Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 7 hours ago
PoC for CVE-2026-78435
A path traversal vulnerability exists in the Faveo Helpdesk, affecting versions up to 2.0.3, specifically in the unlink function of the Logo Handler component. By manipulating the argument data1, attackers can exploit this vulnerability remotely, which poses a significant security risk. This issu...
PoC for CVE-2026-78434
A missing authentication vulnerability exists in the Faveo Helpdesk software up to version 2.0.3. Specifically, the flaw is related to the FormController::post_ticket_reply function in the app/Http/Controllers/Client/helpdesk/FormController.php file. This vulnerability allows attackers to initiat...
Discovered 8 hours ago
PoC for CVE-2026-72714
Rocq Prover contains a vulnerability where the universe graph fails to restore the checking flag for universe validation after a module that disables this check is closed. Normally, this local setting should only persist for the lifespan of the module, reverting to a global state upon closure. Ho...
PoC for CVE-2026-72711
The Lean 4 kernel contains a flaw where it fails to properly check that the body of an opaque declaration is closed. Specifically, the method environment::add_opaque omits the crucial check found in the definition and theorem paths, allowing for a scenario where a value may contain free variables...
PoC for CVE-2026-72705
The guard checker in Rocq Prover is susceptible to a type safety violation where recursive calls using fixpoint arguments are inadequately tracked. This could lead to scenarios where a type becomes definitionally equal to its negation. Consequently, self-application can produce false results with...
PoC for CVE-2026-72704
The Rocq Prover's guard checker contains a significant flaw whereby alterations to a recursive type parameter are not validated post-transport. This oversight allows a fixpoint to apply rewrites based on type equality, which may lead to the acceptance of an altered recursive tree that has not und...
PoC for CVE-2026-72703
The guard checker in Rocq Prover erroneously classifies a nested mutual fixpoint parameter as uniform without performing a thorough analysis of inter-body calls. The function find_uniform_parameters only evaluates self-recursive calls, leading to the risk of accepting a non-terminating definition...
PoC for CVE-2020-37268
The Print Assumptions feature in Rocq Prover is vulnerable to a flaw arising from the failure to report the disabling of universe checking during specific operations. When a definition is created under these conditions, it can be inlined through parameters without retaining any record of the unsa...
Discovered 9 hours ago
PoC for CVE-2026-78430
A vulnerability exists in Sworddut's MCP-FFmpeg-Helper affecting versions 0.1.0, 0.1.1, and 0.2.1 that allows for OS command injection. This is due to improper handling of input arguments in the 'handleToolCall' function specifically in the 'src/tools/handlers.ts' file. Exploitation requires loca...
PoC for CVE-2026-71511
Dolibarr ERP & CRM prior to version 24.0.0 suffers from a sensitive data exposure vulnerability within the Members REST API. This allows authenticated attackers with member-read permissions to access bcrypt password verifiers by querying specific member endpoints. Unfiltered data output from both...
PoC for CVE-2026-71510
Dolibarr versions prior to 24.0.0 contain a SQL injection vulnerability in the users REST API. This flaw allows authenticated users with read access to manipulate unfiltered parameters within SQL WHERE clauses, which can lead to unauthorized data extraction. Attackers can exploit this issue to pe...
PoC for CVE-2026-71509
Dolibarr before version 24.0.0 is susceptible to an improper authorization vulnerability within its expense report REST API update endpoint. This flaw permits authenticated users with rights to create expenses to override the approval workflow. By manipulating certain fields through the API, atta...
PoC for CVE-2026-71508
Dolibarr prior to version 24.0.0 features an improper authorization vulnerability within its user REST API update endpoint. This flaw allows users who possess write permissions to modify sensitive payroll information. By leveraging an incomplete credential denylist that fails to adequately secure...
PoC for CVE-2026-71507
Dolibarr ERP & CRM prior to version 24.0.0 is susceptible to a broken object-level authorization vulnerability within its REST API. This flaw allows authenticated attackers who possess permissions for third-party creation to illicitly create, modify, or remove bank account information for any com...
PoC for CVE-2026-71506
Dolibarr prior to version 24.0.0 is susceptible to an improper authorization vulnerability within its payments REST API delete endpoint. This flaw enables authenticated users possessing rights to delete invoices to exploit a misconfigured permission check. As a result, attackers can effectively b...
PoC for CVE-2026-71505
Dolibarr versions prior to 24.0.0 are susceptible to a broken object-level authorization flaw in their REST API. This vulnerability permits authenticated attackers, who possess third-party creation rights, to manipulate the WebPortal passwords of enterprises by circumventing access checks that ar...
PoC for CVE-2026-71504
Dolibarr ERP & CRM prior to version 24.0.0 is susceptible to an improper authorization flaw within the Members REST API. This vulnerability enables attackers who possess member-creation rights to reset the passwords of any user account, including sensitive accounts like that of the system adminis...
PoC for CVE-2026-71503
Dolibarr versions prior to 24.0.0 introduce a reflected cross-site scripting (XSS) vulnerability in the extra fields administration template. The issue arises because the 'type' request parameter is displayed on the webpage without proper JavaScript-context encoding and lacks a Content-Security-P...
Discovered 13 hours ago
PoC for CVE-2026-76071
The Netis NC63 firmware versions up to V3.0.0.3327 exhibits a vulnerability where unauthenticated remote attackers can exploit a stack-based buffer overflow by providing an oversized 'destHost' parameter in a specific CGI action. This vulnerability allows attackers to manipulate the stack state, ...
PoC for CVE-2026-76071
The Netis NC63 firmware versions up to V3.0.0.3327 exhibits a vulnerability where unauthenticated remote attackers can exploit a stack-based buffer overflow by providing an oversized 'destHost' parameter in a specific CGI action. This vulnerability allows attackers to manipulate the stack state, ...
PoC for CVE-2026-76070
The Netis NC63 firmware version V3.0.0.3327 contains a vulnerability due to a stack-based buffer overflow. This issue arises when an attacker submits an oversized Base64-encoded password to the login handler in /bin/netis.cgi. The vulnerability enables unauthenticated remote attackers to exploit ...
PoC for CVE-2026-76070
The Netis NC63 firmware version V3.0.0.3327 contains a vulnerability due to a stack-based buffer overflow. This issue arises when an attacker submits an oversized Base64-encoded password to the login handler in /bin/netis.cgi. The vulnerability enables unauthenticated remote attackers to exploit ...
Discovered 14 hours ago
PoC for CVE-2026-65053
The Horde IMP AppleDouble MIME viewer is vulnerable to stored cross-site scripting due to improper handling of attachment names. An attacker can craft a multipart/appledouble message with an unsafe name parameter that gets rendered without escaping in the HTML output. This allows scripts to execu...
Discovered 15 hours ago
PoC for CVE-2026-78250
A vulnerability exists in Bytebot AI's Bytebot 0.0.1, specifically within the Agent Execution Workflow component. This issue allows an attacker to execute a remote exploit that induces an infinite loop, causing server unresponsiveness. The vulnerability primarily affects versions that are no long...
PoC for CVE-2026-78248
A SQL injection vulnerability exists in the SourceCodester Simple Online Food Ordering System version 1.0 within the file /fos/admin/ajax.php when the 'Name' argument is manipulated. This flaw allows remote attackers to execute arbitrary SQL commands, potentially compromising the integrity and se...
Discovered 16 hours ago
PoC for CVE-2026-78247
A security vulnerability has been identified in the Simple Online Food Ordering System version 1.0 by SourceCodester. This flaw is located in the /fos/admin/ajax.php file, specifically in the confirm_order action. By manipulating the ID parameter, an attacker can execute SQL injection, potentiall...
Discovered 17 hours ago
PoC for CVE-2026-78246
A SQL injection vulnerability has been identified in version 1.0 of the itsourcecode Online Clinic Management System, specifically within the Admin Login feature's login.php file. By manipulating the Username parameter, an attacker could exploit this flaw to execute arbitrary SQL commands remotel...
PoC for CVE-2026-78245
A vulnerability exists in itsourcecode Online Pharmacy System 1.0 due to an improper handling of file uploads in the User Registration component. Specifically, the flaw lies within the 'move_uploaded_file' function in 'all_users/register.php', where manipulation of the 'photo' argument enables un...
Discovered 18 hours ago
PoC for CVE-2026-78244
A SQL injection vulnerability exists in the search.php file of the itsourcecode Real Estate Management System 1.0. This flaw allows attackers to manipulate parameters such as search/delivery_type/search_price/property_type, potentially leading to unauthorized access to the database. The exploit c...
Discovered 22 hours ago
PoC for CVE-2026-78202
A significant vulnerability has been discovered in the itsourcecode Payroll System 1.0, specifically within the save_settings function of the admin_class.php file. This weakness allows attackers to manipulate the 'img' argument, which results in an unrestricted upload capability. The vulnerabilit...
PoC for CVE-2026-78201
A SQL injection vulnerability exists in the login function of the admin_class.php file within itsourcecode Payroll System 1.0, allowing attackers to manipulate the Username argument. This manipulation can be executed remotely, posing significant risks to data integrity and system security. The vu...
Discovered 23 hours ago
PoC for CVE-2026-78200
A significant security flaw exists in the itsourcecode Library Management System version 1.0, specifically within an unidentified function in the editbooks.php file. This issue allows an attacker to manipulate the argument ID for SQL injection attacks, which can be executed remotely. Given the ex...
PoC for CVE-2026-78199
A significant SQL injection vulnerability has been identified in the SourceCodester Simple Online Food Ordering System, specifically affecting the view_prod.php file. This vulnerability occurs due to improper handling of the ID argument, allowing attackers to manipulate SQL queries and potentiall...
PoC for CVE-2026-78198
A security vulnerability has been identified in the Simple Online Food Ordering System developed by SourceCodester, specifically relating to the processing of the file /fos/admin/ajax.php with the action parameter set to add_to_cart. Unsanitized input for the 'pid' argument can lead to SQL inject...
PoC for CVE-2026-78197
A SQL injection vulnerability exists in the SourceCodester Simple Online Food Ordering System found in the /fos/admin/ajax.php file's save_user action. By manipulating the Username parameter, an attacker can execute arbitrary SQL queries on the database. This vulnerability can be exploited remote...
Discovered 1 day ago
PoC for CVE-2026-78187
A vulnerability has been identified in Piwigo 16.3.0 that affects the Public Authentication Page component, allowing attackers to exploit an unknown function via manipulation of the lang parameter. This can lead to cross site scripting (XSS), where malicious scripts can be executed in the user's ...
PoC for CVE-2026-78186
A vulnerability has been identified in Open5GS within the HSS component, specifically in the src/hss/hss-cx-path.c file. This issue allows for a manipulation of the User-Name argument, leading to a reachable assertion that can be exploited remotely. The vulnerability could allow attackers to exec...
PoC for CVE-2026-78185
An SQL injection vulnerability exists in the itsourcecode Sales and Inventory System version 1.0 due to improper handling of input in the /pages/cust_edit.php file. By manipulating the ID argument, an attacker can execute remote commands, potentially leading to unauthorized access to the database...
PoC for CVE-2026-78182
A security flaw has been discovered in the function PlanController.getImmediatePlans of the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System, specifically affecting versions up to 300R004C00B300. This vulnerability allows an attacker to manipulate the order and sort of ar...
PoC for CVE-2026-78181
A vulnerability exists in Ractive.js, affecting version 1.4.4 and earlier, specifically in the Keypath Handler's Ractive#set function. This weakness allows attackers to manipulate object prototype attributes, potentially leading to unauthorized modifications. The vulnerability can be exploited re...
PoC for CVE-2020-5504
In versions prior to 4.9.4 for phpMyAdmin 4 and 5.0.1 for phpMyAdmin 5, an SQL injection vulnerability exists on the user accounts page. This flaw allows an attacker with a valid MySQL account to inject malicious SQL statements by altering their username input when querying the user accounts. Suc...
PoC for CVE-2026-78177
A vulnerability exists in TanStack's devtools-vite, specifically in version 0.7.0, where the 'installPackage' function of the Development Devtools Event Bus component is susceptible to OS command injection. This occurs through improper handling of the 'packageName' argument, allowing an attacker ...
PoC for CVE-2026-78171
A vulnerability exists in the itsourcecode Sales and Inventory System 1.0, specifically within the file /pages/processlogin.php. This security issue allows for SQL injection through manipulation of the 'User' argument, enabling a remote attacker to exploit the system. As the exploit has been publ...
PoC for CVE-2026-78170
A significant vulnerability has been identified in the UTT HiPER 1200GW router, specifically within the strcpy function in the /goform/formConfigFastDirectionW file. The flaw allows an attacker to execute arbitrary manipulation of the 'ssid' argument, potentially leading to a buffer overflow cond...
PoC for CVE-2026-78169
A vulnerability exists in the UTT HiPER 1250GW that affects its HTTP Request Handler, specifically in the function 'strcpy' utilized within the file '/goform/aspRemoteApConfTempSend'. An attacker can exploit a manipulation of the 'Profile' argument leading to a stack-based buffer overflow. This v...
PoC for CVE-2026-78168
A vulnerability in the EFM ipTIME T24000M model compromises the function responsible for checking session URLs, leading to improper authentication. This flaw can be exploited remotely, posing a significant risk as it allows potential attackers to manipulate the authentication process without prop...
PoC for CVE-2026-78167
A significant weakness has been identified in the EFM ipTIME T16000M router due to a flaw in the session validation handler, specifically in the function httpcon_check_session_url. This vulnerability allows attackers to exploit the device remotely, leading to improper authentication and potential...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-15718
A security flaw in Mozilla Firefox allows for potential remote code execution exploits. Although the exploit code for this vulnerability is publicly available, there have been no confirmed instances of its exploitation in the wild. Users are advised to upgrade to Firefox version 152.0.6 or later ...
PoC for CVE-2026-78166
A security flaw exists in the Apache Kafka user interface provided by Provectus, specifically in the executeSmartFilterTest function within the Groovy Code Handler. This vulnerability permits an attacker to inject malicious code remotely, leading to potential unauthorized access and manipulation ...