Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 21 seconds ago

PoC for CVE-2026-23744

McpjamInspector🟣 EPSS 30%9.8CRITICAL
Remote Code Execution Vulnerability in MCPJam Inspector by MCP

MCPJam Inspector, designed for local-first development on MCP servers, has a vulnerability allowing remote code execution (RCE) due to improper binding settings. In versions 1.4.2 and earlier, the platform listens on 0.0.0.0 by default, enabling attackers to exploit this configuration through cra...

Discovered 1 hour ago

PoC for CVE-2026-6815

CasdoorCasdoor5.9MEDIUM
Arbitrary File Write Vulnerability in Casdoor's Local File System S...

The arbitrary file write vulnerability in Casdoor's Local File System storage provider is caused by insufficient path sanitization. An authenticated attacker with administrative privileges can exploit this vulnerability to perform a Path Traversal attack, allowing them to create or overwrite file...

Discovered 2 hours ago

PoC for CVE-2026-10875

ProjectworldsOnline Art Gallery Sho...5.3MEDIUM
projectworlds Online Art Gallery Shop Project adminHome.ph sql inje...

A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /admin/adminHome.ph. The manipulation of the argument social_twitter results in sql injection. The attack may be launched remotely. The exploit has bee...

Discovered 3 hours ago

PoC for CVE-2026-10874

ProjectworldsOnline Art Gallery Sho...5.3MEDIUM
projectworlds Online Art Gallery Shop Project adminHome.php sql inj...

A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation of the argument social_insta leads to sql injection. The attack may be initiated remotely. The exploit is publicly av...

PoC for CVE-2026-45247

MirasvitFull Page Cache Warmer...9.3CRITICAL
PHP Object Injection Vulnerability in Mirasvit Full Page Cache Warm...

The Mirasvit Full Page Cache Warmer, specifically for Magento 2, is susceptible to a PHP object injection flaw that permits unauthenticated attackers to execute arbitrary code. This vulnerability arises from an unrestricted invocation of PHP's native unserialize() function when handling malformed...

PoC for CVE-2026-10872

ShibbyTomato8.6HIGH
Shibby Tomato Web UI rc start_vpnserver os command injection

A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. ...

PoC for CVE-2026-10871

ShibbyTomato8.6HIGH
Shibby Tomato Web UI rc start_6rd_tunnel os command injection

A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay leads to os command injection. It is possible to launch the attack remotely. The...

Discovered 6 hours ago

PoC for CVE-2013-6117

DahuasecurityDvr Firmware🟣 EPSS 90%
Authentication Bypass in Dahua DVR Products by Dahua Technology

The Dahua DVR products version 2.608.0000.0 and 2.608.GV00.0 are susceptible to a critical authentication bypass vulnerability that allows malicious remote attackers to gain unauthorized access to sensitive information. By exploiting this flaw via TCP port 37777, attackers can retrieve user crede...

Discovered 8 hours ago

PoC for CVE-2025-71316

SqliteSqldiff9.2CRITICAL
SQLite sqldiff remote code execution via argument injection

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misint...

PoC for CVE-2026-25551

Seagull Software,...Bartender 20218.5HIGH
Seagull Software BarTender Deserialization Privilege Escalation via...

Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe, limiting the attack ...

Discovered 9 hours ago

PoC for CVE-2026-5076

WordPressArmember Premium – Mem...9.8CRITICAL
Insecure Password Reset Mechanism in ARMember Premium Plugin for Wo...

The ARMember Premium plugin for WordPress is compromised by an insecure password reset mechanism present in all versions up to and including 7.3.1. When a user requests a password reset, the plugin unintentionally stores the plaintext password reset key in the `arm_reset_password_key` user meta f...

Discovered 10 hours ago

PoC for CVE-2026-10815

Lakshayd02Hostel-management-syst...5.3MEDIUM
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php a...

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization....

PoC for CVE-2026-10814

Milvus-ioMilvus2LOW
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of weak hash. The attack needs to be performed locally. The at...

Discovered 11 hours ago

PoC for CVE-2026-10813

Lmcache2LOW
LMCache KV Cache utils.py hex_hash_to_int16 weak hash

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high lev...

PoC for CVE-2026-10812

ZilliztechGptcache2LOW
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash

A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component Cache Key Handler. Performing a manipulation of the argument input_data["image"] results in use of weak hash. The att...

PoC for CVE-2026-10811

ItsourcecodeFees Management System5.3MEDIUM
itsourcecode Fees Management System receipt.php sql injection

A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such manipulation of the argument ef_id leads to sql injection. The attack may be performed from remote. The exploit has been...

Discovered 12 hours ago

PoC for CVE-2019-25745

WordPressGoogle Review Slider8.8HIGH
WordPress Plugin Google Review Slider 6.1 SQL Injection via tid

WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with malicious 'tid' val...

PoC for CVE-2019-25744

WordPressPopup Builder5.1MEDIUM
WordPress Popup Builder 3.49 Persistent Cross-Site Scripting

WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payload...

PoC for CVE-2019-25743

WordPressSoliloquy Lite5.1MEDIUM
WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting

WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script payloads in the pos...

PoC for CVE-2019-25742

WordPressZoner Real Estate5.1MEDIUM
WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS

WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property creation form that execu...

PoC for CVE-2019-25741

MobatekMobatek Mobaxterm9.3CRITICAL
Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File

Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vul...

PoC for CVE-2019-25740

JoomskyJs Jobs7.1HIGH
Joomla com_jsjobs 1.2.6 Arbitrary File Deletion

Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2 parameter to delete arbi...

PoC for CVE-2019-25738

WordPressHybrid Composer9.3CRITICAL
WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set t...

PoC for CVE-2019-25739

GigtodoscriptGigtodo5.1MEDIUM
GigToDo Freelance Marketplace Script 1.3 Persistent XSS

GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers can craft XSS payloads in the create_proposal endpoint that execute when administrators or other ...

PoC for CVE-2019-25737

ScreetsLive Chat Unlimited5.1MEDIUM
Live Chat Unlimited 2.8.3 Stored Cross-Site Scripting

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie th...

PoC for CVE-2019-25736

LabfLabf Nfsaxe8.6HIGH
LabF nfsAxe 3.7 Ping Client Buffer Overflow

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.ex...

PoC for CVE-2019-25735

AllplayerAllplayer8.6HIGH
AllPlayer 7.4 Local Buffer Overflow via SEH Unicode

AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code ex...

PoC for CVE-2019-25734

Web-doradoContact Form Maker5.1MEDIUM
Contact Form by WD 1.13.1 CSRF to Local File Inclusion

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint ...

PoC for CVE-2019-25733

NsauditorNetsharewatcher8.6HIGH
NetShareWatcher 1.5.8.0 SEH Buffer Overflow

NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to tr...

PoC for CVE-2019-25731

ZuzZuz Music5.1MEDIUM
Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole Contact

Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inject script code through the name, subject, and message parameters in POST requests to /gmusic/zuzco...

PoC for CVE-2019-25732

EitubeEi-tube8.8HIGH
PHP EI-Tube Script 3 SQL Injection via search parameter

PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to the search endpoint with crafted SQL payloads in the query parameter to ...

PoC for CVE-2019-25730

ThemerigListing Hub Cms8.8HIGH
Listing Hub CMS 1.0 SQL Injection via pages.php id

Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to...

PoC for CVE-2019-25729

Simcy CreativePDF Signer9.3CRITICAL
PDF Signer 3.0 Server-Side Template Injection RCE via CSRF Cookie

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_e...

PoC for CVE-2019-25727

WordPressAd Manager Wd9.3CRITICAL
WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parame...

PoC for CVE-2019-25728

Care2xCare2x8.8HIGH
Care2x 2.7 Hospital Information System SQL Injection via ck_config

Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject malicious SQL through the ck_config cookie in multiple endpoints including login.php, indexframe.p...

PoC for CVE-2019-25726

NicheofficeAll In One Video Downl...8.8HIGH
All in One Video Downloader 1.2 SQL Injection via admin page-edit

All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id...

PoC for CVE-2026-10810

ItsourcecodeFees Management System5.3MEDIUM
itsourcecode Fees Management System navbar.php cross site scripting

A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to t...

PoC for CVE-2026-10809

ItsourcecodeFees Management System5.3MEDIUM
itsourcecode Fees Management System manage_user.php sql injection

A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be ...

Discovered 13 hours ago

PoC for CVE-2026-10808

ItsourcecodeFees Management System5.3MEDIUM
itsourcecode Fees Management System manage_student.php sql injection

A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

PoC for CVE-2026-10807

MjperpinosaStumasy5.3MEDIUM
mjperpinosa stumasy change_profile_image.php unrestricted upload

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of the argument pr_profile_image can lead to unrestricted upload. The attack may be launched remotely....

PoC for CVE-2026-10806

MjperpinosaStumasy5.3MEDIUM
mjperpinosa stumasy add_post.php unrestricted upload

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post results in unrestricted upload. The attack may be initiated remotely. The exploit has b...

PoC for CVE-2026-10804

Streamlit2LOW
Streamlit Palette hashing.py weak hash

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a ...

Discovered 14 hours ago

PoC for CVE-2020-17103

MicrosoftWindows 10 Version 20h27HIGH
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulne...

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17134, CVE-2020-17136.

PoC for CVE-2026-10803

Mlflow2LOW
MLflow Dataset Digest Computation digest_utils.py mlflow.data.diges...

A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipulation causes use of weak hash. It is possible to launch the attack on the local host. The attack ...

PoC for CVE-2026-10802

KeystonejsKeystone5.3MEDIUM
keystonejs keystone GraphQL API Endpoint output-field.ts resource c...

A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The manipulation results in resource consumption. It is possible to launch the attac...

PoC for CVE-2026-10801

ModelscopeMs-swift2LOW
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_...

A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache Key Handler. The manipulation leads to use of weak hash. An attack has to be approached locally. A ...

Discovered 15 hours ago

PoC for CVE-2026-23631

RedisRedis6.1MEDIUM
Use-After-Free Vulnerability in Redis Affects In-Memory Data Struct...

An authenticated attacker can exploit a use-after-free vulnerability in the master-replica synchronization mechanism of Redis, specifically when Lua scripting is enabled and replica-read-only is disabled. This exploit can potentially lead to remote code execution on affected replicas. To mitigate...

Discovered 1 day ago

PoC for CVE-2026-10783

Gradio-appGradio2LOW
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash

A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack must be initiated from a local position. The attack is considered to have high...

PoC for CVE-2021-44228

ApacheApache Log4j2🟣 EPSS 94%10CRITICAL
Apache Log4j2 JNDI features do not protect against attacker control...

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...

PoC for CVE-2026-10777

Ealpha072Student-management-system6.9MEDIUM
ealpha072 Student-Management-System Administrative Backend config.p...

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php of the component Administrative Backend. Such manipulation leads to improper authentication. The ...