Publicly Disclosed
PoC Exploits

πŸ”΄ Alway take caution when working with PoC Exploits πŸ”΄

Discovered 6 hours ago

PoC for CVE-2026-4474

ItsourcecodeUniversity Management ...4.8MEDIUM
Cross Site Scripting in itsourcecode University Management System b...

A security flaw in the itsourcecode University Management System version 1.0 permits remote attackers to exploit cross site scripting vulnerabilities via manipulation of the 'st_name' parameter in the /admin_single_student_update.php file. This issue can lead to unauthorized script execution in u...

PoC for CVE-2026-4473

ItsourcecodeOnline Doctor Appointm...5.1MEDIUM
SQL Injection Vulnerability in itsourcecode Online Doctor Appointme...

A security flaw has been identified in the itsourcecode Online Doctor Appointment System 1.0, specifically related to the processing of the 'appointment_id' parameter in the /admin/appointment_action.php file. This vulnerability enables an attacker to execute SQL injection attacks remotely, poten...

Discovered 7 hours ago

PoC for CVE-2026-4472

ItsourcecodeOnline Frozen Foods Or...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Online Frozen Foods Ord...

A security vulnerability in the itsourcecode Online Frozen Foods Ordering System version 1.0 allows for SQL injection through the /admin/admin_edit_supplier.php file. By manipulating the Supplier_Name argument, an attacker could execute arbitrary SQL commands. This vulnerability can be exploited ...

PoC for CVE-2026-4471

ItsourcecodeOnline Frozen Foods Or...5.1MEDIUM
SQL Injection Vulnerability in itsourcecode Online Frozen Foods Ord...

A vulnerability has been discovered in the itsourcecode Online Frozen Foods Ordering System 1.0, specifically in the /admin/admin_edit_employee.php file. This weakness can be exploited through manipulation of the First_Name argument, leading to SQL injection attacks. As it allows remote attackers...

PoC for CVE-2026-4470

ItsourcecodeOnline Frozen Foods Or...5.1MEDIUM
SQL Injection Vulnerability in itsourcecode Online Frozen Foods Ord...

A security vulnerability has been identified in the itsourcecode Online Frozen Foods Ordering System version 1.0, specifically in the /admin/admin_edit_menu.php file. The vulnerability allows attackers to exploit a flaw by manipulating the 'product_name' argument, facilitating SQL injection attac...

Discovered 8 hours ago

PoC for CVE-2026-4469

ItsourcecodeOnline Frozen Foods Or...5.1MEDIUM
SQL Injection Vulnerability in itsourcecode Online Frozen Foods Ord...

A vulnerability has been discovered in the itsourcecode Online Frozen Foods Ordering System version 1.0, specifically within the file /admin/admin_edit_menu_action.php. This issue arises from improper handling of the product_name argument, which can be exploited to perform SQL injection attacks. ...

PoC for CVE-2026-4468

ComfastCf-ac1005.1MEDIUM
Command Injection Vulnerability in Comfast CF-AC100 by Comfast

A command injection vulnerability exists in the Comfast CF-AC100 (version 2.6.0.8) in the file /cgi-bin/mbox-config?method=SET&section=update_interface_png. This flaw allows an attacker to execute arbitrary commands via crafted requests, potentially enabling unauthorized access to the device. The...

Discovered 9 hours ago

PoC for CVE-2026-4467

ComfastCf-ac1005.1MEDIUM
Command Injection Vulnerability in Comfast CF-AC100 Router

A vulnerability has been identified in the Comfast CF-AC100 router, specifically in version 2.6.0.8, which allows for command injection through an insecure function within the /cgi-bin/mbox-config?method=SET&section=wireless_device_dissoc endpoint. This could enable remote attackers to execute ar...

Discovered 10 hours ago

PoC for CVE-2026-4466

ComfastCf-ac1005.1MEDIUM
Command Injection Vulnerability in Comfast CF-AC100 Router

A command injection vulnerability has been identified in the Comfast CF-AC100 router, specifically in the configuration file handler located at /cgi-bin/mbox-config?method=SET&section=ntp_timezone. This vulnerability allows attackers to execute arbitrary commands remotely, potentially compromisin...

PoC for CVE-2026-4465

D-linkDir-5135.3MEDIUM
OS Command Injection Vulnerability in D-Link DIR-513 Device

A vulnerability exists in the D-Link DIR-513 1.10, specifically within an undisclosed function related to the /goform/formSysCmd file. By manipulating the sysCmd parameter, an attacker can exploit this flaw to execute arbitrary OS commands remotely. This vulnerability primarily affects devices th...

Discovered 20 hours ago

PoC for CVE-2026-32255

KanbnKan8.6HIGH
Open-Source Project Management Tool Vulnerability in Kan

The Kan project management tool has a serious security flaw in its /api/download/attachment endpoint present in versions 0.5.4 and earlier. This vulnerability allows unauthenticated users to pass a URL query parameter directly to the server, which could lead to unintended HTTP requests being made...

Discovered 22 hours ago

PoC for CVE-2025-71260

Bmc Software, Inc.Footprints8.7HIGH
Deserialization Vulnerability Affecting BMC FootPrints ITSM

The BMC FootPrints ITSM application is susceptible to a vulnerability in its ASP.NET VIEWSTATE handling mechanism that allows authenticated users to exploit the system. By supplying specially crafted serialized objects through the VIEWSTATE parameter, attackers can gain the ability to execute arb...

Discovered 1 day ago

PoC for CVE-2026-32731

ApostrophecmsImport-export10CRITICAL
File Write Path Vulnerability in ApostropheCMS by Apostrophe

ApostropheCMS is an open-source content management framework that has a vulnerability in the `@apostrophecms/import-export` package prior to version 3.5.3. The vulnerability lies within the `extract()` function in `gzip.js`, where file-write paths are constructed using `fs.createWriteStream(path....

PoC for CVE-2026-2991

WordPressKivicare – Clinic & Pa...9.8CRITICAL
Authentication Bypass Vulnerability in KiviCare Plugin for WordPress

The KiviCare – Clinic & Patient Management System for WordPress has a critical vulnerability that allows attackers to bypass authentication checks. The flaw exists in the `patientSocialLogin()` function, which does not properly verify the access token provided by social providers. As a result, an...

PoC for CVE-2023-46604

ApacheApache ActiveMQ🟣 EPSS 94%10CRITICAL
Remote Code Execution Vulnerability Affects Java OpenWire Protocol ...

The Java OpenWire protocol marshaller in Apache ActiveMQ is susceptible to a remote code execution vulnerability, allowing attackers with network access to execute arbitrary shell commands. By manipulating serialized class types in the OpenWire protocol, an attacker can cause the client or broker...

PoC for CVE-2026-24291

MicrosoftWindows 10 Version 16077.8HIGH
Elevation of Privilege Vulnerability in Windows Accessibility Infra...

An elevation of privilege vulnerability exists in the Windows Accessibility Infrastructure due to incorrect permission assignment for critical resources within ATBroker.exe. This flaw enables authorized attackers to gain elevated access to system resources, potentially allowing them to execute un...

PoC for CVE-2008-0166

OpenSSLOpenSSL7.5HIGH
Predictable Random Number Generation in OpenSSL on Debian Systems

On Debian-based operating systems, certain versions of OpenSSL utilize a flawed random number generator that produces predictable outputs. This vulnerability can facilitate brute force attacks, enabling adversaries to guess cryptographic keys with higher success rates. Organizations using affecte...

PoC for CVE-2026-3888

7.8HIGH
Local Privilege Escalation in Snapd Affecting Ubuntu Linux

A local privilege escalation vulnerability in Snapd on Linux systems allows attackers to exploit the automatic cleanup of Snap's private /tmp directory. By re-creating this directory under certain configurations of systemd-tmpfiles, an attacker can potentially gain root privileges. This issue imp...

Discovered 2 days ago

PoC for CVE-2025-4396

WordPressRelevanssi – A Better ...🟣 EPSS 25%7.5HIGH
SQL Injection Vulnerability in Relevanssi Search Plugin for WordPress

The Relevanssi – A Better Search plugin for WordPress presents a vulnerability that allows time-based SQL injection through the cats and tags query parameters. This issue affects all versions up to and including 4.24.4 for free and 2.27.4 for premium users. The vulnerability arises from inadequat...

PoC for CVE-2026-32746

GnuInetutils9.8CRITICAL
Out-of-Bounds Write Vulnerability in GNU Inetutils Telnetd

The telnetd component of GNU Inetutils, specifically versions up to 2.7, is susceptible to an out-of-bounds write vulnerability. This flaw occurs in the LINEMODE SLC (Set Local Characters) suboption handler due to insufficient checks in the add_slc function, allowing for data to be written past t...

PoC for CVE-2026-25873

Beijing Academy O...Omnigen2-rl9.3CRITICAL
Remote Code Execution Vulnerability in OmniGen2-RL Reward Server by...

The OmniGen2-RL reward server component is vulnerable to an unauthenticated remote code execution flaw. By exploiting insecure pickle deserialization, an attacker can send specially crafted HTTP POST requests to execute arbitrary commands on the server. This vulnerability allows for potential una...

PoC for CVE-2026-26801

bpampuchpdfmake7.5HIGH
Server-Side Request Forgery in pdfmake by bpampuch

A Server-Side Request Forgery (SSRF) vulnerability exists in pdfmake versions 0.3.0-beta.2 through 0.3.5. This flaw enables a remote attacker to exploit the src/URLResolver.js component, potentially allowing access to sensitive information from the server. To mitigate this risk, version 0.3.6 int...

PoC for CVE-2021-41773

ApacheApache Http Server🟣 EPSS 94%7.5HIGH
Path traversal and file disclosure vulnerability in Apache HTTP Ser...

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default config...

PoC for CVE-2025-15363

WordPressGet Use Apis5.9MEDIUM
Cross-Site Scripting Vulnerability in Get Use APIs WordPress Plugin

The Get Use APIs plugin for WordPress versions before 2.0.10 is susceptible to a Cross-Site Scripting (XSS) vulnerability. This security flaw enables users with low-level roles, such as contributors, to execute arbitrary JavaScript code through imported JSON data under specific server configurati...

PoC for CVE-2026-20643

AppleMac OS5.4MEDIUM
Cross-Origin Vulnerability in Apple Navigation API

A cross-origin vulnerability exists within the Navigation API that could allow maliciously crafted web content to bypass the Same Origin Policy. This issue has been rectified with enhanced input validation in version updates for iOS, iPadOS, and macOS, specifically in versions 26.3.1 and 26.3.2. ...

PoC for CVE-2023-52235

SpaceXStarlink8.8HIGH
DNS Rebinding Attack Affects SpaceX Starlink Wi-Fi Router GEN 2 Bef...

The SpaceX Starlink Wi-Fi router GEN 2 and Starlink Dish are susceptible to a Cross-Site Request Forgery (CSRF) attack, allowing malicious actors to exploit a DNS rebinding technique. This vulnerability permits unauthorized actions, such as rebooting the device without user consent, posing signif...

PoC for CVE-2026-30048

NotChatbotWebChat widget5.4MEDIUM
Stored XSS Vulnerability in NotChatbot WebChat Widget

A stored cross-site scripting (XSS) vulnerability in the NotChatbot WebChat widget allows attackers to inject arbitrary JavaScript code. User input is inadequately sanitized before being stored and displayed in chat conversations. When the chat history is loaded, the injected scripts are executed...

PoC for CVE-2026-4356

ItsourcecodeUniversity Management ...4.8MEDIUM
Cross-Site Scripting Vulnerability in itsourcecode University Manag...

A vulnerability in itsourcecode's University Management System 1.0 affects an undisclosed function within the /add_result.php file. This flaw allows for manipulation of the 'vr' argument, ultimately facilitating cross-site scripting attacks. Such vulnerabilities pose serious risks as they can be ...

Discovered 3 days ago

PoC for CVE-2026-4355

PortabilisI-educar5.1MEDIUM
Cross-Site Scripting Flaw in Portabilis i-Educar by Portabilis

A security flaw has been identified in Portabilis i-Educar 2.11, specifically affecting the endpoint located at /intranet/educar_servidor_curso_lst.php. This vulnerability allows remote attackers to conduct cross-site scripting (XSS) attacks by manipulating the 'Name' parameter. The exploitation ...

PoC for CVE-2026-4354

TrendnetTew-824dru5.1MEDIUM
Cross Site Scripting Vulnerability in TRENDnet TEW-824DRU Web Inter...

A Cross Site Scripting (XSS) vulnerability has been discovered in the TRENDnet TEW-824DRU's web interface, specifically within the apply_sec.cgi file's sub_420A78 function. Manipulating the Language argument allows for the execution of malicious scripts, which can be triggered remotely. The ease ...

PoC for CVE-2025-5548

FreefloatFtp Server6.9MEDIUM
Buffer Overflow Vulnerability in FreeFloat FTP Server

A vulnerability in FreeFloat FTP Server 1.0 affects the NOOP Command Handler, allowing for remote buffer overflow attacks. This flaw can be exploited, leading to unauthorized data access and potential control of the affected system. The issue has been publicly disclosed, emphasizing the need for ...

PoC for CVE-2026-32981

Ray-projectRay8.7HIGH
Path Traversal Vulnerability in Ray Dashboard by Ray

A path traversal vulnerability was discovered in Ray Dashboard, hosted on the default port 8265, impacting versions prior to 2.8.1. This flaw arises from the inadequate validation and sanitization of user-supplied paths within the static file handling mechanism. An attacker can exploit this vulne...

PoC for CVE-2021-25741

KubernetesKubernetes🟣 EPSS 33%8.8HIGH
Symlink Exchange Can Allow Host Filesystem Access

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

PoC for CVE-2026-4319

Code-projectsSimple Food Order System6.9MEDIUM
SQL Injection Vulnerability in Simple Food Order System by Code-Pro...

A vulnerability in the Simple Food Order System 1.0 allows attackers to exploit the file /routers/add-item.php by manipulating the price argument, leading to SQL injection. This flaw can be targeted remotely, and the exploit code is publicly available, posing a significant risk to users of the sy...

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 71%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

PoC for CVE-2026-4318

UttHiper 810g8.7HIGH
Buffer Overflow Vulnerability in UTT HiPER 810G by UTT

A buffer overflow vulnerability exists in the UTT HiPER 810G model, specifically within the strcpy function of the /goform/formApLbConfig file. This flaw allows an attacker to manipulate the loadBalanceNameOld argument, potentially leading to unauthorized access or execution of arbitrary code. Th...

PoC for CVE-2023-50965

StarnightMicro Http Server9.8CRITICAL
Buffer Overflow Vulnerability in Micro HTTP Server by Starnight

The Micro HTTP Server is susceptible to a buffer overflow due to improper handling of long URIs in the _ReadStaticFiles function within the lib/middleware.c file. This flaw allows attackers to send specially crafted requests that can exploit the vulnerability, potentially leading to remote code e...

PoC for CVE-2026-4308

FrdelAgent-zero5.3MEDIUM
Server-Side Request Forgery Vulnerability in frdel/agent0ai agent-z...

A vulnerability has been discovered in frdel/agent0ai agent-zero version 0.9.7, specifically affecting the handle_pdf_document function located in python/helpers/document_query.py. This flaw enables remote attackers to execute server-side request forgery (SSRF) attacks, allowing them to send unau...

PoC for CVE-2026-4307

FrdelAgent-zero5.3MEDIUM
Path Traversal Vulnerability in frdel Agent-Zero by frdel

A security flaw has been identified in frdel's Agent-Zero product, specifically in version 0.9.7-10. This vulnerability is associated with the 'get_abs_path' function located in the 'python/helpers/files.py' file. It allows an attacker to manipulate file paths, resulting in unauthorized access to...

PoC for CVE-2026-4289

TiandyEasy7 Integrated Manag...6.9MEDIUM
SQL Injection Vulnerability in Tiandy Easy7 Integrated Management P...

A SQL injection vulnerability exists in the Tiandy Easy7 Integrated Management Platform in versions up to 7.17.0, specifically within the /rest/preSetTemplate/getRecByTemplateId function. The vulnerability arises from improper validation of the ID argument, allowing attackers to manipulate SQL qu...

PoC for CVE-2026-4288

TiandyEasy7 Integrated Manag...6.9MEDIUM
SQL Injection Vulnerability in Tiandy Easy7 Integrated Management P...

A vulnerability has been discovered in the Tiandy Easy7 Integrated Management Platform version 7.17.0, specifically within an undisclosed function of the /rest/devStatus/getDevDetailedInfo endpoint. This issue allows attackers to manipulate the argument ID, potentially leading to SQL injection at...

Discovered 4 days ago

PoC for CVE-2026-4287

TiandyEasy7 Integrated Manag...6.9MEDIUM
SQL Injection Vulnerability in Tiandy Easy7 Integrated Management P...

A vulnerability has been identified in the Tiandy Easy7 Integrated Management Platform 7.17.0 that allows for SQL injection through an undisclosed function in the /rest/devStatus/queryResources endpoint. This security flaw enables attackers to manipulate the areaId argument, potentially allowing ...

PoC for CVE-2026-4285

TaoofagiEasegen-admin5.1MEDIUM
Path Traversal Vulnerability in Taoofagi Easegen-Admin Software

A path traversal vulnerability exists within the Taoofagi Easegen-Admin software, specifically in the 'recognizeMarkdown' function of the 'Pdf2MdUtil.java' file. This vulnerability allows attackers to manipulate the 'fileUrl' argument, potentially gaining unauthorized access to the underlying fil...

PoC for CVE-2026-4284

TaoofagiEasegen-admin5.1MEDIUM
Server-Side Request Forgery in Taoofagi Easegen-Admin Product

A vulnerability exists in the Taoofagi Easegen-Admin product due to improper handling of the 'url' parameter in the downloadFile function of the PPT File Handler. This flaw allows an attacker to exploit server-side request forgery (SSRF) vulnerabilities, potentially leading to unauthorized access...

PoC for CVE-2021-41773

ApacheApache Http Server🟣 EPSS 94%7.5HIGH
Path traversal and file disclosure vulnerability in Apache HTTP Ser...

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default config...

PoC for CVE-2018-18912

Sharing-fileEasy File Sharing Web ...9.8CRITICAL
Stack-Based Buffer Overflow in Easy File Sharing Web Server

A stack-based buffer overflow vulnerability affects Easy File Sharing (EFS) Web Server 7.2. This issue arises when attackers send a specially crafted POST request to the system while creating new topics in the forums. Successfully exploiting this vulnerability allows remote attackers to execute a...

PoC for CVE-2025-66034

FonttoolsFonttools6.3MEDIUM
Arbitrary File Write Vulnerability in fontTools Affects Remote Code...

The fontTools library, used for font manipulation in Python, contains an arbitrary file write vulnerability affecting versions from 4.33.0 to before 4.60.2. This flaw allows an attacker to execute remote code when a specially crafted .designspace file is processed through the fonttools varLib scr...

PoC for CVE-2026-4254

TendaAc89.3CRITICAL
Stack-Based Buffer Overflow in Tenda AC8 Router HTTP Component

A vulnerability has been discovered in the Tenda AC8 router, specifically affecting the HTTP Endpoint component. This issue arises from improper handling of the argument local_2c in the doSystemCmd function located in the /goform/SysToolChangePwd file. Exploitation of this vulnerability can lead ...

PoC for CVE-2026-4253

TendaAc85.1MEDIUM
OS Command Injection in Tenda AC8 Router's Web Interface

A security vulnerability has been identified in the Tenda AC8 router, specifically affecting version 16.03.50.11. This flaw is found in the route_set_user_policy_rule function within the /cgi-bin/UploadCfg component of the web interface. By manipulating the wans.policy.list1 argument, an attacker...

PoC for CVE-2017-9805

ApacheApache Struts🟣 EPSS 94%8.1HIGH
Remote Code Execution Vulnerability in Apache Struts REST Plugin

A vulnerability exists in the REST Plugin of Apache Struts that allows for Remote Code Execution due to the use of an XStreamHandler without type filtering during XML payload deserialization. This flaw, present in specific versions of the software, can be exploited by attackers to execute arbitra...