Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-67363
The Balbooa Forms extension for Joomla is susceptible to a significant vulnerability where the stripeCharges and payAuthorize endpoints accept payment amounts from user-controlled parameters. This flaw allows unattended attackers to manipulate payment amounts, potentially allowing them to purchas...
PoC for CVE-2026-48611
The OAuth implementation in phpBB has a critical flaw where improper authentication checks can lead to account hijacking. This vulnerability is particularly concerning as it may allow unauthorized users to gain access to accounts even if OAuth is not configured or enabled. Default installations a...
Discovered 2 hours ago
PoC for CVE-2026-76581
The WPMU DEV Dashboard plugin for WordPress is prone to an authentication bypass vulnerability due to inconsistent handling of HMAC message construction between the `wdpsso_step1` and `wdpsso_step2` AJAX actions. The first step improperly exposes a concatenation of sensitive tokens, while the sec...
PoC for CVE-2018-7600
Multiple versions of Drupal, including those prior to 7.58 and various 8.x releases, are susceptible to a vulnerability that permits remote attackers to execute arbitrary code. This exploit takes advantage of configuration flaws in several subsystems, particularly those using default or common mo...
PoC for CVE-2014-6271
GNU Bash versions up to 4.3 are vulnerable to a code injection flaw due to the mishandling of trailing strings after function definitions in environment variables. This vulnerability enables remote attackers to execute arbitrary code by crafting specific environment variables under various condit...
PoC for CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...
Discovered 4 hours ago
PoC for CVE-2026-18741
The Worksuite SaaS platform, in versions prior to 6.0.14, is affected by a stored cross-site scripting vulnerability within its Asset Management module. This allows authenticated administrators to submit malicious JavaScript payloads in the Location and Description fields when adding new assets. ...
PoC for CVE-2026-82587
A vulnerability has been identified in Open5GS versions up to 2.7.7, specifically within the AMF component. The issue arises from the amf_namf_comm_decode_ue_mm_context_list function, where improper handling of the ueContext.mmContextList[*].allowedNssai parameter may lead to memory corruption, a...
Discovered 6 hours ago
PoC for CVE-2026-82556
A vulnerability exists in the Repository Migration Handler of Forgejo, specifically in the function net.LookupIP located in the file services/migrations/allowlist/is_migrate_allowed.go. This issue can be exploited remotely, allowing attackers to perform server-side request forgery. The public dis...
PoC for CVE-2026-82555
A significant vulnerability exists within the TOTOLINK N600R Router, specifically in the loginAuth function of the Authentication Handler component. This flaw arises from the use of insufficiently random values, making the system susceptible to remote exploitation. Attackers could leverage this v...
PoC for CVE-2026-82554
A security flaw exists in the SourceCodester Queue Management System 1.0, specifically within the /api/add_customer.php file. This vulnerability allows attackers to manipulate the 'Name' argument, facilitating cross-site scripting (XSS) attacks. The flaw can be exploited remotely, putting users a...
PoC for CVE-2026-82553
A vulnerability exists in the sambitraj Student Management System's Student Dashboard component, specifically within the function mysqli_query in the file student_dashboard.php. This flaw arises due to improper handling of the roll_no argument, enabling unauthorized access to sensitive informatio...
Discovered 7 hours ago
PoC for CVE-2026-82552
A vulnerability exists in Linux Foundation Magma 1.9.0 within the gNB Termination Handler's ngap_amf.c file. This flaw enables an attacker to initiate a denial-of-service attack remotely, potentially leading to service disruption. The specific functionalities that could be manipulated remain undi...
PoC for CVE-2026-82551
A vulnerability exists in version 1.9.0 of Linux Foundation Magma, specifically within the NGSetup Handler component located in the ngap_amf_handlers.c file. This flaw can be exploited remotely, allowing attackers to execute manipulations that lead to significant state issues. Given that exploit ...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 8 hours ago
PoC for CVE-2026-82550
A security vulnerability exists in the Magma component's NGSetupRequest Handler, specifically related to improper input validation when handling the argument NG-IoT-DefaultPagingDRX. This flaw could allow for remote exploitation, potentially facilitating unauthorized access or control over affect...
PoC for CVE-2026-82549
A security vulnerability has been identified in the Linux Foundation Magma's SecurityModeComplete handler, specifically affecting version 1.9.0. This flaw allows for improper validation of integrity check values, which could be exploited remotely. The existence of publicly available exploits incr...
PoC for CVE-2026-82548
An information disclosure vulnerability has been identified in Linux Foundation Magma version 1.9.0, specifically affecting the InitialUEMessage Handler component. This vulnerability allows attackers to exploit an unknown function within the application, resulting in the potential exposure of sen...
Discovered 9 hours ago
PoC for CVE-2026-82547
A vulnerability exists in Linux Foundation Magma version 1.9.0, specifically within the Registration Complete Message Handler implemented in the file tasks/amf/amf_fsm.cpp. This flaw can allow unauthorized remote attackers to manipulate the system's authentication processes. It is crucial for use...
PoC for CVE-2026-82545
A SQL injection vulnerability has been identified in itsourcecode's Sales and Inventory System version 1.0. This flaw resides in the argument handling of the /pages/sup_searchfrm.php file, where improper validation allows remote attackers to manipulate the ID parameter. Such exploitation can lead...
PoC for CVE-2026-82222
A deserialization vulnerability exists in the GiveWP plugin, allowing unsanitized user input to manipulate object states and trigger remote code execution. This issue can lead to unauthorized actions being performed on the server, potentially impacting sensitive data and system integrity. The aff...
Discovered 11 hours ago
PoC for CVE-2026-82543
A race condition vulnerability has been identified in vastsa FileCodeBox, specifically affecting the update_file_usage function within the Pickup Limit Handler component. This flaw allows an attacker to manipulate the system remotely, potentially leading to unauthorized access or alterations of f...
PoC for CVE-2026-82542
A vulnerability has been identified in the Tenda HG10, specifically within the Boa Web Server's formIPv6Routing function. This issue arises due to improper handling of the argument destNet, leading to a buffer overflow condition. This flaw allows attackers to execute remote exploits, potentially ...
PoC for CVE-2026-82541
A significant security flaw has been identified in the itsourcecode Sales and Inventory System, specifically within the file /pages/sup_edit.php. This vulnerability allows attackers to manipulate the argument ID, leading to SQL injection attacks. The nature of this flaw enables remote exploitatio...
Discovered 12 hours ago
PoC for CVE-2026-82540
A SQL injection vulnerability has been discovered in the itsourcecode Sales and Inventory System 1.0. This vulnerability affects a specific function in the /pages/cust_searchfrm.php file. By manipulating the argument ID, attackers can execute unauthorized SQL commands, leading to potential data b...
Discovered 13 hours ago
PoC for CVE-2026-82222
A deserialization vulnerability exists in the GiveWP plugin, allowing unsanitized user input to manipulate object states and trigger remote code execution. This issue can lead to unauthorized actions being performed on the server, potentially impacting sensitive data and system integrity. The aff...
PoC for CVE-2026-82539
A vulnerability exists in the TOTOLINK A720R router due to improper handling of the 'desc' argument in the MAC Filtering functionality within the cstecgi.cgi file. This flaw can be exploited remotely, allowing attackers to manipulate memory and potentially execute malicious code. The vulnerabilit...
PoC for CVE-2026-82488
A cross site scripting vulnerability has been identified in the Beetel 450TC3 router, specifically within the User Management component. By manipulating the Username argument, an attacker can execute arbitrary scripts in the context of the user's session. This vulnerability can be exploited remot...
Discovered 14 hours ago
PoC for CVE-2026-82487
A security flaw has been identified in the Beetel 450TC3 router's password recovery mechanism that allows remote attackers to manipulate the system, potentially leading to weak password retrieval. This vulnerability could be exploited by unauthorized users who aim to gain access through insecure ...
PoC for CVE-2026-82485
A security vulnerability in the itsourcecode Sales and Inventory System 1.0 has been identified in the pro_edit.php file. This vulnerability allows an attacker to manipulate the ID parameter, leading to potential SQL injection attacks. Such vulnerabilities may enable unauthorized access to sensit...
Discovered 15 hours ago
PoC for CVE-2026-82484
A vulnerability exists in the itsourcecode Sales and Inventory System 1.0, where the /pages/emp_searchfrm.php file is susceptible to SQL injection via an improper handling of the ID argument. This flaw allows an attacker to execute arbitrary SQL commands, potentially exposing sensitive database i...
PoC for CVE-2026-45071
The Symfony PHP framework has a vulnerability in its Crawler component due to improper handling of XML content. Specifically, prior to versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the method Crawler::addXmlContent() enabled DOMDocument::$validateOnParse, allowing for external entity resolution. T...
PoC for CVE-2026-82483
A vulnerability in Coppermine Photo Gallery affects versions up to 1.6.28, specifically impacting the db_input.php file within the Hidden Album Update Endpoint. This vulnerability enables attackers to execute cross site scripting attacks remotely, potentially compromising user data and site integ...
Discovered 17 hours ago
PoC for CVE-2026-82482
A security vulnerability has been identified in Coppermine Photo Gallery, affecting versions up to 1.6.28. This vulnerability resides in the 'edit_profile' endpoint, specifically in the 'profile.php' file, where improper handling of the 'Biography' argument allows for Cross Site Scripting (XSS) a...
PoC for CVE-2026-81766
The Really Simple Security WordPress plugin, prior to version 9.8.0, allows administrators of subsites within a multisite network to execute arbitrary code. This is due to the absence of checks ensuring that the user is permitted to install the plugin, which compromises the security of the direct...
PoC for CVE-2026-81660
The Groundhogg CRM, Newsletters, and Marketing Automation WordPress plugin prior to version 4.5.13 fails to properly validate and escape values received from optional web form fields. This flaw enables unauthenticated attackers to execute Stored Cross-Site Scripting (XSS) attacks, potentially com...
PoC for CVE-2026-76585
The Customer Reviews for WooCommerce plugin prior to version 5.118.0 has a vulnerability that fails to properly sanitize and escape customer review content submitted through its endpoints. This oversight enables unauthenticated users to potentially launch Stored Cross-Site Scripting (XSS) attacks...
PoC for CVE-2026-19722
The WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.133 is susceptible to an arbitrary file write vulnerability. This issue arises as the plugin fails to properly validate the destination paths for files extracted from backup packages during restoration. As a result,...
PoC for CVE-2026-78364
The MW WP Form plugin for WordPress prior to version 5.1.6 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient sanitization and escaping of its form settings. This loophole allows users with Editor permissions to potentially execute malicious scripts in the con...
PoC for CVE-2026-14307
The GeotargetingWP plugin for WordPress versions prior to 3.5.6.2 is susceptible to cross-site scripting attacks due to inadequate sanitization and escaping of certain parameters in AJAX responses served with an HTML content type. This vulnerability enables unauthenticated attackers to inject mal...
PoC for CVE-2026-14835
The SOGO Add Script to Individual Pages Header Footer plugin for WordPress allows users with contributor-level access and above to insert unverified JavaScript code into the post metadata. This occurs because the plugin does not adequately sanitize or escape custom header/footer script values. As...
Discovered 1 day ago
PoC for CVE-2026-82424
A security flaw has been discovered in the PHPGurukul Student Information System version 1.0, specifically in the /student_edit1.php file. This vulnerability arises due to improper handling of the ID argument, allowing attackers to execute SQL injection attacks remotely. The exploit has been publ...
PoC for CVE-2026-23989
The Reva interoperability platform from OpenCloud contains a vulnerability in the GRPC authorization middleware that allows malicious users to bypass scope verification associated with public links. This flaw can be exploited through the archiver service to create archives (zip or tar files) cont...
PoC for CVE-2026-82422
A security flaw has been identified in the itSourceCode Sales and Inventory System 1.0, specifically within an unknown function in the file /pages/emp_del.php. This vulnerability is exploited by manipulating the argument ID, which can lead to SQL injection attacks. As the exploit code is publicly...
PoC for CVE-2026-82421
A vulnerability has been identified in the itsourcecode Sales and Inventory System 1.0 concerning improper handling of the argument ID in the file /pages/emp_edit.php. This flaw allows an attacker to manipulate SQL queries, potentially leading to unauthorized access and data manipulation. The exp...
PoC for CVE-2022-38694
The vulnerability occurring in UNISOC's BootRom allows a possible unchecked write address, enabling local escalation of privilege without requiring additional execution privileges. This flaw poses a significant security risk, as it can be exploited by malicious actors to gain unauthorized access ...
PoC for CVE-2026-82473
The KubeEdge CloudCore component, up to version 1.23.1, is vulnerable to an authentication bypass that allows attackers to submit node task status reports without any authentication. This flaw is exploitable via the HTTPS service on port 10002, enabling unauthorized users to manipulate the percei...
PoC for CVE-2026-4001
The Woocommerce Custom Product Addons Pro plugin for WordPress has a vulnerability that allows Remote Code Execution due to insufficient sanitization of user inputs. Specifically, in the process_custom_formula() function, user-defined custom pricing formulas are not properly validated before bein...
Discovered 2 days ago
PoC for CVE-2026-82286
The gpt-crawler, up to version 1.5.1, contains a significant flaw in its handling of the outputFileName parameter in the POST /crawl endpoint. This vulnerability permits unauthenticated users to write arbitrary files to any location within the filesystem. By providing carefully crafted input that...
PoC for CVE-2026-81346
The Frontend Admin plugin developed by DynamiApps suffers from an improper authorization vulnerability due to the absence of a capability check on certain AJAX actions. This flaw permits any authenticated user, including subscribers, to delete arbitrary membership plans. As a result, this vulnera...