Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2025-3194

no2chemBigint-buffer8.7HIGH
Buffer Overflow Vulnerability in bigint-buffer by no2chem

The bigint-buffer package is susceptible to a buffer overflow vulnerability in its toBigIntLE() function. This exploitation can lead to application crashes, allowing attackers to disrupt service and potentially execute arbitrary code. Users of this package should evaluate their current versions a...

Discovered 1 hour ago

PoC for CVE-2026-3810

TendaFh12028.7HIGH
Stack-Based Buffer Overflow in Tenda FH1202 Router

A stack-based buffer overflow vulnerability exists in the Tenda FH1202 router, specifically in the fromDhcpListClient function located in the /goform/DhcpListClient endpoint. By manipulating the 'page' argument, an attacker can potentially exploit this vulnerability to execute unauthorized action...

Discovered 2 hours ago

PoC for CVE-2026-3809

TendaFh12028.7HIGH
Stack-Based Buffer Overflow in Tenda FH1202 Router by Tenda

A stack-based buffer overflow vulnerability exists in the Tenda FH1202's fromNatStaticSetting function. By manipulating the argument page within the /goform/NatSaticSetting file, an attacker can exploit this flaw remotely, potentially compromising the device's integrity. This vulnerability poses ...

PoC for CVE-2026-3808

TendaFh12028.7HIGH
Stack-Based Buffer Overflow in Tenda FH1202 Router by Tenda

A stack-based buffer overflow vulnerability exists in the webtypelibrary function of Tenda FH1202 routers. An attacker can exploit this flaw by manipulating the webSiteId parameter, potentially allowing remote code execution. The affected version is V1.2.0.14(408), and this vulnerability is now p...

Discovered 3 hours ago

PoC for CVE-2026-3807

TendaFh12028.7HIGH
Stack-Based Buffer Overflow in Tenda FH1202 Device

A security vulnerability has been identified in the Tenda FH1202 device, specifically involving the formWrlsafeset function located in the /goform/AdvSetWrlsafeset file. The manipulation of arguments such as mit_ssid and mit_ssid_index can lead to a stack-based buffer overflow, potentially allowi...

PoC for CVE-2026-3806

SourcecodesterResort Reservation System5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Janobe Resort Reserva...

A security weakness has been identified in the janobe Resort Reservation System, where manipulation of the 'q' argument in the /room_rates.php file can lead to SQL injection. This vulnerability allows attackers to execute arbitrary SQL queries, potentially compromising sensitive data. The exploit...

Discovered 4 hours ago

PoC for CVE-2026-3804

TendaI38.7HIGH
Stack-Based Buffer Overflow in Tenda i3 Router

A security flaw has been identified in the Tenda i3 router version 1.0.0.6(2204), specifically within the function formWifiMacFilterSet located in the /goform/WifiMacFilterSet file. This vulnerability allows for manipulation of the argument index, leading to a stack-based buffer overflow conditio...

PoC for CVE-2026-3803

TendaI38.7HIGH
Stack-Based Buffer Overflow in Tenda i3 Router

A vulnerability exists in the Tenda i3 router version 1.0.0.6 (2204) related to the function formWifiMacFilterGet. An attacker can manipulate an argument index to trigger a stack-based buffer overflow. This exploit can be executed remotely, exposing the router to potential attacks. As details of ...

Discovered 5 hours ago

PoC for CVE-2024-56348

JetBrainsTeamcity4.3MEDIUM
Improper Access Control Vulnerability in JetBrains TeamCity

CVE-2024-56348 is a critical security vulnerability found in JetBrains TeamCity versions prior to 2024.12. The flaw arises from improper access control mechanisms that permit unauthorized users to view sensitive information related to agents that should be restricted. This vulnerability poses a s...

PoC for CVE-2026-3802

TendaI38.7HIGH
Stack-based Buffer Overflow in Tenda i3 Router

A vulnerability exists in the Tenda i3 router's execution command function located at /goform/exeCommand. By manipulating the input argument 'cmdinput', an attacker can trigger a stack-based buffer overflow. This flaw allows for remote exploitation, potentially giving malicious actors control ove...

PoC for CVE-2026-3801

TendaI38.7HIGH
Buffer Overflow Vulnerability in Tenda i3 Router Software

A buffer overflow vulnerability exists in the Tenda i3 router within the formSetAutoPing function found in the /goform/setAutoPing file. By manipulating the ping1 or ping2 arguments, an attacker can trigger a stack-based buffer overflow. This vulnerability can be exploited remotely, allowing unau...

Discovered 6 hours ago

PoC for CVE-2026-3800

SourcecodesterResort Reservation System5.3MEDIUM
Unrestricted Upload Vulnerability in janobe Resort Reservation Syst...

A security flaw has been identified in the janobe Resort Reservation System, impacting version 1.0. The vulnerability resides in the doInsert function within the /controller.php file, where an attacker can manipulate the 'image' argument. This flaw allows for unrestricted file uploads, enabling r...

PoC for CVE-2026-3799

TendaI38.7HIGH
Buffer Overflow Vulnerability in Tenda i3 Router by Tenda

A vulnerability in the Tenda i3 router's firmware allows a stack-based buffer overflow due to inadequate input validation in the formSetCfm function. Exploiting this flaw via remote access could allow attackers to execute arbitrary code, leading to potential unauthorized access to the device. It ...

PoC for CVE-2024-51482

ZoneminderZoneminder🟣 EPSS 50%10CRITICAL
ZoneMinder vulnerable to SQL Injection, fix released in 1.37.64

ZoneMinder, a popular open-source closed-circuit television software, has a vulnerability that exposes versions v1.37.* up to and including v1.37.64 to a boolean-based SQL injection attack through the web/ajax/event.php endpoint. This flaw can allow an attacker to manipulate SQL queries, potentia...

PoC for CVE-2026-3798

ComfastCf-ac1005.1MEDIUM
Command Injection Vulnerability in Comfast CF-AC100 Product

A detected command injection vulnerability in the Comfast CF-AC100 version 2.6.0.8 allows attackers to exploit the function sub_44AC14 within the /cgi-bin/mbox-config?method=SET&section=ping_config path handler. This exploitation can be initiated remotely, posing significant security risks. Despi...

Discovered 7 hours ago

PoC for CVE-2024-4367

MozillaFirefox🟣 EPSS 35%8.8HIGH
Arbitrary JavaScript Execution Vulnerability in Firefox

A vulnerability has been identified in PDF.js, specifically related to a missing type check when processing fonts. This oversight permits arbitrary JavaScript execution within the PDF.js environment. As a result, users of affected versions of Mozilla Firefox and Thunderbird could be vulnerable to...

PoC for CVE-2026-3797

TiandyVideo Surveillance Sys...5.3MEDIUM
Unrestricted Upload Vulnerability in Tiandy Video Surveillance System

A security flaw in Tiandy Video Surveillance System version 7.17.0 allows unauthorized users to exploit the uploadFile function located in CLS_REST_File.java. By manipulating the 'fileName' parameter, attackers can achieve unrestricted uploads of potentially malicious files. This vulnerability po...

PoC for CVE-2026-3796

Qi-anxinQax Virus Removal4.8MEDIUM
Improper Access Controls in Qi-ANXIN QAX Virus Removal Mini Filter ...

A vulnerability has been identified in the Qi-ANXIN QAX Virus Removal software, specifically affecting the ZwTerminateProcess function within the QKSecureIO_Imp.sys library of the Mini Filter Driver component. This weakness can lead to improper access controls, allowing a local attacker to execut...

Discovered 8 hours ago

PoC for CVE-2026-3793

SourcecodesterSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Sales and Inventory S...

A vulnerability has been identified in the SourceCodester Sales and Inventory System version 1.0, specifically affecting the code within the sales_invoice1.php file. This vulnerability arises from improper handling of the GET parameter 'sellid', allowing attackers to execute SQL injection attacks...

PoC for CVE-2026-3792

SourcecodesterSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Sales and Inventory S...

A vulnerability exists in the SourceCodester Sales and Inventory System 1.0 due to improper handling of the 'purchaseid' parameter within the purchase_invoice.php file. This flaw allows an attacker to manipulate the argument, potentially leading to SQL injection attacks. Such an exploitation can ...

Discovered 9 hours ago

PoC for CVE-2026-3791

SourcecodesterSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Sales and Inventory S...

A critical SQL injection vulnerability has been identified in the SourceCodester Sales and Inventory System, specifically within the dashboard.php file of the Search component. An attacker can manipulate the 'searchtxt' argument, leading to unauthorized database queries. This exploitation can be ...

PoC for CVE-2024-2083

Zenml-ioZenml-io/zenml9.9CRITICAL
Directory Traversal Vulnerability in zenml Repository

A directory traversal vulnerability has been identified in ZenML, specifically within the /api/v1/steps endpoint. This flaw allows attackers to manipulate the 'logs' URI path within requests to access arbitrary files on the server, circumventing established access control mechanisms. The underlyi...

Discovered 10 hours ago

PoC for CVE-2024-21413

MicrosoftMicrosoft Office 2019🟣 EPSS 93%9.8CRITICAL
Remote Code Execution Vulnerability Affects Microsoft Outlook

A remote code execution vulnerability in Microsoft Outlook allows an attacker to run arbitrary code on a user's system. This can occur when the vulnerable version processes specially crafted email messages, which can result in unauthorized access or control over the affected system. Attackers can...

PoC for CVE-2026-3789

BytedeskBytedesk5.3MEDIUM
Server-Side Request Forgery in Bytedesk Affected by Vulnerability

A vulnerability was identified in Bytedesk versions up to 1.3.9 within the 'getModels' function located in 'SpringAIGiteeRestService.java'. This issue arises from improper handling of the 'apiUrl' argument, leading to a server-side request forgery (SSRF) risk. Attackers may exploit this vulnerabi...

PoC for CVE-2026-3788

BytedeskBytedesk5.3MEDIUM
Server-Side Request Forgery Vulnerability in Bytedesk Affected Vers...

A security flaw has been identified in Bytedesk affecting versions up to 1.3.9. The issue arises in the getModels function within the SpringAIOpenrouterRestService.java file, specifically related to the manipulation of the apiUrl argument. This unintended behavior can allow attackers to perform s...

Discovered 11 hours ago

PoC for CVE-2026-3786

TeamEasyEasycms5.3MEDIUM
SQL Injection Vulnerability in EasyCMS by TeamEasy

A security flaw has been identified in EasyCMS versions up to 1.6, specifically in the Request Parameter Handler component. This vulnerability arises from an unknown function located in the /RbacuserAction.class.php file. Through manipulation of the argument '_order', an attacker can execute SQL ...

PoC for CVE-2026-3785

EasyCMSEasycms5.3MEDIUM
SQL Injection Vulnerability in EasyCMS Request Parameter Handler

A vulnerability has been discovered in EasyCMS versions up to 1.6, specifically within the Request Parameter Handler located at /RbacnodeAction.class.php. This flaw allows an attacker to manipulate the '_order' argument, leading to SQL injection attacks. The exploit can be executed remotely, and ...

Discovered 12 hours ago

PoC for CVE-2026-3771

SourcecodesterResort Reservation System5.3MEDIUM
SQL Injection Vulnerability in SourceCodester's Resort Reservation ...

A SQL injection vulnerability has been identified in SourceCodester's janobe Resort Reservation System version 1.0. This flaw resides in the unknown code of the '/accomodation.php' file, where manipulation of the 'q' argument can lead to unauthorized access to the database. Attackers can exploit ...

PoC for CVE-2026-3770

SourcecodesterComputer Laboratory Ma...5.3MEDIUM
Cross-Site Request Forgery Vulnerability in SourceCodester Computer...

A vulnerability has been identified in the SourceCodester Computer Laboratory Management System version 1.0, allowing attackers to exploit a cross-site request forgery (CSRF) flaw. This security issue permits unauthorized commands to be transmitted from a user whom the website trusts. Attackers c...

PoC for CVE-2026-3769

TendaF4538.7HIGH
Stack-Based Buffer Overflow in Tenda F453 Router

A stack-based buffer overflow vulnerability exists in the Tenda F453 Router, specifically within the WrlclientSet function located in the /goform/WrlclientSet file. This vulnerability can be exploited remotely by manipulating the GO argument, leading to potential unauthorized access and execution...

Discovered 13 hours ago

PoC for CVE-2026-3768

TendaF4538.7HIGH
Stack-Based Buffer Overflow in Tenda F453 Router by Tenda

A security vulnerability exists in the Tenda F453 router, specifically within the formWrlExtraSet function located in the /goform/WrlExtraSet file. An issue arises from improper handling of the GO argument, leading to a stack-based buffer overflow. This flaw allows for potential remote exploitati...

PoC for CVE-2026-3767

ItsourcecodeSanitize Or Validate T...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Teacher Attendance System

A vulnerability exists within the itsourcecode Teacher Attendance System, specifically in the /admin/teacher-attendance.php file. An attacker can exploit this weakness by manipulating the 'teacher_id' argument, potentially leading to unauthorized SQL code execution. This vulnerability may be expl...

PoC for CVE-2026-3766

SourcecodesterWeb-based Pharmacy Pro...5.1MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Web-based Phar...

A security flaw has been identified in the SourceCodester Web-based Pharmacy Product Management System affecting version 1.0. This vulnerability resides in the edit-profile.php file, where inadequate input validation allows an attacker to exploit the argument 'fullname'. By manipulating this argu...

PoC for CVE-2026-3765

ItsourcecodeUniversity Management ...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode University Management S...

A severe SQL injection vulnerability exists within the itsourcecode University Management System version 1.0, specifically in the /att_single_view.php file. This flaw occurs when an attacker manipulates the 'dt' parameter, allowing unauthorized access to the database. Since the attack can be exec...

Discovered 14 hours ago

PoC for CVE-2026-3764

SourcecodesterClient Database Manage...6.9MEDIUM
Improper Authorization Flaw in SourceCodester Client Database Manag...

A vulnerability exists in SourceCodester Client Database Management System version 1.0, specifically within the /superadmin_user_update.php file. This weakness allows attackers to exploit improper authorization mechanisms, enabling remote exploitation. As the flaw has been publicly disclosed, the...

PoC for CVE-2026-3763

Code-projectsSimple Flight Ticket B...5.3MEDIUM
Cross Site Scripting in Simple Flight Ticket Booking System by Code...

A cross site scripting vulnerability has been identified in the Simple Flight Ticket Booking System, specifically within an unknown function in the showhistory.php file. This issue allows remote attackers to inject arbitrary web script or HTML into the application. Given that the exploit has been...

Discovered 15 hours ago

PoC for CVE-2026-3762

SourcecodesterClient Database Manage...6.9MEDIUM
Improper Authorization in SourceCodester Client Database Management...

A vulnerability exists in the SourceCodester Client Database Management System where an unidentified function in the /superadmin_delete_manager.php file allows improper authorization through the manipulation of the manager_id argument. This flaw enables remote attackers to exploit the system, pot...

PoC for CVE-2026-3761

SourcecodesterClient Database Manage...5.3MEDIUM
Improper Authorization in SourceCodester Client Database Management...

A vulnerability exists in the SourceCodester Client Database Management System 1.0 that allows attackers to exploit improper authorization through the manipulation of the user_id parameter in the /superadmin_user_delete.php file. This flaw can be leveraged remotely, potentially compromising user ...

PoC for CVE-2026-3760

ItsourcecodeUniversity Management ...6.9MEDIUM
SQL Injection Vulnerability in itsourcecode University Management S...

A SQL injection vulnerability exists in the itsourcecode University Management System 1.0, specifically within the /view_result.php file. This vulnerability arises from improper handling of user input in the seme argument, allowing attackers to execute arbitrary SQL queries. The exploitation of t...

PoC for CVE-2026-20127

CiscoCisco Catalyst Sd-wan ...10CRITICAL
Authentication Bypass in Cisco Catalyst SD-WAN Products

A vulnerability in the peering authentication process of Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to bypass authentication measures. By sending specially crafted requests, an attacker could gain unauthorized access to a system as a high-privileged non-r...

PoC for CVE-2026-3759

ProjectworldsOnline Art Gallery Shop6.9MEDIUM
SQL Injection Vulnerability in Projectworlds Online Art Gallery Sho...

A security vulnerability exists in the Projectworlds Online Art Gallery Shop version 1.0, specifically affecting the file /admin/adminHome.php. This vulnerability allows an attacker to manipulate the 'reach_nm' argument, leading to SQL injection. The attack can be executed remotely, posing signif...

PoC for CVE-2026-3758

ProjectworldsOnline Art Gallery Shop6.9MEDIUM
SQL Injection Vulnerability in Projectworlds Online Art Gallery Sho...

A vulnerability exists in Projectworlds Online Art Gallery Shop version 1.0 that allows for SQL injection through the manipulation of the 'Info' argument in the /admin/adminHome.php file. This weakness can be exploited remotely, leading to unauthorized database access and potential data compromis...

PoC for CVE-2026-3757

ProjectworldsOnline Art Gallery Shop6.9MEDIUM
SQL Injection Vulnerability in Projectworlds Online Art Gallery Shop

A security flaw present in Projectworlds' Online Art Gallery Shop version 1.0 exposes the application to SQL injection attacks via the /?pass=1 endpoint. By manipulating the input parameter 'fnm', an attacker can execute unauthorized SQL queries. This type of vulnerability permits attackers to la...

Discovered 16 hours ago

PoC for CVE-2026-3756

SourcecodesterSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Sales and Inventory S...

A vulnerability has been detected in the SourceCodester Sales and Inventory System version 1.0. This vulnerability exists in the file /check_item_details.php, where the manipulation of the stock_name1 parameter can enable an attacker to execute unauthorized SQL commands. The attack can be perform...

PoC for CVE-2026-3755

SourcecodesterSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Sales and Inventory S...

A security gap has been identified in the SourceCodester Sales and Inventory System version 1.0, specifically within the POST handler located in the /check_customer_details.php file. This vulnerability allows for SQL Injection through the manipulation of the 'stock_name1' argument. As a result, a...

PoC for CVE-2026-3754

SourcecodesterSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Sales and Inventory S...

A SQL injection vulnerability has been identified in the SourceCodester Sales and Inventory System version 1.0, specifically in the /add_stock.php file. By manipulating the 'cost' parameter, an attacker can execute unauthorized SQL commands, potentially compromising the database. This vulnerabili...

PoC for CVE-2026-3753

SourcecodesterSales And Inventory Sy...5.3MEDIUM
SQL Injection Vulnerability in SourceCodester Sales and Inventory S...

A security flaw has been identified in the SourceCodester Sales and Inventory System, specifically in the /add_sales_print.php file. This vulnerability arises from inadequate validation of the 'sid' argument, enabling an attacker to execute SQL injection attacks. Such vulnerabilities can permit u...

PoC for CVE-2026-3752

SourcecodesterEmployee Task Manageme...5.1MEDIUM
SQL Injection Vulnerability in SourceCodester Employee Task Managem...

A vulnerability exists in the SourceCodester Employee Task Management System up to version 1.0, where the file /daily-task-report.php is susceptible to SQL injection via the Date argument. This allows attackers to manipulate SQL queries and potentially gain unauthorized access to sensitive databa...

Discovered 17 hours ago

PoC for CVE-2026-3751

SourcecodesterEmployee Task Manageme...5.1MEDIUM
SQL Injection Vulnerability in SourceCodester Employee Task Managem...

A vulnerability in the SourceCodester Employee Task Management System has been identified, specifically within the `daily-attendance-report.php` file. An issue arises from the GET parameter handling, where manipulation of the 'Date' argument allows for SQL injection attacks. This vulnerability ca...

PoC for CVE-2026-3750

ContiNewContinew Admin5.1MEDIUM
Server-Side Request Forgery Vulnerability in ContiNew Admin Storage...

A security vulnerability has been identified within the storage management module of ContiNew Admin versions up to 4.2.0, specifically in the URI.create function of S3ClientFactory.java. This flaw allows attackers to perform server-side request forgery (SSRF), enabling them to send crafted reques...