Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered 2 hours ago
PoC for CVE-2026-18969
A vulnerability has been discovered in the Rongzhitong Visual Integrated Command and Dispatch Platform, affecting versions up to 20260617. This issue arises from an unknown function within the file path /dm/dispatch/userinfo/upload, which permits unrestricted file uploads due to improper validati...
Discovered 3 hours ago
PoC for CVE-2025-32432
Craft CMS, a customizable content management system, has a remote code execution vulnerability present in specific versions. Attackers could exploit this flaw to execute arbitrary code on the server, posing a significant security risk. The affected versions span from 3.0.0-RC1 to just before 3.9....
PoC for CVE-2026-18968
A cross site scripting vulnerability exists in ttttonyhe OBlog, specifically within the file /tags.php. This flaw arises from improper handling of the argument 'day', allowing for remote attackers to inject malicious scripts into web pages viewed by users. The exploitation of this vulnerability c...
Discovered 4 hours ago
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...
Discovered 6 hours ago
PoC for CVE-2026-18959
A security vulnerability has been identified in Yushine InnoShop, specifically within the FileManagerController::destroyFiles function found in the panel-api.php file. This issue is categorized as a path traversal vulnerability, allowing unauthorized access to files on the server through crafted ...
PoC for CVE-2026-18958
The Imranrisal-Dev Student-Management-System is susceptible to SQL injection through the loginCheckTest.php file. By manipulating the username and password parameters, an attacker can execute unauthorized SQL commands, potentially compromising the database and gaining access to sensitive informat...
PoC for CVE-2026-70616
Boringproxy versions up to 0.10.0 are vulnerable to a resource exhaustion issue through the GET /loading endpoint. This vulnerability allows authenticated users to send crafted requests, consuming server resources indefinitely. An absence of validation checks on the query parameter allows malicio...
PoC for CVE-2026-70615
Boringproxy versions up to 0.10.0 are susceptible to a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permissions to inject arbitrary lines into the SSH authorized_keys file of the server account. This can be exploited by supplying a percent-en...
Discovered 7 hours ago
PoC for CVE-2026-69111
The vulnerability in Milvus allows remote attackers to exploit the unprotected /management/stop endpoint, leading to a denial of service. By sending a crafted HTTP GET request to the management server on port 9091, attackers can terminate service components such as the proxy, datanode, or queryno...
PoC for CVE-2026-15430
The improper access control in the IRP_MJ_WRITE command interface of Wellbia XIGNCODE3, specifically in the xhunter2.sys component version 2026.6.1.192, potentially allows a local unprivileged attacker to escalate their privileges to the NT AUTHORITY\SYSTEM level. This vulnerability also poses ri...
Discovered 9 hours ago
PoC for CVE-2026-18927
The imranrisal-dev Student Management System contains a vulnerability in the function storeProfileImage located in student_profile_pic.php. This flaw allows for unrestricted file uploads when manipulating the argument choose_file, potentially leading to remote code execution. As the exploit is pu...
Discovered 12 hours ago
PoC for CVE-2026-17532
The Seraphinite Accelerator plugin for WordPress is susceptible to a reflected cross-site scripting (XSS) vulnerability. This issue arises through improper validation of the 'seraph_accel_prep' parameter in versions 2.29.15 and earlier. Specifically, the CacheExtractPreparePageParams() function f...
PoC for CVE-2024-21413
A remote code execution vulnerability in Microsoft Outlook allows an attacker to run arbitrary code on a user's system. This can occur when the vulnerable version processes specially crafted email messages, which can result in unauthorized access or control over the affected system. Attackers can...
Discovered 15 hours ago
PoC for CVE-2026-66747
The Zbtlink router firmware contains an embedded remote-control implant known as ENDLESSDOORS, present in all published builds. This implant is based on the open-source tool rctl, functioning as a package within OpenWrt (librctl.so). It operates at boot time with root privileges, disguising itsel...
PoC for CVE-2026-54917
SeaweedFS, a distributed storage solution for object storage and Iceberg tables, has a vulnerability where specific URL patterns can bypass security measures. With the S3 API gateway and the Iceberg REST catalog gateway configured with path cleaning disabled, attackers can exploit this flaw using...
Discovered 17 hours ago
PoC for CVE-2026-60137
A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...
Discovered 20 hours ago
PoC for CVE-2026-15372
The WP 2FA plugin for WordPress, prior to version 4.1.0, contains a critical flaw that fails to validate the secondary authentication factor when one of the supported methods is chosen during the login process. This oversight allows an unauthorized individual who possesses the valid password of a...
PoC for CVE-2026-17515
The IDX Plugin & MLS Plugin for Real Estate Listings for WordPress before version 7.0.4 lacks necessary authorization and Cross-Site Request Forgery (CSRF) checks within its AJAX actions. This oversight permits any authenticated user to gain unauthorized access to sensitive information, including...
PoC for CVE-2026-16055
The Contest Gallery plugin for WordPress, prior to version 30.0.7, contains a security flaw that allows attackers to bypass standard authentication mechanisms. By issuing an authentication cookie directly after verifying credentials, the plugin defeats the purpose of brute-force protections and t...
PoC for CVE-2026-16036
The miniOrange 2FA WordPress plugin prior to version 6.2.7 contains a security flaw that fails to correctly bind the second factor during the pre-login verification process. This allows an attacker, who knows a victim's password, to reconfigure the victim's second factor to an address controlled ...
PoC for CVE-2026-15360
The Ajax Load More plugin for WordPress prior to version 8.0.1 suffers from a vulnerability where it inadequately sanitizes and escapes input parameters. This flaw can be exploited by attackers lacking authentication, enabling them to execute time-based blind SQL injection attacks. Such exploits ...
PoC for CVE-2026-15210
The OTP Login With Phone Number plugin for WordPress before version 1.8.71 is vulnerable as it lacks limitations on the number of OTP verification attempts. This oversight permits unauthorized users to continuously request login codes for any account without invalidating previous attempts. As the...
PoC for CVE-2026-16993
The DHL Shipping for WooCommerce plugin prior to version 4.0.1 is susceptible to an access control vulnerability that allows unauthenticated users to access sensitive shipping labels. This flaw arises from inadequate protection of its shipping-label storage directory, depending solely on an Apach...
PoC for CVE-2026-14553
The Zportals WordPress plugin fails to adequately validate uploaded files, relying on the content type provided by the client and preserving the original file extension. This security oversight allows authenticated users with roles of Subscriber or higher to upload arbitrary PHP files, potentiall...
PoC for CVE-2026-16981
The DHL Shipping Germany plugin for WooCommerce prior to version 4.0.1 has a significant vulnerability that allows attackers to exploit a lack of authorization checks on its shipping-label download endpoints. Without requiring any form of authentication or verification such as capability checks, ...
PoC for CVE-2026-15230
The YayPricing plugin for WordPress prior to version 3.5.7 contains a security flaw where it fails to enforce proper capability checks on various REST API endpoints. This oversight permits any authenticated user, including those with minimal privileges like subscribers, to manipulate the store's ...
PoC for CVE-2025-15677
The GeoDirectory WordPress plugin versions prior to 2.8.110 lacks adequate sanitization and escaping of input for the place-category setting on admin pages. This oversight allows users with high privileges, such as editors and above, to execute Stored Cross-Site Scripting (XSS) attacks, even in c...
PoC for CVE-2026-16940
The Custom Fields WordPress plugin, prior to version 1.5.1, contains a security flaw that permits unauthenticated users to execute file deletion commands by failing to properly validate user-supplied file paths. This vulnerability can potentially allow attackers to delete critical files, includin...
PoC for CVE-2026-16746
The MultiVendorX WordPress plugin, prior to version 5.0.11, contains a vulnerability in its REST API that fails to ensure proper ownership checks. This allows vendor-level users to access and disclose sensitive commission and financial data associated with other vendors, compromising user data in...
PoC for CVE-2026-16736
The User Registration & Membership plugin for WordPress, prior to version 5.2.6, fails to respect the site's registration-disabled setting during the processing of registration form submissions. This oversight permits unauthenticated users to create new accounts, even if the WordPress administrat...
PoC for CVE-2026-16942
The WP Custom HTML Page plugin up to version 0.6.2 fails to properly sanitize HTML inputs through its custom page handlers. This vulnerability allows users with an Author role to store unfiltered JavaScript, leading to potential execution of malicious scripts at public URLs when accessed by any v...
PoC for CVE-2026-16613
The GDPR Cookie Compliance plugin for WordPress, prior to version 5.1.0, contains an authentication bypass vulnerability that allows an attacker to exploit cookie expiration functionality. Due to a lack of authentication checks, an unauthorized user can craft a link to log out any visitor and rem...
PoC for CVE-2026-16968
The GeoDirectory WordPress plugin, prior to version 2.8.168, contains a vulnerability that permits authenticated users with Contributor-level permissions or higher to exploit a user-search handler. This oversight allows these users to retrieve email addresses of all registered users, including th...
PoC for CVE-2026-16573
The Bit Form WordPress plugin prior to version 3.2.0 allows unauthenticated users to upload malicious SVG files that contain JavaScript code. When these files are viewed, the embedded code can execute within the context of the user’s browser session, potentially leading to unauthorized actions an...
PoC for CVE-2026-16602
The Passster plugin for WordPress prior to version 4.3.6 is vulnerable due to insufficient checks on post status when returning content from a REST endpoint. This flaw enables unauthorized users to access and disclose the content of private, draft, or pending posts on websites using a captcha pro...
PoC for CVE-2026-16605
A security flaw in the MultiVendorX WordPress plugin allows authenticated vendors (Store Owners and above) to exploit the REST API functionality without verifying ownership. This oversight enables them to view, take control of, permanently delete, or alter any other vendor's store on the marketpl...
PoC for CVE-2026-16583
The Orbit Fox WordPress plugin versions prior to 3.0.8 have a significant vulnerability that permits authenticated users to upload SVG files without proper sanitization. This lack of validation can lead to the injection of JavaScript code that executes within the site's context when the malicious...
PoC for CVE-2026-16603
The Passster WordPress plugin prior to version 4.3.6 contains a vulnerability that compromises category-based content protection. This flaw permits unauthenticated users to access the full content, titles, and excerpts of posts that are intended to be restricted through the WordPress REST API. As...
PoC for CVE-2026-16604
The Passster plugin for WordPress, prior to version 4.3.6, is susceptible to a vulnerability that exposes password-protected block content to unauthenticated users. This occurs because the plugin fails to properly verify the password before rendering the protected content in the public response. ...
PoC for CVE-2026-16561
The Sunshine Photo Cart plugin for WordPress, in versions prior to 3.6.12, lacks proper access control measures for certain AJAX actions. This oversight permits unauthenticated users to access and retrieve comments from images that are part of private, password-protected, or otherwise restricted ...
Discovered 21 hours ago
PoC for CVE-2026-18903
A vulnerability exists in YeQifu Warehouse, specifically within the processing of the FileController.java file. This flaw allows an attacker to manipulate the argument path, resulting in potential path traversal. As this exploit has been publicly disclosed, it exposes the affected systems to remo...
PoC for CVE-2026-18902
A command injection vulnerability exists in the H3C NX15 Router version V100R017. The issue arises from the improper handling of the 'my2P4key' argument in the esps.wan.repeater.set/repeaterproc function located in the /api/esps file. Remote attackers can exploit this vulnerability to execute arb...
Discovered 22 hours ago
PoC for CVE-2026-18901
A security vulnerability has been identified in the H3C NX15 V100R017, specifically within the service.add function of the Web API component located at /api/esps. This vulnerability exposes a dangerous routine that can be manipulated remotely, potentially allowing an attacker to execute arbitrary...
PoC for CVE-2026-18900
A vulnerability has been discovered in the H3C NX15 product, specifically in the Backend RPC component's file.exec function located at /api/esps. This flaw allows for remote command injection through manipulation of the argument File. Attackers may exploit this weakness to execute arbitrary comma...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 23 hours ago
PoC for CVE-2026-18898
A critical security flaw has been identified in the UTT HiPER 1200GW device, specifically affecting versions up to 2.5.3-170306. The vulnerability lies within the strcpy function located in the /goform/ConfigAdvideo file. Improper manipulation of the 'timestart' argument can lead to a stack-based...
Discovered 1 day ago
PoC for CVE-2026-18897
A stack-based buffer overflow vulnerability has been identified in the UTT HiPER 1250GW router, specifically within the strcpy function of the /goform/getOneApConfTempEntry file. By manipulating the tempName argument, an attacker can exploit this flaw remotely, potentially compromising the device...
PoC for CVE-2026-18896
The Lavkush Maurya Student Registration System 1.0 contains a vulnerability that allows for SQL injection through improper handling of the 'oldpass' argument in the /student/changepass.php file. This weakness can be exploited remotely, leading to unauthorized access and manipulation of the databa...
PoC for CVE-2026-18895
A vulnerability exists in the UTT HiPER 1250GW, affecting versions up to 3.2.7-210907-180535. The flaw is found in the strcpy function within the /goform/APSecurity_5g file, which leads to a stack-based buffer overflow when the argument cipher is manipulated. This vulnerability allows for remote ...
PoC for CVE-2026-18859
A vulnerability has been discovered in the ESAFENET CDG product, where improper handling of the 'keyid' parameter in the file '/CDGServer3/ukey/usbkey;logindojojs' allows attackers to execute SQL injection attacks. This flaw exposes systems to potential unauthorized access and manipulation of the...