC for CVE-2026-13344

WordPressEssential Addons For E...4.8MEDIUM
Stored Cross-Site Scripting Vulnerability in Essential Addons for E...

The Essential Addons for Elementor WordPress plugin prior to version 6.6.10 is susceptible to Stored Cross-Site Scripting due to inadequate validation of HTML tag names in the Pricing Table widget title. This vulnerability allows users with Contributor-level access and above to inject malicious J...

PoC for CVE-2026-13345

WordPressEssential Addons For E...
Improper Access Control in Essential Addons for Elementor by WPDeve...

The Essential Addons for Elementor plugin for WordPress, prior to version 6.6.10, lacks necessary authorization checks in its product-comparison feature. This oversight allows unauthenticated users to access sensitive information, such as the titles, prices, and SKUs of draft, pending, and privat...

PoC for CVE-2026-13395

WordPressOnline Scheduling And ...
SQL Injection Vulnerability in Online Scheduling and Appointment Bo...

The Online Scheduling and Appointment Booking System plugin for WordPress prior to version 27.8 is vulnerable to SQL injection. This flaw arises from the plugin's failure to properly sanitize or cast user-supplied parameters in unauthenticated front-end booking requests. Attackers can exploit thi...

PoC for CVE-2026-13145

WordPressWP Travel
Information Disclosure Vulnerability in WP Travel Plugin by WordPress

The WP Travel plugin for WordPress, prior to version 11.8.1, is susceptible to an information disclosure vulnerability. The flaw occurs because the plugin fails to verify the ownership of booking requests made through the customer account dashboard. Consequently, this allows any authenticated use...

PoC for CVE-2026-13330

WordPressAnimation Addons For E...6.1MEDIUM
Stored Cross-Site Scripting in Animation Addons for Elementor Plugi...

The Animation Addons for Elementor plugin for WordPress allows users with the upload_files capability (Author and above) to upload SVG/SVGZ files without proper sanitization. This oversight enables the potential injection of malicious JavaScript into the application, resulting in stored cross-sit...

PoC for CVE-2026-13143

WordPressWP Travel
Unauthorized Payment Notification Processing in WP Travel Plugin by...

The WP Travel plugin for WordPress, prior to version 11.8.1, contains a vulnerability that allows unauthenticated attackers to manipulate payment statuses. This flaw stems from the plugin's failure to authenticate PayPal Instant Payment Notifications via the necessary post-back handshake. Consequ...

PoC for CVE-2026-13178

WordPressEventin
Unauthorized Order Creation in Eventin WordPress Plugin by Vendor

The Eventin WordPress plugin, prior to version 4.1.16, contains a vulnerability that allows unauthorized order creation. This occurs due to improper authorization checks, enabling attackers to modify order statuses without completing any payment process. As a result, unauthenticated users can cre...

PoC for CVE-2026-11881

WordPressFluent Forms6.1MEDIUM
Stored Cross-Site Scripting Vulnerability in Fluent Forms WordPress...

The Fluent Forms WordPress plugin prior to version 6.2.6 contains a vulnerability that fails to properly sanitize and escape a specific form field configuration setting. When a form is rendered, this oversight enables users with low-level roles, such as Contributor with specific permissions, to p...

PoC for CVE-2026-11870

WordPressWP Ghost (hide My WP G...
IP Spoofing Vulnerability in WP Ghost Plugin Affects WordPress Sites

The WP Ghost (Hide My WP Ghost) WordPress plugin prior to version 7.0.05 fails to properly verify that the client IP address originates from a trusted proxy. This oversight allows attackers to manipulate HTTP headers to spoof their IP addresses. As a result, unauthenticated attackers can circumve...

PoC for CVE-2026-11867

WordPressFrontend Admin By Dyna...
Arbitrary Taxonomy Term Management Flaw in Frontend Admin Plugin by...

The Frontend Admin plugin by DynamiApps, prior to version 3.29.7, contains a flaw that allows authenticated users with minimal privileges, like Subscribers, to perform unrestricted operations on taxonomy terms. This vulnerability permits these users to create, modify, and delete arbitrary taxonom...

PoC for CVE-2026-12500

WordPressWP Travel Engine
Unauthorized Option Overwrite in WP Travel Engine Plugin for WordPress

The WP Travel Engine plugin for WordPress prior to version 6.8.2 is vulnerable due to insufficient access checks on AJAX actions. This flaw allows unauthenticated users to execute certain actions, specifically overwriting critical site-wide options, as the public nonce required for these actions ...

PoC for CVE-2026-15382

WordPressUltimate Addons For WP...
Unauthenticated Deletion Vulnerability in Ultimate Addons for WPBak...

The Ultimate Addons for WPBakery Page Builder plugin allows for unauthorized deletion of a website's custom-uploaded icon font packs. Prior to version 3.21.4, the plugin fails to implement necessary capability and nonce checks, enabling unauthenticated attackers to issue a single request that can...

PoC for CVE-2026-11782

WordPressPoints And Rewards For...
Authorization Flaw in Points and Rewards for WooCommerce by WordPress

The Points and Rewards for WooCommerce plugin does not implement necessary authorization checks on wallet and points update actions, which are exposed to unauthenticated users. This vulnerability allows attackers to modify or corrupt the wallet balance and loyalty points of any user without verif...

PoC for CVE-2026-15255

WordPressRegistrationmagic
Improper Validation in RegistrationMagic Plugin Exposes User Data

The RegistrationMagic WordPress plugin prior to version 6.0.9.4 contains a security flaw that permits unauthenticated attackers to access sensitive user data. The issue arises from inadequate validation of one-time passwords stored in cookies, which enables unauthorized individuals to retrieve fr...

PoC for CVE-2026-15257

WordPressRegistrationmagic
Unauthorized Access Flaw in RegistrationMagic Plugin for WordPress

The RegistrationMagic WordPress plugin prior to version 6.0.9.4 allows unauthorized users to exploit the absence of proper authorization and nonce checks on front-end editing actions. This vulnerability enables attackers to overwrite the form submissions and associated profile fields of non-admin...

PoC for CVE-2026-15252

WordPressSearch Atlas Seo
Authentication Bypass in Search Atlas SEO Plugin Affects WordPress

The Search Atlas SEO plugin for WordPress prior to version 2.6.12 is susceptible to an authentication bypass flaw due to insufficient validation in an AJAX handler. This vulnerability allows authenticated users, such as Subscribers, to interact with the site's Google Indexing API. Consequently, t...

PoC for CVE-2026-15240

WordPressCustomer Switching
User Session Vulnerability in Customer Switching Plugin for WordPress

The Customer Switching plugin for WordPress prior to version 2.1.3 has a security flaw that allows a user with lower privileges to exploit an active session. When an operator switches to another user account, the session is not securely bound, enabling the lower-privileged user to perform actions...

PoC for CVE-2026-14231

WordPressLifterlms
Unauthorized Access in LifterLMS WordPress Plugin Allows Exposure o...

The LifterLMS WordPress plugin prior to version 10.0.10 has a vulnerability that fails to adequately verify user capabilities in one of its AJAX handlers. This oversight allows any authenticated user, even those with minimal subscriber-level permissions, to access sensitive titles of internal pos...

PoC for CVE-2026-14318

WordPressGiveWP
Cross-Site Scripting Vulnerability in GiveWP Plugin Affecting WordP...

The GiveWP plugin for WordPress, specifically versions prior to 4.16.3, is vulnerable to a Cross-Site Scripting (XSS) issue. This vulnerability arises from a lack of proper escaping for donation-form template settings before they are displayed in HTML attributes. As a result, users with the 'Give...

PoC for CVE-2026-14207

WordPressLifterlms6.1MEDIUM
Cross-Site Scripting Vulnerability in LifterLMS WordPress Plugin

The LifterLMS plugin for WordPress prior to version 10.0.10 is susceptible to a cross-site scripting vulnerability. This flaw arises from the plugin's failure to sanitize event-handler attributes within a course pricing field. As a result, users with editing privileges can inject malicious JavaSc...

PoC for CVE-2026-15250

WordPressAppointment Booking Pl...
Unauthorized Access in Appointment Booking Plugin for WordPress

The Appointment Booking Plugin for WordPress has a significant security flaw that permits unauthenticated users to manipulate certain booking fields through the public booking interface. This vulnerability enables unauthorized individuals to assign privileged values, such as the approval status, ...

PoC for CVE-2026-15153

WordPressWP Hotel Booking
SQL Injection Risk in WP Hotel Booking Plugin by WordPress

The WP Hotel Booking plugin for WordPress prior to version 2.3.2 is susceptible to SQL injection due to improper sanitization and escaping of search parameters in administrative listings. Attackers with appropriate booking-management roles could exploit this vulnerability to execute unauthorized ...

PoC for CVE-2026-15235

WordPressMotopress Hotel Booking
Unauthorized Data Exposure in MotoPress Hotel Booking Plugin by Mot...

The MotoPress Hotel Booking WordPress plugin prior to version 6.0.4 lacks sufficient capability checks in its AJAX functionalities. This oversight allows authenticated users with minimal privileges, such as Subscribers, to access sensitive customer information. Specifically, personal data includi...

PoC for CVE-2026-12687

WordPressProfilegrid7.5HIGH
ProfileGrid WordPress Plugin Privilege Escalation Vulnerability

The ProfileGrid WordPress plugin prior to version 5.9.9.8 contains a security flaw that allows anonymous users to bypass registration restrictions. As a result, these users can register into privileged groups without authentication, potentially being assigned roles with elevated permissions, incl...

PoC for CVE-2026-15054

WordPressBit Form
Form Submission Bypass in Bit Form Plugin for WordPress

The Bit Form plugin for WordPress has a security flaw that permits unauthenticated users to submit entries through public form submission handlers, even for forms that have been deactivated or unpublished. This oversight allows users to trigger configured workflows, such as email notifications, p...

PoC for CVE-2026-14592

WordPressWP Real Ip-based Acces...6.1MEDIUM
Access Control Flaw in WP Real IP-based Access Control Plugin by Wo...

The WP Real IP-based Access Control plugin prior to version 1.3.1 is susceptible to an access control vulnerability, allowing unauthenticated users to insert arbitrary JavaScript into a specific option value. This JavaScript becomes executable when an administrator accesses the plugin's settings ...

PoC for CVE-2026-14923

WordPressSync Post With Other Site
Authorization Flaw in Sync Post With Other Site Plugin for WordPress

The Sync Post With Other Site plugin for WordPress prior to version 1.9.3 contains a serious flaw in its authorization mechanism on a REST route that manages post creation and updates. Due to an operator-precedence error, it fails to enforce proper page-editing capabilities, allowing authenticate...

PoC for CVE-2026-14602

WordPressRemote Api
Remote Code Execution Vulnerability in Remote API WordPress Plugin ...

The Remote API WordPress plugin versions up to 0.2 contains a serious security flaw in its handling of user-supplied input. This vulnerability allows unauthenticated attackers to inject malicious PHP objects through deserialization, which could lead to remote code execution if a suitable exploit ...

PoC for CVE-2026-14226

WordPressEasy Appointments
Insufficient Access Control in Easy Appointments WordPress Plugin

The Easy Appointments plugin for WordPress up to version 3.12.26 contains an access control vulnerability that permits users with minimal permissions to access sensitive appointment data through certain REST API endpoints. Specifically, the plugin only checks for a basic user capability that any ...

PoC for CVE-2026-14221

WordPressEasy Appointments
Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclo...

The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and t...

PoC for CVE-2026-14188

WordPressEasy Appointments
Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure

The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.

PoC for CVE-2026-14223

WordPressEasy Appointments
Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure ...

The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.

PoC for CVE-2026-14222

WordPressEasy Appointments
Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via...

The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.

Discovered 11 hours ago

PoC for CVE-2026-57827

Rsjoomla.comRsjoomla.com Rsfiles E...10CRITICAL
Unauthenticated File Upload Vulnerability in RSFiles Joomla Extension

The RSFiles Joomla extension presents a security vulnerability that allows for unauthenticated users to upload arbitrary files, potentially enabling the execution of malicious code remotely. This flaw can lead to significant security risks for affected Joomla installations as it opens pathways fo...

PoC for CVE-2024-36104

ApacheApache Ofbiz🟣 EPSS 87%9.1CRITICAL
Apache OFBiz vulnerable to Path Traversal attack

Apache OFBiz is affected by a Path Traversal vulnerability that allows attackers to gain unauthorized access to restricted directories. This issue can lead to sensitive data exposure and requires urgent remediation. Users are strongly encouraged to upgrade to version 18.12.14 or later to mitigate...

PoC for CVE-2026-43813

AppleiOS And iPad OS7.1HIGH
Input Validation Flaw in Apple iOS and macOS Products

A vulnerability exists that stems from improper input validation, which has been resolved through enhanced input sanitization. This flaw allowed a maliciously crafted application to potentially bypass code signing enforcement mechanisms in various Apple operating systems. Users are encouraged to ...

Discovered 13 hours ago

PoC for CVE-2022-38181

ArmMidguard Gpu Kernel Dr...🟣 EPSS 13%8.8HIGH
Memory Access Vulnerability in Arm Mali GPU Kernel Driver

The Arm Mali GPU kernel driver is vulnerable due to mishandled GPU memory operations, which allows unprivileged users to access freed memory. This issue affects multiple versions across the Bifrost, Valhall, and Midgard architectures, posing potential risks for system integrity and data security.

Discovered 14 hours ago

PoC for CVE-2026-2586

Eclipse FoundationEclipse Glassfish9.1CRITICAL
Remote Code Execution Vulnerability in GlassFish Administration Con...

An authenticated Remote Code Execution vulnerability exists in the Administration Console of GlassFish. This flaw allows authorized users to send specially crafted requests, potentially resulting in the execution of arbitrary commands on the operating system with the privileges of the application...

Discovered 22 hours ago

PoC for CVE-2026-41939

Care Everywhere LlcCare Everywhere Gateway9.3CRITICAL
Hard-Coded Credentials Vulnerability in Care Everywhere Gateway by ...

The Care Everywhere Gateway version 14.3.10 contains a vulnerability due to hard-coded credentials in the embedded WildFly 8.2.0.Final management interface. This issue allows unauthenticated remote attackers to exploit default credentials, which are identical across all installations. By accessin...

Discovered 23 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...