Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 2 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 4 hours ago

PoC for CVE-2026-86851

WordPressLivees Checkout6.5MEDIUM
Vulnerability in Livees Checkout Plugin Allows Unauthorized Order M...

The Livees Checkout WordPress plugin (up to version 7.0.2) suffers from a serious security flaw where it fails to validate user permissions, nonce tokens, or order keys on the order confirmation page. This lack of security checks enables unauthenticated attackers to change the status of any order...

PoC for CVE-2026-103329

WordPressSuper Payments5.3MEDIUM
Web Application Vulnerability in Super Payments for WooCommerce by ...

The Super Payments plugin for WooCommerce does not adequately authenticate payment webhook notifications. This flaw arises because the signing key used for signature validation is empty by default. Consequently, this allows malicious actors to create valid signatures, enabling them to indicate th...

PoC for CVE-2026-87846

WordPressShipping For Nova Poshta5.3MEDIUM
AJAX Vulnerability in Nova Poshta Shipping Plugin for WordPress

The Nova Poshta Shipping plugin for WordPress versions up to 1.19.8 is exposed to serious security risks due to a lack of authorization, nonce, and ownership checks on an AJAX action. This oversight allows unauthenticated users to delete shipment records associated with arbitrary orders. Attacker...

PoC for CVE-2026-89235

WordPressTestimonials By Bestwe...6.8MEDIUM
SQL Injection Vulnerability in Testimonials by BestWebSoft WordPres...

The Testimonials by BestWebSoft plugin for WordPress, up to version 1.0.8, has a vulnerability where it fails to properly sanitize and escape a user-supplied parameter in a SQL query. This oversight allows unauthenticated attackers to manipulate the SQL query by appending additional SQL commands,...

PoC for CVE-2026-85348

WordPressGdpr Data Request Form4.3MEDIUM
CSRF Vulnerability in GDPR Data Request Form Plugin for WordPress

The GDPR Data Request Form plugin for WordPress, up to version 1.7.1, lacks adequate CSRF protections when updating its settings. This oversight allows attackers to exploit the vulnerability by tricking a site administrator into executing a malicious request. If successful, this could lead to una...

Discovered 7 hours ago

PoC for CVE-2026-84220

WordPressKirki4.8MEDIUM
Code Execution Vulnerability in Kirki Plugin for WordPress

The Kirki WordPress plugin prior to version 6.3.2 is vulnerable to a serious issue where it allows shortcodes in comments to be executed. This happens because the plugin renders comments without properly filtering or moderating them. As a result, unauthenticated users can exploit this vulnerabili...

PoC for CVE-2026-84224

WordPressKirki4.1MEDIUM
Remote Code Execution in Kirki WordPress Plugin Affecting Site Secu...

The Kirki WordPress plugin prior to version 6.3.2 contains a flaw that fails to properly validate the host of a provided URL before making a fetch request. This oversight allows users with at least editor-level permissions to send requests to internal services that should ideally be unreachable f...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 9 hours ago

PoC for CVE-2026-93548

WordPressFoosales
User Impersonation Vulnerability in FooSales Plugin by WordPress

The FooSales plugin for WordPress, prior to version 1.43.3, contains a serious vulnerability that allows any authenticated user to impersonate other users, including administrators. This flaw arises from the lack of proper verification to establish if a user is authorized to act on behalf of anot...

PoC for CVE-2026-106097

WordPressCode Snippets
SQL Injection Vulnerability in Code Snippets Plugin for WordPress

The Code Snippets plugin for WordPress, prior to version 3.10.0, contains a SQL Injection vulnerability due to improper sanitization and escaping of user-supplied parameters in certain snippet-migration import endpoints. This flaw is particularly concerning for environments utilizing WordPress Mu...

PoC for CVE-2025-15700

WordPressAWP Classifieds
Remote Code Execution Vulnerability in AWP Classifieds Plugin by Wo...

The AWP Classifieds plugin for WordPress prior to version 4.4.9 has a significant vulnerability in its listing-import feature. It fails to properly validate the type of files that users can extract from uploaded ZIP archives. Consequently, users with management capabilities can upload arbitrary P...

PoC for CVE-2026-87841

WordPressUnitecHPay
Payment Notification Vulnerability in UnitechPay WordPress Plugin

The UnitechPay WordPress plugin version 1.0.6.3 suffers from a significant flaw where it fails to authenticate payment notifications. This vulnerability allows attackers to mark orders as paid without any legitimate payment being processed, in addition to the ability to arbitrarily change the sta...

PoC for CVE-2026-106095

WordPressCode Snippets
Insufficient Capability Check in Code Snippets Plugin for WordPress

The Code Snippets plugin for WordPress, prior to version 3.10.0, contains a vulnerability that allows an administrator of a single subsite within a multisite network to manipulate snippets for the entire network. This occurs because the plugin does not conduct a proper capability check on certain...

PoC for CVE-2026-92990

WordPressSendpress Newsletters
Unauthorized Access Vulnerability in SendPress Newsletters Plugin b...

The SendPress Newsletters plugin for WordPress contains a security flaw where it secures a logging endpoint with a hardcoded token, consistent across all installations. This design flaw allows unauthorized users to access sensitive newsletter sending logs. Consequently, attackers could obtain inf...

PoC for CVE-2026-88931

WordPressSocial Web Suite
Unauthenticated Settings Overwrite in Social Web Suite Plugin for W...

The Social Web Suite plugin for WordPress prior to version 4.1.12 contains a vulnerability that fails to restrict unverified access to its configuration settings. This oversight allows attackers to exploit an unauthenticated endpoint to manipulate arbitrary plugin options, including critical ones...

PoC for CVE-2026-86850

WordPressSku Error Fixer For Wo...
AJAX Action Flaw in SKU Error Fixer for WooCommerce Plugin

The SKU Error Fixer for WooCommerce WordPress plugin allows unauthenticated users to execute certain AJAX actions without performing necessary capability or nonce checks. This oversight enables malicious actors to permanently delete product variations deemed obsolete and exposes sensitive details...

PoC for CVE-2026-92989

WordPressSendpress Newsletters
Security Flaw in SendPress Newsletters Plugin for WordPress

The SendPress Newsletters plugin for WordPress fails to adequately restrict user capabilities when managing newsletters. Authenticated users with subscriber-level access can exploit this oversight, allowing them to synchronize all site users into a mailing list and manipulate the newsletter sendi...

PoC for CVE-2026-91940

UnclecodeCrawl4ai8.7HIGH
Arbitrary File Write Vulnerability in crawl4ai by UncleCode

The crawl4ai tool prior to version 0.9.3 has a vulnerability where the PDFContentScrapingStrategy's _filter_untrusted_fields function fails to properly validate untrusted configuration fields. This flaw enables attackers to submit specially crafted configuration bodies, potentially containing mal...

Discovered 12 hours ago

PoC for CVE-2026-92555

Akin Software Com...Akinsoft Wolvox Contro...9.8CRITICAL
Sensitive Data Exposure in AKINSOFT WOLVOX Control Panel

The AKINSOFT WOLVOX Control Panel contains a vulnerability that allows sensitive information to be inserted into data sent by the application. This exposure enables unauthorized access to system resources, highlighting the need for users to update to the latest version to mitigate potential risks...

Discovered 15 hours ago

PoC for CVE-2026-21589

AtlassianBamboo Data Center9.3CRITICAL
Arbitrary File Access Vulnerability in Atlassian Products

This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerat...

Discovered 16 hours ago

PoC for CVE-2021-30535

GoogleChrome8.8HIGH
Heap Corruption Vulnerability in Google Chrome by ICU

A double free vulnerability exists in the International Components for Unicode (ICU) library within Google Chrome versions prior to 91.0.4472.77. This flaw allows a remote attacker to potentially exploit heap corruption by crafting a malicious HTML page. Successful exploitation could lead to arbi...

Discovered 18 hours ago

PoC for CVE-2026-11318

Zuler TechnologyDeskin8.5HIGH
Privilege Escalation in Deskin Service on macOS by Unauthenticated ...

Deskin versions up to 3.3.4.3 have a significant vulnerability in the com.deskin.service.installer XPC service. This flaw allows local unprivileged attackers to connect to the root-owned service without authentication, enabling them to execute arbitrary installer packages as the root user. By exp...

Discovered 19 hours ago

PoC for CVE-2026-107707

IntegoIntego Antivirus8.5HIGH
Local Privilege Escalation Vulnerability in Intego Antivirus for Wi...

Intego Antivirus for Windows versions through 3.0.0.1 contains a vulnerability in its optimization module that permits local unprivileged users to delete arbitrary folders as the SYSTEM account. Exploitation occurs when an attacker alters the directory of a scanned duplicate file, leveraging a ju...

Discovered 21 hours ago

PoC for CVE-2026-5430

Wso2Wso2 Universal Gateway10CRITICAL
JWT Authentication Vulnerability in WSO2 Products

The vulnerability in WSO2 products relates to the JWT authentication mechanism, which improperly validates tokens signed with algorithms not explicitly configured or supported. This flaw enables an attacker to create a JSON Web Token (JWT) using an unsupported signing algorithm. If an attacker su...

PoC for CVE-2025-9974

NokiaNokia Ont8HIGH
Input Handling Flaw in ONT/Beacon Device from Nokia

The ONT/Beacon device by Nokia features a critical input handling flaw in its unified WEBUI application. This vulnerability allows low-privileged authenticated users to exploit insufficient validation of user-supplied data, enabling them to execute arbitrary commands on the device's operating sys...

PoC for CVE-2026-18963

Red HatRed Hat Build Of Keycl...9.1CRITICAL
Authorization Flaw in Keycloak Services by Red Hat

A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...

PoC for CVE-2026-31857

CraftcmsCms8.1HIGH
Remote Code Execution in Craft CMS from Craft

Craft CMS has a remote code execution vulnerability due to improper handling of user-controlled input in the conditions system prior to version 5.9.9 and 4.17.4. The affected method, BaseElementSelectConditionRule::getElementIds(), makes use of the unprotected renderObjectTemplate() function, all...

Discovered 22 hours ago

PoC for CVE-2026-107696

FfmpegFfmpeg7.1HIGH
Infinite Loop Vulnerability in FFmpeg's RTSP Redirect Handling

FFmpeg versions up to 9.0.2 have a vulnerability in the RTSP redirect handling within the ff_rtsp_connect() function in libavformat/rtsp.c. The flaw allows attackers with control over the RTSP server to send continuous 302 redirects to the same or a different server. This leads to an infinite loo...

PoC for CVE-2026-107695

FfmpegFfmpeg7.1HIGH
Infinite Loop Vulnerability in FFmpeg HLS Demuxer

FFmpeg versions prior to 8.1.3 contain a vulnerability in the HLS demuxer that can be exploited by remote attackers to create a denial of service condition. This occurs when the parse_playlist() function improperly handles Master Playlist tags embedded in Media Playlists. Attackers may deceive us...

Discovered 1 day ago

PoC for CVE-2026-9209

MjobMjobtime9.3CRITICAL
Unauthenticated SQL Execution in mJobTime Admin Panel

The mJobTime application, specifically build 15.7.3.32, features an unauthenticated SQL execution vulnerability found in the Login.aspx admin panel. This flaw allows attackers to exploit the runQueryButton postback and exportSqlQuery_Server PageMethod, executing arbitrary SQL commands against the...

PoC for CVE-2026-21589

AtlassianBamboo Data Center9.3CRITICAL
Arbitrary File Access Vulnerability in Atlassian Products

This vulnerability affects several Atlassian Data Center products, enabling an unauthenticated remote attacker to gain access to specific files within the web application root directory. Essential exploitation requires prior knowledge of the exact file names and paths, with no ability to enumerat...

PoC for CVE-2026-105192

LmcacheLmcache9.8CRITICAL
Unauthorized Code Execution in LMCache Distributed Mode by LMCache

The LMCache distributed mode introduces a vulnerability where an unauthenticated ZeroMQ ROUTER allows worker processes to register and share key-value cache blocks. This may lead to code execution as the user running the LMCache process, potentially with elevated privileges if running as root. It...

PoC for CVE-2026-107640

IntegricsEnswitch9.3CRITICAL
Authentication Bypass in Integrics Enswitch API

Integrics Enswitch versions 3.13 through 4.4 are affected by an authentication bypass vulnerability that enables unauthenticated attackers to change account passwords. This issue arises from a flaw in the /api/json/user/password/update/ endpoint, allowing attackers to circumvent authentication by...

PoC for CVE-2026-93509

WordPressWallet System For WooC...6.5MEDIUM
Improper Input Validation in Wallet System for WooCommerce Plugin

The Wallet System for WooCommerce plugin suffers from an improper input validation flaw that allows authenticated attackers with Subscriber-level access to manipulate wallet transfer amounts. An attacker can exploit this vulnerability by minting wallet funds, as the system fails to ensure that tr...

PoC for CVE-2026-105190

WordPressEasy Digital Downloads5.3MEDIUM
User Account Creation Vulnerability in Easy Digital Downloads WordP...

The Easy Digital Downloads plugin for WordPress prior to version 3.7.1 contains a security flaw that permits unauthenticated users to create accounts without properly checking the user registration settings of the site. This issue enables unauthorized account creation and grants the created accou...

PoC for CVE-2026-104671

WordPressTutorstarter5.3MEDIUM
User Registration Bypass in TutorStarter WordPress Theme by TutorStar

The TutorStarter WordPress theme prior to version 4.0.4 contains a vulnerability where one of its AJAX registration handlers fails to respect the site's user registration setting. This weakness enables unauthenticated visitors to create user accounts on the WordPress site even when user registrat...

PoC for CVE-2026-103517

WordPressAirwallex Online Payme...5.3MEDIUM
Vulnerability in Airwallex Online Payments Gateway Plugin for WordP...

The Airwallex Online Payments Gateway plugin for WordPress lacks proper verification of incoming payment notifications when a webhook secret is not configured. This issue enables attackers to forge notifications, potentially leading to unauthorized marking of orders as paid. Website owners using ...

PoC for CVE-2026-105110

IskratelInnbox9.3CRITICAL
OS Command Injection Vulnerability in Iskratel Innbox GPON ONT Devices

An OS Command Injection vulnerability exists in the login.xgi CGI endpoint of Iskratel Innbox GPON ONT devices, allowing unauthorized remote attackers to execute arbitrary commands with root privileges using specific parameters. This security flaw poses a significant risk as it can lead to unauth...

PoC for CVE-2026-94258

WordPressSms Alert2.7LOW
Information Disclosure Vulnerability in SMS Alert WordPress Plugin

The SMS Alert plugin for WordPress has a significant information disclosure flaw found in versions prior to 4.0.1. This vulnerability enables an unauthorized administrator within a multisite network to access and reveal the billing phone numbers of users across different sites. The issue arises f...

PoC for CVE-2026-94246

WordPressWallet System For WooC...6.3MEDIUM
Authorization Flaw in Wallet System for WooCommerce by WordPress

The Wallet System for WooCommerce plugin for WordPress prior to version 2.8.0 contains an authorization flaw that allows authenticated users, such as subscribers, to make unauthorized withdrawal requests. This issue arises because the plugin fails to confirm that the specified wallet account for ...

PoC for CVE-2026-94275

WordPressTrack Orders For WooCo...5.3MEDIUM
Authorization Bypass in Track Orders Plugin Exposes Customer Inform...

The Track Orders for WooCommerce plugin prior to version 1.2.7 contains a security flaw that allows unauthorized access to sensitive customer information. This vulnerability permits unauthenticated attackers to view critical personal details of users simply by providing their email addresses. As ...

PoC for CVE-2026-86828

WordPressBackWPup6.6MEDIUM
File Extraction Vulnerability in BackWPup Plugin by WordPress

The BackWPup plugin for WordPress prior to version 5.7.7 has a security flaw that fails to adequately restrict the destination path for files extracted during backup restores. This issue arises when the fallback archive library is utilized, allowing high-privileged users to manipulate the backup ...

PoC for CVE-2026-94244

WordPressWallet System For WooC...4.3MEDIUM
Vulnerability in Wallet System for WooCommerce Plugin Exposes User ...

The Wallet System for WooCommerce plugin for WordPress versions prior to 2.8.0 lacks proper capability checks, allowing any authenticated user to access sensitive wallet transaction reports. This oversight can lead to unauthorized disclosure of sensitive user data, including customer names, email...

PoC for CVE-2026-94245

WordPressWallet System For WooC...6.5MEDIUM
Improper Wallet Transfer Authorization in WooCommerce Plugin by Wor...

The Wallet System for WooCommerce plugin for WordPress prior to version 2.8.0 contains a security flaw that permits authenticated users to execute wallet transfers without the necessary permissions. Specifically, this vulnerability allows any authenticated individual, including those with minimal...

PoC for CVE-2026-86827

WordPressBackWPup5.3MEDIUM
Unauthenticated Backup Trigger Vulnerability in BackWPup WordPress ...

The BackWPup plugin for WordPress, prior to version 5.7.7, is susceptible to a vulnerability that permits unauthenticated attackers to trigger backup jobs on the system. By exploiting this flaw, attackers can initiate any scheduled backup task regardless of its original trigger conditions or timi...

PoC for CVE-2026-105197

WordPressAppointment Booking Pl...2.7LOW
Authorization Flaw in Appointment Booking Plugin for WordPress

The Appointment Booking Plugin for WordPress versions earlier than 5.6.5 contains an authorization flaw that permits an authenticated user with a staff role to delete any order, customer, or transaction record. This happens even if the records belong to different staff members or exceed their des...

PoC for CVE-2026-86826

WordPressBackWPup5.9MEDIUM
File Download Exposure in BackWPup Plugin for WordPress

The BackWPup plugin for WordPress, prior to version 5.7.7, suffers from improper access control, allowing unauthorized users to access the plugin's working directory. This flaw enables unauthenticated attackers to download backup archives containing sensitive information like database dumps, site...

PoC for CVE-2026-105260

WordPressDatabase Addon For WPf...4.3MEDIUM
CSRF Vulnerability in Database Addon for WPForms by WordPress

A security flaw has been identified in the Database Addon for WPForms plugin. The vulnerability arises from the lack of proper CSRF nonce verification and insufficient capability checks. As a result, attackers can potentially exploit this weakness to delete arbitrary stored form entries. This is ...

PoC for CVE-2026-105198

WordPressAppointment Booking Pl...5.3MEDIUM
Unauthorized Access Vulnerability in Appointment Booking Plugin for...

The Appointment Booking Plugin for WordPress prior to version 5.7.3 contains an improper authentication vulnerability. This flaw allows unauthenticated users to access sensitive customer information such as names, contact details, and order confirmation codes by manipulating the order-item identi...