Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 5 hours ago
PoC for CVE-2026-49114
In ONNX versions prior to 1.21.0, a vulnerability exists in the 'save_external_data' function that allows a local attacker to exploit symlinks when writing external data. This issue arises because the function constructs the file path from the model's external_data location field and opens it wit...
Discovered 9 hours ago
PoC for CVE-2026-19848
The ProfilePress plugin for WordPress, prior to version 4.17.1, is susceptible to a vulnerability that fails to adequately sanitize input in profile fields before rendering. This flaw enables unauthenticated attackers to inject shortcodes, which are executed when the affected profile page is view...
PoC for CVE-2026-18356
The Limit Login Attempts Reloaded plugin for WordPress is susceptible to an authentication bypass due to its failure to perform case-insensitive comparisons on its username denylist. Furthermore, the plugin does not consider the account's associated email address, which allows blocked accounts to...
PoC for CVE-2026-17559
The Passster plugin for WordPress prior to version 4.3.9 contains a flaw that allows unauthenticated attackers to bypass globally set password protections due to improper comparison of REST API endpoint paths. Instead of accurately matching resolved routes, the plugin evaluates paths as unanchore...
PoC for CVE-2026-16650
The Charitable WordPress plugin prior to version 1.8.12 contains a critical flaw that allows unauthenticated attackers to forge payment webhook notifications. This occurs due to the plugin's failure to verify the authenticity of incoming Square payment webhooks, enabling attackers to mark donatio...
PoC for CVE-2026-15150
The myCred plugin for WordPress prior to version 3.2.5 contains a security flaw that allows attackers to manipulate the in-site currency system. Specifically, the plugin fails to validate whether the payment notification received corresponds to a legitimate merchant account configured by the site...
PoC for CVE-2026-15046
The LitExtension WordPress plugin, up to version 1.2.5, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This issue stems from the plugin's failure to verify nonce tokens before allowing administrative actions. An attacker can exploit this oversight by tricking an authenticate...
PoC for CVE-2026-13176
The Eventin WordPress plugin prior to version 4.1.21 has a significant vulnerability where it fails to validate user-provided webhook URLs associated with events. This oversight allows users with contributor-level access or higher to send concealed server-side requests to any external server, pot...
Discovered 10 hours ago
PoC for CVE-2026-77686
A vulnerability exists in Dolibarr versions up to 23.0.4, specifically within the Account Handler component located in htdocs/user/card.php. The issue arises from improper handling of the argument ID, allowing unauthenticated users to gain access to functionalities they should not be permitted to...
PoC for CVE-2026-77683
A security flaw has been identified in the Comfast CF-N1-S, specifically in version 2.6.0.1. The vulnerability affects the /cgi-bin/mbox-config?method=SET§ion=ntp_timezone file, where manipulation of the 'timestr' argument can lead to command injection attacks. This vulnerability can be explo...
Discovered 11 hours ago
PoC for CVE-2026-77681
A vulnerability exists within the CodeAstro Online Job Portal 1.0 that allows attackers to exploit the file '/users/update-profile.php'. This security flaw enables remote attackers to manipulate the 'Name' argument, leading to unrestricted file uploads. The exploitation does not require any speci...
Discovered 15 hours ago
PoC for CVE-2026-19085
The Duplicate Post plugin for WordPress before version 1.5.6 fails to properly validate user permissions, allowing users with limited roles to duplicate posts that are password-protected. This oversight enables unauthorized users to republish sensitive content without permission, posing a signifi...
PoC for CVE-2026-19435
The Duplicate Post plugin for WordPress prior to version 1.5.6 has a serious access control flaw that fails to properly verify user capabilities when retrieving post data. This oversight allows users with delegated roles to access sensitive content, including metadata and passwords associated wit...
PoC for CVE-2026-75796
The AI Engine plugin for WordPress, prior to version 3.6.1, contains a vulnerability that fails to properly validate user permissions for privileged management actions. This allows unauthorized users with Administrator roles on Multisite sub-sites to gain control over any account within the netwo...
PoC for CVE-2026-14601
The Link Whisper Free WordPress plugin versions before 0.9.7 is susceptible to SQL injection due to inadequate sanitization and escaping of parameters in SQL queries. This vulnerability allows authenticated users with the Editor role or higher to manipulate database queries, potentially compromis...
PoC for CVE-2026-16576
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress versions prior to 5.0.14 contains a flaw in its admin REST API routes. Specifically, it fails to accurately verify user capabilities, allowing unauthorized users—such as Shop Managers—access to install and act...
PoC for CVE-2026-16575
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress, prior to version 5.0.14, suffers from an access control vulnerability. This flaw arises from the plugin's failure to adequately restrict access to commission configuration data available through unauthenticat...
PoC for CVE-2026-16577
The Dokan plugin for WordPress suffers from a significant payment processing flaw. Versions prior to 5.0.14 allow vendors to submit reverse-withdrawal payment amounts without proper validation against their actual outstanding balances. This deficiency enables malicious vendors to manipulate their...
PoC for CVE-2026-16959
The Media Library Assistant plugin for WordPress is susceptible to SQL injection due to improper validation of search parameters used in media-library query handlers. This vulnerability enables users with the Author role to inject malicious SQL code into queries, potentially compromising the data...
PoC for CVE-2026-18781
The Drag and Drop Multiple File Upload functionality in the Contact Form 7 WordPress plugin is susceptible to a security flaw where it fails to validate the final name of uploaded files after removing certain characters. This oversight allows unauthenticated users to bypass restrictions on file t...
PoC for CVE-2026-14325
The Drag and Drop Multiple File Upload for Contact Form 7 plugin, prior to version 1.3.9.9, contains a vulnerability where it fails to properly escape one of its settings used as an HTML tag name during front-end output. This flaw enables users with administrator access to inject arbitrary web sc...
PoC for CVE-2026-16962
The Tamara Checkout plugin for WordPress is susceptible to a vulnerability where it fails to properly verify the order key and nonce during payment cancellation and failure processes. This fault allows an unauthenticated attacker to manipulate WooCommerce order statuses by simply providing numeri...
PoC for CVE-2025-15671
The Welcart e-Commerce plugin for WordPress prior to version 2.12.1 is susceptible to a session fixation vulnerability. This allows an unauthenticated attacker to manipulate the session identifier by supplying a crafted request parameter. Consequently, if a victim logs in after being lured, the a...
PoC for CVE-2026-13736
The NewPath WildApricotPress Add-on for WordPress, up to version 1.0.0, has a vulnerability that fails to protect the privacy of members' fields. This issue allows unauthenticated users to access sensitive information, namely member email addresses and phone numbers, that should only be visible t...
Discovered 19 hours ago
PoC for CVE-2026-77392
A vulnerability exists in the SourceCodester Dynamic Input Field Generator where the 'saveUser' function within the 'submit.php' file fails to properly validate input. Specifically, the manipulation of the 'Researcher' argument allows for SQL injection attacks, which can be executed remotely. Giv...
PoC for CVE-2026-77391
A security flaw has been identified in the SourceCodester Dynamic Input Field Generator, which utilizes HTML, CSS, and PHP. This vulnerability allows an attacker to manipulate a specific function, resulting in cross-site request forgery (CSRF) attacks that can be executed remotely. Exploiting thi...
Discovered 23 hours ago
PoC for CVE-2026-53804
The OTRS Community Edition is affected by an OS command injection flaw within its PGP encryption module. This vulnerability allows administrators to execute arbitrary commands on the operating system by crafting specific values for the PGP binary path and command options. Because user-supplied co...
Discovered 1 day ago
PoC for CVE-2026-77148
A stack-based buffer overflow vulnerability exists in the Comfast CF-N1-S Web Management interface within the function sub_44B50C of the mbox-config component. This issue can be exploited remotely, allowing attackers to manipulate certain inputs to overflow the stack, potentially leading to arbit...
PoC for CVE-2026-77036
A vulnerability exists in elunez eladmin versions up to 2.7, specifically within the EmailController, AliPayController, GeneratorController, and GenConfigController functions. This flaw allows for improper authorization that can be exploited remotely. The vulnerability was reported to the project...
PoC for CVE-2026-72844
The Lean 4 kernel fails to verify the structure within a projection expression aligns with the projected value's type. Consequently, the function environment::add_inductive does not properly type check nested inductive applications. This oversight permits a metaprogram to construct an ill-typed n...
PoC for CVE-2026-72844
The Lean 4 kernel fails to verify the structure within a projection expression aligns with the projected value's type. Consequently, the function environment::add_inductive does not properly type check nested inductive applications. This oversight permits a metaprogram to construct an ill-typed n...
PoC for CVE-2026-77031
A command injection vulnerability exists in the Tenda CH22 router, specifically within the function formcreateFileName of the file /goform/formcreateFileName. An attacker can manipulate the argument fileNameMit, enabling unauthorized execution of commands remotely. The potential for exploitation ...
PoC for CVE-2026-77025
A SQL injection vulnerability exists in the itsourcecode Hospital Management System version 1.0, specifically within the /viewappointmentpending.php file. This flaw allows attackers to manipulate the 'delid' argument, enabling them to execute unauthorized SQL queries. The vulnerability may be exp...
PoC for CVE-2026-77022
A security flaw has been identified in Comfast CF-N1-S version 2.6.0.1, specifically in the SSID Configuration component. This vulnerability resides in the function sub_44B438 within the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid. By manipulating the ssid argument, an attacker can tr...
PoC for CVE-2026-77020
A SQL injection vulnerability exists in the CodeAstro Apartment Visitor Management System version 1.0, specifically in the password-recovery.php file. This security flaw allows an attacker to manipulate the 'email' parameter, potentially leading to unauthorized data access. The exploitation can b...
PoC for CVE-2026-77019
A vulnerability exists in the CodeAstro Apartment Visitor Management System version 1.0, specifically within the file /apartment-visitor/forgotpw.php. An improperly handled argument 'secode' allows a SQL injection attack, enabling remote execution of unauthorized SQL commands. This vulnerability ...
PoC for CVE-2026-77004
A command injection vulnerability exists in the Comfast CF-N1-S version 2.6.0.1, specifically within the sprintf function of the /cgi-bin/mbox-config?method=SET§ion=ptest_sn endpoint. By manipulating the argument 'sn', an attacker can execute arbitrary commands remotely, leading to potential ...
PoC for CVE-2026-76998
A security vulnerability has been identified in the SourceCodester Simple Online Food Ordering System version 1.0. An SQL injection flaw exists in the /admin/ajax.php file, specifically in the delete_category action. This vulnerability allows attackers to manipulate the ID argument, potentially l...
PoC for CVE-2026-76997
A vulnerability exists in SourceCodester's Simple Online Food Ordering System version 1.0 that exposes the application to SQL injection attacks through the 'save_category' action in the 'ajax.php' file. This flaw allows a remote attacker to manipulate the 'ID' argument, facilitating unauthorized ...
PoC for CVE-2026-76996
A significant security flaw has been identified in the SourceCodester Simple Online Food Ordering System version 1.0, specifically within the /fos/admin/view_order.php file. This vulnerability involves a manipulation of the 'ID' argument, which can lead to SQL injection attacks. Such exploitation...
PoC for CVE-2026-76995
A vulnerability has been discovered in the SourceCodester Simple Online Food Ordering System that allows for unrestricted file uploads through manipulation of the img argument in the /admin/ajax.php?action=save_menu endpoint. This flaw can be exploited remotely, potentially allowing attackers to ...
PoC for CVE-2026-76993
A security vulnerability exists in GreyDGL's PentestGPT, specifically affecting the web-page crawling component. This flaw allows attackers to manipulate the Traceback argument, enabling remote code injection. Although the complexity of the exploit is considered high, its potential for exploitati...
PoC for CVE-2026-76991
A serious SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0, specifically within the /viewappointmentapproved.php file. This flaw allows an attacker to manipulate the 'delid' argument, potentially leading to unauthorized access to the database. Remote explo...
PoC for CVE-2026-76990
A remote SQL injection vulnerability is present in the Code-Projects Simple Inventory System 1.0, specifically in the /delete.php file. By manipulating the argument ID, an attacker can execute unauthorized SQL commands against the database, potentially leading to unauthorized data exposure or mod...
PoC for CVE-2026-76989
A security vulnerability exists within the liftoff-sr CIPster product that affects the TCP Encapsulation Receive Path. Specifically, an unknown function in the source file source/src/enet_encap/encap.cc allows for out-of-bounds reading due to improper input validation. This flaw can be exploited ...
PoC for CVE-2026-76988
A vulnerability has been identified in the Liftoff-sr CIPster, specifically in the function CipConnMgrClass::forward_open located in cipconnectionmanager.cc. This can be exploited through manipulation of the product_code_ argument, leading to potential out-of-bounds read conditions. The vulnerabi...
PoC for CVE-2026-76987
A significant vulnerability has been identified in the liftoff-sr CIPster's Generic Attribute Logic, specifically in the CipAttribute::GetAttrData and CipAttribute::SetAttrData functions located in the ciptypes.h file. This flaw can lead to memory corruption through manipulation, enabling potenti...
Discovered 2 days ago
PoC for CVE-2026-75860
The JSON Options WordPress plugin prior to version 0.0.4 contains a significant security flaw that lacks proper capability checks and nonce verification. This oversight permits unauthenticated users to trigger actions that alter arbitrary WordPress options on every request. By exploiting this vul...
PoC for CVE-2026-74992
The Kirki WordPress plugin, prior to version 6.2.3, features a vulnerability where file validation for user-uploaded archives is inadequate. Users with the Editor role can upload malicious files, as the plugin fails to securely handle these uploads by not correctly removing all unnecessary files ...
PoC for CVE-2026-19699
The GutenKit plugin for WordPress, prior to version 2.5.0, lacks adequate capability verification on certain REST API endpoints. This oversight allows users with Contributor privileges and higher to access sensitive mailing-list audience metadata linked to the site's marketing account. Without pr...