Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 3 hours ago
PoC for CVE-2026-80214
The Virtualization Discovery module of LibreNMS is susceptible to a command line injection vulnerability that allows an authenticated admin user to execute arbitrary commands on the host server. This substantial flaw poses a risk to system integrity and confidentiality, enabling potential attacke...
Discovered 6 hours ago
PoC for CVE-2026-79912
A security flaw has been discovered in the TOTOLINK N600R router that allows for a command injection via the ntp_server argument in the getCurrentTime function located in the /cgi-bin/cstecgi.cgi file. This vulnerability enables an attacker to send specially crafted commands remotely, potentially...
PoC for CVE-2026-79911
A security vulnerability exists in the TOTOLINK N600R router, specifically in the setSystemConfig function within the CGI Handler component. The flaw arises due to inadequate handling of the Hostname argument, which can lead to a stack-based buffer overflow. This vulnerability allows attackers to...
Discovered 7 hours ago
PoC for CVE-2026-79845
A vulnerability exists in the Simple Inventory System version 1.0, specifically within the edit.php file. By manipulating the ID argument, an attacker can execute SQL injection attacks, allowing unauthorized access and manipulation of the database. This vulnerability can be exploited remotely and...
PoC for CVE-2026-79804
A vulnerability exists within the SililaWijesinghe Food Ordering System relating to improper handling of user input in the /search.php file. An attacker can exploit this flaw by manipulating the search_box parameter, leading to potential SQL injection attacks. Such exploitation can allow unauthor...
Discovered 8 hours ago
PoC for CVE-2026-79793
A cross site scripting vulnerability exists in the Online Shopping System 1.0, specifically in the /admin/sumit_form.php file. This vulnerability allows attackers to manipulate the 'Success' argument, which can lead to the execution of malicious scripts in the context of the user's session. The e...
PoC for CVE-2026-79792
A security flaw has been identified in Zackees Transcribe-Anything up to version 4.1.0, specifically within the function ytdlp_download located in the ytldp_download.py file. This vulnerability allows attackers to manipulate the input URL, potentially leading to OS command injection. The attack c...
Discovered 9 hours ago
PoC for CVE-2026-74932
The WP Fastest Cache plugin for WordPress, prior to version 1.5.1, is susceptible to a vulnerability stemming from the lack of Host header validation. This deficiency allows unauthenticated attackers to manipulate cached pages by embedding references to a malicious server. Consequently, this can ...
PoC for CVE-2026-74970
A site isolation vulnerability exists in the Graphics component of Mozilla Firefox, which could allow attackers to execute unauthorized actions across different sites. This issue has been addressed in Firefox version 154 and Firefox Extended Support Release (ESR) version 153.1, enhancing user sec...
PoC for CVE-2026-74945
A vulnerability within the Graphics: Text component of Firefox allows for unintended information disclosure. This issue could potentially expose sensitive data that should remain protected. Mozilla has addressed this vulnerability in various versions, ensuring enhanced security and privacy for us...
PoC for CVE-2026-6765
This vulnerability involves an information disclosure flaw in the Form Autofill component of Firefox and Firefox ESR. When exploited, it can reveal sensitive user data. Mozilla has addressed this issue in versions 150 of Firefox and 140.10 of Firefox ESR, emphasizing the importance of updating to...
PoC for CVE-2026-74943
A use-after-free vulnerability has been discovered in the Graphics: ImageLib component of Firefox. This issue may allow an attacker to cause a crash or potentially execute arbitrary code on the affected system. Mozilla has released updates addressing this vulnerability in Firefox version 154, and...
Discovered 10 hours ago
PoC for CVE-2026-80049
The Airbyte Platform has a vulnerability that allows an attacker to bypass workspace authorization checks. This issue arises from the platform's dependency on the caller-supplied workspace ID without proper validation against the actual owning workspace. When handling requests, the system extract...
Discovered 11 hours ago
PoC for CVE-2026-80051
The GraphQL for Go library, up to version 0.8.1, contains a vulnerability that fails to validate scalar variable values against their declared types. Specifically, the built-in functions coerceString and coerceBool do not enforce type checking, allowing improperly typed input. This oversight can ...
PoC for CVE-2026-26211
The Ekushey Project Manager CRM contains a vulnerability that allows stored Cross-Site Scripting (XSS) attacks through improper output encoding of the administrator-configured system name. When this name is displayed on the login page, it is rendered without adequate encoding, permitting any HTML...
Discovered 15 hours ago
PoC for CVE-2026-41551
A path traversal vulnerability has been discovered in ROS# that affects all versions prior to V2.2.2. This issue arises from inadequate sanitization of user input, potentially allowing remote attackers to navigate the file system and access sensitive files on the device. Addressing this vulnerabi...
PoC for CVE-2026-79623
A security flaw has been identified in the FishCodeTech Muteki application up to version 0.2.5, due to an unspecified function within the .claude/settings.json file of the Default Local Worker Backend. This vulnerability permits attackers to perform OS command injection, which can be initiated re...
PoC for CVE-2026-79622
A path traversal vulnerability has been detected in the dekdee Adobe XD MCP product, specifically within the function of the file-access-from-request endpoint located in src/parsers/xd-parser.ts. This weakness allows attackers to manipulate the outputFile/outputDir arguments, potentially gaining ...
Discovered 16 hours ago
PoC for CVE-2026-57863
Crater Invoice versions up to 6.0.6 are susceptible to a path traversal vulnerability within their self-update API. This weakness allows authenticated company owners to manipulate crafted ZIP archives to bypass directory restrictions, enabling the writing of arbitrary files outside the intended e...
Discovered 17 hours ago
PoC for CVE-2026-16348
An authenticated command injection vulnerability exists in the TP-Link Archer BE800 V1 router. With administrative access, an attacker can execute arbitrary system commands with root privileges by injecting shell metacharacters through a VPN connection. This exploitation can lead to serious secur...
PoC for CVE-2026-15469
A vulnerability has been identified in the mesh functionality of TP-Link's Deco XE75, XE5300, and WE10800 products, where a shared RSA-512 mesh group private key is hard-coded into the firmware. This key is utilized for node authentication within the mesh protocol. An attacker with local network ...
PoC for CVE-2026-18963
A security flaw exists in the Keycloak Services component of Red Hat, specifically within the reset-credentials workflow. This vulnerability permits an attacker to initiate a password reset for any user without the need for email verification. As a consequence, it enables unauthorized users to as...
Discovered 19 hours ago
PoC for CVE-2026-12295
A sandbox escape vulnerability exists in the navigation component of Firefox, which could potentially allow attackers to circumvent security restrictions and execute unauthorized scripts. This type of vulnerability may compromise user data and system integrity. Mozilla has addressed this issue in...
Discovered 22 hours ago
PoC for CVE-2026-78656
A vulnerability exists in the itsourcecode Sales and Inventory System 1.0 that can be exploited through a flaw in the /pages/cust_del.php file. The vulnerability arises from improper handling of the ID parameter, leading to SQL injection attacks. This issue allows an attacker to manipulate SQL qu...
Discovered 23 hours ago
PoC for CVE-2026-78654
A vulnerability identified in the Cleverbrush framework allows for improper control over modifications to object prototype attributes via the deepExtend function in deepExtend.ts file. This can lead to potential exploitation by attackers remotely. Users of versions up to 4.4.0 are advised to upgr...
PoC for CVE-2021-30327
A buffer overflow vulnerability exists in the Sahara protocol utilized within Qualcomm's Snapdragon mobile platforms. This flaw can lead to the unintended overwriting of secure configuration data, potentially compromising system integrity and security across a range of Snapdragon products, includ...
PoC for CVE-2026-78638
A security flaw has been identified in the unzip-crx library developed by Peerigon, specifically impacting versions up to 0.2.0. This vulnerability arises in the 'unzip' function located within the 'dist/index.js' file of the Archive Extraction component. By manipulating the 'destination' argumen...
Discovered 1 day ago
PoC for CVE-2026-74939
A security flaw in the Mozilla Firefox navigation component allows unauthorized users to escalate their privileges, potentially exposing critical parts of the application. This vulnerability was addressed in multiple versions, including Firefox 154 and various releases of Firefox ESR. Users are s...
PoC for CVE-2019-0708
A remote code execution vulnerability in Microsoft Remote Desktop Services allows an unauthenticated attacker to connect to the target system via RDP and execute arbitrary code by sending specially crafted requests. This exploitation can lead to significant security breaches if not mitigated adeq...
PoC for CVE-2025-46359
A path traversal vulnerability has been identified in the backup and restore features of multiple versions of PowerCMS. This flaw allows product administrators to execute arbitrary code by restoring a crafted backup file. This issue emphasizes the importance of securing backup functionalities wit...
PoC for CVE-2026-63039
An SQL Injection vulnerability has been identified in Apache InLong, where improper neutralization of special elements in SQL commands allows an attacker to inject malicious strings into SQL statements. This can compromise the integrity and confidentiality of the database. Affected users should u...
PoC for CVE-2026-28672
A command injection vulnerability exists in Apache Ranger, affecting versions from 0.6 to 2.8. This flaw allows attackers to execute arbitrary commands on the host system. Improper handling of special elements in command inputs can lead to significant security risks, enabling unauthorized access ...
PoC for CVE-2026-78329
An improper input validation vulnerability in the Undertow component of Apache Camel allows unauthorized header manipulation. The default headerFilterStrategy configuration leads to failure in applying specific filtering rules on endpoint-configured routes, resulting in legacy websocket headers b...
PoC for CVE-2026-71300
An improper input validation vulnerability exists in Apache Camel's Atmosphere Websocket component, affecting several versions. This issue allows external senders to manipulate message delivery by injecting harmful values into specific headers. When bridging an HTTP consumer into an atmosphere-we...
PoC for CVE-2026-60093
A relative path traversal vulnerability has been identified in the Apache Camel Azure Storage Datalake component. This issue enables unauthorized access, allowing malicious users to manipulate file paths during file downloads. Specifically, the component fails to properly validate file paths, per...
PoC for CVE-2026-66906
The Apache Camel Azure Storage Blob component is susceptible to a relative path traversal vulnerability, allowing unauthorized access to the local filesystem. Through its downloadBlobToFile operation, an attacker can exploit the lack of proper path validation, potentially overwriting files outsid...
PoC for CVE-2026-66907
A relative path traversal vulnerability exists in the Apache Camel Google Storage component, allowing unauthorized file overwrite on the local filesystem. When the downloadFileName option is set without proper filtering or normalization, it constructs local paths that may lead outside the intende...
PoC for CVE-2026-66908
Apache Camel's HTTP component exhibits an improper authentication vulnerability that affects versions 4.8.0 to 4.21.x. When JWT authentication is configured, the server fails to validate the 'iss' and 'aud' claims of incoming tokens if neither the jwtIssuer nor jwtAudience are specified, leading ...
PoC for CVE-2026-68820
A use after free vulnerability exists in the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to exploit the driver and potentially elevate privileges locally, threatening the integrity of the operating system. To mitigate risk, it is essential to apply the ...
PoC for CVE-2026-63621
The Apache Camel Knative component contains a vulnerability that allows unauthenticated attackers to inject Camel-internal headers through structured-mode CloudEvent requests. This occurs when CloudEvent extension fields are read directly from JSON bodies, bypassing essential header filter strate...
PoC for CVE-2026-59230
An improper input validation vulnerability in Apache Camel affects the handling of MIME multipart messages within the camel-mail component. When configured with headersInline set to true, the component indiscriminately copies MIME headers from incoming messages to Camel messages, lacking any head...
PoC for CVE-2026-78435
A path traversal vulnerability exists in the Faveo Helpdesk, affecting versions up to 2.0.3, specifically in the unlink function of the Logo Handler component. By manipulating the argument data1, attackers can exploit this vulnerability remotely, which poses a significant security risk. This issu...
PoC for CVE-2026-78434
A missing authentication vulnerability exists in the Faveo Helpdesk software up to version 2.0.3. Specifically, the flaw is related to the FormController::post_ticket_reply function in the app/Http/Controllers/Client/helpdesk/FormController.php file. This vulnerability allows attackers to initiat...
PoC for CVE-2026-72714
Rocq Prover contains a vulnerability where the universe graph fails to restore the checking flag for universe validation after a module that disables this check is closed. Normally, this local setting should only persist for the lifespan of the module, reverting to a global state upon closure. Ho...
PoC for CVE-2026-72711
The Lean 4 kernel contains a flaw where it fails to properly check that the body of an opaque declaration is closed. Specifically, the method environment::add_opaque omits the crucial check found in the definition and theorem paths, allowing for a scenario where a value may contain free variables...
PoC for CVE-2026-72705
The guard checker in Rocq Prover is susceptible to a type safety violation where recursive calls using fixpoint arguments are inadequately tracked. This could lead to scenarios where a type becomes definitionally equal to its negation. Consequently, self-application can produce false results with...
PoC for CVE-2026-72704
The Rocq Prover's guard checker contains a significant flaw whereby alterations to a recursive type parameter are not validated post-transport. This oversight allows a fixpoint to apply rewrites based on type equality, which may lead to the acceptance of an altered recursive tree that has not und...
PoC for CVE-2026-72703
The guard checker in Rocq Prover erroneously classifies a nested mutual fixpoint parameter as uniform without performing a thorough analysis of inter-body calls. The function find_uniform_parameters only evaluates self-recursive calls, leading to the risk of accepting a non-terminating definition...
PoC for CVE-2020-37268
The Print Assumptions feature in Rocq Prover is vulnerable to a flaw arising from the failure to report the disabling of universe checking during specific operations. When a definition is created under these conditions, it can be inlined through parameters without retaining any record of the unsa...
PoC for CVE-2026-78430
A vulnerability exists in Sworddut's MCP-FFmpeg-Helper affecting versions 0.1.0, 0.1.1, and 0.2.1 that allows for OS command injection. This is due to improper handling of input arguments in the 'handleToolCall' function specifically in the 'src/tools/handlers.ts' file. Exploitation requires loca...