Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2026-12478
This vulnerability arises due to the improper placement of an integer overflow guard in libsoup, specifically within the conditional block for masked frames. As a result, unmasked server-to-client frames are vulnerable. A malicious WebSocket server could exploit this flaw by sending a specially c...
PoC for CVE-2023-44487
The HTTP/2 protocol is susceptible to a denial of service vulnerability that can be exploited via rapid stream resets. This allows attackers to overwhelm servers by rapidly canceling requests, leading to significant resource consumption and potential service disruption. Exploitation of this vulne...
Discovered 1 hour ago
PoC for CVE-2026-53576
The Kestra orchestration platform suffers from an authentication bypass vulnerability in its REST API. Specifically, any request ending with '/configs' is treated as public, bypassing necessary credential checks. This lack of authentication allows unauthorized users to create and execute flows, p...
Discovered 2 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-8239
Concrete CMS versions 9.5.0 and earlier are susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. The '/ccm/frontend/conversations/get_rating' endpoint allows unauthorized users to confirm the existence of any message's ID and retrieve its rating score. This exposes sensitive i...
Discovered 13 hours ago
PoC for CVE-2026-14839
The Mapster WP Maps plugin for WordPress, prior to version 1.24.0, is susceptible to an unauthorized access vulnerability. The plugin fails to implement necessary authorization or post-status checks on a public REST endpoint. This oversight permits unauthenticated users to access sensitive data, ...
PoC for CVE-2026-14840
The YOP Poll plugin for WordPress prior to version 7.0.6 is susceptible to a flaw that fails to properly validate the origin of connection IP addresses. This vulnerability allows unauthorized users to exploit the plugin's per-IP vote restrictions by trusting client-controlled forwarding headers. ...
PoC for CVE-2026-14823
The Event Tickets and Registration plugin for WordPress versions before 5.29.0.1 is susceptible to an authorization bypass issue. This flaw allows users with contributor-level access and higher privileges to manipulate seating arrangements, adjust ticket inventory, and reassign attendee seating f...
PoC for CVE-2026-14315
The Pixel Tag Manager for WooCommerce plugin prior to version 2.2.1 is susceptible to an authorization check failure in one of its AJAX actions. This vulnerability allows unauthenticated users to exploit the system by submitting forged e-commerce conversion events. The unauthorized use can lead t...
PoC for CVE-2026-14561
The Authora: Easy login with mobile number WordPress plugin prior to version 1.7.7 has a serious flaw that exposes its one-time login code during unauthenticated actions. This vulnerability allows attackers to retrieve the login code along with a valid verification token, granting them unauthoriz...
PoC for CVE-2026-14822
The Event Tickets and Registration plugin for WordPress before version 5.29.0.1 features a significant security issue where it lacks authorization checks on its order-management REST endpoints. This deficiency enables unauthenticated users to manipulate the status of existing orders, potentially ...
PoC for CVE-2026-14214
The Booking for Appointments and Events Calendar plugin for WordPress prior to version 2.4.4 permits users with the Amelia Manager role to manipulate arbitrary fields in user records through its import feature. This vulnerability allows for unauthorized alterations, potentially compromising the i...
PoC for CVE-2026-14292
The Download Manager plugin for WordPress prior to version 3.3.66 contains a vulnerability where it fails to properly escape the titles of packages before rendering them on the frontend. This oversight allows users with the Author role or higher to inject arbitrary JavaScript into these titles. C...
PoC for CVE-2026-13596
The Participants Database plugin for WordPress versions prior to 2.7.8.4 is susceptible to SQL injection due to insufficient sanitization and escaping of user-supplied parameters. This flaw enables attackers without authentication to execute arbitrary SQL queries, potentially compromising the dat...
PoC for CVE-2026-13604
The Pixelavo WordPress plugin prior to version 1.5.4 exposes an unauthenticated AJAX action that relies solely on a publicly available nonce. This security gap permits malicious users to send unauthorized event data to the Facebook Conversions API, leveraging the administrator's access token. Con...
PoC for CVE-2026-13725
The Dynamic Pricing With Discount Rules for WooCommerce plugin, prior to version 5.0.0, fails to validate nonces and user capabilities during certain AJAX requests. This weakness allows attackers to inject unsanitized input, potentially leading to reflected cross-site scripting (XSS) attacks. If ...
PoC for CVE-2026-14195
The Brizy plugin for WordPress fails to adequately verify user authorization on its request handler prior to content retrieval. This oversight permits users with a Contributor role or higher to access and read the content of arbitrary posts. Consequently, users can potentially view other users' p...
PoC for CVE-2026-13729
The Podlove Podcast Publisher WordPress plugin fails to implement nonce validation for various administrative create and delete actions. This oversight opens the door for potential attackers to execute unauthorized actions, such as creating rogue records or deleting legitimate ones. Such exploits...
PoC for CVE-2026-13329
The Buckaroo Woocommerce Payments Plugin for WordPress prior to version 4.9.0 contains a vulnerability that stems from the lack of proper capability checks and nonce validation on an AJAX action responsible for processing refunds on captured payments. This flaw allows any authenticated user, incl...
PoC for CVE-2026-13157
The Demo Import plugin for WordPress, up to version 1.1.3, exhibits a significant security flaw that permits high-privilege users, typically Administrators, to upload arbitrary files without proper validation. The plugin disables the WordPress file-type test during the demo-content import process...
PoC for CVE-2026-12696
A security vulnerability in the wpForo Forum WordPress plugin allows subscriber-level users to inject malicious JavaScript into their profile fields. This unfiltered output can compromise the security of the profile page, enabling attackers to execute scripts in the browsers of other users, inclu...
PoC for CVE-2026-10827
The Spectra Legacy WordPress plugin, prior to version 2.20.0, lacks proper validation and escaping for specific block style attributes, enabling users with a Contributor role or higher to insert arbitrary CSS. This vulnerable behavior allows these users to affect the styling of pages viewed by an...
PoC for CVE-2026-11882
The Builderall for WordPress plugin versions prior to 3.0.2 contains a security flaw that allows unauthenticated attackers to exploit its public OAuth authentication routes. This vulnerability permits attackers to manipulate the connection flow, enabling them to overwrite existing third-party int...
PoC for CVE-2026-13158
The Everest Toolkit WordPress plugin, specifically versions up to 1.2.3, suffers from a file upload vulnerability that fails to validate the types of files uploaded during demo-content import. With the WordPress file-type verification disabled, this opens a significant security risk where high-pr...
PoC for CVE-2026-15262
The Admin Columns for ACF Fields plugin for WordPress allows attackers with contributor-level access or higher to inject malicious JavaScript payloads. This vulnerability arises because the plugin fails to properly escape values from Advanced Custom Fields before rendering them in the WordPress a...
PoC for CVE-2026-15234
The Codeless Page Builder plugin for WordPress fails to properly sanitize and validate shortcode attributes before utilizing them as HTML tag names. This critical flaw enables users with contributor-level access and above to inject malicious HTML and JavaScript code. The injected scripts execute ...
PoC for CVE-2026-15368
The User Profile Builder plugin for WordPress is vulnerable due to a flaw in the binding of automatic user login following registration. This security issue allows unauthenticated attackers to exploit the vulnerability by gaining an authenticated session of any existing user, including those with...
PoC for CVE-2026-14836
The Login & Register Forms plugin for WordPress prior to version 3.2.5 features a serious security issue where the rate limit enforcement on password-reset verification codes can be manipulated. Specifically, the plugin lets unauthorized users control a key component used for verifying password-r...
PoC for CVE-2026-15244
The HUSKY WordPress plugin, prior to version 1.4.1, contains a vulnerability that fails to properly sanitize a stored setting value, enabling directory traversal. This flaw allows users with shop manager capabilities to manipulate file inclusion paths, leading to the potential execution of arbitr...
PoC for CVE-2026-14309
The Chat On Desk Order Notifications plugin for WordPress, specifically versions prior to 1.0.9, contains a vulnerability that fails to adequately verify one-time passwords before processing password reset requests. This oversight allows unauthorized individuals to exploit the system and reset th...
PoC for CVE-2026-14596
The DynamicKit for Elementor plugin prior to version 1.0.3 has a security flaw that fails to validate the host in user-supplied URLs used for password-reset links. This oversight allows attackers to craft a phishing email that appears legitimate, enabling them to send a password reset request lin...
PoC for CVE-2026-14197
The Fluent Support plugin for WordPress prior to version 2.3.1 is susceptible to an access control issue that permits a restricted support agent to modify the customer assigned to any support ticket. This vulnerability arises from the lack of proper access checks during the reassignment process, ...
PoC for CVE-2026-12966
The Direct Payments for WooCommerce plugin for WordPress prior to version 2.5.3 is susceptible to a serious vulnerability where unauthenticated users can manipulate WooCommerce order statuses through insecure AJAX handlers. This flaw allows attackers to change order states to 'payment sent', over...
PoC for CVE-2025-15669
The Bit Form plugin for WordPress, prior to version 3.1.4, suffers from a vulnerability where it fails to properly sanitize a critical conversational-form display setting before rendering. This oversight allows users with elevated privileges—specifically administrators lacking the unfiltered_html...
PoC for CVE-2026-15932
The Support Genix WordPress plugin prior to version 1.4.48 is susceptible to a directory traversal vulnerability. This flaw allows unauthenticated attackers to exploit the ticket-attachment download feature, potentially enabling access to arbitrary files on the server. Attackers can read sensitiv...
Discovered 14 hours ago
PoC for CVE-2026-8337
Concrete CMS versions 9.5.0 and earlier contain a vulnerability that allows unauthenticated attackers to exploit insecure direct object references (IDOR) in survey functionalities. A malicious user can manipulate the public survey's endpoint to submit votes for private surveys, bypassing restrict...
Discovered 15 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 17 hours ago
PoC for CVE-2026-66066
Active Storage, a framework component of Rails, has a vulnerability that affects versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1. This issue arises from the framework's failure to disable unsafe libvips operations when handling image uploads from untrusted users. An unauthenticated attacker can e...
Discovered 18 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 19 hours ago
PoC for CVE-2026-47668
DbGate, a cross-platform database management tool, exhibits a vulnerability allowing remote code execution through code injection in the 'functionName' parameter of JSON script 'assign' commands. This security flaw is present in versions 7.1.8 and earlier, where untrusted input is directly incorp...
Discovered 22 hours ago
PoC for CVE-2026-32286
A vulnerability exists within the DataRow.Decode function of the PostgreSQL server, where it inadequately checks field lengths. An attacker utilizing a malicious PostgreSQL server could send a DataRow message with a negative field length, resulting in a slice bounds out of range panic condition. ...
Discovered 1 day ago
PoC for CVE-2026-43284
A vulnerability exists in the Linux kernel that concerns the handling of shared skb fragments during the decryption process in ESP-in-UDP packets. When pages are attached from a pipe directly to an skb using MSG_SPLICE_PAGES, the kernel marked these SKBs with SKBFL_SHARED_FRAG, which plays a cruc...
PoC for CVE-2026-8347
A vulnerability in Concrete CMS versions 9.5.0 and earlier allows an attacker to exploit IDOR (Insecure Direct Object Reference) and incorrect authorization levels in the Express association Reorder dialog. This could enable a malicious user to manipulate state across entities with view-only perm...
PoC for CVE-2026-54121
A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...
PoC for CVE-2026-16723
A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk...
PoC for CVE-2026-54121
A vulnerability exists in Microsoft Active Directory Certificate Services (AD CS) that allows an authorized attacker to exploit improper authorization mechanisms to elevate privileges within a network. This weakness can potentially enable attackers to access sensitive information, configure permi...
PoC for CVE-2021-1931
This security vulnerability is caused by improper validation of the buffer length when processing fast boot commands across various Qualcomm Snapdragon products. An attacker could exploit this flaw to execute arbitrary code or cause unintended behavior, potentially compromising the affected devices.
PoC for CVE-2022-24903
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for remote code execu...
Discovered 2 days ago
PoC for CVE-2026-14919
The ShopMonitor.io plugin for WordPress before version 1.2.0 contains a flaw that allows unauthorized users to exploit the email rerouting feature. This security gap allows attackers to redirect sensitive outgoing emails, such as password reset notifications for the WordPress administrator accoun...
PoC for CVE-2026-14862
The Support Genix plugin for WordPress versions prior to 1.4.48 is vulnerable to an improper access control issue that permits unauthenticated users to download private ticket attachments. This flaw occurs due to insufficient checks on access rights, allowing individuals who know the stored attac...