Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 2 hours ago
PoC for CVE-2026-72898
Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...
PoC for CVE-2026-38526
An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...
PoC for CVE-2026-19478
A flaw in GitLab CE/EE allows unauthenticated users to exploit specific GraphQL directives, potentially resulting in unauthorized modification or deletion of public projects and user data. This vulnerability impacts various versions, necessitating immediate user awareness and prompt application o...
Discovered 4 hours ago
PoC for CVE-2026-20303
Cisco's Catalyst SD-WAN product has been identified with vulnerabilities stemming from improper input validation, as revealed during an internal security review. These issues can potentially expose the system to various security risks, underscoring the importance of implementing software hardenin...
Discovered 5 hours ago
PoC for CVE-2026-77542
A security flaw has been identified in the UID Enterprise Agent developed by Ubiquiti, where improper input validation can be exploited by malicious actors with network access and elevated privileges. This vulnerability enables the execution of command injection on the host device, potentially al...
PoC for CVE-2026-18431
The Avada theme for WordPress presents a significant security risk due to an arbitrary file write vulnerability that affects all versions up to 7.16 when paired with an active Fusion Builder plugin (up to version 3.16). This flaw stems from a combination of authorization issues and inadequate inp...
Discovered 6 hours ago
PoC for CVE-2026-81562
A security flaw has been identified in AlexGladkov's claude-in-mobile, specifically affecting the execSync function in src/adb/client.ts. This vulnerability allows for OS command injection, requiring local access to the system for exploitation. An upgrade to version 3.10.3 is necessary to mitigat...
PoC for CVE-2026-8467
A vulnerability exists in Phenix Digital's Phoenix Storybook that allows unauthenticated remote code execution due to unsanitized attribute value interpolation during HEEx template generation. The psb-assign WebSocket event handler permits arbitrary attribute names and values from unauthenticated...
Discovered 7 hours ago
PoC for CVE-2026-74233
A security flaw in the Zbtlink firmware for multiple wireless devices allows remote attackers to exploit the infosrvd service via crafted UDP packets. This vulnerability bypasses authentication mechanisms, as it employs a hardcoded salt, enabling unprivileged users to execute arbitrary commands a...
PoC for CVE-2026-81560
A vulnerability exists in blackms aistack up to version 1.6.1, impacting the Static File Handler component located in src/web/server.ts. This flaw allows for path traversal due to improper handling of the req.url argument, which can be exploited remotely. The exploit code is publicly accessible, ...
Discovered 12 hours ago
PoC for CVE-2026-78333
The 12 Step Meeting List WordPress plugin prior to version 3.19.17 allows unauthenticated users to submit unsanitized input, which is stored in the activity log. This input is later displayed back to users in the admin area without adequate escaping, making it possible for an attacker to execute ...
PoC for CVE-2026-77018
The Workeera plugin for WordPress prior to version 1.0.6 lacks adequate restrictions on profile value submissions by candidates. It fails to validate the file types uploaded, allowing users with minimal privileges, such as subscribers, to upload arbitrary files. Consequently, this can lead to rem...
PoC for CVE-2026-78138
The Finale Lite plugin for WordPress prior to version 2.21.0 contains a security flaw that allows authenticated users, including those with Subscriber roles and above, to access sensitive campaign configuration data through an unprotected AJAX action. This oversight enables users to retrieve conf...
PoC for CVE-2026-78137
The StoreGrowth WordPress plugin prior to version 2.1.2 is vulnerable due to insufficient validation of browser-supplied product prices on certain unauthenticated actions. This flaw permits attackers to specify arbitrary prices when adding products to the shopping cart, especially when the 'Buy O...
PoC for CVE-2026-77017
The Workeera WordPress plugin versions prior to 1.0.6 allows users with minimal permissions, such as a subscriber, to submit any profile values without restrictions. This lack of input validation leads to unauthorized access where these users can read arbitrary files stored on the server. This in...
PoC for CVE-2026-78125
A critical vulnerability in the LearnPress WordPress plugin allows unauthorized attackers to access sensitive information. This flaw exists in the plugin's REST API, where no authorization checks are performed on certain endpoints. As a result, attackers can exploit this weakness to disclose the ...
PoC for CVE-2026-78139
The Notifima WordPress plugin before version 3.1.4 lacks proper validation of subscription ownership on its REST endpoints. This oversight allows authenticated users with Subscriber-level access to manipulate subscription settings, specifically the ability to unsubscribe any customer from receivi...
PoC for CVE-2026-77016
The Workeera WordPress plugin prior to version 1.0.6 allows users with minimal permissions, such as subscribers, to delete arbitrary files from the server. This vulnerability arises due to the lack of restrictions on the values that can be written to a user's candidate profile, coupled with inade...
PoC for CVE-2026-76549
The UpdraftPlus: WP Backup & Migration Plugin for WordPress, prior to version 1.26.7, lacks proper CSRF checks in a critical backup management operation. This vulnerability can potentially allow an attacker to trick an authenticated admin into restoring a backup without their consent, effectively...
PoC for CVE-2026-19715
The WP OAuth Server plugin for WordPress, prior to version 6.3.1, contains a flaw that allows unauthenticated users to access the debug log. This log, stored in a publicly accessible location, may contain sensitive information including OAuth tokens, authorization codes, and user records, such as...
PoC for CVE-2026-19225
The Defender Security plugin for WordPress before version 6.2.0 contains a vulnerability that permits an administrator of any single site within a multisite network to execute arbitrary code across the entire network. This flaw arises from the failure to restrict a critical network-wide setting e...
PoC for CVE-2026-19454
The JetBackup plugin for WordPress prior to version 3.1.23.5 fails to properly enforce multisite authorization checks when serving backup archives and job logs. This oversight enables a network administrator—who does not possess Super Admin privileges—to download complete backups of the entire mu...
PoC for CVE-2026-16569
The ShopApper Mobile App Builder Service for WooCommerce up to version 0.4.62 has a significant security issue where it does not properly verify user capabilities for stock-update operations. This oversight allows any authenticated user, including customers and subscribers, to alter the stock qua...
PoC for CVE-2026-19223
The Smush plugin for WordPress, prior to version 4.3.2, is susceptible to a security flaw that enables an administrator of any individual site within a multisite network to execute arbitrary code across the entire network. This flaw arises from insufficient restrictions placed on network-wide set...
PoC for CVE-2026-16568
The ShopApper Mobile App Builder Service for WooCommerce has a vulnerability where the plugin does not correctly verify user ownership of customer profiles accessed via its REST API endpoints. This oversight enables authenticated users, such as customers or subscribers, to potentially gain unauth...
PoC for CVE-2026-16567
The Document Embedder plugin for WordPress prior to version 2.3.1 has a significant security flaw that allows unauthenticated users to exploit the file download feature. This vulnerability arises because the plugin fails to validate the status of documents before generating a download token. As a...
PoC for CVE-2026-13414
The CMP WordPress plugin prior to version 4.1.18 is susceptible to an authorization bypass vulnerability due to inadequate checks on several AJAX actions. This flaw allows unauthenticated attackers to bypass intended restrictions and disable the maintenance or coming-soon mode. Notably, some acti...
PoC for CVE-2026-13416
The CMP WordPress plugin prior to version 4.1.18 lacks adequate sanitization and escaping of settings values. This flaw permits users assigned the Editor role, if granted access to the admin-bar controls of the plugin, to inject malicious web scripts. These scripts can execute when a visitor view...
PoC for CVE-2026-13415
The CMP WordPress plugin prior to version 4.1.18 lacks robust checks on setting imports, specifically failing to enforce an option-name allow-list when settings are imported via AJAX actions. This oversight can enable users with Editor permissions, if granted access by an administrator, to modify...
Discovered 14 hours ago
PoC for CVE-2026-45585
A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...
Discovered 15 hours ago
PoC for CVE-2026-81491
A flaw in Boxpositron's With-Context-MCP (version up to 3.0.7) exposes a path traversal vulnerability through the ingest_notes, teleport_notes, sync_notes, and project_folder functions contained in the src/index.ts file. This allows remote attackers to manipulate the file paths, potentially leadi...
Discovered 16 hours ago
PoC for CVE-2026-18080
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is susceptible to an unrestricted file type upload due to insufficient validation of file extensions and improper path normalization in its save_attachments() function. This vulnerability allows unauthenticate...
PoC for CVE-2026-63520
A vulnerability exists in Microsoft Office SharePoint due to improper input validation, which could allow an unauthorized attacker to execute arbitrary code over a network. This can lead to significant security breaches if exploited, making it essential for affected users to apply security patche...
PoC for CVE-2026-81486
A vulnerability has been identified in bsmi021's mcp-file-context-server version 1.0.0, specifically in the read_context function located in src/index.ts. This flaw allows attackers to manipulate the argument path, leading to potential path traversal attacks. This vulnerability can be exploited r...
Discovered 17 hours ago
PoC for CVE-2026-81485
A security vulnerability has been identified in the danielpopamd Linkedin Ads MCP version 1.0.0. This vulnerability arises from an unsafe implementation in the function fs.readFileSync located in the file src/tools/campaign-management.ts, which handles media uploads. An attacker can manipulate th...
Discovered 18 hours ago
PoC for CVE-2026-19912
The Kaltura HTML5 player is susceptible to a remote code execution vulnerability due to the unsafe handling of user-supplied data. Specifically, when the mwEmbedLoader.php script processes the ServiceUrl provided by an attacker, it performs deserialization without adequate validation. This exploi...
Discovered 19 hours ago
PoC for CVE-2026-19632
The TranslatePress plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit the 'trp_get_translations_regular' AJAX action. This can lead to the unauthorized extraction of the raw administrator password-reset URL, including sensitive parameters such as the pl...
PoC for CVE-2026-81203
A SQL injection vulnerability has been identified in the SourceCodester Simple Online Food Ordering System version 1.0, specifically within the login function located at /admin/ajax.php?action=login2. By manipulating the email parameter, attackers can execute arbitrary SQL queries, potentially co...
Discovered 20 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-81202
A security flaw exists in the itsourcecode Payroll System 1.0 that compromises the integrity of CRUD operations through the ajax.php file. An attacker can exploit this vulnerability by manipulating the 'action' argument, resulting in missing authentication checks. This raises significant security...
Discovered 1 day ago
PoC for CVE-2026-19632
The TranslatePress plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit the 'trp_get_translations_regular' AJAX action. This can lead to the unauthorized extraction of the raw administrator password-reset URL, including sensitive parameters such as the pl...
PoC for CVE-2026-12684
The Customer Reviews for WooCommerce WordPress plugin, prior to version 5.113.0, lacks necessary authentication and nonce checks in its AJAX actions related to media uploads. When the review media attachment feature is activated, this flaw permits unauthorized users to upload files to the Media L...
PoC for CVE-2026-72530
A vulnerability in TrueConf Server allows remote unauthorized attackers with access to port 4307/TCP to exploit the server versions 5.3.X up to 5.3.9, 5.4.X up to 5.4.9, and 5.5.X up to 5.5.5. By using a crafted script, the attacker can break out of the isolated execution environment and execute ...
PoC for CVE-2026-78146
The Simple Newsletter Plugin for WordPress, prior to version 4.3.3, has a security flaw that allows unauthenticated users to access and disclose personal data of subscribers. This occurs due to the plugin's failure to validate that a requester is indeed the authorized subscriber before presenting...
PoC for CVE-2026-77789
The Stripe Payment Forms plugin by WP Full Pay for WordPress prior to version 8.5.1 contains an authorization flaw that allows a user with a valid session to manipulate subscriptions that do not belong to them. Specifically, this vulnerability permits unauthorized actions such as canceling, react...
PoC for CVE-2026-77758
The Stripe Payment Forms by WP Full Pay plugin for WordPress prior to version 8.5.1 contains a vulnerability where it fails to accurately verify the completion of a customer portal session. This oversight allows unauthenticated users to access sensitive information, such as subscription and billi...
PoC for CVE-2026-77790
The RegistrationMagic plugin for WordPress, prior to version 6.0.9.4, is susceptible to SQL injection due to improper sanitization and escaping of input parameters in SQL statements. This vulnerability enables users with high privileges, such as administrators, to execute malicious SQL queries, p...
PoC for CVE-2026-75798
The AI Engine plugin for WordPress prior to version 3.7.2 lacks essential authorization checks on specific administrative features. Instead of validating permissions, it issues a token to anonymous users. This design flaw permits unauthenticated attackers to execute AI queries on behalf of the si...
PoC for CVE-2026-77694
The Eventin WordPress plugin prior to version 4.1.19 contains a security flaw that permits unauthorized users to exploit the guest checkout token mechanism. This vulnerability enables unauthenticated individuals to manipulate their own unpaid orders, marking them as completed and receiving valid ...
PoC for CVE-2026-77757
The Directorist plugin for WordPress, designed for business directory listings, can be exploited due to insufficient sanitization of user-supplied image references. This flaw permits users with subscriber-level accounts to manipulate server-readable image files, allowing them to move these files ...