Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered just now...

PoC for CVE-2023-45802

ApacheApache Http Server5.9MEDIUM
Apache HTTP Server: HTTP/2 stream memory not reclaimed right away o...

When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causin...

Discovered 1 hour ago

PoC for CVE-2026-31908

ApacheApache Apisix9.1CRITICAL
Header Injection Vulnerability in Apache APISIX by Apache Software ...

A header injection vulnerability exists in Apache APISIX that can be exploited by attackers through improper configuration in the forward-auth plugin. This flaw allows for the injection of malicious headers, posing a risk to the integrity and security of the application. Users are advised to upgr...

Discovered 3 hours ago

PoC for CVE-2026-6591

comfyanonymousComfyui5.3MEDIUM
Path Traversal Vulnerability in ComfyUI LoadImage Node

A vulnerability has been identified in ComfyUI affecting the LoadImage Node component, specifically within the function folder_paths.get_annotated_filepath of the folder_paths.py file. This issue stems from improper handling of input arguments, leading to a path traversal condition. By exploiting...

PoC for CVE-2026-6590

ComfyAnonymousComfyui5.3MEDIUM
Path Traversal Vulnerability in ComfyUI by ComfyAnonymous

A path traversal vulnerability exists in ComfyUI versions up to 0.13.0, specifically affecting the model preview feature within the get_model_preview function in model_manager.py. This flaw enables attackers to manipulate file paths, potentially exposing sensitive files or executing arbitrary cod...

PoC for CVE-2026-6589

ComfyAnonymousComfyui5.3MEDIUM
Cross-Site Request Forgery Vulnerability in ComfyUI by ComfyAnonymous

A security vulnerability has been identified in ComfyUI versions up to 0.13.0, specifically impacting the create_origin_only_middleware function within the server.py file. This vulnerability enables attackers to execute cross-site request forgery (CSRF) attacks, allowing unauthorized actions on b...

PoC for CVE-2026-6588

Serge-chatSerge6.9MEDIUM
Remote Manipulation Flaw in Serge-Chat's Model API Endpoint

A vulnerability has been discovered in the Model API Endpoint of Serge-Chat, specifically in the function download_model/delete_model located in api/src/serge/routers/model.py. This flaw allows for remote manipulation, potentially leading to unauthorized access due to missing authentication contr...

Discovered 4 hours ago

PoC for CVE-2026-6586

TransformeroptimusSuperagi5.3MEDIUM
Authorization Bypass in TransformerOptimus SuperAGI by Vendor

An authorization bypass vulnerability has been discovered in the SuperAGI product from TransformerOptimus. This security flaw affects the `get_budget` and `update_budget` functions within the `budget.py` file of the Budget Endpoint component. Exploiting this vulnerability allows unauthorized mani...

PoC for CVE-2026-6585

TransformeroptimusSuperagi5.3MEDIUM
Authorization Bypass in TransformerOptimus SuperAGI by Vendor

A vulnerability exists in the organisation update function of TransformerOptimus SuperAGI, specifically in the update_organisation method located in the superagi/controllers/organisation.py file. This flaw allows for an authorization bypass due to improper handling of the organisation_id paramete...

PoC for CVE-2026-6584

TransformeroptimusSuperagi5.3MEDIUM
Authorization Bypass in TransformerOptimus SuperAGI User Update End...

A security flaw exists in TransformerOptimus SuperAGI affecting versions up to 0.0.14, specifically within the user update function. An attacker can exploit this vulnerability via remote techniques, leading to unauthorized access. The flaw arises from improper handling of the user_id argument in ...

Discovered 5 hours ago

PoC for CVE-2026-6583

TransformeroptimusSuperagi5.3MEDIUM
Authorization Bypass in TransformerOptimus SuperAGI by Vendor

A vulnerability exists in TransformerOptimus SuperAGI versions up to 0.0.14 within the API Key Management Endpoint, specifically in the delete_api_key/edit_api_key functions located in the superagi/controllers/api_key.py file. This issue allows an attacker to bypass authorization remotely, potent...

PoC for CVE-2026-6582

TransformeroptimusSuperagi6.9MEDIUM
Missing Authentication in TransformerOptimus SuperAGI Vector Databa...

A flaw exists in the Vector Database Management Endpoint of TransformerOptimus SuperAGI, specifically in the function get_vector_db_details. This issue allows attackers to exploit missing authentication, potentially granting unauthorized access to sensitive operations. The vulnerability is exploi...

PoC for CVE-2026-6581

H3cMagic B18.7HIGH
Buffer Overflow Vulnerability in H3C Magic B1 by H3C

A buffer overflow vulnerability exists in the H3C Magic B1, specifically in the SetMobileAPInfoById function within the /goform/aspForm file. This issue allows for manipulation of the parameter input, potentially leading to remote code execution. The exploit is publicly known, and proactive measu...

PoC for CVE-2026-6580

LiangliangyyDjangoblog6.9MEDIUM
DjangoBlog Amap API Call Handler Vulnerability in Liangliangyy Soft...

A security vulnerability has been identified in Liangliangyy's DjangoBlog, specifically within the Amap API Call Handler. An unknown function in the file owntracks/views.py improperly handles input parameters, allowing the use of hard-coded cryptographic keys. This vulnerability can be exploited ...

Discovered 6 hours ago

PoC for CVE-2026-6579

LiangliangyyDjangoblog6.9MEDIUM
Missing Authentication Vulnerability in liangliangyy DjangoBlog

A vulnerability has been detected in liangliangyy DjangoBlog versions up to 2.1.0.0, specifically within the Clean Endpoint component located in blog/views.py. This issue allows for unauthorized access due to the absence of proper authentication checks, potentially enabling malicious actors to ex...

PoC for CVE-2026-6578

LiangliangyyDjangoblog6.3MEDIUM
Security Flaw in liangliangyy DjangoBlog Affects Sensitive Configur...

A security flaw in the liangliangyy DjangoBlog allows for the manipulation of the SECRET_KEY argument within the settings.py file, leading to hard-coded credentials. This vulnerability can be exploited remotely, requiring a sophisticated level of technical knowledge. The potential for exploitatio...

Discovered 8 hours ago

PoC for CVE-2026-6577

LiangliangyyDjangoblog6.9MEDIUM
Missing Authentication in DjangoBlog by liangliangyy

A notable vulnerability exists in DjangoBlog by liangliangyy, impacting versions up to 2.1.0.0. This flaw resides within an undisclosed function in the logtracks Endpoint (owntracks/views.py), resulting in a lack of necessary authentication measures. As a result, unauthorized users can potentiall...

Discovered 9 hours ago

PoC for CVE-2026-6576

LiangliangyyDjangoblog5.3MEDIUM
Command Injection Vulnerability in DjangoBlog WeChat Bot Interface ...

A command injection vulnerability has been identified in the WeChat Bot interface of DjangoBlog up to version 2.1.0.0. This flaw resides in the CommandHandler function of the servermanager/api/commonapi.py file, allowing remote attackers to manipulate the Source argument. If exploited, this vulne...

PoC for CVE-2026-35616

FortinetForticlientems🟣 EPSS 25%9.1CRITICAL
Improper Access Control in Fortinet FortiClientEMS Products

An improper access control issue exists in Fortinet's FortiClientEMS versions 7.4.5 and 7.4.6. This vulnerability may enable an unauthenticated attacker to send crafted requests that can lead to the execution of unauthorized code or commands. Organizations using affected versions should prioritiz...

Discovered 18 hours ago

PoC for CVE-2026-6564

EMQEMQx Enterprise5.3MEDIUM
Improper Authorization Vulnerability in EMQ EMQX Enterprise Session...

EMQX Enterprise versions up to 6.1.0 contain a vulnerability in the session handling component that allows for improper authorization. This flaw enables remote attackers to manipulate access controls and potentially launch unauthorized actions within the system. Despite attempts to notify the ven...

Discovered 19 hours ago

PoC for CVE-2026-6563

H3cMagic B18.7HIGH
Buffer Overflow Vulnerability in H3C Magic B1 Router

A buffer overflow vulnerability exists in the functionality of H3C Magic B1 routers, specifically in the SetAPWifiorLedInfoById function located within the /goform/aspForm file. This vulnerability arises from improper handling of input parameters, allowing remote attackers to potentially exploit ...

PoC for CVE-2026-6562

Dameng100Muucmf6.9MEDIUM
SQL Injection Vulnerability in Dameng100 MuuCmf 1.9.5.20260309

A security flaw has been identified in the Dameng100 MuuCmf version 1.9.5.20260309, specifically within the getListByPage function found in the /index/Search/index.html file. This vulnerability allows attackers to manipulate the `keyword` argument, leading to potential SQL injection attacks. The ...

Discovered 20 hours ago

PoC for CVE-2026-6561

Hainan Zanzan Net...Eyoucms5.1MEDIUM
Unrestricted Upload Vulnerability in EyouCMS by Hainan Zanzan Netwo...

A vulnerability within EyouCMS versions up to 1.7.1 allows attackers to perform unrestricted file uploads via the edit_adminlogo function in the application/admin/controller/Index.php file. This flaw results from improper handling of the 'filename' argument, enabling remote attackers to upload ma...

Discovered 21 hours ago

PoC for CVE-2026-6560

H3cMagic B08.7HIGH
Buffer Overflow in H3C Magic B0 Affected by Remote Exploit

A security vulnerability has been identified in H3C Magic B0 devices, specifically affecting the Edit_BasicSSID function of the /goform/aspForm file. This issue allows for a buffer overflow, enabling remote attackers to exploit the flaw and potentially execute arbitrary code. The vulnerability ha...

Discovered 22 hours ago

PoC for CVE-2026-4631

Red HatRed Hat Enterprise Lin...9.8CRITICAL
Remote Code Execution Vulnerability in Cockpit Web Service by Red Hat

The Cockpit web service's remote login feature is susceptible to a serious vulnerability where it improperly processes user-supplied hostnames and usernames. This lack of validation allows an attacker with network access to manipulate HTTP requests to the login endpoint. As a result, malicious SS...

Discovered 23 hours ago

PoC for CVE-2026-4257

WordPressContact Form By Supsystic🟣 EPSS 20%9.8CRITICAL
Server-Side Template Injection in Contact Form by Supsystic for Wor...

The Contact Form by Supsystic plugin for WordPress is susceptible to a Server-Side Template Injection (SSTI) vulnerability that may lead to Remote Code Execution (RCE). This exposure affects all versions up to and including 1.7.36. The flaw arises from the plugin's integration of the Twig `Twig_L...

Discovered 1 day ago

PoC for CVE-2026-25232

GogsGogs7.1HIGH
Access Control Bypass in Gogs Open Source Git Service

Gogs, a self-hosted Git service, has a significant access control bypass vulnerability present in versions 0.13.4 and earlier. This issue allows any collaborator with Write permissions to delete protected branches, including the default branch, by sending a direct POST request. The vulnerability ...

PoC for CVE-2026-33032

0xjackyNginx-ui9.8CRITICAL
Vulnerability in Nginx UI Web Interface for Nginx Server

The Nginx UI web interface, specifically versions 2.3.5 and earlier, is susceptible to a serious flaw due to improper authentication in its MCP (Model Context Protocol) integration. This vulnerability allows attackers, without any authentication, to exploit the /mcp_message endpoint. Although the...

Discovered 2 days ago

PoC for CVE-2025-55182

MetaReact-server-dom-webpack🟣 EPSS 87%10CRITICAL
Remote Code Execution Vulnerability in React Server Components by Meta

A remote code execution vulnerability found in React Server Components allows attackers to exploit improperly handled payloads. This issue affects versions 19.0.0 through 19.2.0, compromising server function endpoints through unsafe deserialization of HTTP request payloads. As a result, this flaw...

PoC for CVE-2025-7771

TecHPowerupThrottlestop8.7HIGH
Privilege Escalation Vulnerability in ThrottleStop Driver by TechPo...

The ThrottleStop driver, a legitimate component from TechPowerUp, presents a vulnerability due to insecure IOCTL interfaces that permit arbitrary read and write access to the physical memory through the MmMapIoSpace function. This flaw can be exploited by malicious applications running in user mo...

PoC for CVE-2026-1555

WordPressWebstack9.8CRITICAL
Arbitrary File Upload Vulnerability in WebStack Theme for WordPress

The WebStack theme for WordPress contains a vulnerability that permits arbitrary file uploads due to insufficient file type validation in the io_img_upload() function. Any attacker, even those without authentication, can exploit this weakness to upload malicious files to the server hosting the af...

PoC for CVE-2026-33671

MicromatchPicomatch7.5HIGH
ReDoS Vulnerability in Picomatch Library by Micromatch

The Picomatch library, used for glob pattern matching in JavaScript, is prone to a Regular Expression Denial of Service (ReDoS) attack when processing specially crafted extglob patterns. Specifically, versions before 4.0.4, 3.0.2, and 2.3.2 can become susceptible to catastrophic backtracking on c...

PoC for CVE-2007-2447

SambaSamba🟣 EPSS 77%
Remote Command Execution Vulnerability in Samba by The Samba Team

The MS-RPC functionality within the Samba server allows attackers to execute arbitrary commands remotely due to improper handling of shell metacharacters. When the 'username map script' configuration option is enabled, a malicious user can exploit the SamrChangePassword function to inject command...

PoC for CVE-2026-26980

TryghostGhost🟣 EPSS 33%9.4CRITICAL
Unauthenticated Database Read Vulnerability in Ghost CMS

Ghost CMS, a widely used Node.js content management system, contains a vulnerability that enables unauthenticated attackers to execute arbitrary reads from its database. This security flaw affects versions 3.24.0 through 6.19.0, posing a significant risk to the confidentiality of sensitive data s...

PoC for CVE-2019-0708

MicrosoftWindows🟣 EPSS 94%9.8CRITICAL
Remote Code Execution Vulnerability in Microsoft Remote Desktop Ser...

A remote code execution vulnerability in Microsoft Remote Desktop Services allows an unauthenticated attacker to connect to the target system via RDP and execute arbitrary code by sending specially crafted requests. This exploitation can lead to significant security breaches if not mitigated adeq...

PoC for CVE-2023-27163

RbasketsRequest Baskets🟣 EPSS 93%6.5MEDIUM
Server-Side Request Forgery in Request-Baskets by Darklynx

Request-Baskets, up to version 1.2.1, contains a vulnerability that allows attackers to exploit Server-Side Request Forgery (SSRF) through a crafted API request targeting the /api/baskets/{name} endpoint. This security flaw enables unauthorized access to internal network resources and sensitive i...

PoC for CVE-2026-33032

0xjackyNginx-ui9.8CRITICAL
Vulnerability in Nginx UI Web Interface for Nginx Server

The Nginx UI web interface, specifically versions 2.3.5 and earlier, is susceptible to a serious flaw due to improper authentication in its MCP (Model Context Protocol) integration. This vulnerability allows attackers, without any authentication, to exploit the /mcp_message endpoint. Although the...

PoC for CVE-2026-39842

OpenremoteOpenremote10CRITICAL
Expression Injection Vulnerabilities in OpenRemote IoT Platform

The OpenRemote IoT platform, specifically versions 1.21.0 and below, is impacted by two related expression injection vulnerabilities. These flaws exist within the rules engine, allowing unauthorized users to execute arbitrary code on the server. The JavaScript rules engine processes user-defined ...

Discovered 3 days ago

PoC for CVE-2026-6497

PrasathmaniTinyfilemanager5.3MEDIUM
Server-Side Request Forgery in TinyFileManager by prasathmani

A vulnerability exists in TinyFileManager, specifically in the file upload functionality located at /filemanager.php?p=ajax=true&type=upload. This flaw allows an attacker to manipulate the uploadurl parameter, potentially leading to a server-side request forgery (SSRF) attack. Such an attack can ...

PoC for CVE-2026-6496

PrasathmaniTinyfilemanager5.3MEDIUM
Path Traversal Vulnerability in TinyFileManager by prasathmani

A vulnerability exists in prasathmani TinyFileManager versions up to 2.6, specifically within the POST Parameter Handler found in the file /filemanager.php. This issue arises from inadequate input validation, allowing attackers to manipulate the 'file[]' parameter to perform path traversal attack...

PoC for CVE-2026-6493

LukevellaRallly5.1MEDIUM
Cross-Site Scripting Vulnerability in Rallly by Lukevella

A security flaw has been identified in Rallly versions up to 4.7.4, specifically within the Reset Password Handler component. This vulnerability arises from improper handling of the 'redirectTo' argument, which may allow attackers to execute cross-site scripting (XSS) attacks remotely. If exploit...

PoC for CVE-2026-6492

Arnobt78Hotel Booking Manageme...6.9MEDIUM
Information Disclosure Vulnerability in arnobt78 Hotel Booking Mana...

A vulnerability exists in the arnobt78 Hotel Booking Management System, specifically within the health check endpoint, where an unknown function can be exploited to disclose sensitive information. This vulnerability allows remote attackers to perform unauthorized access, leading to potential info...

PoC for CVE-2026-6491

libvipsLibvips4.8MEDIUM
Heap-based Buffer Overflow in libvips Affects Local Applications

A security vulnerability exists in the libvips library prior to version 8.19, specifically within the im_minpos_vec function in the deprecated vips7compat.c file. This vulnerability allows for heap-based buffer overflow due to inadequate handling of the argument n, requiring local access for expl...

PoC for CVE-2026-6490

QuerymineSms6.9MEDIUM
SQL Injection Vulnerability in QueryMine SMS Product by Unknown Vendor

A SQL injection vulnerability exists in the QueryMine sms component, specifically within the admin/deletecourse.php file. This issue arises due to improper handling of the GET request parameter 'ID', allowing attackers to manipulate the input and execute unauthorized SQL queries. The attack can b...

PoC for CVE-2026-6489

QuerymineSms5.3MEDIUM
Unrestricted File Upload Vulnerability in QueryMine sms Background ...

A security flaw has been identified in QueryMine sms, specifically affecting the admin/addteacher.php file within the Background Management Page component. The vulnerability allows attackers to manipulate the image argument, leading to unrestricted file uploads. This can be exploited remotely, po...

PoC for CVE-2026-6488

QuerymineSms5.3MEDIUM
SQL Injection Vulnerability in QueryMine sms by QueryMine

A SQL injection vulnerability has been discovered in QueryMine sms that impacts the GET Request Parameter Handler in the editcourse.php file. This vulnerability arises from improper handling of the ID argument, allowing remote attackers to manipulate SQL queries. Due to the continuous delivery an...

PoC for CVE-2026-0740

WordPressNinja Forms - File Upl...9.8CRITICAL
Arbitrary File Upload Vulnerability in Ninja Forms File Uploads Plu...

The Ninja Forms - File Uploads plugin for WordPress contains a vulnerability allowing unauthenticated attackers to upload arbitrary files due to inadequate file type validation in the upload handling function. This oversight affects all versions upto and including 3.3.26, potentially enabling att...

PoC for CVE-2026-6487

QihuiJtbc5 Cms5.3MEDIUM
Path Traversal Vulnerability in Qihui jtbc5 CMS by Shanghai Qihui N...

A vulnerability exists in the Qihui jtbc5 CMS, specifically in the Code Endpoint component located in manage.php. This flaw allows attackers to manipulate input parameters related to file paths, leading to unauthorized access to files outside of the intended directory. The exploit can be executed...

PoC for CVE-2026-6486

ClassroombookingsClassroombookings5.1MEDIUM
Cross-Site Scripting Vulnerability in Classroom Bookings by Classro...

A cross-site scripting vulnerability was identified in Classroom Bookings versions up to 2.17.0, specifically within the User Display Name Handler component. The vulnerability arises from improper handling of the 'displayname' argument in the file crbs-core/application/views/layout.php, allowing ...

PoC for CVE-2026-6483

WavlinkWl-wn530h48.6HIGH
OS Command Injection in Wavlink Wireless Router

A vulnerability has been identified in the Wavlink WL-WN530H4 model, specifically within the strcat and snprintf functions of the /cgi-bin/internet.cgi file. This security flaw enables remote attackers to inject operating system commands, potentially leading to unauthorized access and control ove...

PoC for CVE-2025-8110

GogsGogs🟣 EPSS 20%8.7HIGH
Improper Symbolic Link Handling in Gogs Product by Gogs Team

The vulnerability in the PutContents API of Gogs arises from improper handling of symbolic links, potentially allowing local execution of arbitrary code. This misconfiguration may expose sensitive data and facilitate unauthorized access to critical systems. Users and administrators are urged to u...