Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2021-43718

EPSONEPSON EH-TW53505.3MEDIUM
Authentication Bypass Vulnerability in EPSON EH-TW5350

An Authentication Bypass vulnerability exists in EPSON EH-TW5350, enabling remote access that may allow unauthorized users to execute commands or compromise the device. This could lead to a Denial of Service, affecting the functionality of the device when exploited with a specific sequence of HTT...

PoC for CVE-2021-43717

EpsoniProjection9.8CRITICAL
Authentication Bypass Vulnerability in Epson iProjection App

A vulnerability exists within the Epson iProjection application for the EH-TW5350 projector, allowing unauthorized access through hard-coded authentication credentials. This flaw enables potential malicious users to control the projector remotely without proper authorization, posing a security ri...

PoC for CVE-2021-43716

EPSONEasyMP Network Updater9.8CRITICAL
Verification Bypass Vulnerability in EPSON EasyMP Network Updater

A verification bypass vulnerability has been identified in the EPSON EasyMP Network Updater, specifically in the version 1.20 of the product. This issue allows malicious actors to exploit weaknesses in the firmware update mechanism that utilizes encrypted firmware via USB. Attackers could potenti...

PoC for CVE-2026-100633

Siyuan-noteSiyuan8.5HIGH
Sensitive-Path Guard Bypass in SiYuan Personal Knowledge Management...

SiYuan, a self-hosted personal knowledge management system, has a vulnerability in versions 3.8.0 through 3.8.3 that affects the sensitive-path guard due to an incomplete fix. The MCP file tool allows an authenticated administrator to bypass the protected-workspace-file denylist during recursive ...

PoC for CVE-2026-101894

XhmikosrDecompress9.1CRITICAL
Node.js Decompress Package Vulnerability Allowing External File Access

The decompress package for Node.js enables extraction of archives but contains a vulnerability in its default decompress(input, output) API. It fails to adequately check for symlink chains, allowing an attacker to craft malicious archives with chained symlink entries. This results in the potentia...

Discovered 5 hours ago

PoC for CVE-2020-13664

DrupalDrupal Core8.8HIGH
Arbitrary PHP Code Execution Vulnerability in Drupal Core by Drupal

This vulnerability in Drupal Core allows for arbitrary PHP code execution under specific conditions. An attacker may deceive an administrator into visiting a malicious page, resulting in the creation of a specially named directory on the server's filesystem. This directory could potentially be ex...

Discovered 7 hours ago

PoC for CVE-2026-87902

WordPressWordPress🟣 EPSS 22%8.1HIGH
Local File Inclusion in WordPress Leading to Remote Code Execution

An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...

PoC for CVE-2026-38526

WebkulKrayin CRM9.9CRITICAL
Arbitrary File Upload Vulnerability in Webkul Krayin CRM

An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...

Discovered 8 hours ago

PoC for CVE-2026-102293

RealjerrytangTacomall6.9MEDIUM
Improper Authorization in realjerrytang tacomall Backend

A vulnerability exists in the realjerrytang tacomall application, specifically within the OrgStaffServiceImpl.add function in ApiMaApplication.java. This flaw stems from inadequate validation of the isAdmin/jobId parameters, allowing attackers to manipulate them and gain unauthorized access. The ...

PoC for CVE-2026-102292

Coolbeans1212Mateishomepage-website5.3MEDIUM
Cross-Site Scripting Vulnerability in coolbeans1212 MateisHomePage-...

A vulnerability exists in the coolbeans1212 MateisHomePage-Website that allows for cross-site scripting (XSS) through inadequate handling of input in the users.php file. Malicious actors can exploit this flaw remotely, allowing them to execute arbitrary scripts in the context of a victim's browse...

PoC for CVE-2026-102290

CodecanyonRocket Lms5.1MEDIUM
Cross-Site Scripting Vulnerability in CodeCanyon Rocket LMS Student...

A cross-site scripting vulnerability has been identified in CodeCanyon's Rocket LMS, specifically affecting the Student Profile Image Upload feature in versions up to 2.2. This flaw allows attackers to execute remote scripts through manipulation of the upload function, potentially compromising us...

PoC for CVE-2026-5053

NomachineNomachine7.1HIGH
Arbitrary File Deletion Vulnerability in NoMachine Software

The NoMachine software contains a vulnerability that allows local attackers to delete arbitrary files by exploiting improper validation of environment variables. An attacker needs to execute low-privileged code on the target system to exploit this weakness. By supplying a malicious path, the atta...

PoC for CVE-2026-5054

NomachineNomachine7.8HIGH
Local Privilege Escalation Vulnerability in NoMachine by NoMachine

This vulnerability in NoMachine involves improper validation of user-supplied file paths during command line operations. Local attackers can exploit this flaw by executing low-privileged code, leading to unauthorized privilege escalation and the potential execution of arbitrary code within a root...

Discovered 9 hours ago

PoC for CVE-2026-102249

Unknown VendorRebuild6.9MEDIUM
Authorization Flaw in REBUILD Product by Unknown Vendor

A significant security flaw has been identified in the REBUILD application, specifically in the `/commons/file-editor-save` functionality. This vulnerability arises from a missing authorization check in the processing of the `url/fileKey` argument, which may allow an unauthorized user to execute ...

PoC for CVE-2026-102248

Unknown VendorRebuild6.9MEDIUM
Improper Authentication Vulnerability in Rebuild by Unknown Vendor

A vulnerability has been found in Rebuild versions up to 4.4.7 and 4.5.0-beta5 that allows for improper authentication through the login endpoint located at /user/login. This flaw enables remote attackers to exploit the authentication process, potentially leading to unauthorized access. The explo...

Discovered 10 hours ago

PoC for CVE-2026-102247

FastAdminFastadmin8.5HIGH
Excessive Privilege Vulnerability in FastAdmin Database Management ...

A vulnerability has been identified in FastAdmin versions 1.6.1.20250430 and 1.6.5.20260602, specifically within an unspecified function of the application/database.php file in the Database Management component. This flaw allows for potential execution with unnecessary privileges, enabling attack...

PoC for CVE-2026-102245

ModsetterSurfsense6.9MEDIUM
Weakness in MODSetter SurfSense Component Circleback Endpoint

A vulnerability has been identified in the MODSetter SurfSense product, specifically affecting version 2.0.3 or earlier. This flaw resides in an unspecified function within the circleback Endpoint, present in the surfsense_backend/app/routes/circleback_webhook_route.py file. A remote attacker can...

PoC for CVE-2026-102244

ModsetterSurfsense5.3MEDIUM
Server-Side Request Forgery Vulnerability in MODSetter SurfSense Do...

A security flaw has been identified in the Document Export Feature of MODSetter SurfSense, specifically within the function located at surfsense_backend/app/routes/editor_routes.py. This vulnerability allows attackers to craft a manipulation that can lead to server-side request forgery (SSRF). Th...

PoC for CVE-2026-102243

ModsetterSurfsense5.3MEDIUM
Command Injection Vulnerability in MODSetter SurfSense MCP Connecto...

A command injection vulnerability exists in the MCP Connector Integration of MODSetter SurfSense versions up to 2.0.3. This issue allows attackers to manipulate the handling of requests sent to the '/api/search-source/connectors/mcp/test' endpoint. With this exploit, it becomes possible for a rem...

Discovered 11 hours ago

PoC for CVE-2026-102241

NetcoreNap9305.1MEDIUM
Remote Code Execution Vulnerability in Netcore NAP930 Backup/Restor...

A critical security issue has been identified within the Netcore NAP930 product, specifically in the Backup/Restore component. The vulnerability allows for the exploitation of an unknown portion of code in the '/lib/functions/backup_common.sh' file. The flaw arises due to improper handling of the...

PoC for CVE-2026-102240

NetcoreNap93010CRITICAL
OS Command Injection Vulnerability in Netcore NAP930 Network Tools CGI

An OS command injection vulnerability was identified in the Netcore NAP930 router's Network Tools CGI component. This flaw occurs within the eval function of the /www/cgi-bin/network_tools file, where manipulation of the input parameter 'sid' enables attackers to execute arbitrary operating syste...

PoC for CVE-2026-101878

BitwardenBitwarden Server7.7HIGH
Authentication Bypass Vulnerability in Bitwarden Server Software

Bitwarden Server versions below 2026.5.0 contain a vulnerability involving the handling of the @ExternalId parameter in the User_ReadBySsoUserOrganizationIdExternalId stored procedure. The procedure improperly declares this parameter as NVARCHAR(50), conflicting with the NVARCHAR(300) definition ...

PoC for CVE-2026-101860

RaspapRaspap-webgui8.7HIGH
Improper Privilege Management in RaspAP WebGUI by RaspAP

A notable security concern exists within the RaspAP WebGUI, particularly through the PluginInstaller::addSudoers function located in src/RaspAP/Plugins/PluginInstaller.php. This vulnerability allows for improper privilege management, which can be exploited remotely. The exploit has been publicly ...

Discovered 12 hours ago

PoC for CVE-2026-58225

Elixir-ectoPostgrex2.1LOW
SQL Injection Vulnerability in Postgrex Affected by Elixir Ecto

An SQL Injection vulnerability exists in Postgrex through Elixir's Ecto, allowing attackers to manipulate LISTEN channel names. This exploitation can lead to a denial of service, as malformed channel names cause the notification connection to break. While it does not permit arbitrary SQL executio...

PoC for CVE-2026-101354

FastFac1203r9.4CRITICAL
Stack-Based Buffer Overflow in FAST FAC1203R by FAST

A security flaw has been identified in the FAST FAC1203R product, specifically within the _tWlanTask function of the MmtAtePrase Parser. This vulnerability allows for a stack-based buffer overflow, which could potentially be exploited by attackers with access to the local network. The exploit cod...

Discovered 13 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2020-28707

WordpressStockdio Historical Chart6.1MEDIUM
Cross Site Scripting Vulnerability in Stockdio Historical Chart Plu...

The Stockdio Historical Chart plugin prior to version 2.8.1 for WordPress is susceptible to Cross Site Scripting (XSS) due to inadequate validation of the origin of postMessage() events. This vulnerability occurs in the stockdio_chart_historical-wp.js file, where the stockdio_eventer function lis...

PoC for CVE-2026-101279

Trusted Domain Pr...Opendmarc6.9MEDIUM
Integer Overflow Vulnerability in Trusted Domain Project OpenDMARC

A security vulnerability has been identified in the Trusted Domain Project OpenDMARC, specifically within the DMARC Parser component. This vulnerability affects the function located in libopendmarc/opendmarc_policy.c, where manipulation of the argument 'pct' can lead to an integer overflow. This ...

PoC for CVE-2026-38526

WebkulKrayin CRM9.9CRITICAL
Arbitrary File Upload Vulnerability in Webkul Krayin CRM

An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-101277

Trusted Domain Pr...Opendkim6.9MEDIUM
Security Flaw in Trusted Domain Project OpenDKIM Tag Tokenizer Affe...

A security vulnerability has been identified in the Trusted Domain Project OpenDKIM, specifically in the Tag Tokenizer component. The flaw resides within the dkim_process_set function in the dkim.c file, allowing attackers to manipulate the system into utilizing less trusted sources. This vulnera...

PoC for CVE-2026-102367

Gz-yamiMall4j5.3MEDIUM
Insufficient Session Expiration in mall4j by Yami Technologies

The mall4j product by Yami Technologies has a vulnerability in its token refresh mechanism that allows disabled user accounts to renew their sessions indefinitely. This occurs because the system fails to validate the enabled flag during the session renewal process at the POST /token/refresh endpo...

PoC for CVE-2026-102366

Gz-yamiMall4j2.1LOW
Unrestricted File Upload in mall4j Affects HTML and SVG Files

A vulnerability in mall4j prior to version 4.0 allows authenticated users to perform unrestricted file uploads through the FileController endpoints. This weakness occurs due to a lack of authorization checks and insufficient file type validation. Consequently, attackers can upload malicious HTML ...

PoC for CVE-2026-102365

Gz-yamiMall4j7.1HIGH
Authorization Bypass in Mall4j User Address Controller

The Mall4j application, specifically versions through 4.0, suffers from a lack of proper authorization checks in the UserAddrController. This oversight allows authenticated attackers to access sensitive customer address data via the /user/addr/page and /user/addr/info endpoints. As a result, atta...

PoC for CVE-2026-102364

Gz-yamiMall4j5.3MEDIUM
Improper Authentication in Mall4j Affects Storefront and Admin Users

The Mall4j product up to version 4.0 contains a vulnerability where the sysType field in sa-token sessions is not properly validated. This oversight permits unauthorized storefront customers to authenticate as back-office users by reusing their existing session tokens. As a result, attackers can ...

PoC for CVE-2026-102364

Gz-yamiMall4j5.3MEDIUM
Improper Authentication in Mall4j Affects Storefront and Admin Users

The Mall4j product up to version 4.0 contains a vulnerability where the sysType field in sa-token sessions is not properly validated. This oversight permits unauthorized storefront customers to authenticate as back-office users by reusing their existing session tokens. As a result, attackers can ...

PoC for CVE-2026-102363

Gz-yamiMall4j6.3MEDIUM
Unauthenticated Shipment Tracking Vulnerability in Mall4j by Yami

A missing authentication vulnerability exists in Mall4j versions up to 4.0 within the DeliveryController's checkDelivery endpoint. This flaw enables unauthorized attackers to retrieve sensitive shipment tracking information by simply providing an order number parameter. As a result, attackers can...

PoC for CVE-2026-102361

Gz-yamiMall4j9.3CRITICAL
Missing Authentication Vulnerability in mall4j Affected by Unauthor...

The mall4j software, up to version 4.0, contains a security flaw where the PUT /user/updatePwd endpoint lacks proper authentication mechanisms. This allows malicious actors to reset passwords of any storefront account simply by providing the target username in the request body, bypassing any nece...

PoC for CVE-2026-102362

Gz-yamiMall4j6.9MEDIUM
Authentication Bypass in Product Review Deletion for Mall4j by GZ-Yami

Mall4j, a product by GZ-Yami, has a vulnerability that allows unauthenticated users to bypass authorization checks when attempting to delete product reviews through the DELETE /prodComm endpoint. Attackers can exploit this flaw by providing the necessary prodCommId, enabling them to remove arbitr...

Discovered 14 hours ago

PoC for CVE-2026-101264

ZiroomZhome A01019.4CRITICAL
Command Injection Vulnerability in Ziroom ZHOME A0101 Product

A command injection vulnerability has been identified in the Ziroom ZHOME A0101 version 1.0.1.0. This flaw exists in the /api/ZRnetwork/set_passwd function, where improper handling of the 'password1' argument allows an attacker to execute arbitrary commands remotely. Despite attempts to inform th...

PoC for CVE-2026-101263

ZiroomZhome A01019.4CRITICAL
Command Injection Vulnerability in Ziroom ZHOME A0101 by Ziroom

A command injection vulnerability exists in the Ziroom ZHOME A0101 version 1.0.1.0, affecting the processing of the /api/ZRQos/set_online_client file. The flaw arises from improper handling of the 'mac' argument, allowing attackers to execute arbitrary commands remotely. An exploit has been publi...

PoC for CVE-2026-101262

ZiroomZhome A01019.4CRITICAL
Command Injection Vulnerability in Ziroom ZHOME A0101 by Ziroom

A command injection vulnerability has been identified in the Ziroom ZHOME A0101 version 1.0.1.0, specifically within the /api/ZRQos/set_online_client endpoint. This security flaw allows attackers to manipulate the 'ip' argument, which can lead to arbitrary command execution on the server. Since t...

PoC for CVE-2026-101261

ZiroomZhome A01019.4CRITICAL
Command Injection Vulnerability in Ziroom ZHOME A0101 by Ziroom

A command injection vulnerability exists in the Ziroom ZHOME A0101 version 1.0.1.0, specifically within the /api/ZRnetwork/firstSetup_wifi file. This flaw allows remote attackers to execute arbitrary commands by manipulating the 'login_pwd' argument during the setup process. The exploitation can ...

PoC for CVE-2026-18110

Concrete CmsConcrete Cms8.7HIGH
Authorization Bypass in Concrete CMS Denies User Security

Concrete CMS versions 9.0.0 through 9.5.2 have a significant vulnerability that allows attackers to bypass authorization checks in the user selector autocomplete endpoint. This issue arises because the endpoint only validates a CSRF-style access token tied to the display options, without authenti...

Discovered 15 hours ago

PoC for CVE-2026-101260

ZiroomZhome A01019.4CRITICAL
Command Injection Vulnerability in Ziroom ZHOME A0101

A command injection vulnerability has been identified in the Ziroom ZHOME A0101 firmware version 1.0.1.0, specifically within the /api/ZRnetwork/firstLogin endpoint. An attacker can manipulate the input argument of firstLogin to execute arbitrary commands on the server. This issue allows remote e...

PoC for CVE-2026-34990

OpenprintingCups5MEDIUM
Local Privilege Escalation in OpenPrinting CUPS by Unprivileged Users

OpenPrinting's CUPS, an open source printing system for Linux and other Unix-like operating systems, is susceptible to a local privilege escalation vulnerability. An unprivileged user can exploit this flaw to trick the cupsd service into authenticating with an attacker-controlled IPP service on l...

Discovered 16 hours ago

PoC for CVE-2026-101188

NetcorePower136.9MEDIUM
Weak Password Recovery Flaw in Netcore POWER13 from Netcore

A vulnerability exists in Netcore POWER13 versions, specifically in the routerd.passwd_set function located in the /ubus file. This flaw allows for weak password recovery mechanisms that can be exploited remotely, potentially enabling unauthorized access to systems using this product. Although th...

PoC for CVE-2026-101187

ZiroomZhome A01019.4CRITICAL
Command Injection Vulnerability in Ziroom ZHOME A0101 USB Device Ma...

A command injection vulnerability exists in the USB Device Management API of the Ziroom ZHOME A0101 1.0.1.0 product. Specifically, the flaw is located within the 'pop_usb_device' function in the 'usr/lib/lua/luci/controller/api/zrUsb.lua' file. An adversary could exploit this weakness through cra...

PoC for CVE-2026-101146

EleveoQuality Management5.3MEDIUM
Information Disclosure Vulnerability in Eleveo Quality Management b...

A security flaw has been identified in Eleveo Quality Management version 9.7.0, specifically in the UtilsService.createAndSaveAudit function located in the GWT RPC Handler. This vulnerability enables unauthorized parties to disclose sensitive information through remote manipulation of affected co...

Discovered 17 hours ago

PoC for CVE-2026-101145

EleveoCall Recording Software5.3MEDIUM
LDAP Injection Vulnerability in Eleveo Call Recording Software 9.7.0

A vulnerability exists in Eleveo Call Recording Software version 9.7.0 where improper handling of user input in the user management component allows for LDAP injection. This flaw can be exploited remotely, enabling attackers to manipulate LDAP queries by crafting specific usernames. The exploit p...