Publicly Disclosed
PoC Exploits
🔴 Alway take caution when working with PoC Exploits 🔴
Discovered just now...
PoC for CVE-2024-1086
A use-after-free vulnerability exists in the nf_tables component of the Linux kernel, specifically within the nft_verdict_init() function. This vulnerability can be exploited when a drop error is incorrectly handled, resulting in a potential double free situation during packet verdict processing....
Discovered 1 hour ago
PoC for CVE-2026-19193
A vulnerability has been identified in Jiangmin Antivirus 21 that affects the MessageNotifyCallback function within the kvcore.sys library of the Minifilter Port. This flaw allows for improper access controls, enabling local attackers to potentially exploit the system through unauthorized manipul...
Discovered 2 hours ago
PoC for CVE-2026-19192
A vulnerability exists in DeepCool DisplayService version 1.2.12 that allows for improper access controls related to the handling of the executable file DeepCoolDisplayService.exe. This flaw can be exploited locally, potentially enabling an attacker to manipulate the service and gain unauthorized...
PoC for CVE-2026-19191
A security flaw has been identified in StableBit DrivePool version 2.3.13.1687, affecting the DrivePoolService component. This vulnerability enables local users to manipulate permissions within the application, potentially leading to unauthorized access and control over sensitive operations. The ...
Discovered 3 hours ago
PoC for CVE-2026-19190
A local execution vulnerability has been discovered in StableBit Scanner version 2.6.13.4088, which affects the ScannerService component located in C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe. This issue can lead to permission manipulation, allowing unauthorized access to...
PoC for CVE-2026-18649
A vulnerability exists in the GStreamer gst-plugins-good package where the rtph264depay and rtph265depay RTP depayloader elements fail to enforce a limit on the size of the reassembly buffer utilized during the processing of fragmented RTP packets. This flaw permits a remote, unauthenticated atta...
Discovered 4 hours ago
PoC for CVE-2026-19189
A security vulnerability has been identified in Power Software's PowerISO version 9.3.0.0, which affects the kernel driver component found at C:\Windows\System32\drivers\scdemu.sys. This flaw enables improper privilege management, allowing attackers with local access to exploit the issue. The pot...
Discovered 7 hours ago
PoC for CVE-2026-56164
A vulnerability exists in Microsoft Office SharePoint where a critical function lacks proper authentication. This flaw allows unauthorized attackers to gain elevated privileges over a network, potentially leading to unauthorized actions and data exposure. Microsoft has released guidance for mitig...
Discovered 8 hours ago
PoC for CVE-2026-0300
A buffer overflow vulnerability exists within the User-ID™ Authentication Portal of Palo Alto Networks PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by manipulating specially crafted packets. To miti...
PoC for CVE-2026-70636
Flowise versions up to 3.1.4 have a significant security vulnerability that allows unauthenticated attackers to exploit the OAuth2 credential refresh endpoint. This is achieved through a flaw in the prefix-based whitelist matching within the authentication middleware. By sending a specifically cr...
PoC for CVE-2026-67622
The Flowise OpenAI Assistants integration, particularly in version 3.1.4, is susceptible to an insecure direct object reference vulnerability. This flaw enables authenticated attackers to gain unauthorized access to sensitive credentials linked to other workspaces. By exploiting this vulnerabilit...
PoC for CVE-2026-67621
The Flowise product versions up to 3.1.4 exhibit a significant vulnerability due to missing authorization checks. This flaw enables authenticated users with mere view-level permissions to carry out unauthorized actions on the document store. By exploiting unprotected mutation endpoints, an attack...
Discovered 9 hours ago
PoC for CVE-2026-19110
A cross site scripting vulnerability exists in DataGear products prior to version 5.0.0, specifically in the function HtmlTplDashboardWidgetHtmlRenderer located in HtmlTplDashboardWidgetHtmlRenderer.java. This flaw allows attackers to manipulate the Title argument, which can lead to unauthorized ...
PoC for CVE-2026-0163
A significant vulnerability exists in the Android operating system, specifically within the vpu_ioctl.c file, where multiple functions permit a use after free scenario. This flaw could allow an attacker to escalate privileges remotely without requiring any interaction from users, making it partic...
PoC for CVE-2026-19108
A use after free vulnerability was identified in MZ Automation's libiec61850 version 1.6.1 impacting the deleteDataSetValuesShadowBuffer function within the URCB Revalidation component. This flaw enables local attackers to manipulate memory allocation, potentially leading to application crashes o...
PoC for CVE-2026-19071
A vulnerability has been identified in the itsourcecode Hospital Management System 1.0, specifically within the /viewappointment.php file. An unvalidated input in the function handling 'delid' parameters exposes the application to SQL injection attacks. This flaw allows an attacker to manipulate ...
Discovered 10 hours ago
PoC for CVE-2026-19070
A SQL injection vulnerability has been identified in the itsourcecode Hospital Management System version 1.0. This flaw affects the file /viewadmin.php, where manipulation of the 'delid' argument allows attackers to execute arbitrary SQL queries on the database. The exploit can be executed remote...
PoC for CVE-2026-19069
A SQL injection vulnerability exists in the itsourcecode Hospital Management System 1.0, specifically affecting the /treatmentrecord.php file. This vulnerability allows remote attackers to manipulate the 'editid' parameter, leading to unauthorized database access and potential exposure of sensiti...
PoC for CVE-2026-67598
Emlog Pro, as of version 2.6.23, is susceptible to a TLS certificate validation vulnerability that allows attackers in the same network vicinity to intercept HTTPS requests. This exploitation arises from the unconditional disabling of the CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST options ...
PoC for CVE-2026-19068
A vulnerability exists in the itsourcecode Hospital Management System version 1.0, specifically in the treatmentdetail.php file. An attacker can exploit this weakness by manipulating the 'patientid' argument, which may lead to unauthorized access to the database. The attack can be executed remote...
Discovered 11 hours ago
PoC for CVE-2026-19067
A vulnerability has been identified in the itsourcecode Hospital Management System 1.0 that allows an attacker to perform SQL injection through the manipulation of the 'editid' argument in the '/treatment.php' file. This flaw can be exploited remotely, posing a significant risk as the exploit has...
Discovered 12 hours ago
PoC for CVE-2025-15674
The Passster WordPress plugin prior to version 4.3.7 contains a vulnerability that allows users with low privileges, specifically those holding the edit_posts capability, to bypass password protection on globally protected content. When global protection is enabled, this flaw allows contributors ...
PoC for CVE-2026-16620
The WPC Name Your Price for WooCommerce WordPress plugin, prior to version 2.2.5, is vulnerable due to inadequate server-side enforcement of price allowlists for products set to 'Select' price mode. This oversight allows unauthenticated users to manipulate product prices below the merchant's appr...
PoC for CVE-2026-16619
The miniOrange 2FA WordPress plugin versions prior to 6.2.8 contain a flaw that permits unlimited second-factor verification attempts. The plugin tracks these attempts using a client-supplied identifier, which is changed on every login. This design oversight allows an attacker who is aware of a u...
PoC for CVE-2026-19062
A vulnerability has been identified in Chiuwingyan House, specifically affecting the file /paid/selectall.action. This flaw arises from improper handling of the argument 'zuname', leading to SQL injection, which can be exploited remotely. The vendor has been notified of the issue but has not resp...
PoC for CVE-2026-16067
The Event Booking Manager for WooCommerce (Pro) plugin versions prior to 5.0.3 inadequately validates ticket pricing during native checkout. Instead of re-confirming the configured ticket price on the server, it relies on the client-supplied price. This flaw permits unauthorized users to register...
PoC for CVE-2026-15256
The Ninja Forms plugin for WordPress allows unauthenticated adversaries to exploit a vulnerability that arises when user-supplied query-string input is not adequately sanitized. This flaw enables attackers to input data into a form field that bypasses validation, processing it as a shortcode. Whe...
PoC for CVE-2026-17032
Multiple Supsystic Pro plugins were found to contain malicious code due to a compromise of the vendor's update server. This vulnerability permits unauthenticated attackers to execute a second-stage payload, which can lead to the exfiltration of sensitive credentials and data. Furthermore, this ex...
PoC for CVE-2026-13342
The Security Optimizer WordPress plugin, versions 1.5.8 through 1.6.4, has a critical security flaw that allows bypassing the IP-based login restriction feature. This vulnerability occurs due to improper validation of requests, enabling unauthenticated users from non-allowlisted IPs to access the...
PoC for CVE-2026-15208
The RegistrationMagic plugin for WordPress, prior to version 6.0.9.5, has a significant security flaw that undermines its payment verification process. The plugin fails to verify critical payment details—such as the amount, currency, payee, and prior usage—against the registration it is finalizin...
PoC for CVE-2026-15149
The WP Hotel Booking plugin prior to version 2.3.3 includes a critical input validation flaw, where it fails to ensure that room quantities and order totals are non-negative. This oversight permits unauthenticated users to manipulate cart data, potentially allowing them to secure confirmed reserv...
PoC for CVE-2026-15147
The Five Star Restaurant Reservations plugin for WordPress prior to version 2.7.23 contains a flaw in its handling of payment notifications. It does not properly authenticate incoming payment messages, allowing unauthorized actors to manipulate existing reservations. Attackers can mark any pendin...
PoC for CVE-2026-10524
The CoCart WordPress plugin, especially in versions prior to 4.9.0, has a significant flaw where it does not properly validate user-supplied price values against the actual prices of products. This weakness allows unauthenticated users to bypass typical security measures, enabling them to set arb...
Discovered 13 hours ago
PoC for CVE-2026-14831
The Easy Booking WordPress plugin prior to version 3.5.0 lacks proper server-side enforcement of the minimum booking duration for products. This vulnerability enables unauthorized users to bypass the configured settings, facilitating the placement of bookings that do not meet the minimum duration...
PoC for CVE-2026-14936
The Simple Membership plugin for WordPress, prior to version 4.7.7, exposes a vulnerability that allows unauthenticated individuals to activate or extend memberships. This occurs because the plugin fails to verify that a PayPal payment notification is directed to the configured merchant account o...
PoC for CVE-2026-12901
The GetPaid WordPress plugin prior to version 2.8.55 contains a critical flaw that permits unauthenticated attackers to manipulate incoming Worldpay payment notifications. This vulnerability can be exploited to falsely mark pending invoices as paid, effectively allowing the attacker to bypass pay...
PoC for CVE-2026-12501
The WP Travel Engine plugin in WordPress fails to verify incoming PayPal payment notifications against the site's configured merchant account and the order total. This lax verification process allows unauthorized attackers to mark bookings as fully paid by using tokens from a compromised payment ...
PoC for CVE-2026-15152
The WP Hotel Booking plugin for WordPress has a vulnerability where it fails to verify the authenticity of payment notifications. An attacker can exploit this by submitting false payment notifications, allowing them to mark bookings as fully paid without actual payment being made. This could lead...
PoC for CVE-2026-14842
The Events Made Easy WordPress plugin, prior to version 3.1.2, exhibits a critical flaw in its payment processing mechanism. This vulnerability allows unauthenticated users to exploit the system by binding payment authorization tokens incorrectly. Consequently, an attacker can pay a minimal fee f...
PoC for CVE-2026-14225
The Easy Appointments WordPress plugin, up to version 3.12.26, is affected by a flaw in its handling of shortcode input. This vulnerability arises from insufficient validation during a block-rendering process, where the plugin only checks the first tag of a supplied string against a predefined al...
PoC for CVE-2026-14812
The Premium SEO WordPress plugin contains a serious vulnerability that allows unauthorized access through an unauthenticated backdoor. This flaw creates a hidden administrator account, enabling potential attackers to gain full control over the affected WordPress site. In certain builds, it also f...
PoC for CVE-2026-13399
The Payment Plugins for PayPal WooCommerce before version 2.0.20 lacks necessary authorization checks on a critical REST endpoint. This vulnerability enables unauthorized users to bypass the payment process, potentially leading to unauthorized transactions or exposure to sensitive payment data. P...
PoC for CVE-2026-14306
The Tutor LMS WordPress plugin prior to version 3.9.14 contains a flaw in its access control mechanism. The vulnerability allows authenticated users who have subscriber-level access or higher and are enrolled in at least one course to bypass restrictions on protected content. This misconfiguratio...
PoC for CVE-2026-12584
The Payment Gateway for Redsys & WooCommerce Lite plugin, prior to version 7.0.2, contains a flaw where it fails to validate the authenticity of payment notifications from providers. This oversight allows attackers to impersonate legitimate payment confirmations, thus marking orders as paid witho...
PoC for CVE-2026-11361
The Formidable Forms plugin for WordPress prior to version 6.32.1 contains a flaw that allows unauthenticated users to bypass the necessary validation for PayPal subscription payments. As a result, these users can improperly trigger actions typically reserved for paying customers, including acces...
PoC for CVE-2026-10599
The Integrate PhonePe with WooCommerce WordPress plugin prior to version 1.2.1 is susceptible to an improper authorization vulnerability. This issue allows an attacker to bypass payment verification processes by reusing a valid payment transaction. Consequently, an attacker can manipulate the sta...
PoC for CVE-2026-19060
A vulnerability has been identified in FoundationAgents' MetaGPT product, affecting versions up to 0.8.2, which enables local manipulation leading to code injection. This vulnerability occurs through an unknown function within the application, allowing attackers to execute malicious code if they ...
PoC for CVE-2026-11976
The update distribution for MonsterInsights Pro was compromised, involving the presence of a malicious file named 'class-system-check.php' in both version 10.2.2 and the rolled-back version 10.2.0. This breach occurred through the official update bucket hosted on an Amazon S3 server. A single att...
PoC for CVE-2026-5336
The DataPress (Dataverse Integration) plugin for WordPress prior to version 2.91 contains an access control vulnerability that inadequately restricts access to its template rendering feature. This oversight allows users with low-level roles, such as Contributor, to access sensitive data. Specific...
PoC for CVE-2026-19059
A path traversal vulnerability exists in FoundationAgents MetaGPT up to version 0.8.2, particularly affecting the read function in metagpt/tools/libs/editor.py. This vulnerability allows attackers with local access to manipulate file paths, potentially enabling unauthorized file access. The explo...