Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2024-3400

Palo Alto NetworksPan-os🟣 EPSS 94%10CRITICAL
Palo Alto Networks PAN-OS Command Injection Vulnerability

A vulnerability exists in the GlobalProtect feature of Palo Alto Networks PAN-OS software, allowing for arbitrary file creation. This issue can be exploited by an unauthenticated attacker to execute code with root privileges on the affected firewall systems. Specific configurations and versions a...

PoC for CVE-2025-9485

WordPressOauth Single Sign On –...9.8CRITICAL
Improper Cryptographic Signature Verification in WordPress Plugin b...

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress suffers from a significant vulnerability due to its improper handling of JSON Web Tokens (JWT). Versions up to and including 6.26.12 do not adequately verify or validate the signatures of incoming tokens in the `get_resource_owner...

Discovered 32 minutes ago

PoC for CVE-2026-8732

WordPressWP Maps Pro9.8CRITICAL
Privilege Escalation in WP Maps Pro Plugin by WordPress

The WP Maps Pro plugin contains a vulnerability that allows unauthenticated attackers to escalate their privileges by creating a new administrator account. This occurs due to insufficient protection around a public AJAX action, which can be exploited using a nonce that is easily accessible. By in...

Discovered 4 hours ago

PoC for CVE-2026-0257

Palo Alto NetworksCloud Ngfw7.8HIGH
Authentication Bypass in Palo Alto Networks PAN-OS Software

The authentication bypass vulnerability in Palo Alto Networks' PAN-OS software presents a significant security risk by allowing unauthorized access to the GlobalProtect portal and gateway. This flaw enables attackers to circumvent authentication mechanisms, potentially gaining unauthorized VPN co...

PoC for CVE-2026-39987

Marimo-teamMarimo🟣 EPSS 82%9.3CRITICAL
Pre-Authentication Remote Code Execution in Marimo Python Notebook

Marimo, a reactive Python notebook, exhibits a significant security vulnerability prior to version 0.23.0. The terminal WebSocket endpoint (/terminal/ws) allows unauthenticated access, enabling attackers to gain a complete pseudo-terminal shell and execute arbitrary commands on the host system. U...

PoC for CVE-2026-10127

EdimaxBr-6478ac5.3MEDIUM
Command Injection Vulnerability in Edimax Router

A security flaw in the Edimax BR-6478AC version 1.23 affects the function formStaDrvSetup within the POST request handler. This vulnerability allows an attacker to inject commands through manipulation of the argument 'rootAPmac'. Due to its nature, the attack can be executed remotely, increasing ...

Discovered 5 hours ago

PoC for CVE-2026-10126

EdimaxBr-6478ac8.7HIGH
Buffer Overflow Vulnerability in Edimax BR-6478AC Routers

A security flaw has been identified in Edimax BR-6478AC routers, specifically affecting version 1.23. The issue is rooted in the formQoS function located in the /goform/formQoS file, where improper handling of the selSSID argument can lead to a buffer overflow. This vulnerability allows remote at...

PoC for CVE-2026-7392

SourcecodesterPharmacy Sales And Inv...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Pharmacy Sales and In...

A vulnerability exists within the SourceCodester Pharmacy Sales and Inventory System version 1.0 that allows for remote SQL injection through the delete_supplier function found in the ajax.php file. By manipulating the ID argument, an attacker can execute arbitrary SQL commands, potentially compr...

PoC for CVE-2026-10125

EdimaxBr-6478ac8.7HIGH
Stack-based Buffer Overflow in Edimax BR-6478AC Router

A stack-based buffer overflow vulnerability has been discovered in the Edimax BR-6478AC router, specifically in the function formPPPoESetup within the POST Request Handler component. The vulnerability arises from improper handling of the 'pppUserName' argument, allowing an attacker to manipulate ...

PoC for CVE-2026-42589

GotenbergGotenberg9.8CRITICAL
Unvalidated Input Vulnerability in Gotenberg PDF Processing API

The Gotenberg API, designed for handling PDF file processing via Docker, suffers from a severe vulnerability prior to version 8.31.0. Specifically, the /forms/pdfengines/metadata/write HTTP endpoint fails to validate JSON metadata object keys before passing them to ExifTool through the go-exiftoo...

PoC for CVE-2026-10124

ShibbyTomato8.7HIGH
Buffer Overflow Vulnerability in Shibby Tomato Router Firmware

A vulnerability exists in Shibby Tomato firmware version 1.28, specifically in the rip_zebra_read_ipv4 function of the Zserv Handler. This issue allows attackers to exploit a stack-based buffer overflow which can be triggered remotely, leading to potential unauthorized access and control over the...

PoC for CVE-2026-10123

TrendnetTew-432brp8.7HIGH
Stack-Based Buffer Overflow in TRENDnet TEW-432BRP Router

A stack-based buffer overflow vulnerability has been identified in the TRENDnet TEW-432BRP router, specifically affecting the function formSetDomainFilter located in /goform/formSetDomainFilter. By manipulating the arguments for blocked_domain, permitted_domain, blocked_domain_list, or permitted_...

Discovered 6 hours ago

PoC for CVE-2026-10122

TrendnetTew-432brp8.7HIGH
Buffer Overflow Vulnerability in TRENDnet TEW-432BRP Router

A stack-based buffer overflow vulnerability exists in the TRENDnet TEW-432BRP router within the formSetProtocolFilter function. Exploiting this vulnerability, an attacker can manipulate the protocol_name argument to potentially execute arbitrary code from a remote location. It is important to not...

PoC for CVE-2026-10121

TrendnetTew-432brp8.7HIGH
Stack-Based Buffer Overflow in TRENDnet TEW-432BRP Router

A flaw has been discovered in the TRENDnet TEW-432BRP router, specifically within the formSetUrlFilter function located in the /goform/formSetUrlFilter file. This vulnerability arises from improper handling of the 'keyword_list' argument, which can lead to a stack-based buffer overflow. The explo...

PoC for CVE-2018-25426

WinmtrWinmtr8.7HIGH
Denial of Service Vulnerability in WinMTR Software by WinMTR

WinMTR 0.91 is susceptible to a denial of service vulnerability that can lead to application crashes. By crafting a specific input file that contains a large buffer of repeated characters totaling 238 bytes, attackers are able to trigger a buffer overflow condition. This vulnerability allows for ...

PoC for CVE-2018-25425

YotYot Cms8.8HIGH
SQL Injection Vulnerability in Yot CMS by Yot

Yot CMS version 3.3.1 is susceptible to an SQL injection vulnerability that enables attackers to execute arbitrary SQL queries. By leveraging crafted HTTP GET requests with malicious input in the 'aid' or 'cid' parameters, unauthorized individuals can extract sensitive database information, inclu...

PoC for CVE-2018-25424

LivebmsGate Pass Management S...8.8HIGH
SQL Injection Vulnerability in Gate Pass Management System by LiveBMS

The Gate Pass Management System 2.1 contains an SQL injection flaw that permits hackers to bypass authentication mechanisms. By crafting specific POST requests to the login-exec.php endpoint with malicious SQL payloads in the login and password fields, attackers can authenticate without valid cre...

PoC for CVE-2018-25422

Spider312Mogg Web Simulator Script8.8HIGH
SQL Injection Vulnerability in MOGG Web Simulator Script

The MOGG Web Simulator Script has a security flaw that allows attackers to exploit an SQL injection vulnerability via the 'id' parameter in GET requests to play.php. This flaw can enable unauthorized individuals to execute arbitrary SQL commands, potentially revealing sensitive database informati...

PoC for CVE-2018-25423

ArmcodeArm Whois6.9MEDIUM
Buffer Overflow Vulnerability in Arm Whois Product by Arm

Arm Whois 3.11 is susceptible to a buffer overflow vulnerability that can be exploited by local attackers. By providing excessively large input strings, typically around 700 bytes, an attacker can trigger a denial of service condition that crashes the application. This flaw critically undermines ...

PoC for CVE-2018-25421

OpenstamanagerOpen Sta Manager7.1HIGH
Path Traversal Vulnerability in Open STA Manager 2.3 from Open STA

The Open STA Manager 2.3 is susceptible to a path traversal vulnerability that can be exploited by authenticated users. By crafting specific GET requests to the 'modules/backup/actions.php' endpoint, attackers can manipulate the file parameter to navigate through directories using '../' sequences...

PoC for CVE-2018-25420

AiopmsdAiopmsd Final8.8HIGH
SQL Injection Vulnerability in AiOPMSD Final by SourceForge

AiOPMSD Final 1.0.0 is subjected to a SQL injection vulnerability through the 'id' parameter in watch.php, enabling attackers to manipulate SQL queries. By sending specially crafted GET requests, unauthenticated attackers can extract sensitive data including usernames, database names, and version...

PoC for CVE-2018-25412

DeltasqlDelta Sql9.3CRITICAL
Arbitrary File Upload Vulnerability in Delta SQL 1.8.2 by DeltaSQL

Delta SQL version 1.8.2 is vulnerable to an arbitrary file upload, which allows unauthenticated attackers to exploit the system. By sending specifically crafted POST requests to the 'docs_upload.php' endpoint, attackers can upload malicious files, including PHP scripts, to the server's upload dir...

PoC for CVE-2018-25411

M-gbMgb Opensource Guestbook8.8HIGH
SQL Injection Vulnerability in MGB OpenSource Guestbook by MGB

MGB OpenSource Guestbook version 0.7.0.2 is susceptible to an SQL injection vulnerability that enables unauthenticated attackers to craft GET requests with malicious SQL payloads via the 'id' parameter in email.php. This allows attackers to execute arbitrary SQL queries, potentially leading to th...

PoC for CVE-2018-25410

SimpkhSim-pkh7.1HIGH
SQL Injection Vulnerability in SIM-PKH by SourceForge

The SIM-PKH 2.4.1 version is vulnerable to an SQL injection flaw that allows authenticated users to execute arbitrary SQL commands via the 'id' parameter. By crafting GET requests to /admin/media.php with specific parameters (module=pengurus and act=editpengurus), attackers can inject SQL UNION s...

PoC for CVE-2018-25409

SimpkhSim-pkh8.7HIGH
Arbitrary File Upload in SIM-PKH 2.4.1 by SourceForge

SIM-PKH version 2.4.1 is susceptible to an arbitrary file upload vulnerability. Authenticated users can exploit this flaw by uploading malicious files through the 'fupload' parameter. This can occur via the 'aksi_pengurus.php' endpoint when the 'module' and 'act' parameters are set to 'pengurus' ...

PoC for CVE-2018-25408

OpenisesOpen Ises Project8.7HIGH
Path Traversal Vulnerability in Open ISES Project 3.30A by Open ISES

The Open ISES Project version 3.30A is susceptible to a path traversal vulnerability in the ajax/download.php endpoint. This flaw enables unauthenticated attackers to download arbitrary files by manipulating the filename parameter. By injecting directory traversal sequences such as ../, an attack...

PoC for CVE-2018-25407

EndonesiaEndonesia Portal8.8HIGH
SQL Injection Vulnerabilities in eNdonesia Portal by eNdonesia

The eNdonesia Portal 8.7 is susceptible to multiple SQL injection vulnerabilities that enable unauthenticated attackers to execute arbitrary SQL queries. Through manipulating parameters in mod.php, such as artid, cid, did, contid, and aboutid, an attacker can inject malicious SQL code. This can l...

PoC for CVE-2026-10120

TrendnetTew-432brp8.7HIGH
Buffer Overflow Vulnerability in TRENDnet TEW-432BRP Router

A stack-based buffer overflow vulnerability has been identified in the TRENDnet TEW-432BRP router within the 'formSetFirewallRule' function of the '/goform/formSetFirewallRule' file. The issue arises from improper handling of the 'firewall_name' argument, allowing for remote manipulation and pote...

Discovered 7 hours ago

PoC for CVE-2026-10119

TrendnetTew-432brp8.7HIGH
Stack-Based Buffer Overflow in TRENDnet TEW-432BRP Router

A security vulnerability has been identified in the TRENDnet TEW-432BRP version 3.10B20, specifically within the formSetMACFilter function of the /goform/formSetMACFilter file. This issue allows for a stack-based buffer overflow when the filter_name argument is manipulated, which can be exploited...

Discovered 8 hours ago

PoC for CVE-2026-10117

Open5GSOpen5gs5.3MEDIUM
Denial of Service Vulnerability in Open5GS by Open5GS

A vulnerability exists in Open5GS versions up to 2.7.7, specifically in the function ogs_pool_id_calloc within /lib/sbi/nghttp2-server.c. This weakness can be exploited remotely, leading to a denial of service condition. Attackers may manipulate the function, causing the affected system to become...

Discovered 9 hours ago

PoC for CVE-2025-38352

LinuxLinux7.4HIGH
Race Condition in Linux Kernel Affecting CPU Timer Handling

A race condition has been identified in the Linux kernel's handling of POSIX CPU timers. When a non-autoreaping task reaches the exit_notify() state and subsequently calls handle_posix_cpu_timers() from an interrupt request (IRQ), it may be reaped by its parent or debugger immediately after unloc...

Discovered 10 hours ago

PoC for CVE-2026-10116

Open5GSOpen5gs5.3MEDIUM
Denial of Service Vulnerability in Open5GS by Open5GS

A vulnerability has been identified in versions of Open5GS up to 2.7.7, specifically in the function ogs_sbi_xact_add within the /lib/core/ogs-timer.c library of the ue-authentications Endpoint. This flaw allows for a denial of service condition, where an attacker can exploit the vulnerability re...

Discovered 11 hours ago

PoC for CVE-2026-10115

Open5GSOpen5gs5.3MEDIUM
Denial of Service Vulnerability in Open5GS from Open5GS

A vulnerability exists in Open5GS’s Shared NF-profile Parser component located in lib/sbi/nnrf-handler.c, allowing remote attackers to cause a denial of service. The vulnerability is present in versions up to 2.7.7, and the exploit is publicly accessible. Implementing the recommended patches is e...

PoC for CVE-2026-10114

Open5GSOpen5gs5.3MEDIUM
Out-of-Bounds Write Vulnerability in Open5GS Shared NF-profile Parser

A critical vulnerability exists in Open5GS versions up to 2.7.7, specifically in the function handle_scp_info within the shared NF-profile parser component. This vulnerability allows remote attackers to exploit the system through an out-of-bounds write, potentially leading to data corruption or s...

Discovered 12 hours ago

PoC for CVE-2026-10113

Open5GSOpen5gs5.3MEDIUM
Denial of Service Vulnerability in Open5GS by Open5GS

A vulnerability has been identified in the Open5GS networking software, specifically within the shared NF-profile parser component in lib/sbi/nnrf-handler.c. This flaw allows attackers to execute a denial of service attack remotely, potentially impacting system availability. An exploit for this v...

Discovered 13 hours ago

PoC for CVE-2026-10112

SambitrajStudent-management-system4.8MEDIUM
Cross-Site Scripting Vulnerability in sambitraj STUDENT-MANAGEMENT-...

A cross-site scripting vulnerability exists in the Dashboard Page of sambitraj's STUDENT-MANAGEMENT-SYSTEM 1.0 due to improper handling of user-supplied input. This flaw allows attackers to manipulate the 'Name' argument, potentially executing malicious scripts in the context of the user's sessio...

PoC for CVE-2026-10111

SambitrajStudent-management-system6.9MEDIUM
SQL Injection Vulnerability in sambitraj Student Management System ...

A vulnerability in the sambitraj Student Management System version 1.0 has been identified, specifically affecting the login page functionality. An attacker can exploit this weakness through parameter manipulation of the email argument, potentially leading to unauthorized database access via SQL ...

Discovered 15 hours ago

PoC for CVE-2026-10110

Code-projectsStudent Details Manage...6.9MEDIUM
SQL Injection Vulnerability in Code-Projects Student Details Manage...

A SQL injection vulnerability has been discovered in the Student Details Management System version 1.0. This flaw exists in an unspecified function within the '/index.php' file, allowing attackers to manipulate the 'roll' parameter to execute arbitrary SQL commands. This vulnerability can be expl...

Discovered 18 hours ago

PoC for CVE-2019-9053

CmsmadesimpleCms Made Simple🟣 EPSS 93%8.1HIGH
SQL Injection Vulnerability in CMS Made Simple by CMS Made Simple, ...

A vulnerability exists in CMS Made Simple version 2.2.8, where the News module can be exploited through a specially crafted URL, allowing an unauthenticated attacker to perform blind time-based SQL injection utilizing the m1_idlist parameter. This can potentially expose sensitive information and ...

Discovered 1 day ago

PoC for CVE-2026-0257

Palo Alto NetworksCloud Ngfw7.8HIGH
Authentication Bypass in Palo Alto Networks PAN-OS Software

The authentication bypass vulnerability in Palo Alto Networks' PAN-OS software presents a significant security risk by allowing unauthorized access to the GlobalProtect portal and gateway. This flaw enables attackers to circumvent authentication mechanisms, potentially gaining unauthorized VPN co...

PoC for CVE-2022-26923

MicrosoftWindows 10 Version 1809🟣 EPSS 92%8.8HIGH
Active Directory Domain Services Elevation of Privilege Vulnerability

Active Directory Domain Services Elevation of Privilege Vulnerability

PoC for CVE-2024-31317

GoogleAndroid7.8HIGH
Unpatched Deserialization Vulnerability in ZygoteProcess.java Could...

A vulnerability has been identified in the Android Framework that allows potential code execution through unsafe deserialization in multiple functions of ZygoteProcess.java. This flaw enables local privilege escalation, requiring user execution privileges but eliminating the need for user interac...

PoC for CVE-2026-40564

ApacheApache Flink Kubernete...
Server-Side Request Forgery in Apache Flink Kubernetes Operator

A Server-Side Request Forgery (SSRF) vulnerability exists in the Apache Flink Kubernetes Operator that allows users with create permissions to access sensitive files on the operator pod's filesystem. The flaw arises from the lack of validation of the FlinkSessionJob jarURI, enabling the potential...

PoC for CVE-2018-25404

Open IsesOpen Ises Project8.8HIGH
SQL Injection Vulnerability in Open ISES Project 3.30A

The Open ISES Project 3.30A contains a vulnerability that permits unauthenticated attackers to inject malicious SQL code via the ticket_id parameter in add_facnote.php. By sending specially crafted GET requests, an attacker can execute arbitrary SQL queries, potentially exposing sensitive databas...

PoC for CVE-2018-25397

JoeyrushPHP-shop Master6.9MEDIUM
Cross-Site Request Forgery Vulnerability in PHP-SHOP by Joey Rush

PHP-SHOP 1.0 is vulnerable to a Cross-Site Request Forgery (CSRF) attack, enabling unauthenticated attackers to create unauthorized administrative accounts. By tricking authenticated users into visiting a web page containing a maliciously crafted HTML form, an attacker can exploit the users.php e...

PoC for CVE-2018-25396

HeatmiserHeatmiser Wifi Thermostat8.7HIGH
Credential Disclosure Vulnerability in Heatmiser Wifi Thermostat by...

The Heatmiser Wifi Thermostat 1.7 has a significant vulnerability which permits unauthenticated attackers to access sensitive administrative credentials through the networkSetup.htm page. By sending a request to this endpoint, attackers can extract plaintext username and password values from HTML...

PoC for CVE-2018-25395

KadosKados R10 Greenbee8.8HIGH
SQL Injection Vulnerability in Kados R10 GreenBee Product

The Kados R10 GreenBee product is exposed to an SQL injection vulnerability through the feature_id parameter in the boards_buttons/update_feature.php endpoint. Attackers can exploit this flaw to send maliciously crafted GET requests that manipulate SQL queries, enabling them to extract sensitive ...

PoC for CVE-2018-25393

NavigatecmsNavigate Cms7.1HIGH
Path Traversal Vulnerability in Navigate CMS 2.8.5 by Navigate

Navigate CMS version 2.8.5 is affected by a path traversal vulnerability that enables authenticated users to exploit it. By manipulating the 'id' parameter in GET requests sent to navigate_download.php, attackers can inject directory traversal sequences, such as '../../../cfg/globals.php'. This e...

PoC for CVE-2018-25392

TalagasoftMaxon Erp7.1HIGH
SQL Injection Vulnerability in MaxOn ERP Software by Talagasoft

MaxOn ERP Software versions 8.x to 9.x contain an SQL injection vulnerability that enables authenticated users to execute arbitrary SQL queries. This can be achieved by manipulating the nomor, user, and jenis parameters in the log_activity function. Attackers can exploit this vulnerability by sen...

PoC for CVE-2018-25391

SitejoHape Pkh8.7HIGH
Unauthorized Record Deletion in HaPe PKH 1.1 by HaPe

The HaPe PKH 1.1 software component contains a vulnerability that allows unauthorized deletion of records. Specifically, the application fails to enforce proper authorization checks within its record deletion endpoints. This oversight enables attackers to exploit the system by crafting specific r...