Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 58%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

Discovered 2 hours ago

PoC for CVE-2026-2218

D-linkDcs-933l5.3MEDIUM
Command Injection Vulnerability in D-Link DCS-933L Products

A command injection vulnerability exists in D-Link DCS-933L firmware versions up to 1.14.11 due to improper handling of parameters in the '/setSystemAdmin' functionality of the alphapd component. This flaw allows an attacker to remotely execute arbitrary commands by manipulating the AdminID argum...

PoC for CVE-2024-46987

Owen2345Camaleon-cms7.7HIGH
Camaleon CMS Vulnerability in Download Private File Method

Camaleon CMS, a robust content management system built on Ruby on Rails, has a path traversal vulnerability in the MediaController's download_private_file method. This flaw permits authenticated users to potentially download any file stored on the web server, depending on file permissions configu...

PoC for CVE-2026-2217

ItsourcecodeEvent Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Event Management System

A security flaw has been identified in version 1.0 of the itsourcecode Event Management System, specifically within the /admin/manage_user.php file. The vulnerability arises due to improper handling of user input in an unknown function, allowing an attacker to manipulate the ID argument. This res...

Discovered 3 hours ago

PoC for CVE-2026-2216

RachelosWerss We-mp-rss5.3MEDIUM
Path Traversal Vulnerability in WeRSS Plugin by rachelos

A vulnerability has been identified in the WeRSS we-mp-rss plugin versions up to 1.4.8. The flaw resides in the function download_export_file located in apis/tools.py, where improper validation of the filename argument can enable attackers to perform path traversal. This can lead to unauthorized ...

PoC for CVE-2026-2215

RachelosWerss We-mp-rss6.3MEDIUM
Weak Authentication in rachelos WeRSS we-mp-rss Product

A vulnerability has been identified in the rachelos WeRSS we-mp-rss component, particularly regarding the JWT Handler in the core/auth.py file. An attacker can manipulate the SECRET_KEY argument, leading to the use of a default cryptographic key. This scenario poses significant risks as it allows...

Discovered 4 hours ago

PoC for CVE-2026-2214

Code-projectsFor Plugin4.8MEDIUM
Cross Site Scripting Vulnerability in Code-Projects Plugin for Onli...

A vulnerability has been discovered in the Code-Projects Plugin specifically within the AdminAddAlbum.php file. This weakness allows attackers to manipulate the txtalbum argument, leading to potential cross site scripting attacks. Exploitation of this vulnerability could be executed remotely, pos...

PoC for CVE-2026-2213

Code-projectsOnline Music Site5.1MEDIUM
Unrestricted File Upload Vulnerability in Code-Projects Online Musi...

A security flaw has been identified in the Code-Projects Online Music Site 1.0, specifically within the functionality of the file located at /Administrator/PHP/AdminAddAlbum.php. The vulnerability allows for an unrestricted file upload due to improper handling of the argument 'txtimage'. This fla...

Discovered 5 hours ago

PoC for CVE-2026-2212

Code-projectsOnline Music Site6.9MEDIUM
SQL Injection Vulnerability in Online Music Site by Code-Projects

A vulnerability exists in the Online Music Site 1.0 developed by Code-Projects, specifically within the file /Administrator/PHP/AdminEditCategory.php. This flaw enables an SQL injection attack via manipulation of the argument ID, allowing remote attackers to execute unauthorized SQL commands. The...

PoC for CVE-2026-2211

Code-projectsOnline Music Site6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Online Music Site by C...

A security vulnerability exists in Code-Projects' Online Music Site version 1.0, specifically within the /Administrator/PHP/AdminDeleteCategory.php file. An attacker can manipulate the ID argument, resulting in a SQL injection. This vulnerability allows for unauthorized access and manipulation of...

Discovered 6 hours ago

PoC for CVE-2026-2210

D-linkDir-823x8.6HIGH
OS Command Injection Vulnerability in D-Link DIR-823X Product

A vulnerability exists in the D-Link DIR-823X router that allows remote attackers to exploit the 'set_filtering' function. By manipulating specific parameters, an attacker can execute arbitrary operating system commands, potentially leading to unauthorized access and control over the affected dev...

PoC for CVE-2026-2203

TendaAc88.7HIGH
Buffer Overflow Vulnerability in Tenda AC8 Embedded Httpd Service

A vulnerability exists in the Tenda AC8 router's Embedded Httpd Service, specifically within the /goform/fast_setting_wifi_set function. This flaw arises when manipulating the 'timeZone' argument, leading to a buffer overflow. Such a vulnerability can allow remote attackers to exploit the flaw, p...

PoC for CVE-2026-2202

TendaAc88.7HIGH
Buffer Overflow Vulnerability in Tenda AC8 Router

A buffer overflow vulnerability exists in the Tenda AC8 router, specifically in the 'fromSetWifiGusetBasic' function of the '/goform/WifiGuestSet' component. The flaw is triggered by improper handling of the 'shareSpeed' argument, which allows an attacker to execute arbitrary code remotely. The e...

Discovered 7 hours ago

PoC for CVE-2026-2201

ZerowddStudentmanager4.8MEDIUM
Cross-Site Scripting Vulnerability in ZeroWdd StudentManager

A security vulnerability has been identified in the ZeroWdd StudentManager, specifically within the addLeave function of LeaveController.java. This vulnerability allows for cross-site scripting (XSS) attacks through improper handling of the 'Reason for Leave' input, potentially enabling remote at...

PoC for CVE-2026-2200

HeyeweiJfinalcms4.8MEDIUM
Cross-Site Scripting Vulnerability in heyewei JFinalCMS 5.0.0

A weakness has been discovered in heyewei JFinalCMS 5.0.0, specifically in the API Endpoint's save function located at /admin/admin/save. This vulnerability allows attackers to perform cross-site scripting (XSS) attacks, which can be executed remotely. Publicly available exploit vectors have been...

PoC for CVE-2026-2199

Code-projectsOnline Reviewer System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Online Reviewer System...

A security flaw exists in the Code-Projects Online Reviewer System 1.0, specifically affecting the user deletion functionality located in the file /reviewer/system/system/admins/manage/users/user-delete.php. An unauthenticated attacker can exploit this flaw by manipulating the 'ID' parameter, lea...

PoC for CVE-2026-2198

Code-projectsOnline Reviewer System6.9MEDIUM
SQL Injection Vulnerability in the Online Reviewer System by Code-P...

A vulnerability exists in the Online Reviewer System 1.0 from Code-Projects, specifically within the file /system/system/admins/assessments/pretest/loaddata.php. This flaw, stemming from the manipulation of the 'difficulty_id' parameter, allows for SQL injection attacks. Attackers can exploit thi...

Discovered 8 hours ago

PoC for CVE-2026-2195

Code-projectsOnline Reviewer System6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Online Reviewer System...

A security flaw has been identified in the Online Reviewer System 1.0 by Code-Projects, located in the admin assessment interface. This vulnerability enables an attacker to manipulate the argument ID within the questions-view.php file, leading to potential SQL injection attacks. This exploit can ...

PoC for CVE-2026-2194

D-linkDi-7100g C15.3MEDIUM
Command Injection Flaw in D-Link DI-7100G C1 Router

A security flaw has been identified in the D-Link DI-7100G C1 router, specifically within the start_proxy_client_email function. This vulnerability allows an attacker to execute commands on the device remotely, potentially compromising its security. Exploitation can be carried out without physica...

Discovered 9 hours ago

PoC for CVE-2026-2192

TendaAc98.6HIGH
Stack-Based Buffer Overflow in Tenda AC9 Router by Tenda

A security vulnerability affecting the Tenda AC9 router has been identified, specifically in its function formGetRebootTimer. By manipulating arguments like sys.schedulereboot.start_time and sys.schedulereboot.end_time, an attacker can induce a stack-based buffer overflow. This vulnerability can ...

PoC for CVE-2026-2191

TendaAc98.6HIGH
Stack-Based Buffer Overflow in Tenda AC9 Router

A vulnerability in the Tenda AC9 router has been identified, specifically in the function formGetDdosDefenceList. This flaw allows for the manipulation of the argument security.ddos.map, leading to a stack-based buffer overflow. This weakness can be exploited remotely, presenting significant secu...

PoC for CVE-2026-2190

ItsourcecodeSchool Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode School Management Syste...

A security flaw has been identified in the itsourcecode School Management System version 1.0, which affects the processing of user input in the controller.php file. This vulnerability allows remote attackers to exploit an unvalidated argument ID, leading to SQL injection attacks. By manipulating ...

Discovered 10 hours ago

PoC for CVE-2026-2189

ItsourcecodeSchool Management System6.9MEDIUM
SQL Injection Vulnerability in itsourcecode School Management Syste...

A critical SQL injection vulnerability has been discovered in the itsourcecode School Management System version 1.0. This flaw is located in the file /ramonsys/report/index.php, where improper handling of a user-supplied argument, 'ay', allows an attacker to execute arbitrary SQL queries against ...

PoC for CVE-2026-2188

Utt进取 521g8.6HIGH
OS Command Injection Vulnerability in UTT 进取 521G by UTT

A notable security vulnerability has been identified in UTT 进取 521G version 3.1.1-190816, specifically within the function sub_446B18 of the file /goform/formPdbUpConfig. This vulnerability allows an attacker to manipulate the argument 'policyNames', potentially leading to remote OS command injec...

PoC for CVE-2025-49132

PterodactylPanel🟣 EPSS 35%10CRITICAL
Remote Code Execution Vulnerability in Pterodactyl Game Server Mana...

Pterodactyl, a widely used free and open-source game server management panel, has a significant vulnerability that allows unauthorized remote code execution. This occurs through the /locales/locale.json endpoint when specific query parameters are manipulated. Attackers exploiting this flaw can ex...

Discovered 11 hours ago

PoC for CVE-2026-2187

TendaRx38.7HIGH
Stack-Based Buffer Overflow in Tenda RX3 Router by Tenda

A stack-based buffer overflow vulnerability exists in the Tenda RX3 router, specifically within the set_qosMib_list function of the /goform/formSetQosBand file. This weakness allows an attacker to manipulate the argument list, potentially leading to unauthorized remote code execution. Given that ...

PoC for CVE-2026-2186

TendaRx38.7HIGH
Stack-based Buffer Overflow in Tenda RX3 Router

The Tenda RX3 router suffers from a stack-based buffer overflow vulnerability in the fromSetIpMacBind function located in the /goform/SetIpMacBind file. This flaw allows attackers to manipulate the argument list remotely, potentially leading to arbitrary code execution. The public disclosure of t...

PoC for CVE-2026-2185

TendaRx38.7HIGH
Stack-Based Buffer Overflow in Tenda RX3 Router

A security flaw has been identified in the Tenda RX3 router, specifically in the MAC Filtering Configuration Endpoint. The vulnerability lies in the function set_device_name located in the /goform/setBlackRule file, where improper handling of the devName/mac argument leads to a stack-based buffer...

Discovered 12 hours ago

PoC for CVE-2026-2182

Utt进取 521g8.6HIGH
Command Injection Vulnerability in UTT 进取 521G by UTT

A security weakness has been discovered in the UTT 进取 521G, specifically within the doSystem function of the /goform/setSysAdm file. Manipulating the argument 'passwd1' can allow an attacker to perform command injection, leading to potential unauthorized execution of commands. This vulnerability ...

PoC for CVE-2026-2181

TendaRx38.7HIGH
Stack-based Buffer Overflow in Tenda RX3 Router

A security vulnerability has been identified in the Tenda RX3 router, specifically in the '/goform/openSchedWifi' file. This flaw allows for a stack-based buffer overflow when the arguments 'schedStartTime' and 'schedEndTime' are manipulated. The issue can be exploited remotely, posing significan...

PoC for CVE-2026-2180

TendaRx38.7HIGH
Stack-Based Buffer Overflow in Tenda RX3 Wireless Router

A vulnerability in Tenda RX3 firmware version 16.03.13.11 has been discovered, leading to a stack-based buffer overflow due to unauthorized manipulation of the ssid_5g parameter in the /goform/fast_setting_wifi_set function. This issue can be exploited remotely, posing a significant risk as the e...

PoC for CVE-2026-2179

PHPgurukulHospital Management Sy...5.1MEDIUM
SQL Injection Vulnerability in PHPGurukul Hospital Management System

A vulnerability has been identified in the PHPGurukul Hospital Management System 4.0, specifically within the /admin/manage-users.php file. This issue arises from improper handling of the ID argument, allowing attackers to execute SQL injection attacks. As a consequence, malicious actors could po...

PoC for CVE-2026-2179

PHPgurukulHospital Management Sy...5.1MEDIUM
SQL Injection Vulnerability in PHPGurukul Hospital Management System

A vulnerability has been identified in the PHPGurukul Hospital Management System 4.0, specifically within the /admin/manage-users.php file. This issue arises from improper handling of the ID argument, allowing attackers to execute SQL injection attacks. As a consequence, malicious actors could po...

Discovered 13 hours ago

PoC for CVE-2026-2178

R-huijtsXcode-mcp-server5.3MEDIUM
Command Injection Vulnerability in r-huijts xcode-mcp-server

A command injection vulnerability exists in the registerXcodeTools function of the r-huijts xcode-mcp-server, which affects versions prior to f3419f00117aa9949e326f78cc940166c88f18cb. When manipulating the 'args' argument, an attacker can exploit this vulnerability to execute arbitrary commands r...

PoC for CVE-2026-2177

SourcecodesterPrison Management System6.9MEDIUM
Session Fixation Vulnerability in SourceCodester Prison Management ...

A session fixation vulnerability has been identified in the Login component of SourceCodester's Prison Management System version 1.0. This weakness allows attackers to manipulate session identifiers, potentially compromising user sessions. The vulnerability can be exploited remotely, making it ur...

PoC for CVE-2026-2175

D-linkDir-823x8.6HIGH
OS Command Injection Vulnerability in D-Link DIR-823X Router

A security weakness has been discovered in the D-Link DIR-823X router, specifically within the sub_420618 function of the /goform/set_upnp file. This vulnerability allows attackers to manipulate the upnp_enable argument, potentially leading to OS command injection. The remote exploit is publicly ...

Discovered 14 hours ago

PoC for CVE-2026-2169

D-linkDwr-m9215.3MEDIUM
Command Injection Vulnerability in D-Link DWR-M921 Router

A command injection vulnerability exists in the D-Link DWR-M921 router version 1.1.50. This flaw affects a specific function within the file /boafrm/formLtefotaUpgradeFibocom, allowing an attacker to manipulate the 'fota_url' argument. Exploiting this vulnerability enables unauthorized users to e...

PoC for CVE-2026-2168

D-linkDwr-m9215.3MEDIUM
Command Injection Vulnerability in D-Link DWR-M921 Router

A command injection flaw exists in the D-Link DWR-M921 router, specifically within the sub_419920 function found in the /boafrm/formLtefotaUpgradeQuectel file. This vulnerability allows attackers to manipulate the fota_url argument, enabling remote execution of arbitrary commands. Given that an e...

Discovered 15 hours ago

PoC for CVE-2026-2167

TotolinkWa3005.3MEDIUM
OS Command Injection Vulnerability in Totolink WA300 Router

An OS command injection vulnerability has been identified in the Totolink WA300 router, specifically within the setAPNetwork function located in /cgi-bin/cstecgi.cgi. This flaw allows an attacker to manipulate the Ipaddr argument, leading to the execution of arbitrary operating system commands. T...

PoC for CVE-2026-2166

Code-projectsOnline Reviewer System6.9MEDIUM
SQL Injection Vulnerability in Online Reviewer System by Code-Projects

A critical security flaw exists in the Online Reviewer System 1.0 developed by Code-Projects, related to SQL injection vulnerabilities within the login functionality found in the /login/index.php file. Malicious actors can manipulate the username and password fields to execute arbitrary SQL comma...

PoC for CVE-2026-2165

DetronetdipE-commerce6.9MEDIUM
Missing Authentication Flaw in Detronetdip E-Commerce Software

A vulnerability has been detected in Detronetdip E-commerce 1.0.0, specifically within the account creation endpoint located at /Admin/assets/backend/seller/add_seller.php. This issue arises when the email argument is improperly handled, resulting in missing authentication protections. This flaw ...

PoC for CVE-2026-2164

DetronetdipE-commerce6.9MEDIUM
Unrestricted File Upload Vulnerability in detronetdip E-commerce So...

A security flaw has been identified in detronetdip E-commerce version 1.0.0, specifically affecting the processing of the /seller/assets/backend/profile/addadhar.php file. This vulnerability enables attackers to exploit argument manipulation in the File parameter, leading to an unrestricted file ...

PoC for CVE-2026-2163

D-linkDir-6005.1MEDIUM
Command Injection Vulnerability in D-Link DIR-600 by D-Link

A command injection vulnerability exists in the D-Link DIR-600 router affecting versions up to 2.15WWb02. This flaw is found in the ssdp.cgi file, where improper handling of arguments such as HTTP_ST, REMOTE_ADDR, REMOTE_PORT, and SERVER_ID can allow an attacker to execute arbitrary commands remo...

Discovered 16 hours ago

PoC for CVE-2026-2162

ItsourcecodeNews Portal Project5.1MEDIUM
SQL Injection Vulnerability in itsourcecode News Portal Project

A vulnerability exists in the itsourcecode News Portal Project 1.0 within the /admin/aboutus.php file. This weakness arises from improper handling of the 'pagetitle' argument, leading to a potential SQL injection attack. Remote attackers can exploit this vulnerability to manipulate queries execut...

PoC for CVE-2026-2161

ItsourcecodeDirectory Management S...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode Directory Management Sy...

A security flaw exists in the itsourcecode Directory Management System version 1.0, specifically in the /admin/forget-password.php file. This vulnerability allows an attacker to exploit the email parameter, leading to SQL injection attacks. Given that the vulnerability can be triggered remotely, ...

PoC for CVE-2026-2160

SourcecodesterSimple Responsive Tour...5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Simple Respons...

A vulnerability exists in the SourceCodester Simple Responsive Tourism Website version 1.0, specifically affecting the save_package function located in /tourism/classes/Master.php. This vulnerability enables an attacker to exploit the argument 'Title' to execute arbitrary scripts in the context o...

PoC for CVE-2026-2159

SourcecodesterSimple Responsive Tour...5.3MEDIUM
Cross Site Scripting Vulnerability in SourceCodester Simple Respons...

A vulnerability has been identified in the SourceCodester Simple Responsive Tourism Website 1.0 affecting an unknown function in the Master.php file associated with the registration component. By manipulating the arguments such as firstname, lastname, or username, an attacker can execute cross si...

Discovered 17 hours ago

PoC for CVE-2026-2157

D-linkDir-823x8.6HIGH
OS Command Injection Vulnerability in D-Link DIR-823X Router

A security vulnerability has been identified in the D-Link DIR-823X 250416, specifically within the sub_4175CC function in the file /goform/set_static_route_table. This vulnerability allows for OS command injection when manipulating parameters such as interface, destip, netmask, gateway, and metr...

PoC for CVE-2026-2156

Code-projectsOnline Student Managem...4.8MEDIUM
Cross-Site Scripting Vulnerability in Online Student Management Sys...

A vulnerability exists within the Online Student Management System 1.0, specifically in the Announcement Management Module's handling of user input. The affected file, located at /admin/announcement/index.php?view=add, is susceptible to cross-site scripting attacks. Attackers can exploit this vul...

Discovered 18 hours ago

PoC for CVE-2026-2155

D-linkDir-823x8.6HIGH
OS Command Injection Vulnerability in D-Link DIR-823X Router

A security flaw has been identified in the D-Link DIR-823X router, specifically within the sub_4208A0 function of the Configuration Handler component. This vulnerability allows remote attackers to manipulate the 'dmz_host' and 'dmz_enable' parameters, leading to potential OS command injection. Th...