Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2022-24903
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execu...
PoC for CVE-2026-33937
In Handlebars versions 4.0.0 through 4.7.8, a vulnerability exists where `Handlebars.compile()` can accept a pre-parsed AST object directly. This leads to the potential injection of arbitrary JavaScript into the generated code because the `value` field of a `NumberLiteral` AST node is emitted dir...
Discovered 57 minutes ago
PoC for CVE-2025-64446
A relative path traversal vulnerability exists in Fortinet FortiWeb products versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.4, 7.4.0 to 7.4.9, 7.2.0 to 7.2.11, and 7.0.0 to 7.0.11. This vulnerability allows an attacker to potentially execute unauthorized administrative commands on the system by sending sp...
Discovered 8 hours ago
PoC for CVE-2022-24355
This vulnerability exists in the TP-Link TL-WR940N router, allowing attackers in the network vicinity to execute arbitrary code due to insufficient validation of user-supplied data lengths when parsing file name extensions. This flaw can be exploited without authentication, enabling attackers to ...
Discovered 9 hours ago
PoC for CVE-2026-67207
Wolf CMS versions up to 0.8.3.1 contain an authorization bypass vulnerability in the BackupRestoreController component. This flaw allows authenticated non-administrative users to gain access to sensitive backup functionalities. The issue arises from a PHP operator precedence flaw in the expressio...
PoC for CVE-2026-67206
Wolf CMS versions up to 0.8.3.1 are susceptible to a remote code execution vulnerability due to inadequate file extension validation in the FileManagerController. This flaw enables authenticated attackers with the 'file_manager_mkfile' capability to craft arbitrary PHP files. By exploiting this v...
PoC for CVE-2020-7882
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
Discovered 11 hours ago
PoC for CVE-2024-28000
The CVE-2024-28000 vulnerability is found in the widely-used LiteSpeed Cache Plugin for WordPress websites, allowing unauthenticated users to gain administrator-level access and create new user accounts with the administrator role. This critical privilege escalation vulnerability has a high CVSS ...
Discovered 12 hours ago
PoC for CVE-2026-16723
A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...
Discovered 14 hours ago
PoC for CVE-2026-67349
The OpenCost application prior to version 1.121.0 exhibits significant security vulnerabilities that jeopardize sensitive information. It fails to authenticate requests to the GET /helmValues endpoint, which allows unauthorized access to base64-decoded HELM_VALUES, potentially revealing critical ...
PoC for CVE-2026-67348
The Julep software is exposed to an insecure direct object reference vulnerability within the get_execution_details endpoint. This flaw permits authenticated users to access execution data of other tenants by manipulating the execution_id parameter. Unauthorized retrieval of sensitive execution r...
PoC for CVE-2026-67347
Vendure, up to version 3.7.1, is susceptible to a cross-channel authorization bypass in the stock-location.service.ts and asset.service.ts update methods. This vulnerability allows administrators with channel-scoped permissions to manipulate data from other tenants by supplying global IDs of Stoc...
PoC for CVE-2026-67345
The MaxKey authentication framework up to version 4.1.12 suffers from an insufficient redirect URI validation vulnerability in the DefaultRedirectResolver.hostMatches() method. This flaw allows attackers to hijack OAuth 2.0 authorization codes by manipulating the redirect_uri. If an attacker cont...
Discovered 18 hours ago
PoC for CVE-2026-10702
A JIT (Just-In-Time) miscompilation vulnerability has been identified in the JavaScript Engine of Firefox. This flaw could potentially allow attackers to exploit the JIT component, leading to unexpected behavior or execution of arbitrary code. This issue has been addressed in Firefox version 151....
PoC for CVE-2026-59726
The Ruflo Agent Meta-Harness prior to version 3.16.3 had a critical security flaw wherein its default Docker deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without any authentication. This oversight potentially allowed an unauthenticated attacker to execute commands, g...
Discovered 22 hours ago
PoC for CVE-2026-66066
Active Storage, a framework component of Rails, has a vulnerability that affects versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1. This issue arises from the framework's failure to disable unsafe libvips operations when handling image uploads from untrusted users. An unauthenticated attacker can e...
PoC for CVE-2026-45746
The Termix Web Management Platform includes a vulnerability related to Broken Access Control, specifically in its File Manager feature. This issue stems from inadequate validation of the sessionId parameter, allowing attackers to exploit the backend's trust in a client-controlled identifier. As a...
PoC for CVE-2026-14310
The Tutor LMS WordPress plugin prior to version 4.0.0 features a significant flaw in its user access control mechanism. This vulnerability permits authenticated users, regardless of their role, to access Q&A threads not associated with courses they are enrolled in. Moreover, it enables such users...
PoC for CVE-2026-14239
The Tourmaster WordPress plugin prior to version 5.4.8 is vulnerable due to inadequate nonce checks when saving a custom-filter label from user input. This weakness allows unauthenticated attackers to exploit it and potentially inject malicious JavaScript. If a logged-in administrator is tricked ...
PoC for CVE-2026-14305
The WP Delicious plugin for WordPress prior to version 1.10.2 is susceptible to an authorization bypass vulnerability. This flaw allows unauthenticated users to exploit AJAX actions without proper authorization. As a result, users can modify certain post metadata, specifically the like counter an...
PoC for CVE-2026-13344
The Essential Addons for Elementor WordPress plugin prior to version 6.6.10 is susceptible to Stored Cross-Site Scripting due to inadequate validation of HTML tag names in the Pricing Table widget title. This vulnerability allows users with Contributor-level access and above to inject malicious J...
PoC for CVE-2026-13395
The Online Scheduling and Appointment Booking System plugin for WordPress prior to version 27.8 is vulnerable to SQL injection. This flaw arises from the plugin's failure to properly sanitize or cast user-supplied parameters in unauthenticated front-end booking requests. Attackers can exploit thi...
PoC for CVE-2026-13345
The Essential Addons for Elementor plugin for WordPress, prior to version 6.6.10, lacks necessary authorization checks in its product-comparison feature. This oversight allows unauthenticated users to access sensitive information, such as the titles, prices, and SKUs of draft, pending, and privat...
PoC for CVE-2026-13178
The Eventin WordPress plugin, prior to version 4.1.16, contains a vulnerability that allows unauthorized order creation. This occurs due to improper authorization checks, enabling attackers to modify order statuses without completing any payment process. As a result, unauthenticated users can cre...
PoC for CVE-2026-13330
The Animation Addons for Elementor plugin for WordPress allows users with the upload_files capability (Author and above) to upload SVG/SVGZ files without proper sanitization. This oversight enables the potential injection of malicious JavaScript into the application, resulting in stored cross-sit...
PoC for CVE-2026-13143
The WP Travel plugin for WordPress, prior to version 11.8.1, contains a vulnerability that allows unauthenticated attackers to manipulate payment statuses. This flaw stems from the plugin's failure to authenticate PayPal Instant Payment Notifications via the necessary post-back handshake. Consequ...
PoC for CVE-2026-13145
The WP Travel plugin for WordPress, prior to version 11.8.1, is susceptible to an information disclosure vulnerability. The flaw occurs because the plugin fails to verify the ownership of booking requests made through the customer account dashboard. Consequently, this allows any authenticated use...
PoC for CVE-2026-11867
The Frontend Admin plugin by DynamiApps, prior to version 3.29.7, contains a flaw that allows authenticated users with minimal privileges, like Subscribers, to perform unrestricted operations on taxonomy terms. This vulnerability permits these users to create, modify, and delete arbitrary taxonom...
PoC for CVE-2026-11870
The WP Ghost (Hide My WP Ghost) WordPress plugin prior to version 7.0.05 fails to properly verify that the client IP address originates from a trusted proxy. This oversight allows attackers to manipulate HTTP headers to spoof their IP addresses. As a result, unauthenticated attackers can circumve...
PoC for CVE-2026-11881
The Fluent Forms WordPress plugin prior to version 6.2.6 contains a vulnerability that fails to properly sanitize and escape a specific form field configuration setting. When a form is rendered, this oversight enables users with low-level roles, such as Contributor with specific permissions, to p...
PoC for CVE-2026-12500
The WP Travel Engine plugin for WordPress prior to version 6.8.2 is vulnerable due to insufficient access checks on AJAX actions. This flaw allows unauthenticated users to execute certain actions, specifically overwriting critical site-wide options, as the public nonce required for these actions ...
PoC for CVE-2026-15257
The RegistrationMagic WordPress plugin prior to version 6.0.9.4 allows unauthorized users to exploit the absence of proper authorization and nonce checks on front-end editing actions. This vulnerability enables attackers to overwrite the form submissions and associated profile fields of non-admin...
PoC for CVE-2026-15255
The RegistrationMagic WordPress plugin prior to version 6.0.9.4 contains a security flaw that permits unauthenticated attackers to access sensitive user data. The issue arises from inadequate validation of one-time passwords stored in cookies, which enables unauthorized individuals to retrieve fr...
PoC for CVE-2026-15382
The Ultimate Addons for WPBakery Page Builder plugin allows for unauthorized deletion of a website's custom-uploaded icon font packs. Prior to version 3.21.4, the plugin fails to implement necessary capability and nonce checks, enabling unauthenticated attackers to issue a single request that can...
PoC for CVE-2026-11782
The Points and Rewards for WooCommerce plugin does not implement necessary authorization checks on wallet and points update actions, which are exposed to unauthenticated users. This vulnerability allows attackers to modify or corrupt the wallet balance and loyalty points of any user without verif...
PoC for CVE-2026-15252
The Search Atlas SEO plugin for WordPress prior to version 2.6.12 is susceptible to an authentication bypass flaw due to insufficient validation in an AJAX handler. This vulnerability allows authenticated users, such as Subscribers, to interact with the site's Google Indexing API. Consequently, t...
PoC for CVE-2026-14207
The LifterLMS plugin for WordPress prior to version 10.0.10 is susceptible to a cross-site scripting vulnerability. This flaw arises from the plugin's failure to sanitize event-handler attributes within a course pricing field. As a result, users with editing privileges can inject malicious JavaSc...
PoC for CVE-2026-14231
The LifterLMS WordPress plugin prior to version 10.0.10 has a vulnerability that fails to adequately verify user capabilities in one of its AJAX handlers. This oversight allows any authenticated user, even those with minimal subscriber-level permissions, to access sensitive titles of internal pos...
PoC for CVE-2026-15250
The Appointment Booking Plugin for WordPress has a significant security flaw that permits unauthenticated users to manipulate certain booking fields through the public booking interface. This vulnerability enables unauthorized individuals to assign privileged values, such as the approval status, ...
PoC for CVE-2026-14318
The GiveWP plugin for WordPress, specifically versions prior to 4.16.3, is vulnerable to a Cross-Site Scripting (XSS) issue. This vulnerability arises from a lack of proper escaping for donation-form template settings before they are displayed in HTML attributes. As a result, users with the 'Give...
PoC for CVE-2026-15240
The Customer Switching plugin for WordPress prior to version 2.1.3 has a security flaw that allows a user with lower privileges to exploit an active session. When an operator switches to another user account, the session is not securely bound, enabling the lower-privileged user to perform actions...
PoC for CVE-2026-15054
The Bit Form plugin for WordPress has a security flaw that permits unauthenticated users to submit entries through public form submission handlers, even for forms that have been deactivated or unpublished. This oversight allows users to trigger configured workflows, such as email notifications, p...
PoC for CVE-2026-15153
The WP Hotel Booking plugin for WordPress prior to version 2.3.2 is susceptible to SQL injection due to improper sanitization and escaping of search parameters in administrative listings. Attackers with appropriate booking-management roles could exploit this vulnerability to execute unauthorized ...
PoC for CVE-2026-15235
The MotoPress Hotel Booking WordPress plugin prior to version 6.0.4 lacks sufficient capability checks in its AJAX functionalities. This oversight allows authenticated users with minimal privileges, such as Subscribers, to access sensitive customer information. Specifically, personal data includi...
PoC for CVE-2026-12687
The ProfileGrid WordPress plugin prior to version 5.9.9.8 contains a security flaw that allows anonymous users to bypass registration restrictions. As a result, these users can register into privileged groups without authentication, potentially being assigned roles with elevated permissions, incl...
PoC for CVE-2026-14226
The Easy Appointments plugin for WordPress up to version 3.12.26 contains an access control vulnerability that permits users with minimal permissions to access sensitive appointment data through certain REST API endpoints. Specifically, the plugin only checks for a basic user capability that any ...
PoC for CVE-2026-14923
The Sync Post With Other Site plugin for WordPress prior to version 1.9.3 contains a serious flaw in its authorization mechanism on a REST route that manages post creation and updates. Due to an operator-precedence error, it fails to enforce proper page-editing capabilities, allowing authenticate...
PoC for CVE-2026-14592
The WP Real IP-based Access Control plugin prior to version 1.3.1 is susceptible to an access control vulnerability, allowing unauthenticated users to insert arbitrary JavaScript into a specific option value. This JavaScript becomes executable when an administrator accesses the plugin's settings ...
PoC for CVE-2026-14602
The Remote API WordPress plugin versions up to 0.2 contains a serious security flaw in its handling of user-supplied input. This vulnerability allows unauthenticated attackers to inject malicious PHP objects through deserialization, which could lead to remote code execution if a suitable exploit ...
PoC for CVE-2026-14223
The Easy Appointments WordPress plugin prior to version 3.12.26 contains a significant oversight in its handling of customer data. It fails to properly verify ownership or user capabilities when retrieving stored customer details. This flaw allows users with subscriber-level permissions to access...