Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 6 hours ago
PoC for CVE-2026-31431
A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...
Discovered 7 hours ago
PoC for CVE-2026-6471
A security vulnerability exists in PostgreSQL's logical decoding feature, where a non-superuser with REPLICATION privileges can exploit missing authorization. This flaw enables the execution of arbitrary code by allowing access to any file that is visible to the operating system account running t...
Discovered 8 hours ago
PoC for CVE-2026-19516
mcp-grafana allows an attacker to manipulate the X-Grafana-URL request header, which can direct outbound requests to unintended internal destinations, including sensitive network services and metadata endpoints. This oversight permits attackers to exploit the system for unauthorized data access, ...
Discovered 9 hours ago
PoC for CVE-2026-85704
A security flaw has been identified in the Ramon-Victor FreeGPT-WebUI, specifically in the Jailbreak Mode component. This vulnerability arises from a race condition in the getJailbreak function within the server/config.py file. Given its complexity, the attack can be executed remotely, posing sig...
PoC for CVE-2026-85703
A vulnerability exists in the Ramon-Victor FreeGPT-WebUI related to the Jailbreak Mode component. Specifically, a flaw in the getJailbreak function found in the server/backend.py file allows for remote manipulation, potentially leading to undesired allocation of system resources. This issue affec...
PoC for CVE-2026-85702
A security issue exists in the Ramon-Victor FreeGPT-WebUI that affects the Backend Conversation API, specifically the _conversation function in server/backend.py. This vulnerability allows an attacker to manipulate the model argument, which can result in missing authentication checks. The exploit...
PoC for CVE-2026-85046
A type confusion vulnerability has been identified in the V8 JavaScript engine of Google Chrome. Prior to version 152.0.7977.82, this flaw allows malicious attackers to execute arbitrary code within the browser's sandbox environment by crafting a specially designed HTML page. This vulnerability p...
PoC for CVE-2026-85701
A vulnerability exists in the ramon-victor freegpt-webui affecting the ChatCompletion.create function within the authentication check component found in g4f/__init__.py. This manipulation results in missing authentication, allowing remote attackers to exploit the flaw. The product operates under ...
Discovered 10 hours ago
PoC for CVE-2026-85643
A vulnerability exists in the Online Shopping System by Code-Projects, specifically in the admin/adduser.php file's mysqli_query function. By manipulating the 'mobile' argument, an attacker can execute SQL injection attacks, potentially allowing unauthorized access or data manipulation. The explo...
Discovered 11 hours ago
PoC for CVE-2026-85639
A security vulnerability has been identified within the jofpin trape 2.0 software that affects the telemetry endpoint feature. Specifically, the issue lies in the core/user.py file, where improper handling of the vId argument can lead to a race condition. This weakness allows an attacker to explo...
PoC for CVE-2026-85638
A vulnerability in jofpin Trape 2.0 has been discovered in the file core/user.py, allowing unauthorized access through argument manipulation of vId/id. This flaw enables remote exploitation, offering attackers potential access to sensitive functionalities without proper authorization. Despite bei...
PoC for CVE-2026-80119
An information disclosure vulnerability exists in DirectIo64.sys, affecting several PassMark products. Local attackers can exploit this vulnerability by supplying a caller-controlled file path to an exposed IOCTL mechanism. This allows the attacker to dump complete physical memory contents, inclu...
PoC for CVE-2026-85637
A security vulnerability has been identified in jofpin trape affecting versions 1.0.0 and 2.0. This flaw is located in the 'join_room' function of the 'core/sockets.py' component, which lacks sufficient authentication controls. As a consequence, an attacker may exploit this weakness to gain unaut...
Discovered 12 hours ago
PoC for CVE-2026-85636
A vulnerability has been identified in the jofpin trape version 1.0.0, affecting the functionality of the file core/stats.py within the Login Endpoint. This flaw allows unauthorized remote access due to missing authentication measures, posing significant security risks. The exploit is publicly av...
PoC for CVE-2026-82329
JFrog Artifactory has a significant authentication weakness that could permit an attacker with network access to gain administrative privileges without authentication, particularly when the product is left in its default configuration. This vulnerability can expose sensitive resources and operati...
PoC for CVE-2020-5741
A security flaw in Plex Media Server for Windows enables remote, authenticated attackers to exploit deserialization of untrusted data. This vulnerability allows the execution of arbitrary Python code, potentially compromising the system’s security. Users are urged to update their software to miti...
PoC for CVE-2026-85046
A type confusion vulnerability has been identified in the V8 JavaScript engine of Google Chrome. Prior to version 152.0.7977.82, this flaw allows malicious attackers to execute arbitrary code within the browser's sandbox environment by crafting a specially designed HTML page. This vulnerability p...
Discovered 14 hours ago
PoC for CVE-2026-44402
The Voltronic Power SNMP Web Pro 1.1 is susceptible to an unauthenticated remote code execution vulnerability through the upload.cgi firmware update interface. This flaw enables remote attackers to execute commands with root privileges simply by uploading a specially crafted tar archive, bypassin...
Discovered 15 hours ago
PoC for CVE-2026-6958
A local privilege escalation vulnerability exists in Acunetix 25.11.251107123 due to the missing hardcoded directory path for OpenSSL-related files in the Web Vulnerability Scanning Engine (wvsc.exe). Low-privileged local attackers can exploit this flaw by creating the missing directory and placi...
PoC for CVE-2026-6958
A local privilege escalation vulnerability exists in Acunetix 25.11.251107123 due to the missing hardcoded directory path for OpenSSL-related files in the Web Vulnerability Scanning Engine (wvsc.exe). Low-privileged local attackers can exploit this flaw by creating the missing directory and placi...
Discovered 16 hours ago
PoC for CVE-2025-8518
A code injection vulnerability has been identified in the Vvveb 1.0.5 Code Editor component, specifically within the Save function of the file admin/controller/editor/code.php. This flaw allows an attacker to execute arbitrary code remotely, significantly compromising the security of affected sys...
PoC for CVE-2026-85522
A security flaw has been identified in the Valkey component related to Slot Migration, specifically within the createSlotImportJob function of the src/cluster_migrateslots.c file. This vulnerability allows a malicious actor to manipulate the job_name argument, leading to out-of-bounds read condit...
PoC for CVE-2026-85517
A security flaw exists in the code-projects Vehicle Management System version 1.0, specifically within an unknown function related to the SQL Database Backup File Handler. This vulnerability allows for remote exploitation, leading to potential information disclosure. Malicious actors could manipu...
Discovered 17 hours ago
PoC for CVE-2026-85516
A vulnerability has been identified in the Vehicle Management System version 1.0 developed by Code-Projects. An SQL injection flaw exists in an unspecified function within the file /busprofile.php. This vulnerability allows attackers to manipulate the 'busid' argument, enabling them to execute un...
PoC for CVE-2020-1938
The Apache JServ Protocol (AJP) Connector in Apache Tomcat allowed for misconfigured connections that could be exploited by attackers. By default, the AJP Connector is enabled, listening on all configured IP addresses. This elevated trust can lead to unauthorized access and manipulation of files ...
PoC for CVE-2026-85514
A vulnerability has been identified in the StackStorm st2 API Key Handler, affecting versions up to 3.9.0. This issue arises from an unidentified flaw in the file st2api/st2api/controllers/v1/auth.py, specifically concerning the manipulation of the api_key_api.user argument, leading to improper p...
PoC for CVE-2026-85513
A vulnerability has been identified in StackStorm st2 versions up to 3.9.0, specifically in the NoOp RBAC backend. The flaw lies within the function handling user privileges, which can be exploited remotely due to improper management of user authorization. Attackers can manipulate user query para...
Discovered 19 hours ago
PoC for CVE-2026-85512
The SourceCodester Class and Exam Timetabling System 1.0 contains a security flaw located in the /admin/session.php file, where improper handling of the argument ID leads to missing authorization. This vulnerability allows an attacker to exploit the system remotely, potentially gaining unauthoriz...
Discovered 20 hours ago
PoC for CVE-2026-31787
A vulnerability exists in the Linux kernel's privcmd module that can lead to a double free situation due to improper management of virtual memory areas (VMAs). When a partial unmap operation is performed on a privcmd mapping, the kernel can erroneously split the VMA without the necessary controls...
PoC for CVE-2026-84045
The E-cab Taxi Booking Manager for WooCommerce plugin prior to version 2.0.5 lacks necessary validation for client-supplied trip distance and base price values. This oversight permits unauthenticated users to exploit the system, allowing them to set the order total to zero. Consequently, attacker...
PoC for CVE-2026-84044
The Restaurant Menu and Food Ordering WordPress plugin, prior to version 2.4.12, is vulnerable due to its failure to validate PayPal payment notifications. This oversight allows attackers to exploit the system by submitting fraudulent payment notifications, thereby marking their orders as paid wi...
PoC for CVE-2026-82923
The AI Website Builder plugin for WordPress (version 1.0.0) is susceptible to an authorization bypass vulnerability due to the absence of authentication checks on its REST API routes. This flaw permits unauthenticated attackers to carry out a range of malicious activities, such as installing and ...
PoC for CVE-2026-84043
The ePayco Payment Gateway for WooCommerce WordPress plugin prior to version 8.4.7 features a critical flaw in its payment confirmation request verification process. This vulnerability allows unauthenticated attackers to fraudulently mark orders as paid without a valid signature from the payment ...
Discovered 21 hours ago
PoC for CVE-2026-20212
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches permits unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability arises from the accessibility of TCP ports 43210 and 43211 within the default Layer 3 (L3) virtual routin...
Discovered 23 hours ago
PoC for CVE-2023-54391
Proxmox Virtual Environment versions from 7.0 to 8.0 are affected by an authentication bypass vulnerability in the libpve-access-control component. Attackers can exploit this vulnerability by sending an arbitrary tfa-challenge value to the API login endpoint, which allows them to bypass password ...
Discovered 1 day ago
PoC for CVE-2026-84066
The Directorist plugin for WordPress prior to version 8.9 has a security vulnerability that does not adequately verify whether a user requesting to modify a post's metadata is the actual owner of that post. This oversight allows users with subscriber-level permissions and above to modify image me...
PoC for CVE-2026-84146
The Xpro Addons for Elementor WordPress plugin prior to version 1.7.8 is susceptible to information exposure due to a lack of proper capability checks. This flaw permits unauthenticated users to access detailed information about WooCommerce products, including title, price, SKU, description, and ...
PoC for CVE-2026-82194
A vulnerability exists in the WPvivid Backup, Migration & Staging plugin for WordPress prior to version 0.9.134, allowing unauthorized file deletions. The plugin fails to properly validate user-supplied paths in its file deletion routine. As a result, an attacker, potentially an administrator, ca...
PoC for CVE-2026-80438
The Ninja Forms plugin for WordPress, up to version 3.15.2, has a significant access control issue that allows unauthorized users with specific capabilities to access sensitive data. This vulnerability enables such users to read the plugin's configuration settings and stored form submissions. Fur...
PoC for CVE-2026-82186
The WPLP Cookie Consent plugin for WordPress prior to version 4.4.2 has a flaw in the validation of the pagination parameter utilized in SQL queries. This vulnerability enables users with administrative access to execute malicious SQL queries, potentially compromising the database. Administrators...
PoC for CVE-2026-82193
The WPvivid Backup, Migration & Staging plugin for WordPress allows an attacker with administrative access to exploit insufficient validation of user-supplied file names. This leads to arbitrary file write capabilities, permitting administrators to save files to unintended locations on the server...
PoC for CVE-2026-81347
The Frontend Admin plugin for WordPress, developed by DynamiApps, has a vulnerability that allows unauthenticated attackers to exploit improper validation of user-controllable directory paths. This flaw permits the deletion of critical files such as index.php and .htaccess, which can severely dis...
PoC for CVE-2026-79632
The WPFunnels WordPress plugin before version 3.13.0 has a significant vulnerability that lacks proper authorization or nonce checks in an opt-in submission handler. This oversight enables unauthenticated users to exploit the system, potentially sending emails to any recipient with a chosen subje...
PoC for CVE-2026-79631
The WPFunnels plugin for WordPress prior to version 3.13.0 features an access control oversight, permitting unauthenticated users to download sensitive log files stored in a predictable location within the public uploads directory. This issue arises when logging is enabled, potentially exposing c...
PoC for CVE-2026-19224
The Hummingbird Performance plugin for WordPress is vulnerable due to improper restrictions on network-wide settings. This flaw enables an administrator of any individual site within a multisite network to execute arbitrary code, thereby compromising the entire network's security. This vulnerabil...
PoC for CVE-2026-74853
The Pods WordPress plugin versions earlier than 3.3.9.2 have a vulnerability that permits users with the author role and higher to access unauthorized files on the server. This occurs due to insufficient restrictions on display callback functions, enabling the retrieval of arbitrary files, includ...
PoC for CVE-2026-79630
The WPFunnels plugin for WordPress, prior to version 3.13.0, contains a security issue where it fails to properly verify that the product selected through a checkout order bump corresponds to the product intended for the discount. As a result, this flaw allows unauthenticated users to exploit the...
PoC for CVE-2026-16281
The Classified Listing WordPress plugin before version 6.1.1 contains a vulnerability due to insufficient authorization checks. This flaw permits authenticated users, including those with minimal privileges such as subscribers, to execute AI image-editing actions via AJAX. Consequently, these use...
PoC for CVE-2026-17517
The Content Views plugin for WordPress prior to version 4.5.1.2 is susceptible to an access control vulnerability. It fails to verify whether a user requesting a view has the appropriate permissions to access the posts it returns. As a result, unauthenticated attackers can gain access to the titl...
PoC for CVE-2025-15691
The WPFunnels plugin for WordPress prior to version 3.13.0 has a vulnerability that permits unauthenticated attackers to create user accounts without verifying if user registration is enabled. This flaw stems from the plugin's reliance on request-supplied values, which compromises site security b...