Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 8 hours ago
PoC for CVE-2026-81847
A vulnerability has been discovered in the MAA-AI MaaMCP software, specifically in the save_pipeline/load_pipeline functions within the pipeline_tools.py file. This flaw allows remote attackers to manipulate the system through path traversal, enabling unauthorized access to sensitive files. The a...
PoC for CVE-2026-81845
A path traversal vulnerability exists in the mcp-sequential-thinking component's import_session/export_session functionality. This issue is due to improper validation of the 'file_path' argument in server.py, allowing attackers to access unintended files on the server. This vulnerability can be e...
PoC for CVE-2021-27876
A vulnerability has been identified in Veritas Backup Exec versions prior to 21.2 that compromises secure communication between clients and agents. This flaw arises from weaknesses in the SHA Authentication scheme, allowing an unauthorized attacker to bypass authentication. Once exploited, the at...
PoC for CVE-2026-81837
A security flaw within RooCodeInc's Roo-Code software allows for path traversal through the ApplyPatchTool component. Specifically, this issue affects the path.resolve function in the src/core/tools/ApplyPatchTool.ts file, enabling remote attackers to manipulate file paths. This vulnerability is ...
Discovered 9 hours ago
PoC for CVE-2026-81836
A security issue in RooCodeInc's Roo-Code software allows for the cleartext transmission of sensitive information through the OAuth Callback component. Specifically, the vulnerability is found in the file src/integrations/claude-code/oauth.ts, leading to potential exposure of critical data during...
PoC for CVE-2026-81835
A code injection vulnerability has been identified in the RooCodeInc Roo-Code application, specifically within the fetch_instructions function of the malicious_mcp_server.py file. This issue arises within the MCP Integration Trust Model and enables attackers to manipulate functions remotely, lead...
Discovered 10 hours ago
PoC for CVE-2026-81834
A code injection vulnerability exists in Roo-Code by RooCodeInc, specifically in the ExecaTerminalProcess function of the README File Handler component. This flaw allows an attacker to remotely execute malicious code by manipulating the affected feature. With the product no longer actively suppor...
PoC for CVE-2026-81833
A security flaw has been found in RooCodeInc's Roo-Code product up to version 3.51.1. The vulnerability resides in the 'optimizeQuery' function of the 'src/utils/helpers.ts' file within the CodeIndexManager component. This weakness allows for code injection via manipulation, resulting in a potent...
PoC for CVE-2026-81934
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which processes incoming TLS data. When configured for TLS support, this vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands with the privileges of the Redis server. This cou...
PoC for CVE-2004-2687
distcc 2.x, often utilized in XCode 1.5 and other software, is prone to vulnerabilities when improperly configured. This flaw enables remote attackers to execute arbitrary commands through compilation jobs processed by the server without proper authorization checks. If access to the server port i...
Discovered 12 hours ago
PoC for CVE-2026-76640
The Unitree G1 EDU firmware exposes critical flaws through its BLE GATT server and WiFi provisioning stack, allowing proximity-based attackers to execute arbitrary code without authentication. By exploiting an unquoted heredoc variable in the WiFi provisioning script alongside a buffer overflow i...
PoC for CVE-2015-3246
The vulnerability in the libuser library affects the userhelper program, allowing for a local user to directly modify the /etc/passwd file. If this modification fails, it may result in an inconsistent file state, leading to a denial of service. Additionally, this issue can potentially be exploite...
Discovered 13 hours ago
PoC for CVE-2015-5287
The Automatic Bug Reporting Tool (ABRT) prior to version 2.7.1 is susceptible to a local privilege escalation vulnerability. This flaw allows local users with specific permissions to execute a symlink attack on files with predictable names, such as '/var/tmp/abrt/abrt-hax-coredump' or '/var/spool...
PoC for CVE-2026-19092
The Tutor LMS WordPress plugin, prior to version 4.0.6, contains a significant security flaw that permits unauthenticated users to manipulate request data, leading to the overwriting of internal variables during template rendering. This vulnerability enables attackers to invoke arbitrary zero-arg...
Discovered 14 hours ago
PoC for CVE-2026-72898
Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...
PoC for CVE-2026-38526
An authenticated arbitrary file upload vulnerability exists in the /admin/tinymce/upload endpoint of Webkul Krayin CRM version 2.2.x. This flaw enables attackers to upload crafted PHP files, which can subsequently lead to the execution of arbitrary code on the server. Such vulnerabilities can be ...
PoC for CVE-2026-19478
A flaw in GitLab CE/EE allows unauthenticated users to exploit specific GraphQL directives, potentially resulting in unauthorized modification or deletion of public projects and user data. This vulnerability impacts various versions, necessitating immediate user awareness and prompt application o...
Discovered 16 hours ago
PoC for CVE-2026-20303
Cisco's Catalyst SD-WAN product has been identified with vulnerabilities stemming from improper input validation, as revealed during an internal security review. These issues can potentially expose the system to various security risks, underscoring the importance of implementing software hardenin...
Discovered 17 hours ago
PoC for CVE-2026-77542
A security flaw has been identified in the UID Enterprise Agent developed by Ubiquiti, where improper input validation can be exploited by malicious actors with network access and elevated privileges. This vulnerability enables the execution of command injection on the host device, potentially al...
PoC for CVE-2026-18431
The Avada theme for WordPress presents a significant security risk due to an arbitrary file write vulnerability that affects all versions up to 7.16 when paired with an active Fusion Builder plugin (up to version 3.16). This flaw stems from a combination of authorization issues and inadequate inp...
Discovered 18 hours ago
PoC for CVE-2026-81562
A security flaw has been identified in AlexGladkov's claude-in-mobile, specifically affecting the execSync function in src/adb/client.ts. This vulnerability allows for OS command injection, requiring local access to the system for exploitation. An upgrade to version 3.10.3 is necessary to mitigat...
Discovered 19 hours ago
PoC for CVE-2026-8467
A vulnerability exists in Phenix Digital's Phoenix Storybook that allows unauthenticated remote code execution due to unsanitized attribute value interpolation during HEEx template generation. The psb-assign WebSocket event handler permits arbitrary attribute names and values from unauthenticated...
PoC for CVE-2026-74233
A security flaw in the Zbtlink firmware for multiple wireless devices allows remote attackers to exploit the infosrvd service via crafted UDP packets. This vulnerability bypasses authentication mechanisms, as it employs a hardcoded salt, enabling unprivileged users to execute arbitrary commands a...
PoC for CVE-2026-81560
A vulnerability exists in blackms aistack up to version 1.6.1, impacting the Static File Handler component located in src/web/server.ts. This flaw allows for path traversal due to improper handling of the req.url argument, which can be exploited remotely. The exploit code is publicly accessible, ...
Discovered 1 day ago
PoC for CVE-2026-78333
The 12 Step Meeting List WordPress plugin prior to version 3.19.17 allows unauthenticated users to submit unsanitized input, which is stored in the activity log. This input is later displayed back to users in the admin area without adequate escaping, making it possible for an attacker to execute ...
PoC for CVE-2026-78138
The Finale Lite plugin for WordPress prior to version 2.21.0 contains a security flaw that allows authenticated users, including those with Subscriber roles and above, to access sensitive campaign configuration data through an unprotected AJAX action. This oversight enables users to retrieve conf...
PoC for CVE-2026-78139
The Notifima WordPress plugin before version 3.1.4 lacks proper validation of subscription ownership on its REST endpoints. This oversight allows authenticated users with Subscriber-level access to manipulate subscription settings, specifically the ability to unsubscribe any customer from receivi...
PoC for CVE-2026-77018
The Workeera plugin for WordPress prior to version 1.0.6 lacks adequate restrictions on profile value submissions by candidates. It fails to validate the file types uploaded, allowing users with minimal privileges, such as subscribers, to upload arbitrary files. Consequently, this can lead to rem...
PoC for CVE-2026-78137
The StoreGrowth WordPress plugin prior to version 2.1.2 is vulnerable due to insufficient validation of browser-supplied product prices on certain unauthenticated actions. This flaw permits attackers to specify arbitrary prices when adding products to the shopping cart, especially when the 'Buy O...
PoC for CVE-2026-78125
A critical vulnerability in the LearnPress WordPress plugin allows unauthorized attackers to access sensitive information. This flaw exists in the plugin's REST API, where no authorization checks are performed on certain endpoints. As a result, attackers can exploit this weakness to disclose the ...
PoC for CVE-2026-77017
The Workeera WordPress plugin versions prior to 1.0.6 allows users with minimal permissions, such as a subscriber, to submit any profile values without restrictions. This lack of input validation leads to unauthorized access where these users can read arbitrary files stored on the server. This in...
PoC for CVE-2026-19715
The WP OAuth Server plugin for WordPress, prior to version 6.3.1, contains a flaw that allows unauthenticated users to access the debug log. This log, stored in a publicly accessible location, may contain sensitive information including OAuth tokens, authorization codes, and user records, such as...
PoC for CVE-2026-77016
The Workeera WordPress plugin prior to version 1.0.6 allows users with minimal permissions, such as subscribers, to delete arbitrary files from the server. This vulnerability arises due to the lack of restrictions on the values that can be written to a user's candidate profile, coupled with inade...
PoC for CVE-2026-76549
The UpdraftPlus: WP Backup & Migration Plugin for WordPress, prior to version 1.26.7, lacks proper CSRF checks in a critical backup management operation. This vulnerability can potentially allow an attacker to trick an authenticated admin into restoring a backup without their consent, effectively...
PoC for CVE-2026-19225
The Defender Security plugin for WordPress before version 6.2.0 contains a vulnerability that permits an administrator of any single site within a multisite network to execute arbitrary code across the entire network. This flaw arises from the failure to restrict a critical network-wide setting e...
PoC for CVE-2026-19454
The JetBackup plugin for WordPress prior to version 3.1.23.5 fails to properly enforce multisite authorization checks when serving backup archives and job logs. This oversight enables a network administrator—who does not possess Super Admin privileges—to download complete backups of the entire mu...
PoC for CVE-2026-19223
The Smush plugin for WordPress, prior to version 4.3.2, is susceptible to a security flaw that enables an administrator of any individual site within a multisite network to execute arbitrary code across the entire network. This flaw arises from insufficient restrictions placed on network-wide set...
PoC for CVE-2026-16569
The ShopApper Mobile App Builder Service for WooCommerce up to version 0.4.62 has a significant security issue where it does not properly verify user capabilities for stock-update operations. This oversight allows any authenticated user, including customers and subscribers, to alter the stock qua...
PoC for CVE-2026-16567
The Document Embedder plugin for WordPress prior to version 2.3.1 has a significant security flaw that allows unauthenticated users to exploit the file download feature. This vulnerability arises because the plugin fails to validate the status of documents before generating a download token. As a...
PoC for CVE-2026-16568
The ShopApper Mobile App Builder Service for WooCommerce has a vulnerability where the plugin does not correctly verify user ownership of customer profiles accessed via its REST API endpoints. This oversight enables authenticated users, such as customers or subscribers, to potentially gain unauth...
PoC for CVE-2026-13415
The CMP WordPress plugin prior to version 4.1.18 lacks robust checks on setting imports, specifically failing to enforce an option-name allow-list when settings are imported via AJAX actions. This oversight can enable users with Editor permissions, if granted access by an administrator, to modify...
PoC for CVE-2026-13416
The CMP WordPress plugin prior to version 4.1.18 lacks adequate sanitization and escaping of settings values. This flaw permits users assigned the Editor role, if granted access to the admin-bar controls of the plugin, to inject malicious web scripts. These scripts can execute when a visitor view...
PoC for CVE-2026-13414
The CMP WordPress plugin prior to version 4.1.18 is susceptible to an authorization bypass vulnerability due to inadequate checks on several AJAX actions. This flaw allows unauthenticated attackers to bypass intended restrictions and disable the maintenance or coming-soon mode. Notably, some acti...
PoC for CVE-2026-45585
A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...
PoC for CVE-2026-81491
A flaw in Boxpositron's With-Context-MCP (version up to 3.0.7) exposes a path traversal vulnerability through the ingest_notes, teleport_notes, sync_notes, and project_folder functions contained in the src/index.ts file. This allows remote attackers to manipulate the file paths, potentially leadi...
PoC for CVE-2026-18080
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is susceptible to an unrestricted file type upload due to insufficient validation of file extensions and improper path normalization in its save_attachments() function. This vulnerability allows unauthenticate...
PoC for CVE-2026-63520
A vulnerability exists in Microsoft Office SharePoint due to improper input validation, which could allow an unauthorized attacker to execute arbitrary code over a network. This can lead to significant security breaches if exploited, making it essential for affected users to apply security patche...
PoC for CVE-2026-81486
A vulnerability has been identified in bsmi021's mcp-file-context-server version 1.0.0, specifically in the read_context function located in src/index.ts. This flaw allows attackers to manipulate the argument path, leading to potential path traversal attacks. This vulnerability can be exploited r...
PoC for CVE-2026-81485
A security vulnerability has been identified in the danielpopamd Linkedin Ads MCP version 1.0.0. This vulnerability arises from an unsafe implementation in the function fs.readFileSync located in the file src/tools/campaign-management.ts, which handles media uploads. An attacker can manipulate th...
PoC for CVE-2026-19912
The Kaltura HTML5 player is susceptible to a remote code execution vulnerability due to the unsafe handling of user-supplied data. Specifically, when the mwEmbedLoader.php script processes the ServiceUrl provided by an attacker, it performs deserialization without adequate validation. This exploi...