Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-82329
JFrog Artifactory has a significant authentication weakness that could permit an attacker with network access to gain administrative privileges without authentication, particularly when the product is left in its default configuration. This vulnerability can expose sensitive resources and operati...
Discovered 24 minutes ago
PoC for CVE-2021-3493
The OverlayFS implementation in the Linux kernel failed to adequately validate user namespaces when setting file capabilities on underlying file systems. This weakness, combined with specific patches in the Ubuntu kernel that permit unprivileged overlay mounts, enables attackers to exploit the si...
Discovered 5 hours ago
PoC for CVE-2026-13611
The KiviCare WordPress plugin prior to version 4.5.5 contains a significant security vulnerability that fails to enforce authorization checks on certain REST API endpoints. This oversight allows unauthenticated attackers to gain access to sensitive information, including the patient roster and, i...
PoC for CVE-2026-78363
The MW WP Form WordPress plugin allows shortcodes from user-submitted values to be executed within messages. This occurs when the plugin merges these values into a message, leading to potential exploitation by unauthenticated users to run any registered shortcode on the site. To exploit this vuln...
PoC for CVE-2026-74916
The WP Fastest Cache plugin for WordPress exhibits a vulnerability that permits unauthenticated attackers to exploit the caching mechanism. Specifically, the plugin fails to incorporate a set of query parameters related to tracking within its cache key. As a result, pages cached under these condi...
Discovered 6 hours ago
PoC for CVE-2023-49792
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when a (reverse) proxy is configured as trus...
Discovered 7 hours ago
PoC for CVE-2026-83772
A command injection vulnerability has been identified in the Cobham SATCOM VSAT7090 Maritime Satellite Router affecting the mail-report.sh component. This issue arises from improper handling in the c_set_reports_decode function, which allows manipulation of the sender/recipients argument. Attacke...
PoC for CVE-2026-83744
A security vulnerability exists in the Invoice Ninja application up to version 5.13.26, specifically in the Purify::isHostSafe function located in the app/Services/Pdf/Purify.php file. This flaw allows an attacker to manipulate the 'notes' argument, potentially leading to remote server-side reque...
Discovered 8 hours ago
PoC for CVE-2026-83743
A significant security flaw exists in Invoice Ninja's Vendor Portal Profile Update functionality, specifically affecting version 5.13.26. This vulnerability arises from inadequate authorization checks that allow attackers to manipulate the 'vendor_contact' parameter. As a result, a remote attacke...
Discovered 14 hours ago
PoC for CVE-2026-83524
A security vulnerability has been discovered in the RedPort Optimizer, affecting versions wXa-203, wXa-213, and wXa-223. This flaw resides in the System Clock component, specifically within the exec function found in the datetime.php file. The vulnerability allows for command injection, which cou...
PoC for CVE-2026-82971
A command injection vulnerability exists in the CGI script located at /cgi-bin/net_tr.cgi in QVidium Opera11 version 3.3.2a26-Ax4x-opera11. This vulnerability can be exploited by manipulating the 'ipaddr' argument, allowing attackers to execute arbitrary commands on the server. Given that QVidium...
Discovered 15 hours ago
PoC for CVE-2026-82922
A security vulnerability exists in ShopEx ECShop affecting the flow_update_cart function in the /flow.php file. The flaw allows manipulation of the rec_id argument, leading to SQL injection attacks that can be executed remotely. This vulnerability has been publicly disclosed, posing a risk to unp...
PoC for CVE-2026-82921
A vulnerability exists within ShopEx ECShop versions up to 2.5.1 in the check_img_type functionality located in admin/pack.php. Specifically, this weakness allows an attacker to manipulate the pack_img argument, resulting in unrestricted file uploads. This flaw exposes affected systems to potenti...
Discovered 16 hours ago
PoC for CVE-2026-82914
A security flaw has been identified in version 1.0 of the kishan0725 Hospital Management System, specifically affecting the /search.php file. This vulnerability arises from inadequate input validation in the 'Contact' argument, allowing an attacker to execute SQL injection attacks remotely. The p...
PoC for CVE-2026-82909
The new-api component of QuantumNous contains a vulnerability in its Revoked API Token Handler, allowing attackers to manipulate the system and cause session expiration. This issue arises from an unspecified functionality within the API usage token file, which can be exploited remotely. Affected ...
PoC for CVE-2026-82908
A vulnerability exists in MSI Dragon Center, found in the MmioWritePath function of the NTIOLib_X64.sys library. This issue arises from improper handling of argument counts and element sizes, leading to integer overflow. The exploit requires local access to the affected system, and while the vuln...
PoC for CVE-2026-82906
A significant security flaw has been identified in sdcb chats versions up to 1.12.0. This vulnerability affects the DownloadPublic function within the Signed File Download Endpoint, specifically in the FileController.cs file. The issue arises due to inadequate authentication checks, allowing unau...
Discovered 17 hours ago
PoC for CVE-2026-82905
A vulnerability has been identified in SDCB Chats, specifically in versions up to 1.12.0. The issue resides within the McpController function of the fetch-tools Endpoint, compromising the system's security by allowing unauthorized server-side request forgery. This flaw can be exploited remotely, ...
PoC for CVE-2026-82835
A vulnerability has been discovered in Django-Vue-Admin version 1.0, where an improper access control issue exists in the '/api/file/' endpoint. The flaw allows remote attackers to manipulate the 'file_id' argument, potentially leading to unauthorized access to sensitive files and data. This vuln...
PoC for CVE-2026-82834
A security issue has been identified in the Doccano Open Source Annotation Tools, particularly within the Bulk-Delete Endpoint for the LabelList function. This vulnerability allows for improper access control, potentially enabling remote exploitation. The issue affects versions of Doccano up to a...
PoC for CVE-2026-82833
A vulnerability exists in Doccano Open Source Annotation Tools that affects the Project Example Detail Endpoint in versions up to 1.8.5. This flaw allows unauthorized access due to improper access controls in the ExampleDetail function of the endpoint located at /v1/projects/1/examples/. Given th...
Discovered 18 hours ago
PoC for CVE-2026-82821
A vulnerability exists in FLVMeta, affecting versions up to 1.2.2, specifically within the AMF Object Parsing component. This deficiency enables an attacker to exploit the function amf_object_get located in the src/amf.c file, causing a null pointer dereference. Although the attack can be initiat...
PoC for CVE-2026-82820
A heap-based buffer overflow vulnerability exists in the AMF string processing function `amf_string_new` of FLVMeta up to version 1.2.2. This flaw arises from improper handling of argument length, allowing attackers to potentially exploit the vulnerability remotely. Although the project maintaine...
PoC for CVE-2026-82818
A significant access control vulnerability exists in dibo-software's diboot version 3.8.0, specifically affecting the Tenant Resource Assignment Handler found in the file /api/iam/tenant/resource. The vulnerability arises from improper validation of the tenantId argument, which could allow attack...
PoC for CVE-2026-82817
A vulnerability exists in dibo-software diboot version 3.8.0, related to the Tenant Administrator Management API. Unauthorized manipulation of the 'tenantId' argument leads to improper access controls, potentially enabling remote attackers to exploit the API without proper authorization. Despite ...
Discovered 19 hours ago
PoC for CVE-2026-82816
A vulnerability exists in Dibo-Software's Diboot version 3.8.0 involving the AI Session Endpoint located at /api/ai-session/. This issue allows for an authorization bypass, which can be exploited remotely. The nature of this vulnerability could expose sensitive functionalities of the application ...
PoC for CVE-2026-82815
A vulnerability has been identified in MegaEase EaseProbe up to version 2.3.0 that affects the realIP function in the Middleware component. The flaw involves the improper handling of the X-Forwarded-For/X-Real-IP/True-Client-IP headers, which can lead to unauthorized access. This vulnerability al...
PoC for CVE-2026-82813
A significant vulnerability has been identified in the TubeBuddy for YouTube Extension by BEN Group, affecting versions up to 5.8.4 on Chrome browsers. The flaw resides in the TBGlobal.GetToken function within the tubebuddymaster1.js file, which fails to adequately verify the authenticity of data...
PoC for CVE-2026-82811
A security vulnerability has been identified in the Toggl Track Extension version 4.11.16 that allows remote attackers to exploit an origin validation error through the postMessage handler. This vulnerability could enable an attacker to manipulate messages coming from unauthorized origins. The ve...
Discovered 20 hours ago
PoC for CVE-2026-76569
A reflected XSS vulnerability has been identified in the Phoca Download extension used for Joomla. Malicious actors can exploit this flaw through the search GET parameter, potentially executing arbitrary JavaScript in the context of the user's browser, leading to unauthorized access and data expo...
PoC for CVE-2026-82810
A vulnerability has been discovered in the extension.vn 2FA Authenticator Extension version 1.0.0.2, specifically within the Background Service Worker component. The flaw resides in the function chrome.runtime.onMessageExternal.addListener, which fails to properly manage the sender.id argument. T...
PoC for CVE-2026-82809
An information disclosure vulnerability has been identified in the vidIQ Vision for YouTube Extension (version 3.199.0) for Chrome. The flaw resides in the window.addEventListener method utilized by the postMessage handler, allowing an attacker to manipulate the argument 'vidiqEvent' and extract ...
PoC for CVE-2026-82808
A vulnerability has been detected in the Inbox Foundry ActiveInbox Extension for Chrome, which affects versions up to 7.10.24. It involves the improper handling of Google OAuth Client Secret within the file dist/service-worker.production-esm.js. This flaw allows an attacker to manipulate hard-cod...
PoC for CVE-2026-82807
A local privilege escalation vulnerability exists in the ieungSoft Ultra RAMDisk Pro 1.82. The issue is located in the URDSCSI.sys library within the Kernel Driver component, where inadequate privilege management can be exploited. The attack requires local access to the system, and details of the...
Discovered 21 hours ago
PoC for CVE-2026-82805
A cross-site scripting vulnerability exists in Typora versions up to 1.13.8 and 1.14.6, affecting the Mermaid Rendering Engine. This flaw allows for the manipulation of the classDef/style argument, which can be exploited remotely. The vulnerability has been publicly disclosed, and users are advis...
PoC for CVE-2026-82803
A vulnerability exists in the Armink Struct2json library in version 1.0, specifically in the function S2J_STRUCT_GET_string_ELEMENT located in the header file `s2jdef.h`, which is responsible for JSON deserialization. This flaw arises from the manipulation of the argument `valuestring`, leading t...
PoC for CVE-2026-82802
A vulnerability has been identified in NASA's Earthdata-Search version 1.0.0 related to the OpenSearchGranuleSearchLambda function, located in the handler.js file. This flaw allows an attacker to manipulate the openSearchOsdd argument, potentially leading to a server-side request forgery (SSRF). ...
PoC for CVE-2026-82801
A vulnerability exists in the scaleImage function within the serverless/src/scaleImage/handler.js file of NASA's Earthdata-Search product version 1.0.0. This flaw allows a remote attacker to exploit the scale Endpoint, potentially leading to unauthorized server-side request forgery (SSRF). The ex...
Discovered 22 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-82703
A security vulnerability has been identified in the Edimax BR-6214K router, specifically affecting the asp_setPing endpoint within the file www/ping.asp. This flaw allows an attacker to manipulate the pingstr argument, enabling remote OS command injection. The exploitation of this vulnerability p...
PoC for CVE-2026-82702
A significant OS command injection vulnerability exists in the Edimax BR-6214K Router, specifically within the www/wlanMP.asp file of the asp_WlanMP Endpoint. By manipulating the eatFunc argument, an attacker can exploit this flaw remotely, potentially allowing unauthorized access to execute syst...
PoC for CVE-2026-82701
A vulnerability exists in the Online Shopping System version 1.0, specifically within the Search Functionality component. An attacker can manipulate the 'keyword' parameter in the /action.php file, leading to a SQL injection exploit. This vulnerability can be triggered remotely, making it crucial...
PoC for CVE-2026-82700
A cross-site scripting vulnerability has been identified in the Online Shopping System 1.0 developed by Code-Projects, specifically within the Newsletter Subscription feature accessed via the /offersmail.php file. An attacker can exploit this vulnerability by manipulating the 'email' argument, po...
Discovered 23 hours ago
PoC for CVE-2026-82699
A vulnerability exists within the sambitraj Student Management System, specifically in the Password Handler component of the aca.sql file. This flaw allows for the manipulation of the Password argument, resulting in the potential cleartext storage of sensitive user information. The vulnerability ...
PoC for CVE-2026-82698
The sambitraj Student-Management-System is affected by a vulnerability that allows attackers to exploit a default password found in the aca.sql file. This security flaw enables unauthorized remote access to the system. As the exploit is now publicly available, it presents a significant risk to us...
PoC for CVE-2026-82697
A vulnerability has been identified in the sambitraj Student-Management-System that affects the session management functionality. Specifically, the 'session_start' function does not enforce the 'HttpOnly' flag on session cookies, exposing users to potential session hijacking. This vulnerability c...
PoC for CVE-2026-82696
A security vulnerability exists within version 1.0 of the itsourcecode Sales and Inventory System, specifically in the /pages/inv_searchfrm.php file. This flaw allows attackers to manipulate input arguments, leading to potential SQL injection attacks. These attacks can be executed remotely, makin...
Discovered 1 day ago
PoC for CVE-2026-82695
A security flaw has been identified in Tenda AC18 routers where the Telnet handler is susceptible to missing authentication. This vulnerability allows attackers to access critical functions of the router remotely, making it possible to exploit the device without authentication. The exploit has be...
PoC for CVE-2026-82694
A security vulnerability has been detected in the Tenda AC1206 device, specifically within the Web User Interface (UI) where the R7WebsSecurityHandler function lacks proper authentication checks. This flaw enables remote attackers to gain unauthorized access, potentially leading to exploitation o...
PoC for CVE-2026-82693
A significant security vulnerability has been identified in the Tenda AC1206's Web UI, specifically affecting the Telnet function. This flaw allows unauthorized remote access to the system through the /goform/telnet interface due to inadequate authentication measures. As a result, attackers can e...