Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2025-8110

GogsGogs🟣 EPSS 77%8.7HIGH
Improper Symbolic Link Handling in Gogs Product by Gogs Team

The vulnerability in the PutContents API of Gogs arises from improper handling of symbolic links, potentially allowing local execution of arbitrary code. This misconfiguration may expose sensitive data and facilitate unauthorized access to critical systems. Users and administrators are urged to u...

Discovered 48 minutes ago

PoC for CVE-2025-61155

Hotta StudioGameDriverX64.sys5.5MEDIUM
Denial of Service Vulnerability in Hotta Studio's GameDriverX64.sys...

The GameDriverX64.sys kernel-mode anti-cheat driver from Hotta Studio has a vulnerability that enables local attackers to execute denial of service attacks. By sending specially crafted IOCTL requests, an attacker can induce crashes in arbitrary processes, leading to potential disruptions in game...

Discovered 2 hours ago

PoC for CVE-2021-30327

QualcommSnapdragon Mobile, Sna...7.5HIGH
Buffer Overflow in Sahara Protocol Affects Qualcomm Snapdragon Prod...

A buffer overflow vulnerability exists in the Sahara protocol utilized within Qualcomm's Snapdragon mobile platforms. This flaw can lead to the unintended overwriting of secure configuration data, potentially compromising system integrity and security across a range of Snapdragon products, includ...

PoC for CVE-2026-4253

TendaAc85.1MEDIUM
OS Command Injection in Tenda AC8 Router's Web Interface

A security vulnerability has been identified in the Tenda AC8 router, specifically affecting version 16.03.50.11. This flaw is found in the route_set_user_policy_rule function within the /cgi-bin/UploadCfg component of the web interface. By manipulating the wans.policy.list1 argument, an attacker...

Discovered 3 hours ago

PoC for CVE-2026-23111

LinuxLinux7.8HIGH
Local Privilege Escalation Vulnerability in Linux Kernel Utilizing ...

A vulnerability exists in the Linux kernel's netfilter module that affects the nft_map_catchall_activate() function. This function encounters an inverted element activity check, leading to a failure in appropriately handling catchall map elements during a failed transaction. The bug arises when t...

Discovered 4 hours ago

PoC for CVE-2026-57522

BitwardenServer2.3LOW
JSON Injection Vulnerability in Bitwarden Server from Bitwarden

Bitwarden Server versions prior to 2026.5.0 are susceptible to a JSON injection vulnerability in the IntegrationTemplateProcessor.ReplaceTokens() method. This flaw allows authenticated users to introduce JSON metacharacters into event integration templates, specifically tokens that are derived fr...

PoC for CVE-2026-57521

BitwardenServer5.3MEDIUM
Broken Access Control in Bitwarden Server Affecting User Billing Data

Bitwarden Server versions prior to 2026.5.0 exhibit a broken access control vulnerability that permits authenticated users to retrieve unauthorized organization billing data. By exploiting the PreviewInvoiceController endpoints, attackers can submit arbitrary organization IDs without proper membe...

PoC for CVE-2026-57520

BitwardenServer7.1HIGH
Privilege Escalation Vulnerability in Bitwarden Server by Bitwarden

A privilege escalation vulnerability in Bitwarden Server versions prior to 2026.5.0 allows authenticated Custom users with ManageUsers permission to exploit a lack of role hierarchy verification. This vulnerability permits an attacker to remove Admin accounts from an organization through a malici...

Discovered 5 hours ago

PoC for CVE-2026-56790

CanboatCanboat7HIGH
Off-by-One Buffer Overflow in CANBoat Allows Remote Denial of Service

The CANBoat application prior to version 6.22 is susceptible to an off-by-one global buffer overflow vulnerability within the searchForPgn() function, located in analyzer/pgn.c. This flaw may be exploited by remote attackers who deliver specially crafted NMEA-2000 messages containing out-of-range...

PoC for CVE-2026-56789

TomojitakasuRtklib7.1HIGH
Heap Buffer Overflow in RTKLIB Product from Tomoji Takasu

RTKLIB versions up to 2.4.3 are susceptible to a heap buffer overflow vulnerability within the readrnxobsb function found in src/rinex.c. This security flaw arises when the software does not properly clamp satellite count values specified in RINEX epoch headers. By crafting malicious RINEX files ...

PoC for CVE-2026-56788

TomojitakasuRtklib4.8MEDIUM
Out-of-Bounds Read Vulnerability in RTKLIB by Tomoji Takasu

RTKLIB versions up to 2.4.3 have a vulnerability in the getcodepri function that can be exploited when handling unrecognized RINEX observation codes. Attackers can craft RINEX files with unknown observation types to manipulate the processing, prompting negative array indexing into the codepris ta...

PoC for CVE-2026-56787

TomojitakasuRtklib6.9MEDIUM
Off-by-One Out-of-Bounds Vulnerability in RTKLIB by Tomoji Takasu

RTKLIB versions up to 2.4.3 are susceptible to an off-by-one out-of-bounds read vulnerability, specifically within the decode_ssr3 function. This issue permits remote attackers to instigate a global buffer overflow by transmitting specially crafted RTCM3 SSR messages that include manipulated sign...

PoC for CVE-2026-56786

TomojitakasuRtklib9.3CRITICAL
Out-of-Bounds Write Vulnerability in RTKLIB by Tomoji Takasu

RTKLIB versions up to 2.4.3 are affected by an out-of-bounds write vulnerability in the decode_type1033 function. This flaw arises from the failure to properly clamp length counters to the destination buffer size, allowing attackers to exploit it via crafted RTCM3 messages. By manipulating the NT...

PoC for CVE-2026-56779

1panel-devMaxkb5.3MEDIUM
Server-Side Request Forgery in MaxKB by 1Panel

The MaxKB application, prior to version 2.10.0, contains a vulnerability allowing authenticated users to exploit server-side request forgery. By manipulating unvalidated parameters such as 'downloadCallbackUrl' and 'download_url' within tool creation and update endpoints, attackers with default U...

PoC for CVE-2026-56774

KanboardKanboard5.3MEDIUM
Session Management Flaw in Kanboard by Kanboard

In Kanboard versions up to 1.2.52, a flaw in the UserViewController::removeSession method allows authenticated users to delete other users' Remember Me sessions without proper session ID validation. This vulnerability can be exploited by attackers who are able to enumerate sequential session IDs,...

PoC for CVE-2026-56770

SchwehrLibais8.7HIGH
Out-of-Bounds Memory Access in libais Affects Marine Communication ...

The vulnerability in libais arises from VdmStream::AddLine utilizing an unchecked sentinel value as a vector index. This flaw occurs when processing AIS sentences that contain empty or out-of-range sequential message IDs. Malicious actors can exploit this by sending specially crafted AIVDM senten...

PoC for CVE-2026-56769

HcengineeringPlatform6.3MEDIUM
Server-Side Request Forgery Vulnerability in Huly Platform by Huly ...

The Huly Platform prior to commit 68cbf8a is exposed to an authenticated server-side request forgery vulnerability in its /import endpoint. This flaw allows workspace users to manipulate server requests by submitting malicious URLs, thereby compromising the system's integrity. Attackers could exp...

Discovered 7 hours ago

PoC for CVE-2026-45233

DanprosHtmly7.2HIGH
Path Traversal Vulnerability in HTMLy CMS

HTMLy CMS versions up to 3.1.1 are impacted by a path traversal vulnerability that enables low-privileged authenticated attackers to relocate files arbitrarily. This occurs through the incorporation of unvalidated directory traversal sequences in the 'oldfile' parameter via the admin autosave end...

Discovered 8 hours ago

PoC for CVE-2025-67038

LantronixEDS50009.8CRITICAL
Remote Code Execution Vulnerability in Lantronix EDS5000 Product

A command injection vulnerability has been identified in the Lantronix EDS5000 product version 2.1.0.0R3. This flaw arises from the HTTP RPC module, which improperly handles user authentication log failures. Specifically, the module executes shell commands using a username that is directly concat...

Discovered 9 hours ago

PoC for CVE-2026-56122

RickknowlesWinstone Servlet Conta...8.7HIGH
Path Traversal Vulnerability in Winstone Servlet Engine

Winstone Servlet Engine versions up to 0.9.10 are susceptible to a path traversal vulnerability that enables unauthenticated attackers to access arbitrary files. This occurs when attackers send specially crafted HTTP GET requests that include dot-dot-slash sequences, which are not properly saniti...

Discovered 13 hours ago

PoC for CVE-2016-5195

CanonicalUbuntu Linux🟣 EPSS 84%7HIGH
Privilege Escalation Vulnerability in Linux Kernel by The Linux Fou...

A race condition exists in the Linux kernel that allows local users to gain elevated privileges. By exploiting improper handling of copy-on-write (COW) memory mappings, an attacker could modify files that are meant to be read-only. This vulnerability, known as 'Dirty COW', was notably used in att...

PoC for CVE-2021-29441

AlibabaNacos🟣 EPSS 75%8.6HIGH
Authentication bypass

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor...

Discovered 15 hours ago

PoC for CVE-2021-22205

GitlabGitlab🟣 EPSS 100%10CRITICAL
Remote Command Execution Vulnerability in GitLab Community and Ente...

An issue has been identified in GitLab Community and Enterprise Editions where improper validation of image files allows an attacker to execute arbitrary commands remotely. This vulnerability affects all versions from 11.9 onwards and poses significant security risks, particularly when image file...

Discovered 17 hours ago

PoC for CVE-2026-5305

WordPressEmail Address Encoder8.8HIGH
Stored XSS Vulnerability in Email Address Encoder Plugin by WordPress

The Email Address Encoder WordPress plugin versions prior to 1.0.25 and the email-encoder-premium WordPress plugin before version 0.3.12 exhibit security flaws in their email replacement functionality. This imperfection allows unauthenticated attackers to execute Stored Cross-Site Scripting (XSS)...

PoC for CVE-2026-9702

WordPressInpost Pl7.5HIGH
Unauthorized Request Handling in InPost PL WooCommerce Plugin by In...

The InPost PL WordPress plugin for WooCommerce lacks proper request verification, enabling attackers to exploit this vulnerability by altering the shipping destination of pending or processing orders without authorization. This flaw allows unauthorized users to silently redirect orders, posing a ...

PoC for CVE-2026-10824

WordPressMasteriyo Lms6.5MEDIUM
Authorization Bypass in Masteriyo LMS Plugin for WordPress

The Masteriyo LMS WordPress plugin prior to version 2.2.1 has a significant security flaw where it fails to enforce proper authorization checks within its course-progress REST API controller. This oversight permits unauthenticated users to access and even delete sensitive course progress records ...

Discovered 1 day ago

PoC for CVE-2025-32432

CraftcmsCms🟣 EPSS 100%10CRITICAL
Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic

Craft CMS, a customizable content management system, has a remote code execution vulnerability present in specific versions. Attackers could exploit this flaw to execute arbitrary code on the server, posing a significant security risk. The affected versions span from 3.0.0-RC1 to just before 3.9....

PoC for CVE-2026-48908

Joomshaper.netSp Page Builder Extens...10CRITICAL
Arbitrary File Upload in SP Page Builder for Joomla

A vulnerability in the SP Page Builder for Joomla permits unauthenticated users to upload arbitrary files. This weakness can lead to the execution of PHP code, presenting significant security risks for Joomla websites using this extension.

PoC for CVE-2026-8461

FfmpegFfmpeg8.8HIGH
Out-of-bounds Write Vulnerability in FFmpeg's Libavcodec Library

An out-of-bounds write vulnerability has been identified in the libavcodec library of FFmpeg, particularly within the MagicYUV decoder. This flaw may lead to denial-of-service conditions and has the potential to be exploited for remote code execution. The issue arises from improper handling of ce...

PoC for CVE-2026-49777

WordPressProduct Slider Pro For...10CRITICAL
Input Validation Flaw in Slider Pro for WooCommerce by ShapedPlugin...

An improperly validated quantity input vulnerability in Slider Pro for WooCommerce by ShapedPlugin, LLC can allow attackers to implant malicious software. This flaw affects versions prior to 3.5.4, enabling potential exploitation through unauthorized code execution.

Discovered 2 days ago

PoC for CVE-2026-45504

MicrosoftMicrosoft Exchange Ser...8.8HIGH
Server-Side Request Forgery Vulnerability in Microsoft Exchange Server

A server-side request forgery vulnerability exists in Microsoft Exchange Server, allowing an authorized attacker to craft requests that could lead to unauthorized access and privilege escalation within the network. This makes it crucial for organizations using Microsoft Exchange to apply the nece...

PoC for CVE-2026-55200

Libssh2Libssh29.2CRITICAL
Out-of-Bounds Write Vulnerability in libssh2 Affects Remote Code Ex...

libssh2 contains an out-of-bounds write vulnerability in the ssh2_transport_read() function that fails to impose proper limits on the packet_length field. This flaw allows remote attackers to exploit the vulnerability by sending specially crafted SSH packets with excessively large packet_length v...

PoC for CVE-2026-9710

WordPressCornerstone
Exposure of Sensitive Metadata in Cornerstone Page Builder by X Com...

The Cornerstone Page Builder plugin for WordPress prior to version 7.8.8 has a significant vulnerability due to a lack of enforced capability checks on a specific CSS-preview request handler. This flaw permits any logged-in user to access the nonce required for making requests, making it possible...

PoC for CVE-2026-9709

WordPressCornerstone
Authentication Bypass in Cornerstone WordPress Page Builder Plugin ...

The Cornerstone WordPress plugin prior to version 7.8.9 has a flaw in its REST API routes, failing to enforce capability checks. This oversight allows any authenticated user to access metadata belonging to other users, potentially exposing sensitive information such as user roles, session token p...

PoC for CVE-2026-10735

WordPressSmart-post-show-pro
Malicious Code Distribution in Shapedsmart-post-show-pro, Real Test...

The Shapedsmart-post-show-pro, Real Testimonials Pro, and Product Slider for WooCommerce Pro WordPress plugins have been compromised through a vendor's update server, allowing attackers to inject malicious code. This vulnerability enables unauthenticated users to execute a second-stage payload ca...

PoC for CVE-2026-10749

WordPressPost Duplicator
Security Flaw in Post Duplicator Plugin for WordPress

The Post Duplicator WordPress plugin, prior to version 3.0.15, exhibits a security flaw that inadequately manages custom meta-data during post duplication processes. This oversight allows an attacker with Contributor-level access or higher to inject serialized PHP objects. By bypassing the WordPr...

PoC for CVE-2026-10753

WordPressSite Kit By Google
Improper Access Control in Site Kit by Google WordPress Plugin

The Site Kit by Google WordPress plugin prior to version 1.176.0 contains a vulnerability that fails to adequately restrict a REST API write endpoint. This flaw allows users with lower privileges, such as Editors, who have been granted access to dashboard sharing, to modify site-wide settings tha...

PoC for CVE-2026-10531

WordPressAi Share & Summarize
Stored Cross-Site Scripting Vulnerability in AI Share & Summarize P...

The AI Share & Summarize plugin for WordPress prior to version 2.0.4 has a significant security flaw, where it fails to properly sanitize and escape certain shortcode attributes prior to displaying them on web pages. This oversight allows users with contributor roles and above to execute Stored C...

PoC for CVE-2026-45156

NextcloudSecurity-advisories8.1HIGH
Missing Signature Verification in Nextcloud OIDC Enables User Imper...

Nextcloud, a popular open-source content collaboration platform, has been identified with a vulnerability related to missing signature verification in its User OIDC implementation. This flaw allows a malicious ID4me authority to impersonate any user, potentially leading to unauthorized access and...

PoC for CVE-2026-41096

MicrosoftWindows 11 Version 23h29.8CRITICAL
Heap-Based Buffer Overflow in Microsoft Windows DNS Impacting Netwo...

A heap-based buffer overflow vulnerability in Microsoft Windows DNS can allow unauthorized attackers to execute arbitrary code remotely over the network. This can lead to potential data breaches and unauthorized access to sensitive information. Organizations are strongly encouraged to apply secur...

PoC for CVE-2026-39253

AureaPivotal CRM8.1HIGH
Arbitrary Code Execution Vulnerability in Pivotal CRM by Aurea

A vulnerability exists in Pivotal CRM version 6.6.04.08 that permits remote attackers to execute arbitrary code by manipulating components such as Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll. This flaw can compromise the integrity and confidentiality of the applicati...

PoC for CVE-2025-71382

ArtifexsoftwareMuPDF7.1HIGH
Uncontrolled Recursion Vulnerability in MuPDF EPUB Rendering Engine

MuPDF, a document rendering software, is vulnerable due to an uncontrolled recursion issue in its EPUB CSS rendering engine. This vulnerability allows remote attackers to exploit deeply nested HTML elements and inline CSS styles in specially crafted EPUB files. By triggering this vulnerability, a...

PoC for CVE-2026-56115

GarybowersBootimus8.7HIGH
Stack Out-of-Bounds Write Vulnerability in DHCPCD by Network Config...

DHCPCD versions prior to 10.3.2 contain a vulnerability that allows unauthenticated attackers on the same network link to exploit the dhcp6_makemessage() function. By crafting a malicious DHCPv6 ADVERTISE message with an oversized OPTION_PD_EXCLUDE option, attackers can trigger a stack out-of-bou...

PoC for CVE-2026-40369

MicrosoftWindows 11 Version 24h27.8HIGH
Windows Kernel Elevation of Privilege Vulnerability in Microsoft Pr...

A vulnerability in the Windows Kernel allows an authorized attacker to exploit an untrusted pointer dereference, potentially enabling them to gain higher privileges on the affected system. This could lead to unauthorized access to sensitive data and administrative functionalities. It's critical f...

Discovered 3 days ago

PoC for CVE-2026-21018

SamsungSamsung Devices6.8MEDIUM
Out-of-Bounds Write in Samsung SveService Affects Local Privileged ...

An out-of-bounds write vulnerability in Samsung's SveService prior to SMR May-2026 Release 1 allows local privileged attackers to exploit the flaw and execute arbitrary code. This security issue highlights the importance of promptly applying updates and securing environments against potential una...

PoC for CVE-2017-11882

MicrosoftMicrosoft Office🟣 EPSS 100%7.8HIGH
Memory Corruption Vulnerability in Microsoft Office Products

This vulnerability in Microsoft Office products allows an attacker to execute arbitrary code by exploiting improper handling of objects in memory. By leveraging this flaw, attackers can manipulate the application to run malicious code within the context of the current user. It highlights the impo...

PoC for CVE-2026-6992

LinksysMr96008.6HIGH
OS Command Injection Vulnerability in Linksys MR9600 by Linksys

An OS command injection vulnerability exists in the Linksys MR9600 router, specifically within the JNAP Action Handler. The issue arises from inadequate validation of the 'pin' argument in the function BTRequestGetSmartConnectStatus located in the run_central2.sh script. By exploiting this vulner...

PoC for CVE-2026-49772

WordPressThe Events Calendar9.3CRITICAL
SQL Injection Vulnerability in The Events Calendar by Liquid Web / ...

An SQL injection vulnerability exists in The Events Calendar plugin developed by Liquid Web and StellarWP, allowing for unauthorized access to the database through specifically crafted SQL commands. This can lead to sensitive data exposure or manipulation, impacting the integrity and security of ...

PoC for CVE-2026-8163

WordPressInfility Global8.8HIGH
SQL Injection Vulnerability in Infility Global WordPress Plugin

The Infility Global WordPress plugin, prior to version 2.15.19, is susceptible to a SQL Injection vulnerability caused by insufficient parameter sanitization and escaping. This flaw allows authenticated users with Subscriber-level access or higher to manipulate SQL queries, which could lead to un...

PoC for CVE-2026-7842

WordPressInfility Global6.8MEDIUM
SQL Injection Vulnerability in Infility Global WordPress Plugin

The Infility Global WordPress plugin prior to version 2.15.20 is susceptible to SQL injection due to improper sanitization and validation of input parameters in its admin page callbacks. This vulnerability allows authenticated users with Editor-level access or higher to manipulate SQL queries thr...