Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2026-31816

BudibaseBudibase🟣 EPSS 15%9.1CRITICAL
Unauthorized API Access Vulnerability in Budibase Low Code Platform

Budibase, a low code platform for creating internal tools, exhibits a significant vulnerability in its server's authorization mechanism. In versions 3.31.4 and earlier, the 'authorized()' middleware designed to protect server-side API endpoints can be bypassed entirely by appending a specific web...

Discovered 2 hours ago

PoC for CVE-2026-52715

WordPressGeo My WordPress9.3CRITICAL
Unauthenticated SQL Injection in GEO my WordPress Plugin by GEO my WP

An unauthenticated SQL injection vulnerability exists in the GEO my WordPress plugin prior to version 4.5.5. This vulnerability can be exploited by sending crafted requests that manipulate SQL queries, potentially allowing an attacker to retrieve sensitive data from the database. It is crucial fo...

Discovered 4 hours ago

PoC for CVE-2021-41773

ApacheApache Http Server🟣 EPSS 100%7.5HIGH
Path traversal and file disclosure vulnerability in Apache HTTP Ser...

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default config...

Discovered 5 hours ago

PoC for CVE-2026-53365

LinuxLinux
Linux Kernel Vulnerability in Vsock Handling

A vulnerability exists in the Linux kernel's vsock/virtio implementation regarding zerocopy completion for multi-segment sends. If a large message is fragmented into multiple skbs, only the last skb has the zerocopy user argument (uarg) allocated, leaving non-final skbs with pinned user pages tha...

PoC for CVE-2026-8452

NetscalerAdc8.8HIGH
Memory Overflow Vulnerability in NetScaler ADC and Gateway by Citrix

A memory overflow vulnerability has been identified in Citrix's NetScaler ADC and NetScaler Gateway, which may lead to unpredictable behavior and potential denial of service if configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. This vulnerability can compromise s...

Discovered 7 hours ago

PoC for CVE-2026-54433

RoundcubeWebmail7.2HIGH
Stored Cross-Site Scripting Vulnerability in Roundcube Webmail Product

A stored cross-site scripting (XSS) vulnerability exists in Roundcube Webmail prior to version 1.6.17 and in the 1.7.x series before 1.7.2. An attacker can exploit this vulnerability by sending a specially crafted plain-text email message. Upon the victim opening or previewing the email, the atta...

Discovered 9 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 12 hours ago

PoC for CVE-2026-19847

TotolinkA800r8.7HIGH
Stack-based Buffer Overflow in TOTOLINK A800R Wireless Router

A security flaw has been identified in the TOTOLINK A800R router, specifically in the setWiFiWpsConfig function within the /cgi-bin/cstecgi.cgi file of the wps.so component. By manipulating the argument pin, an attacker can trigger a stack-based buffer overflow, allowing for potential remote expl...

PoC for CVE-2026-19846

TotolinkA800r8.7HIGH
Buffer Overflow in TOTOLINK A800R Firewall Component

A stack-based buffer overflow vulnerability exists in the setUrlFilterRules function of the firewall component in the TOTOLINK A800R router. This vulnerability can be exploited remotely by manipulating the url parameter in the /cgi-bin/cstecgi.cgi file. If successfully executed, it may lead to un...

PoC for CVE-2026-19845

TotolinkA800r8.7HIGH
Stack-based Buffer Overflow in TOTOLINK A800R Router

A vulnerability exists in the TOTOLINK A800R router's setStaticDhcpConfig function, located in the /cgi-bin/cstecgi.cgi file within the lan.so component. An attacker can exploit this vulnerability by manipulating the Comment argument, which can lead to a stack-based buffer overflow. This vulnerab...

PoC for CVE-2026-19844

TotolinkA800r8.7HIGH
Stack-Based Buffer Overflow in TOTOLINK A800R Router Firmware

A stack-based buffer overflow vulnerability exists in the TOTOLINK A800R router firmware version 4.1.2cu.5137_B20200730, specifically within the setRadvdCfg function located in /cgi-bin/cstecgi.cgi of the ipv6.so component. An attacker can exploit this vulnerability by manipulating the radvdinter...

Discovered 13 hours ago

PoC for CVE-2026-19839

SourcecodesterSimple Doctors Appoint...5.1MEDIUM
Unrestricted File Upload Vulnerability in SourceCodester Simple Doc...

The Simple Doctors Appointment System version 1.0 by SourceCodester contains a vulnerability in the save_doctor function located in /save_file.php. This flaw allows attackers to remotely upload files without proper restrictions, posing significant security risks to the system. The exploit method ...

PoC for CVE-2026-19838

WebkulBagisto5.3MEDIUM
Authorization Bypass Vulnerability in Webkul Bagisto Backend Report...

A significant security issue has been identified in the Webkul Bagisto platform, specifically within the Backend Reporting Endpoint located at /admin/reporting/sales/. This vulnerability allows unauthorized users to bypass access controls, potentially leading to unauthorized data exposure and man...

PoC for CVE-2026-72550

FriendicaFriendica9.8CRITICAL
SQL Injection Vulnerability in Friendica Affected by Unauthenticate...

An SQL injection vulnerability exists in Friendica through the 2026.08-dev branch. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. As this parameter is concatenated without proper escaping into a SHOW COLUMNS query through ...

PoC for CVE-2026-19837

WebkulBagisto5.1MEDIUM
Information Disclosure Vulnerability in Webkul Bagisto eCommerce Pl...

A vulnerability has been discovered in the Webkul Bagisto eCommerce platform, specifically affecting versions up to 2.4.4 in the Customer Search component. This weakness allows attackers to manipulate the 'Query' argument in the /admin/customers/search file, potentially leading to information exp...

Discovered 14 hours ago

PoC for CVE-2026-19836

WebkulBagisto5.3MEDIUM
Authorization Bypass Vulnerability in Webkul Bagisto Backend Custom...

A security vulnerability has been identified in Webkul Bagisto, specifically within the Backend Customer Detail Feature. The issue resides in the file /admin/customers/view, where manipulating the argument ID can lead to unauthorized access. This flaw allows attackers to remotely exploit the syst...

PoC for CVE-2026-19835

WebkulBagisto5.1MEDIUM
Access Control Vulnerability in Webkul Bagisto Customer Item Deleti...

A security flaw has been detected in Webkul's Bagisto platform up to version 2.4.4, specifically related to the Customer Item Deletion Endpoint. This flaw allows attackers to bypass normal access controls, leading to unauthorized manipulation of customer data. The vulnerability can be exploited r...

PoC for CVE-2026-19834

WebkulBagisto5.1MEDIUM
Authorization Bypass in Webkul Bagisto Admin Customer Impersonation...

A vulnerability exists in the Admin Customer Impersonation feature of Webkul Bagisto versions up to 2.4.4. This flaw allows unauthorized access due to the manipulation of the argument ID within the login-as-customer function. The exploitation of this vulnerability can be initiated remotely, posin...

Discovered 15 hours ago

PoC for CVE-2026-19829

648540858Wvp-gb28181-pro5.3MEDIUM
Path Traversal Vulnerability in 648540858 wvp-GB28181-pro Product

A vulnerability has been identified in the 648540858 wvp-GB28181-pro product version 2.7.4-20260107, specifically within the Log File Download Endpoint in the LogController.java file. This flaw allows an attacker to manipulate the fileName argument, potentially leading to path traversal attacks. ...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 16 hours ago

PoC for CVE-2026-19828

648540858Wvp-gb28181-pro5.3MEDIUM
Path Traversal Vulnerability in 648540858 wvp-GB28181-pro Product

A path traversal vulnerability was identified in the 648540858 wvp-GB28181-pro version 2.7.4-20260107. The issue resides in the PlayController.java file, specifically concerning the Snapshot Endpoint. An attacker can manipulate the deviceId or channelId arguments, allowing unauthorized access to ...

PoC for CVE-2026-19827

AlldatacenterAlldata6.9MEDIUM
Path Traversal Vulnerability in alldatacenter Alldata Product

A security flaw exists in the 'logDetailCat' endpoint of alldatacenter Alldata up to version 0.6.8, specifically within the FileInputStream function in the JobLogController.java file. This vulnerability arises from improper validation of user input, allowing attackers to perform path traversal by...

PoC for CVE-2026-19826

AlldatacenterAlldata6.9MEDIUM
Deserialization Vulnerability in alldatacenter alldata by alldatace...

A vulnerability has been identified in alldatacenter alldata version 0.6.8, impacting the Hessian2Input.readObject function within the /serialize/impl/HessianSerializer.java file of the xxl-rpc Listener component. This deserialization issue allows remote attackers to manipulate data, leading to p...

PoC for CVE-2026-19825

SourcecodesterSimple Client Manageme...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Simple Client Managem...

A security vulnerability has been identified in SourceCodester Simple Client Management System 1.0, specifically affecting a function within the file /classes/Master.php?f=save_service. By manipulating the argument ID, an attacker can launch a SQL injection attack remotely. The exploit has been m...

Discovered 17 hours ago

PoC for CVE-2026-19824

TendaW20e8.7HIGH
Stack-Based Buffer Overflow in Tenda W20E Router

A vulnerability has been discovered in the Tenda W20E router that allows for a stack-based buffer overflow through the ipMacBindListStore function in the /goform/addIpMacBind file. By manipulating the IPMacBindRule argument, an attacker can exploit this weakness remotely, potentially leading to u...

PoC for CVE-2026-19823

TendaW20e8.7HIGH
Stack-Based Buffer Overflow in Tenda W20E QoS Rule Deletion Function

A security vulnerability has been identified in the Tenda W20E router that affects the QoS Rule Deletion feature. The issue resides within the formQOSRuleDel function located in the /goform/delQos file. An attacker can exploit this flaw by manipulating the qosIndex argument, leading to a stack-ba...

Discovered 18 hours ago

PoC for CVE-2026-19822

TendaW20e8.7HIGH
Remote Stack-Based Overflow in Tenda W20E via QoS Edit Function

A security issue was identified in the Tenda W20E router that affects the QoS Edit functionality. Specifically, the vulnerability resides in the lstAdd function located in the /goform/editQos file, allowing for a stack-based buffer overflow due to improper handling of the qosListConnecttedNum arg...

PoC for CVE-2026-19821

TendaAc128.7HIGH
Buffer Overflow Vulnerability in Tenda AC12 Web Management Interface

A vulnerability exists in the Tenda AC12's web management interface within the formSetRebootTimer functionality located in the file /goform/SetSysAutoRebbotCfg. This flaw allows an attacker to manipulate the rebootTime argument, causing a buffer overflow that could enable remote exploitation. The...

Discovered 21 hours ago

PoC for CVE-2026-19815

TotolinkA800r8.7HIGH
Stack-Based Buffer Overflow in TOTOLINK A800R Firewall Component

A critical flaw has been identified in the TOTOLINK A800R firmware version 4.1.2cu.5137_B20200730, specifically within the setParentalRules function of the firewall component (file: /cgi-bin/cstecgi.cgi). This vulnerability allows for a stack-based buffer overflow that can be triggered by manipul...

PoC for CVE-2026-19814

TotolinkA800r8.7HIGH
Stack-Based Buffer Overflow in TOTOLINK A800R Firewall Component

A vulnerability has been identified in the TOTOLINK A800R router, specifically within the setMacQos function located in the /cgi-bin/cstecgi.cgi file of the firewall component. By manipulating the macAddress argument, a remote attacker could exploit this flaw, leading to a stack-based buffer over...

PoC for CVE-2026-19813

TotolinkA800r8.7HIGH
Buffer Overflow Vulnerability in TOTOLINK A800R Firewall Component

A vulnerability has been identified in the TOTOLINK A800R router, specifically within the firewall component's setMacFilterRules function. This issue arises due to improper handling of the Comment argument in the /cgi-bin/cstecgi.cgi file, leading to a stack-based buffer overflow condition. Attac...

Discovered 22 hours ago

PoC for CVE-2026-19812

TotolinkA800r8.7HIGH
Buffer Overflow in TOTOLINK A800R Router Software

A vulnerability has been found in the TOTOLINK A800R router version 4.1.2cu.5137_B20200730, specifically in the UploadCustomModule function located in the /cgi-bin/cstecgi.cgi file of the product.so component. This vulnerability allows an attacker to manipulate the File argument, potentially lead...

Discovered 23 hours ago

PoC for CVE-2026-19811

TotolinkA800r8.7HIGH
Buffer Overflow Vulnerability in TOTOLINK A800R's Firewall Component

A security flaw has been identified in the TOTOLINK A800R router affecting the setIpQosRules function within the firewall component. This vulnerability enables a remote attacker to manipulate the Comment argument, leading to a stack-based buffer overflow. The Public exploitation of this flaw pose...

PoC for CVE-2026-18039

WordPressEssential Addons For E...8.1HIGH
User Attribute Manipulation in Essential Addons for Elementor by WP...

The Essential Addons for Elementor plugin for WordPress, prior to version 6.7.2, contains a vulnerability that permits unauthenticated users to manipulate user registration fields. This flaw allows attackers to overwrite predefined user attributes, enabling them to assign arbitrary roles—includin...

PoC for CVE-2026-16739

WordPressEpeken All Kurir For W...5.9MEDIUM
Payment Confirmation Vulnerability in Epeken All Kurir for WooComme...

The Epeken All Kurir for WooCommerce plugin version 2.1.2 contains a vulnerability where it fails to authenticate payment-confirmation requests. This oversight allows unauthorized users to falsely confirm orders without verifying their origin or the occurrence of actual transactions. As a result,...

PoC for CVE-2026-15205

WordPressPaymob For WooCommerce8.6HIGH
SQL Injection Vulnerability in Paymob for WooCommerce Plugin by Wor...

The Paymob for WooCommerce plugin prior to version 4.1.9 fails to adequately sanitize a user-supplied identifier used in SQL queries within its public payment callback. This occurs before the payment provider's HMAC signature is verified. As a result, it exposes the plugin to SQL injection attack...

PoC for CVE-2026-14290

WordPressEmbed Google Photos Album6.8MEDIUM
JavaScript Injection Vulnerability in Embed Google Photos Album Plu...

The Embed Google Photos album plugin for WordPress versions up to 2.2.1 is susceptible to a JavaScript injection vulnerability due to improper escaping of shortcode attribute values. This flaw enables authenticated users with a Contributor role or higher to inject malicious JavaScript code. When ...

PoC for CVE-2026-73673

Netis Systems Co....Netis Nc63 Wireless Ac...8.7HIGH
Unauthenticated Firmware Update Vulnerability in Netis NC63 Router

The Netis NC63 router firmware version 3.0.0.3327 has a significant vulnerability that allows attackers to initiate an unauthorized firmware update due to inadequate authentication checks in the web server. This security flaw enables malicious users to upload unsigned firmware images without requ...

Discovered 1 day ago

PoC for CVE-2024-40891

ZyxelVmg4325-b10a Firmware🟣 EPSS 22%8.8HIGH
Command Injection Vulnerability in Zyxel DSL CPE Firmware

A post-authentication command injection vulnerability exists in the management commands of Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615. This flaw allows an authenticated attacker to execute arbitrary operating system commands via Telnet, potentially compromising the security and i...

PoC for CVE-2026-19792

TendaG08.7HIGH
Buffer Overflow Vulnerability in Tenda G0 Web Management Interface

A vulnerability in the web management interface of Tenda G0 devices allows remote attackers to exploit buffer overflow via manipulated arguments in the setPortMapping function. This issue was found in the /goform/module file, which compromises the application's ability to handle input correctly, ...

PoC for CVE-2026-19791

TendaG08.7HIGH
Stack-based Buffer Overflow in Tenda G0 Router Web Management Inter...

A vulnerability has been discovered in the Tenda G0 router related to its web management interface. Specifically, the function addStaticRoute in the /goform/module file has a flaw that allows for a stack-based buffer overflow. By manipulating the argument staticRouteNet, an attacker can execute a...

PoC for CVE-2026-19790

TendaG08.7HIGH
Stack-Based Buffer Overflow in Tenda G0 Web Management Interface

A vulnerability exists in the Tenda G0's Web Management Interface, specifically within the function formSetPortMirror located in the /goform/module file. This issue arises from improper handling of the argument portMirrorMirroredPorts, leading to a stack-based buffer overflow. The vulnerability c...

PoC for CVE-2026-19789

TendaAc12068.7HIGH
Buffer Overflow Vulnerability in Tenda AC1206 Router's Web Manageme...

A security flaw exists in the Tenda AC1206 router's web management interface, specifically within the function set_wl_guest_iplist located in /goform/WifiGuestSet. This vulnerability allows for a stack-based buffer overflow due to improper handling of the shareSpeed argument. Successful exploitat...

PoC for CVE-2026-19788

TendaAc12068.7HIGH
Stack-Based Buffer Overflow in Tenda AC1206 Web Management Interface

A stack-based buffer overflow vulnerability exists in the Tenda AC1206 web management interface, specifically within the set_device_name function of the /goform/SetOnlineDevName endpoint. By manipulating the devName parameter, an attacker can exploit this vulnerability remotely, leading to potent...

PoC for CVE-2026-19787

SourcecodesterAir Cargo Management S...5.1MEDIUM
SQL Injection Vulnerability in SourceCodester Air Cargo Management ...

A vulnerability exists in the SourceCodester Air Cargo Management System version 1.0 that allows for SQL injection through the manipulation of the ID parameter in the Master.php file, specifically within the save_cargo_type function. This vulnerability can be exploited remotely, enabling attacker...

PoC for CVE-2026-19784

FrancoisjacquetRosariOSis5.3MEDIUM
Authorization Bypass in RosarioSIS by Francoiscjacquet

A vulnerability has been identified in RosarioSIS versions prior to 12.9, specifically affecting the DBUpdate function within Discipline/Referrals.php. This flaw results in an authorization bypass that can be exploited remotely. The exploit is publicly available, posing substantial risks to users...

PoC for CVE-2026-19771

BaicellsEg3661m8.6HIGH
OS Command Injection Vulnerability in Baicells EG3661M LuCI Web Int...

A vulnerability exists in the Baicells EG3661M due to improper handling of MaxHops, Timeout, and Size parameters in the LuCI Web Interface. This flaw allows an attacker to execute arbitrary commands on the operating system through remote exploitation. Without a timely vendor response to reported ...

PoC for CVE-2026-19770

FeedmobFm-mcp-servers4.8MEDIUM
Server-Side Request Forgery Vulnerability in Feedmob FM-MCP-Servers

A security vulnerability exists in Feedmob's FM-MCP-Servers version 0.0.3, specifically within the 'downloadReport' function located in the Download Endpoint module. This issue arises from the manipulation of the 'downloadUrl' argument, enabling an attacker to perform server-side request forgery ...

PoC for CVE-2026-19767

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A vulnerability has been detected in the itsourcecode Hospital Management System 1.0, specifically in the file viewdoctortimings.php. This issue arises from improper handling of input parameters, primarily the 'delid' argument, which enables remote attackers to execute SQL injection attacks. Such...

PoC for CVE-2026-41940

WebprosCpanel🟣 EPSS 98%9.3CRITICAL
Authentication Bypass Vulnerability in cPanel and WHM

The affected versions of cPanel and WHM contain a serious authentication bypass flaw in the login flow. This vulnerability enables unauthenticated remote attackers to bypass authentication mechanisms, allowing them to gain unauthorized access to the control panel. Users of the specified versions ...