Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 23 minutes ago

PoC for CVE-2026-42533

F5Nginx Plus9.2CRITICAL
Heap Buffer Overflow in NGINX Plus and Open Source during Regex Map...

A vulnerability in NGINX Plus and NGINX Open Source arises when a map directive improperly utilizes regex matching in conjunction with string expressions referencing the map’s regex capture variables before the map output variable, or when non-cacheable variables are used under specific condition...

Discovered 45 minutes ago

PoC for CVE-2021-41773

ApacheApache Http Server🟣 EPSS 100%7.5HIGH
Path traversal and file disclosure vulnerability in Apache HTTP Ser...

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default config...

Discovered 2 hours ago

PoC for CVE-2026-65702

Vanna-aiVanna8.8HIGH
Path Traversal Vulnerability in Vanna by Vanna Ltd.

The Vanna application prior to version 2.0.2 has a path traversal flaw within its FileSystemConversationStore persistence integration. This vulnerability permits unauthenticated remote attackers to exploit the conversation_id parameter in the chat API. By injecting path traversal sequences, attac...

PoC for CVE-2026-65701

Svc-develop-teamSo-vits-svc9.3CRITICAL
Path Traversal Vulnerability in SoftVC VITS Singing Voice Conversion

The SoftVC VITS Singing Voice Conversion product contains a path traversal vulnerability within its full-song inference server. This flaw allows unauthenticated remote attackers to exploit the system by supplying malicious filesystem paths through the 'audio_path' field in an unauthenticated POST...

Discovered 3 hours ago

PoC for CVE-2026-65700

H2oaiH2ogpt9.3CRITICAL
Path Traversal Vulnerability in h2oGPT Product by OpenAI

The h2oGPT application, up to version 0.2.1, contains a vulnerability allowing unauthenticated attackers to exploit the OpenAI-compatible files API. By leveraging traversal sequences within the bearer token, attackers can bypass authentication mechanisms, leading to unauthorized file reading, wri...

PoC for CVE-2026-65699

ReworkdAgentgpt2.3LOW
Authorization Bypass Vulnerability in AgentGPT by Geo Chen

AgentGPT version 1.0.0 has a critical flaw that permits authenticated users to bypass authorization checks by manipulating request parameters. This vulnerability allows users to attach tasks to agent runs belonging to other users without verifying ownership, posing a significant risk of task hist...

PoC for CVE-2026-65698

VoideditorVoid6MEDIUM
Path Traversal Vulnerability in Void AI Agent File-Reading Tools

Void versions up to 1.3.4 exhibit a path traversal vulnerability in their AI agent file-reading tools, which can be exploited by network-adjacent attackers. This flaw enables unauthorized access to arbitrary host files outside the designated workspace by injecting instructions into the content be...

PoC for CVE-2026-65697

UsefathomFathom5.1MEDIUM
Stored Cross-Site Scripting in Fathom Lite Analytics by Fathom

Fathom Lite versions up to 1.3.1 are vulnerable to a stored cross-site scripting (XSS) issue that affects the analytics collection functionality. This vulnerability allows unauthenticated attackers to inject malicious JavaScript code via crafted hostname and pathname inputs directed to the /colle...

PoC for CVE-2026-65696

SctOverseerr5.3MEDIUM
Authorization Bypass in Overseerr Affects User Record Confidentiality

Overseerr version 1.35.0 contains a significant vulnerability within its push subscription API that allows authenticated users to bypass authorization controls. By manipulating the userId in the API path, attackers can illicitly list, view, and delete push subscriptions belonging to other users. ...

PoC for CVE-2026-65695

GongrzheOffice-word-mcp-server7.6HIGH
Path Traversal Vulnerability in Office-Word-MCP-Server by Geo Chen

The Office-Word-MCP-Server, up to version 1.1.11, has a path traversal vulnerability in its document handling tools. This flaw allows unauthenticated attackers to manipulate the filename argument to read or overwrite .docx files beyond the designated working directory. The vulnerability arises fr...

Discovered 4 hours ago

PoC for CVE-2026-65917

UsmannasirCyberpanel8.7HIGH
Insecure Direct Object Reference Found in CyberPanel's Backup Manag...

CyberPanel, up to version 1.9.1, is susceptible to an insecure direct object reference (IDOR) vulnerability in its IncBackups application. Authenticated users can exploit this flaw to access or manipulate the backup resources of other tenants using a globally sequential IncJob ID that is not rest...

PoC for CVE-2026-65916

UsmannasirCyberpanel7.2HIGH
Authorization Bypass in CyberPanel Affects Backup Management

CyberPanel versions up to 1.9.1 are susceptible to a missing authorization vulnerability in the cancelBackupCreation handler. This flaw permits authenticated users to manipulate backup processes of other tenants, including terminating backups, deleting archives, and corrupting status files. By cr...

Discovered 6 hours ago

PoC for CVE-2026-16735

Release-itConventional-changelog4.8MEDIUM
OS Command Injection Vulnerability in release-it conventional-chang...

A security vulnerability exists in the release-it conventional-changelog component, specifically within the writeChangelog function found in index.js. By manipulating the infile argument, an attacker could execute OS commands, leading to potential exploitation. This vulnerability requires local a...

PoC for CVE-2024-37054

MlflowMlflow8.8HIGH
Arbitrary Code Execution Vulnerability in MLflow Platform

A significant security vulnerability exists within the MLflow platform developed by Databricks. This issue arises from the deserialization of untrusted data in versions 0.9.0 and later. Attackers exploit this vulnerability by uploading a malicious PyFunc model that, once interacted with, can exec...

PoC for CVE-2026-16733

BahmutovFind-cypress-specs4.8MEDIUM
OS Command Injection Vulnerability in bahmutov find-cypress-specs

A vulnerability exists in the bahmutov find-cypress-specs package, specifically in the shell.exec function located in src/index.js of the Branch Handler component. By manipulating the --branch argument, an attacker can execute arbitrary operating system commands. This vulnerability is limited to ...

Discovered 14 hours ago

PoC for CVE-2026-9577

WordPressPost Status Notifier Lite4.8MEDIUM
Reflected Cross-Site Scripting Vulnerability in Post Status Notifie...

The Post Status Notifier Lite WordPress plugin prior to version 1.13.0 is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability. This occurs due to insufficient sanitization of the `mod` URL parameter when reflected on the admin settings page. An attacker can exploit this vulnerabil...

PoC for CVE-2026-9066

WordPressWP Compress6.1MEDIUM
Reflected XSS Vulnerability in WP Compress Plugin for WordPress

The WP Compress plugin for WordPress prior to version 7.10.04 is susceptible to a Reflected XSS vulnerability due to improper validation of a query parameter that directs the asset CDN host. This security flaw allows attackers to manipulate script URLs, injecting malicious JavaScript that execute...

PoC for CVE-2026-12082

WordPressPraison Ai Seo7.5HIGH
Authorization Flaw in Praison AI SEO WordPress Plugin Exposes Confi...

The Praison AI SEO WordPress plugin versions prior to 5.0.7 contain an authorization bypass vulnerability that permits unauthorized users to modify permalinks for published posts. Additionally, this flaw enables access to sensitive configuration data within the plugin, which could compromise site...

PoC for CVE-2026-14291

WordPressSecurity-ninja-premium7.5HIGH
Two-Factor Authentication Bypass in Security Ninja Premium WordPres...

The Security Ninja Premium WordPress plugin versions prior to 5.290 have a significant flaw in their two-factor authentication implementation. An unauthenticated attacker equipped with a user's password can bypass the required one-time code needed for authentication. This vulnerability compromise...

Discovered 15 hours ago

PoC for CVE-2023-36003

MicrosoftWindows 10 Version 18096.7MEDIUM
Elevation of Privilege Vulnerability Affects XAML Diagnostics

XAML Diagnostics Elevation of Privilege Vulnerability

Discovered 16 hours ago

PoC for CVE-2025-64512

PDFminerPDFminer.six8.6HIGH
Arbitrary Code Execution in Pdfminer.six by Malicious PDF Files

Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...

Discovered 17 hours ago

PoC for CVE-2026-58138

Conductor-ossConductor9.3CRITICAL
Unauthenticated Remote Code Execution in Orkes Conductor by Orkes

An unauthenticated remote code execution vulnerability in Orkes Conductor versions prior to 3.30.2 could allow remote attackers to execute arbitrary operating system commands by submitting malicious JavaScript or Python expressions through workflow definitions to the workflow API endpoint without...

Discovered 18 hours ago

PoC for CVE-2026-6330

WolfsslWolfssl6.3MEDIUM
Ciphertext Comparison Flaw in WolfSSL's ML-KEM for ARM64 Architecture

A vulnerability in the ML-KEM implementation for ARM64 architecture in wolfSSL is related to improper ciphertext comparison during the encryption process. Specifically, the comparison method only examines half of the re-encrypted ciphertext, which undermines the effective security measures mandat...

PoC for CVE-2026-63030

WordPressWordPress🟣 EPSS 39%9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2026-16653

BoazsegevFacil.io6.9MEDIUM
Path Traversal Vulnerability in Facil.io by Boaz Segev

A significant security flaw has been identified in the facil.io framework, specifically within the http_sendfile2 function located in the file lib/facil/http/http.c, which serves as a Public Folder Handler. This vulnerability allows for path traversal attacks, enabling unauthorized access to rest...

PoC for CVE-2024-9264

GrafanaGrafana🟣 EPSS 98%9.4CRITICAL
Grafana SQL Expressions Vulnerability: Command Injection and Local ...

The experimental SQL Expressions feature in Grafana enables users to evaluate `duckdb` queries which can contain user input. However, the queries are inadequately sanitized prior to being processed by `duckdb`, creating a vulnerability that could lead to command injection and local file inclusion...

Discovered 20 hours ago

PoC for CVE-2026-16632

BoazsegevFacil.io6.9MEDIUM
Improper Input Validation in WebSocket Frame Parser of Facil.io by ...

A vulnerability has been identified in the facil.io library, affecting versions up to 0.7.4. The flaw resides in the websocket_on_protocol_error function located in the websocket_parser.h file. This vulnerability arises from improper input validation when manipulating the argument on_message, all...

PoC for CVE-2026-16631

Node.jsPublint4.8MEDIUM
OS Command Injection Vulnerability in publint Package Manager by No...

A vulnerability has been identified in the publint package manager affecting versions up to 0.1.4. This vulnerability is linked to the child_process.exec function within the src/node/pack.js file. It enables an attacker to execute arbitrary operating system commands through manipulated input. The...

Discovered 21 hours ago

PoC for CVE-2026-16630

SyncfusionEj2-javascript-ui-cont...4.8MEDIUM
OS Command Injection Vulnerability in Syncfusion EJ2 JavaScript UI ...

A security vulnerability has been discovered in Syncfusion's EJ2 JavaScript UI Controls that allows for an OS command injection via the child_process.exec function in package.json. This vulnerability is present in versions up to 33.2.3. Attackers must exploit this vulnerability locally to manipul...

Discovered 22 hours ago

PoC for CVE-2026-63030

WordPressWordPress🟣 EPSS 39%9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

Discovered 23 hours ago

PoC for CVE-2026-16628

HerokuOclif4.8MEDIUM
OS Command Injection Vulnerability in oclif by Heroku

A security vulnerability exists in oclif versions up to 4.23.16, allowing local users to exploit the 'child_process.exec' functionality in the JIT Plugin Entry Handler. By manipulating the 'jitPlugins' argument, an attacker can execute arbitrary operating system commands, potentially leading to u...

PoC for CVE-2024-3094

🟣 EPSS 86%10CRITICAL
Malicious Code Discovered in xz Upstream Tarballs, Affecting liblzm...

The XZ utility has been compromised due to malicious code introduced in the upstream tarballs starting from version 5.6.0. A sophisticated obfuscation technique is employed where the liblzma build process extracts a prebuilt object file hidden within a disguised test file in the source code. This...

PoC for CVE-2026-45729

ThorvgThorvg4.3MEDIUM
Null Pointer Dereference in Thor Vector Graphics Engine

A null pointer dereference vulnerability was identified in the Thor Vector Graphics Engine (ThorVG) prior to version 1.0.5. This vulnerability can cause the engine to crash when untrusted SVG data is processed through the Picture::load() function via the SvgLoader::run(). Attackers can exploit th...

Discovered 1 day ago

PoC for CVE-2026-63030

WordPressWordPress🟣 EPSS 39%9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2026-56139

ApacheApache Camel Undertow5.3MEDIUM
Sensitive Information Disclosure in Apache Camel Undertow Component

The Apache Camel Undertow Component contains a vulnerability that allows unauthorized clients to receive detailed error messages, including Java stack traces, during route processing failures. This occurs due to a misconfiguration of the muteException option, which defaults to false. This can lea...

PoC for CVE-2026-55994

ApacheApache Camel Iggy7.5HIGH
Server-Side Request Forgery and Information Exposure in Apache Came...

In the Apache Camel framework, the Iggy component has a vulnerability that allows unauthorized actors to exploit improper input validation, resulting in Server-Side Request Forgery (SSRF) and exposure of sensitive information. The issue arises as the Iggy component does not filter Camel-internal ...

PoC for CVE-2026-55993

ApacheApache Camel Atmospher...7.5HIGH
Improper Input Validation and SSRF in Apache Camel's Atmosphere Web...

A vulnerability in the Atmosphere Websocket Component of Apache Camel allows attackers to exploit improper input validation in inbound WebSocket queries. The absence of a HeaderFilterStrategy enables clients to inject control headers into the Camel Exchange. This results in potential server-side ...

PoC for CVE-2025-64512

PDFminerPDFminer.six8.6HIGH
Arbitrary Code Execution in Pdfminer.six by Malicious PDF Files

Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...

PoC for CVE-2026-65013

OnlookRepo8.7HIGH
Broken Object Level Authorization in Onlook Product by Onlook Dev

The Onlook product version 0.2.32 has a broken object level authorization vulnerability, allowing authenticated attackers to exploit tRPC API endpoints. By supplying arbitrary UUID values to procedures such as project.get, member.remove, and chat.conversation.delete, attackers can gain unauthoriz...

PoC for CVE-2026-65012

Invoke-aiInvokeai6.3MEDIUM
Unauthenticated Directory Enumeration in InvokeAI by Stability AI

InvokeAI prior to version 6.13.7 presents a vulnerability in the /api/v2/models/scan_folder endpoint, which allows unauthenticated users to exploit the scan_path parameter. This flaw permits attackers to recursively enumerate server filesystem directories, effectively exposing sensitive informati...

PoC for CVE-2026-64828

FroidenTabletrack5.3MEDIUM
Stored Cross-Site Scripting Vulnerability in Froiden TableTrack

Froiden TableTrack versions up to 1.3.10 are susceptible to a stored cross-site scripting vulnerability through the order notes field. This flaw permits unauthenticated attackers to inject arbitrary HTML and JavaScript into the application, allowing for malicious payloads to execute within the ad...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

PoC for CVE-2026-50522

MicrosoftMicrosoft Sharepoint E...🟣 EPSS 20%9.8CRITICAL
Deserialization Vulnerability in Microsoft SharePoint by Microsoft

The vulnerability allows an attacker to send specially crafted payloads to Microsoft Office SharePoint, potentially resulting in unauthorized remote code execution. This security flaw occurs due to the improper handling of untrusted data. If exploited, it could enable malicious actors to execute ...

PoC for CVE-2026-25632

WaterfuturesEpyt-flow10CRITICAL
Remote Code Execution Vulnerability in EPyT-Flow Python Package

The EPyT-Flow Python package, which facilitates the generation of hydraulic and water quality scenario data for water distribution networks, contains a vulnerability that enables remote code execution. Prior to version 0.16.1, the package's REST API incorrectly processes attacker-manipulated JSON...

Discovered 2 days ago

PoC for CVE-2024-27867

AppleAirpods4.3MEDIUM
Improved State Management Fixes Authentication Issue

The CVE-2024-27867 vulnerability affects a wide range of Apple’s wireless audio devices, including AirPods (2nd generation and later), AirPods Pro (all models), AirPods Max, Powerbeats Pro, and Beats Fit Pro. It allows an attacker within Bluetooth range to spoof the intended source device and gai...

PoC for CVE-2026-12987

WordPressEvents Manager7.5HIGH
PHP Object Injection Vulnerability in Events Manager WordPress Plugin

The Events Manager plugin for WordPress versions prior to 7.3.7 is vulnerable due to improper handling of booking-registration data in No-User-Account Booking Mode. Specifically, a registration field supplied by the booker is stored as booking metadata and later deserialized without restrictions ...

PoC for CVE-2026-12968

WordPressProduct Addons And Pro...8.8HIGH
Unauthenticated File Upload Vulnerability in Product Addons and Opt...

The Product Addons and Product Options With Custom Fields plugin for WordPress prior to version 1.6.15 is susceptible to an unauthenticated file upload vulnerability. This flaw allows attackers to exploit a file-upload endpoint that fails to properly restrict access, letting an unauthenticated us...

PoC for CVE-2026-14322

WordPressTimetics5.3MEDIUM
WordPress Timetics Plugin Vulnerability Allows Unauthenticated Book...

The Timetics WordPress plugin, prior to version 1.0.57, has a significant vulnerability that allows unauthorized users to create fully-approved bookings for paid appointments. This occurs due to the lack of enforcement of a pending or unpaid status for new bookings made through unsupported paymen...

PoC for CVE-2026-57588

TenableNessus1.6LOW
SQL Injection Vulnerability in Nessus by Tenable

A SQL injection vulnerability exists in Nessus that allows attackers to create a harmful scan result file. When a privileged user imports this file, it may result in malicious SQL being injected into the scan results database. This exploitation could lead to unauthorized access and potential data...

PoC for CVE-2026-60137

WordPressWordPress🟣 EPSS 20%5.9MEDIUM
SQL Injection Vulnerability in WordPress Core Affecting Multiple Ve...

A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...