Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 4 hours ago

PoC for CVE-2026-24423

SmartertoolsSmartermail🟣 EPSS 88%9.3CRITICAL
Unauthenticated Remote Code Execution Vulnerability in SmarterMail ...

SmarterMail versions earlier than build 9511 are susceptible to an unauthenticated remote code execution vulnerability via the ConnectToHub API method. An attacker can exploit this weakness by directing the application to a malicious HTTP server that delivers harmful OS commands, which are then e...

Discovered 5 hours ago

PoC for CVE-2026-84888

Rightnow-aiOpenfang5.3MEDIUM
Uncontrolled Memory Allocation in RightNow-AI OpenFang by RightNow-AI

A vulnerability has been identified in RightNow-AI OpenFang, specifically affecting the shell_exec function within the tool_runner.rs file. This flaw leads to uncontrolled memory allocation, enabling remote attackers to exploit the system. The vulnerability has been public since its disclosure, a...

PoC for CVE-2026-84887

Simular-aiAgent-s5.3MEDIUM
Denial of Service Vulnerability in simular-ai Agent-S Product by Si...

A denial of service vulnerability exists in the simular-ai Agent-S, specifically linked to the file grounding.py within the Model-generated GUI Action Execution Workflow. This flaw can be exploited remotely, allowing attackers to disrupt service functionality. Publicly available exploit methods i...

PoC for CVE-2026-84886

Simular-aiAgent-s6.9MEDIUM
Resource Consumption Vulnerability in simular-ai Agent-S OCR HTTP API

A resource consumption vulnerability has been identified in simular-ai's Agent-S product, specifically in the OCR HTTP API's ImageData function within the gui_agents/s1/utils/ocr_server.py file. This vulnerability allows an attacker to manipulate the img_bytes argument, potentially leading to sig...

Discovered 6 hours ago

PoC for CVE-2026-84885

Simular-aiAgent-s5.3MEDIUM
Denial of Service Vulnerability in Simular AI Agent-S by Simular AI

A security flaw has been identified in the Agent-S product, specifically located in the code_agent.py file of the CodeAgent component. Exploiting this vulnerability allows attackers to cause a denial of service, potentially disrupting the functionality of the affected system. This issue can be ex...

PoC for CVE-2026-84857

SigodenAichat6.9MEDIUM
Memory Allocation Flaw in Sigoden Aichat API Endpoint

A significant flaw has been identified in the Sigoden Aichat API Endpoint, specifically within the src/serve.rs component. This vulnerability allows for uncontrolled memory allocation, which can be exploited remotely by attackers. The exploit has been publicly disclosed, posing a risk of a Denial...

PoC for CVE-2026-84856

RowboatlabsRowboat6.9MEDIUM
Denial of Service Vulnerability in Rowboat by Rowboat Labs

A vulnerability has been identified in Rowboat Labs’ Rowboat, specifically in the Composio Webhook Endpoint. This issue arises from a flaw in the request handling function located in the code that can lead to denial of service. Attackers can exploit this vulnerability remotely, which could disrup...

Discovered 7 hours ago

PoC for CVE-2026-82524

UnopimUnopim8.6HIGH
Authenticated File Upload Vulnerability in UnoPim by UnoPim

UnoPim, prior to version 2.1.5, suffers from an authenticated file upload vulnerability that allows administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint. This weakness arises from inadequate validation of file extensions and MIME types. As a consequence, attacker...

PoC for CVE-2022-25765

PDFkit ProjectPDFkit🟣 EPSS 40%7.3HIGH
Command Injection

The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.

PoC for CVE-2026-75134

WordPressSeowriting5.1MEDIUM
Stored Cross-Site Scripting Vulnerability in SEOWriting Plugin for ...

The SEOWriting plugin for WordPress, up to version 1.12.5, contains a stored cross-site scripting vulnerability. Authenticated contributors can exploit this issue by injecting malicious JavaScript into post content. The vulnerability arises from an overly permissive KSES allowlist that allows the...

PoC for CVE-2026-84852

Reader ToolsPDF Reader App4.8MEDIUM
Path Traversal Vulnerability in Reader Tools PDF Reader App for And...

A vulnerability has been uncovered in the Reader Tools PDF Reader App version 98.8 for Android that allows local attackers to exploit the function ActSplashNew.handleDeeplink. By manipulating the argument _display_name, attackers can execute a path traversal attack, potentially allowing unauthori...

PoC for CVE-2026-84841

Tsi-coopTsi-dpdp-cms6.9MEDIUM
Client-Side Security Flaw in TSI Coop TSI-DPDP-CMS by TSI Coop

A security flaw exists in TSI Coop's TSI-DPDP-CMS software that enables client-side enforcement of server-side security protocols. This vulnerability can be exploited remotely, potentially leading to unauthorized access or manipulation of server-side functionalities. Users are strongly encouraged...

Discovered 8 hours ago

PoC for CVE-2026-84840

Tsi-coopTsi-dpdp-cms6.9MEDIUM
Missing Authentication in TSI Coop TSI DPDP CMS up to 0.5.0

A vulnerability affecting TSI Coop's TSI DPDP CMS allows unauthorized access due to missing authentication in the Bootstrap Setup Endpoint component (specifically in the InterceptingFilter.java file). This flaw can be exploited remotely, potentially allowing attackers to manipulate the system wit...

PoC for CVE-2026-84839

Tsi-coopTsi-dpdp-cms6.9MEDIUM
Missing Authentication in TSI Coop TSI DPDP CMS Admin Console

A vulnerability exists in the TSI Coop TSI DPDP CMS Admin Console related to the web.xml file that may allow remote attackers to exploit missing authentication functionalities. This flaw could lead to unauthorized access and manipulation of sensitive information through the Admin Console and DPO ...

PoC for CVE-2026-7899

GoogleChrome8.8HIGH
Out of Bounds Read and Write Vulnerability in Google Chrome

A vulnerability in the V8 JavaScript engine within Google Chrome allows remote attackers to execute arbitrary code within a sandbox environment. This is achieved through an out of bounds read and write technique facilitated by specially crafted HTML content, posing significant security risks to u...

Discovered 9 hours ago

PoC for CVE-2026-84833

NtegralsOpenbrowser5.3MEDIUM
Resource Consumption Vulnerability in ntegrals OpenBrowser Browser ...

A vulnerability exists in ntegrals OpenBrowser, specifically within the Browser Agent Message Construction component. This issue allows attackers to exploit specific functionalities within the agent.ts file, leading to excessive resource consumption. The exploit can be triggered remotely, potenti...

Discovered 10 hours ago

PoC for CVE-2026-9586

SangomaSwitchvox Smb Edition9.3CRITICAL
SQL Injection Vulnerability in Sangoma Switchvox SMB Edition

An unauthenticated SQL injection vulnerability has been identified in Sangoma Switchvox SMB Edition 8.3. The vulnerability resides in the /pa endpoint, which processes XML content starting with <PolycomIPPhone>. This endpoint improperly concatenates the user-controlled PhoneIP value into PostgreS...

Discovered 12 hours ago

PoC for CVE-2026-2811

WordPressAjaxify Comments5.4MEDIUM
HTTP Header Injection Vulnerability in Ajaxify Comments Plugin by W...

The Ajaxify Comments WordPress plugin prior to version 3.2 is susceptible to HTTP Header Injection. This vulnerability arises from inadequate input sanitization and output escaping of data provided by users. As a result, unauthenticated attackers could potentially inject arbitrary HTTP headers, w...

PoC for CVE-2025-9314

WordPressDeveloper Tools9.8CRITICAL
Unauthenticated File Upload Vulnerability in Developer Tools Plugin...

The Developer Tools plugin for WordPress versions up to 1.1.3 is susceptible to an unauthenticated arbitrary file upload vulnerability due to a flaw in the bundled SWFUpload component. This security issue allows malicious actors to upload harmful files without proper authentication, which could p...

PoC for CVE-2025-15490

WordPressPassster5.3MEDIUM
Global Protection Bypass in Passster Plugin for WordPress

The Passster plugin for WordPress, prior to version 4.2.26, contains a security vulnerability related to inadequate global protection checks. This flaw permits unauthenticated users to bypass intended protection mechanisms through specially crafted URLs, potentially compromising site security and...

PoC for CVE-2025-8945

WordPressWP Edit Password Prote...5.3MEDIUM
Bypass Vulnerability in Wp Edit Password Protected Plugin for WordP...

The Wp Edit Password Protected plugin for WordPress, prior to version 1.3.5, contains a security flaw that enables unauthorized users to bypass content protection measures implemented via the plugin. This vulnerability allows attackers to access restricted page content through the REST API, under...

PoC for CVE-2025-15489

WordPressPassster5.3MEDIUM
Input Handling Flaw in Passster WordPress Plugin by Passster

The Passster WordPress plugin prior to version 4.2.24 has a significant input handling issue within its AJAX action operations. This flaw permits unauthenticated users to access and retrieve sensitive information from password-protected content, potentially exposing private data to unauthorized i...

PoC for CVE-2025-15485

WordPressAuto X Line8.2HIGH
Unauthorized Access in Auto x LINE WordPress Plugin by WP-Example

The Auto x LINE plugin for WordPress, up to version 1.0.0, contains a critical vulnerability where several REST endpoints lack proper authorization checks. This oversight allows unauthenticated users to interact with the plugin's functionalities, including updating settings and clearing logs, whi...

PoC for CVE-2025-15481

WordPressNotification Bar For W...5.3MEDIUM
Data Disclosure Vulnerability in Notification Bar Plugin for WordPress

The Notification Bar plugin for WordPress, up to version 1.1.8, has a serious vulnerability that exposes an unauthenticated CSV export script. This script can be exploited by unauthorized users to access and disclose all stored subscriber email addresses, leading to potential privacy breaches and...

PoC for CVE-2024-3773

WordPressLivejournal Shortcode5.9MEDIUM
Stored Cross-Site Scripting in LiveJournal Shortcode Plugin for Wor...

The LiveJournal Shortcode plugin for WordPress versions up to 1.1.1 is susceptible to Stored Cross-Site Scripting attacks due to improper validation and escaping of shortcode attributes. This flaw enables users with contributor access and higher to inject malicious scripts, which can be executed ...

PoC for CVE-2023-3360

WordPressWeaver Show Posts3.3LOW
PHP Object Injection Vulnerability in Weaver Show Posts Plugin for ...

The Weaver Show Posts plugin for WordPress, prior to version 1.8.1, contains a vulnerability that allows for PHP object injection via improperly unserialised content from imported files. This vulnerability can be exploited when a user with elevated privileges imports a malicious file into the blo...

PoC for CVE-2026-83547

WordPressXpro Addons6.8MEDIUM
Stored Cross-Site Scripting in Xpro Addons WordPress Plugin

The Xpro Addons plugin for WordPress, prior to version 1.7.4, is susceptible to Stored Cross-Site Scripting attacks. This vulnerability arises from the plugin's failure to properly escape certain settings of its widgets before rendering them in HTML attributes. As a result, users with a Contribut...

PoC for CVE-2026-83533

WordPressWP Express Checkout5.3MEDIUM
Payment Forgery Vulnerability in WP Express Checkout Plugin by Word...

The WP Express Checkout plugin for WordPress versions prior to 2.4.9 is susceptible to a vulnerability that allows unauthorized users to artificially complete orders without making actual payments. This flaw arises due to the plugin's failure to validate whether a payment transaction was genuinel...

PoC for CVE-2026-82884

WordPressAll In One Seo6.8MEDIUM
Stored Cross-Site Scripting Vulnerability in All in One SEO Plugin

The All in One SEO plugin for WordPress, prior to version 5.0.0.1, contains a vulnerability where it fails to properly sanitize and escape content stored within posts. This oversight allows users with contributor roles and above to conduct Stored Cross-Site Scripting attacks. The vulnerability is...

PoC for CVE-2026-81571

WordPressBrave4.8MEDIUM
Arbitrary Code Execution Vulnerability in Brave WordPress Plugin

The Brave WordPress plugin prior to version 0.8.8 contains a vulnerability that allows unauthenticated attackers to exploit URL parameters used to pre-fill form fields. This exploit enables malicious actors to execute arbitrary shortcodes server-side, posing a significant risk to the security and...

PoC for CVE-2026-8151

WordPressSimple Membership Mail...5.4MEDIUM
Lack of CSRF Protection in Simple Membership MailChimp Integration ...

The Simple Membership MailChimp Integration plugin for WordPress prior to version 1.9.8 lacks essential CSRF checks on its settings page. This deficiency allows attackers to exploit the vulnerability by tricking a logged-in administrator into altering the third-party API key. If successful, the a...

PoC for CVE-2026-78153

WordPressRestrict User Access5.3MEDIUM
Access Control Bypass in Restrict User Access Plugin by WordPress

The Restrict User Access plugin for WordPress prior to version 2.8.1 is susceptible to an access control bypass vulnerability due to insufficient normalization of the REST API routes. This oversight permits unauthorized users to circumvent content protection measures, granting them the ability to...

PoC for CVE-2026-77794

WordPressRegistrationmagic5.3MEDIUM
RegistrationMagic WordPress Plugin Vulnerability Exposes Payment Pr...

The RegistrationMagic plugin for WordPress prior to version 6.0.9.9 contains a flaw in its payment processing system. Specifically, it fails to validate user-supplied quantity multipliers during registration, allowing unauthorized users to bypass payment requirements. This vulnerability enables u...

PoC for CVE-2026-77009

WordPressWatchman-site79.9CRITICAL
Arbitrary Code Execution Vulnerability in WatchMan-Site7 WordPress ...

The WatchMan-Site7 WordPress plugin, prior to version 4.2.0, fails to adequately restrict access to its debugging console. This oversight permits any authenticated user, including those with minimal roles such as subscriber, to execute arbitrary PHP code on the server. Such vulnerabilities can le...

PoC for CVE-2026-77793

WordPressRegistrationmagic5.3MEDIUM
Payment Bypass Vulnerability in RegistrationMagic Plugin by WordPress

The RegistrationMagic WordPress plugin prior to version 6.0.9.9 is susceptible to a security flaw that permits unauthenticated users to exploit insufficient server-side validation of the total payment price. As a result, these users can finalize a paid registration without completing the payment,...

PoC for CVE-2026-4357

WordPressEmbed Html5 Game10CRITICAL
File Upload Vulnerability in Embed HTML5 Game Plugin for WordPress

The Embed HTML5 Game WordPress plugin prior to version 1.3 is susceptible to a serious file upload vulnerability. This security flaw allows unauthorized users to upload arbitrary files, including PHP scripts, which can result in the injection of malicious backdoors on the server. The compromised ...

PoC for CVE-2026-2688

WordPressHipaa Forms6.5MEDIUM
Authentication Bypass Vulnerability in HIPAA FORMS by WordPress

The HIPAA FORMS WordPress plugin before version 3.2.0 is vulnerable to an authentication bypass issue. This is achieved through a hardcoded parameter present in all AJAX requests which allows attackers to bypass nonce validation checks on the server. As a result, unauthenticated users can access ...

PoC for CVE-2026-19698

WordPressGutenkit3.5LOW
Arbitrary CSS Injection Vulnerability in GutenKit WordPress Plugin

The GutenKit WordPress plugin has a vulnerability that allows users with Contributor roles and above to inject arbitrary CSS into posts. This vulnerability arises from the plugin's failure to validate or sanitize style settings before incorporating them into the CSS rendered on the front end. Whi...

PoC for CVE-2026-17563

WordPressUser Frontend5.3MEDIUM
Subscription Bypass Vulnerability in User Frontend WordPress Plugin

The User Frontend plugin for WordPress, prior to version 4.3.11, contains a flaw that fails to enforce subscription requirements during post submissions. As a result, unauthenticated users can exploit this weakness to create and potentially publish posts without proper authorization, enabling the...

PoC for CVE-2026-10821

WordPressYoast Seo Premium6.6MEDIUM
Arbitrary Code Execution Vulnerability in Yoast SEO Premium Plugin ...

The Yoast SEO Premium WordPress plugin prior to version 27.6.1 exhibits a security flaw where it fails to properly sanitize control characters from redirect origins before writing to the site's Apache configuration file. This issue arises when file-based redirection is enabled and the redirect-cr...

PoC for CVE-2026-14326

WordPressTimetics3.8LOW
Authorization Flaw in Timetics WordPress Plugin Affects Appointment...

The Timetics WordPress plugin prior to version 1.0.61 contains a vulnerability that allows users assigned a custom staff role to exploit the REST API and gain unauthorized access to appointments. This flaw permits these users to modify, disable, or take control of appointments originally assigned...

PoC for CVE-2025-15692

WordPressIcegram Express3.5LOW
Stored Cross-Site Scripting in Icegram Express WordPress Plugin

The Icegram Express plugin for WordPress, prior to version 5.8.6, is vulnerable due to improper escaping of a list description setting. This flaw allows users with Administrator privileges and above to inject malicious scripts, leading to potential stored XSS attacks. When executed, such attacks ...

Discovered 20 hours ago

PoC for CVE-2026-82183

WordPressOauth Single Sign On8.1HIGH
OAuth Single Sign On Plugin for WordPress Exposes User Accounts

The OAuth Single Sign On plugin for WordPress suffers from a significant flaw in its handling of the Steam single sign-on process. This flaw permits unauthenticated attackers to bypass authentication mechanisms, allowing them to log in as any non-administrator user. Furthermore, the vulnerability...

PoC for CVE-2026-81737

WordPressFaq Builder Ays8.8HIGH
Stored XSS Vulnerability in FAQ Builder AYS WordPress Plugin

The FAQ Builder AYS WordPress plugin, prior to version 1.8.5, has a vulnerability that permits unauthenticated users to submit content without proper sanitization or escaping. This leads to the potential for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be executed in the...

PoC for CVE-2026-81583

WordPressTheme My Login5.4MEDIUM
Improper Access Control in My Login WordPress Plugin Affects Networ...

The My Login WordPress plugin prior to version 7.2.0 is susceptible to a vulnerability that fails to adhere to the network's registration settings during the sign-up process on multisite installations. This flaw permits users with subscriber accounts and even unauthenticated individuals on certai...

PoC for CVE-2026-81807

WordPressSimple Ajax Chat8.8HIGH
Cross-Site Scripting in Simple Ajax Chat Plugin by WordPress

The Simple Ajax Chat plugin for WordPress, prior to version 20260827, is susceptible to a cross-site scripting vulnerability. This issue arises because the plugin fails to properly escape chat message content before it is displayed. As a result, an unauthenticated user can inject arbitrary HTML a...

PoC for CVE-2026-82182

WordPressWPvivid — Backup, Migr...4.1MEDIUM
SQL Injection Vulnerability in WPvivid Backup, Migration & Staging ...

The WPvivid Backup, Migration & Staging plugin prior to version 0.9.133 is susceptible to SQL injection due to inadequate sanitization of user-supplied identifiers in a SQL query. This vulnerability could be exploited by malicious users to execute arbitrary SQL commands, potentially compromising ...

PoC for CVE-2026-81432

WordPressJetstylemanager For Gu...4.3MEDIUM
CSRF Vulnerability in JetStyleManager for Gutenberg WordPress Plugin

The JetStyleManager for Gutenberg WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) attacks. Specifically, versions prior to 1.3.9 lack adequate CSRF protection on certain AJAX actions. This weakness can be exploited by attackers who can deceive a logged-in user with the edit_po...

PoC for CVE-2026-81428

WordPressWc Vendors6.5MEDIUM
Authorization Flaw in WC Vendors Plugin for WordPress

The WC Vendors plugin for WordPress, prior to version 2.7.2.1, contains a critical oversight that allows authenticated users with vendor roles to manipulate product variations that do not belong to them. By exploiting this flaw, these users can alter the status and title of various posts and prod...

PoC for CVE-2026-81198

WordPressMasterstudy Lms WordPr...3.8LOW
Improper Ownership Verification in MasterStudy LMS Plugin by WordPress

The MasterStudy LMS Plugin for WordPress prior to version 3.7.46 contains a vulnerability that allows authenticated users with instructor privileges to manipulate curriculum objects. This flaw occurs due to inadequate verification of ownership, enabling these users to delete or alter course secti...