Publicly Disclosed
PoC Exploits

πŸ”΄ Alway take caution when working with PoC Exploits πŸ”΄

Discovered just now...

PoC for CVE-2021-42574

UnicodeUnicode🟣 EPSS 12%8.3HIGH
Visual Reordering Vulnerability in Unicode Specification Affecting ...

A vulnerability in the Unicode Specification, particularly in the Bidirectional Algorithm, allows adversaries to manipulate the visual order of characters. This can lead to confusion when analyzing source code, as the logical order of tokens processed by compilers and interpreters may differ from...

Discovered 2 hours ago

PoC for CVE-2026-17544

PHP GroupPHP8.1HIGH
Out-of-Bounds Write Vulnerability in PHP Affects Multiple Versions

A vulnerability exists in PHP that allows an attacker to manipulate input to the bccomp() function, potentially leading to out-of-bounds write conditions. This flaw can cause significant issues, including stack and heap corruption, in various PHP versions, notably impacting those prior to their r...

Discovered 3 hours ago

PoC for CVE-2026-47103

FgmacedoPython-statemachine9.3CRITICAL
Remote Code Execution Vulnerability in Python StateMachine by FG Ma...

A critical security vulnerability exists in Python StateMachine versions prior to 3.2.0, allowing remote code execution through unsafe evaluation of crafted SCXML documents. Attackers can inject malicious expression strings that, when processed by the SCXMLProcessor, are passed to Python's eval()...

Discovered 4 hours ago

PoC for CVE-2026-19725

WordPressWPvivid β€” Backup, Migr...
Unauthorized File Creation Vulnerability in WPvivid Backup, Migrati...

The WPvivid β€” Backup, Migration & Staging WordPress plugin prior to version 0.9.131 contains a vulnerability that allows an unauthenticated attacker, armed with a site-to-site transfer key, to manipulate log file paths. This occurs due to inadequate sanitization of inputs, enabling the attacker t...

PoC for CVE-2026-19714

WordPressSimple Jwt Login
Unauthenticated Access in Simple JWT Login Plugin for WordPress

The Simple JWT Login plugin for WordPress prior to version 3.6.8 fails to properly validate the audience of Google identity tokens. This flaw enables unauthenticated users to authenticate themselves as any user associated with the email address contained in such tokens. Consequently, this vulnera...

PoC for CVE-2026-19717

WordPressCatfolders Document Ga...
Authorization Bypass in CatFolders Document Gallery & PDF Library P...

The CatFolders Document Gallery & PDF Library WordPress plugin before version 2.0.7 contains an authorization flaw in specific REST API endpoints. This vulnerability allows unauthenticated users to access sensitive information such as the title, type, size, and URL of media attachments linked to ...

PoC for CVE-2026-19726

WordPressVisualizer
Authorization Flaw in Visualizer Plugin Affects WordPress Users

The Visualizer Plugin for WordPress, prior to version 4.0.7, contains an authorization flaw that allows users with Contributor privileges and higher to access sensitive chart configurations. This vulnerability enables these users to read full configurations of charts, including those that should ...

PoC for CVE-2026-19712

WordPressMasteriyo Lms
Stored Cross-Site Scripting Vulnerability in Masteriyo LMS Plugin f...

The Masteriyo LMS WordPress plugin prior to version 2.3.3 lacks proper sanitization and escaping of quiz fields, enabling instructor role users to store unfiltered HTML. This vulnerability could lead to Stored Cross-Site Scripting attacks, affecting all visitors, including administrators, of the ...

PoC for CVE-2026-19728

WordPressExtra Product Options ...
File Disclosure Vulnerability in Extra Product Options Builder for ...

The Extra Product Options Builder for WooCommerce plugin prior to version 1.2.176 lacks sufficient verification for user entitlements when serving customer-uploaded files. This vulnerability allows unauthenticated users to retrieve these files if they are aware of their stored names. The plugin's...

PoC for CVE-2026-18653

WordPressWP Directory Kit
SQL Injection Vulnerability in WP Directory Kit Plugin for WordPress

The WP Directory Kit plugin for WordPress, versions prior to 1.5.7, is vulnerable due to improper sanitization and escaping of parameters used in SQL statements. This flaw allows an administrator on a multisite installation to execute SQL injection attacks, potentially granting them unauthorized ...

PoC for CVE-2026-17533

WordPressAll-in-one WP Migratio...
Arbitrary Code Execution in All-in-One WP Migration and Backup Plug...

The All-in-One WP Migration and Backup plugin for WordPress prior to version 7.108 presents a significant security flaw in multisite environments. This vulnerability permits an administrator of a single subsite to access and execute arbitrary PHP code across the entire network. Without sufficient...

PoC for CVE-2026-19711

WordPressPremium Packages
Withdrawal Request Validation Flaw in Premium Packages Plugin by Wo...

The Premium Packages plugin for WordPress, prior to version 7.0.7, has a flaw that permits authenticated users to submit withdrawal requests without validating their actual earned balance. This weakness enables any user, including those with no sales history such as subscribers, to request arbitr...

PoC for CVE-2026-19613

WordPressEcs
Unauthorized Data Access in ECS WordPress Plugin by N3rdish

The ECS WordPress plugin prior to version 4.3.10 features a security flaw where it fails to enforce proper ownership and post-status checks when retrieving custom field values based on user-supplied post identifiers. This oversight permits users with contributor-level access or higher to access a...

PoC for CVE-2026-15384

WordPressManual Image Crop
Cross-Site Scripting Vulnerability in Manual Image Crop Plugin for ...

The Manual Image Crop plugin for WordPress prior to version 1.15 lacks proper capability checks and nonce verification for its AJAX actions. This oversight allows logged-in users, even those with subscriber-level access, to manipulate attachment images. An attacker can exploit this weakness to ch...

PoC for CVE-2026-13712

WordPressDivi
Cross-Site Scripting in Divi WordPress Theme by Elegant Themes

The Divi WordPress Theme, prior to version 5.9.0, contains a vulnerability in its Social Media Follow module where certain settings are not properly escaped before rendering in link attributes. This oversight permits contributors to inject JavaScript code, which could execute when a user with ele...

PoC for CVE-2026-9830

WordPressBookingpress-appointme...8.2HIGH
Unauthorized Access Vulnerability in BookingPress Appointment Booki...

The BookingPress Appointment Booking Pro plugin for WordPress prior to version 5.7.3 contains a vulnerability that fails to properly enforce REST API authentication. As a result, this oversight allows unauthenticated attackers to gain access to sensitive customer booking data and make unauthorize...

PoC for CVE-2026-47117

MaziyarpanahiOpenmed9.3CRITICAL
Remote Code Execution Vulnerability in OpenMed by Maziyar Panahi

OpenMed versions prior to 1.5.2 expose a significant remote code execution vulnerability through improper handling of the 'model_name' parameter in the privacy-filter model loading path. This flaw allows attackers to supply a malicious name, which can lead to the loading of arbitrary Hugging Face...

PoC for CVE-2026-19934

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management System

A security flaw has been identified in itsourcecode's Hospital Management System version 1.0, specifically affecting the /vieworder.php file. This vulnerability arises from improper handling of the 'delid' parameter, allowing for SQL injection attacks. These attacks can be initiated remotely, pro...

Discovered 5 hours ago

PoC for CVE-2026-19933

DefaultfuctionCustomer-relationship-...5.3MEDIUM
Stack-based Buffer Overflow in DefaultFuction Customer-Relationship...

A buffer overflow vulnerability has been discovered in the Customer Search Module of DefaultFuction's Customer-Relationship-Management-In-C-Project version 2.0. This weakness allows remote attackers to exploit the vulnerable function, potentially leading to unauthorized access or execution of mal...

PoC for CVE-2021-4034

Polkit ProjectPolkit🟣 EPSS 95%7.8HIGH
Local Privilege Escalation Vulnerability in polkit's pkexec Utility

A local privilege escalation vulnerability exists within the pkexec utility of polkit, a setuid tool that allows unprivileged users to execute commands as privileged users based on predetermined policies. Due to insufficient handling of the calling parameters, pkexec can misinterpret environment ...

PoC for CVE-2026-19932

DefaultfuctionNotice-system-managent5.3MEDIUM
Code Injection Vulnerability in DefaultFuction Notice-System-Manage...

A security flaw exists in DefaultFuction Notice-System-Managent 2.0, specifically within the GroovyShell.evaluate function located in the /execute component of NoticeController. This vulnerability allows attackers to perform remote code injection, which can potentially compromise the integrity of...

Discovered 6 hours ago

PoC for CVE-2026-20896

GiteaGitea Open Source Git ...🟣 EPSS 32%9.8CRITICAL
Reverse Proxy Vulnerability in Gitea Docker Image Affects User Auth...

The Gitea Docker image is susceptible to a security issue where the configuration REVERSE_PROXY_TRUSTED_PROXIES is set to '*' by default. This improper configuration allows any source IP address to impersonate a user when reverse-proxy authentication headers, such as X-WEBAUTH-USER, are enabled. ...

PoC for CVE-2026-19930

DolibarrDolibarr5.3MEDIUM
LDAP Injection Vulnerability in Dolibarr User Cloning Functionality

A security flaw has been identified in Dolibarr ERP regarding its User Cloning functionality. The vulnerability resides in an undocumented function within the 'htdocs/user/card.php' file. An attacker can manipulate the ID argument, leading to potential LDAP injection. This vulnerability allows fo...

Discovered 7 hours ago

PoC for CVE-2026-19929

OpenBoxesOpenboxes5.3MEDIUM
Template Processing Vulnerability in OpenBoxes by OpenBoxes

A vulnerability has been discovered in OpenBoxes versions up to 0.9.6, specifically affecting the 'buildZebraTemplate' function within the file 'grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy'. This flaw allows improper neutralization of special elements used in the templ...

PoC for CVE-2022-3218

Necta LlcWifi Mouse (mouse Server)🟣 EPSS 73%9.8CRITICAL
Necta WiFi Mouse (Mouse Server) client-side authentication bypass

Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.

PoC for CVE-2026-19928

OpenBoxesOpenboxes5.3MEDIUM
Improper Privilege Management in OpenBoxes by OpenBoxes

The vulnerability affects the function needManager in the Role Interceptor component of OpenBoxes, potentially allowing unauthorized users to manipulate access privileges. An attacker could remotely execute an exploit that compromises the intended access control mechanisms of the application, lea...

Discovered 8 hours ago

PoC for CVE-2026-19927

OpenBoxesOpenboxes5.3MEDIUM
Server-Side Request Forgery Vulnerability in OpenBoxes Product Uplo...

A server-side request forgery vulnerability exists in the OpenBoxes Product Upload Endpoint, impacting versions up to 0.9.7. This allows an attacker to manipulate the 'params.url' argument, potentially leading to unauthorized server requests. The vulnerability can be exploited remotely, posing a ...

PoC for CVE-2025-64512

PDFminerPDFminer.six8.6HIGH
Arbitrary Code Execution in Pdfminer.six by Malicious PDF Files

Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...

PoC for CVE-2026-19926

EvergreenEvergreen6.9MEDIUM
SQL Injection Vulnerability in Evergreen OpenSRF Service

A vulnerability exists in the Evergreen OpenSRF Service's handling of requests within the osrf-gateway-v1 component, allowing remote attackers to execute SQL injection attacks. This issue is present in versions up to 3.14.11, 3.15.11, 3.16.5, and 3.17-beta1. Securing the application is vital, as ...

PoC for CVE-2026-19925

SourcecodesterStock Management System5.1MEDIUM
SQL Injection Vulnerability in SourceCodester Stock Management System

A security vulnerability has been identified in SourceCodester Stock Management System 1.0, affecting the handling of requests to /classes/Master.php?f=delete_supplier. This issue arises from insufficient validation of the 'ID' parameter, allowing malicious actors to execute arbitrary SQL command...

Discovered 9 hours ago

PoC for CVE-2026-19924

TendaAc109.3CRITICAL
Improper Authentication Vulnerability in Tenda AC10 Router

A security weakness has been identified in the Tenda AC10 router that affects its httpd component, specifically the R7WebsSecurityHandler function. This vulnerability allows attackers to manipulate authentication processes remotely, potentially compromising the device's security. The exploit has ...

PoC for CVE-2026-19923

Code-projectsOnline Shopping System5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Online Shopping System

A SQL injection vulnerability has been discovered in the Online Shopping System version 1.0, specifically affecting the /checkout_process.php file. This vulnerability arises from improper handling of the 'total_count' parameter, allowing attackers to execute malicious SQL queries remotely. Given ...

PoC for CVE-2026-19922

Code-projectsOnline Shopping System5.1MEDIUM
Cross Site Scripting Vulnerability in Code-Projects Online Shopping...

A security flaw exists in the Online Shopping System version 1.0 from Code-Projects, specifically in the /checkout.php file. This vulnerability allows for cross site scripting (XSS) attacks by manipulating the 'amount_1' parameter. An attacker can exploit this issue remotely, potentially compromi...

Discovered 10 hours ago

PoC for CVE-2026-19920

Code-projectsOnline Shopping System5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Online Shopping System

A SQL injection vulnerability has been identified in the Online Shopping System 1.0 developed by Code-Projects. This security flaw exists in a particular function within the file action.php, where manipulation of the 'proId' argument can lead to unauthorized database access. The attack can be exe...

PoC for CVE-2026-19919

Code-projectsOnline Shopping System6.9MEDIUM
SQL Injection Vulnerability in Online Shopping System by Code-Projects

A SQL injection vulnerability has been identified in the Online Shopping System version 1.0, specifically affecting the /login.php file within the Login component. The vulnerability arises from a flaw in handling the 'email' argument, allowing attackers to manipulate SQL queries remotely. This ex...

PoC for CVE-2026-71362

AdobeAdobe Commerce9.1CRITICAL
Incorrect Authorization Vulnerability in Adobe Commerce

Adobe Commerce has a vulnerability related to incorrect authorization mechanisms, which may allow an attacker to escalate their privileges and access sensitive resources without any user interaction. This security issue emphasizes the importance of robust authorization checks in e-commerce enviro...

PoC for CVE-2026-19918

SpacexStarlink Router Gen 35.3MEDIUM
Improper Access Controls in SpaceX Starlink Router Gen 3

A vulnerability identified in the SpaceX Starlink Router Gen 3 version 2025.11.14.mr64708.3 affects the 'get_status' function of the gRPC Management Interface. This flaw allows for improper access control manipulations and poses a risk to users within the local network. Since its disclosure, the ...

Discovered 11 hours ago

PoC for CVE-2026-19917

Code-projectsOnline Food Order System5.3MEDIUM
SQL Injection Vulnerability in Code-Projects Online Food Order System

A vulnerability exists in the Online Food Order System 1.0 developed by Code-Projects, specifically within the delete_food_items1.php file. This flaw allows an attacker to manipulate the argument checkbox, enabling remote SQL injection attacks. The exploit can compromise the security of the datab...

Discovered 12 hours ago

PoC for CVE-2026-19916

Code-projectsOnline Food Order System5.1MEDIUM
Cross Site Scripting Vulnerability in Code-Projects Online Food Ord...

An identified risk in Code-Projects' Online Food Order System 1.0 lies within the edit_food_items.php file, where manipulation of the 'dname' argument enables cross site scripting attacks. This vulnerability allows remote attackers to inject malicious scripts, potentially compromising user sessio...

PoC for CVE-2017-7494

SambaSamba🟣 EPSS 99%9.8CRITICAL
Remote Code Execution in Samba Versions 3.5.0 to 4.6.4 by Louis Lu

Samba versions 3.5.0 up to 4.6.4, along with specific earlier releases, contain a serious vulnerability where a malicious client can upload a shared library to a writable share. This exploit allows the server to load and execute the uploaded file, leading to unauthorized control and potential dam...

Discovered 13 hours ago

PoC for CVE-2026-72898

MetabaseMetabase🟣 EPSS 10%10CRITICAL
SQL Injection Vulnerability in Metabase by Metabase, Inc.

Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...

PoC for CVE-2026-8794

PapercutPapercut Ng/mf6.9MEDIUM
Timing Discrepancy Vulnerability in PaperCut NG/MF from PaperCut

PaperCut NG/MF features an undisclosed flaw within its authentication mechanism that allows unauthenticated remote attackers to exploit timing discrepancies. By analyzing the response times of login attempts, attackers can conduct username enumeration. The system engages in password hash comparis...

PoC for CVE-2026-8793

PapercutPapercut Ng/mf6.9MEDIUM
Brute-Force Vulnerability in PaperCut NG/MF Login Component

The PaperCut NG/MF software experiences a vulnerability in its login component that inadequately restricts excessive authentication attempts. This weakness can be exploited by unauthenticated remote attackers to launch brute-force or credential-stuffing attacks. In specific configurations, attack...

Discovered 14 hours ago

PoC for CVE-2026-72898

MetabaseMetabase🟣 EPSS 10%10CRITICAL
SQL Injection Vulnerability in Metabase by Metabase, Inc.

Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...

PoC for CVE-2026-68820

MicrosoftWindows 10 Version 16077HIGH
Privilege Elevation Vulnerability in Windows Ancillary Function Dri...

A use after free vulnerability exists in the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to exploit the driver and potentially elevate privileges locally, threatening the integrity of the operating system. To mitigate risk, it is essential to apply the ...

Discovered 15 hours ago

PoC for CVE-2026-19905

JinherOa6.9MEDIUM
SQL Injection Vulnerability in Jinher OA Product by Jinher

A vulnerability in Jinher OA 1.0 has been discovered, allowing unauthorized SQL injection through an unprotected function located in the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This weakness enables remote attackers to manipulate the argument 'httpOID' for malicious purpose...

Discovered 16 hours ago

PoC for CVE-2026-72898

MetabaseMetabase🟣 EPSS 10%10CRITICAL
SQL Injection Vulnerability in Metabase by Metabase, Inc.

Metabase contains a vulnerability that enables a remote, unauthenticated attacker to perform SQL injection through the '/reset_password' endpoint. This flaw allows attackers to manipulate database queries, potentially gaining unauthorized administrator access to the Metabase instance and compromi...

PoC for CVE-2026-19901

Lb-linkX-pro9.2CRITICAL
Remote code execution vulnerability in LB-LINK X-PRO product by LB-...

A security flaw has been identified in the LB-LINK X-PRO version 1.0.22-20231206 that impacts an unspecified function within the /etc/config/easycwmp file. The vulnerability enables the presence of hard-coded credentials, which could be exploited remotely. Although the complexity of the attack is...

Discovered 17 hours ago

PoC for CVE-2026-19900

Lb-linkX-pro9.2CRITICAL
Hard-Coded Credentials Vulnerability in LB-LINK X-PRO Router

A significant security vulnerability has been discovered in the LB-LINK X-PRO router, specifically in version 1.0.22-20231206. This issue pertains to an unknown function within the /etc/shadow file that exposes hard-coded credentials. Attackers can exploit this vulnerability remotely, allowing ac...

PoC for CVE-2026-19899

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A SQL injection vulnerability has been identified in the SourceCodester Class and Exam Timetabling System, specifically in the 'edit_teacher.php' file. This issue arises from improper handling of the argument ID, enabling attackers to execute malicious SQL code remotely. The exploit has been publ...