Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

60 results

CVE-2026-94130
CRITICAL
CVSS 9.3 CRITICAL CWE-89 Published 2026-09-26 PoCs 1 ★ 2 Last push 2026-09-26 (1 week, 6 days ago)

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.

Show 1 repositories
murrez/CVE-2026-94130

Unauthenticated SQL injection in Joomla YouTube Gallery (joomlaboat.com, com_youtubegallery) ≤ 5.7.2 — video search/sort on the public yg_api endpoint. Python …

★ 2 · 2026-09-26
CVE-2026-93399
CRITICAL
CVSS 9.1 CRITICAL CWE-639 Published 2026-09-25 PoCs 2 ★ 0 Last push 2026-09-26 (1 week, 6 days ago)

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the attacker-controlled 'order_id' from the submitted form_data into a new booking session, which the 'bookly_render_complete' handler then trusts to look up and return the corresponding Order's secret token without verifying that the current session created that order. This makes it possible for unauthenticated attackers to enumerate sequential order IDs, disclose other customers' order tokens, retrieve calendar/appointment information via 'bookly_add_to_calendar' and permanently delete arbitrary non-completed bookings via 'bookly_rollback_order', which cascade-deletes the customer_appointment and (when no other customers are attached) the underlying appointment.

Show 2 repositories
murrez/CVE-2026-93399

Unauthenticated IDOR in Bookly ≤ 28.2: bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; bookly_add_to_calendar exposes appointm…

★ 0 · 2026-09-25
josemour8/CVE-2026-93399

Bookly <= 28.2 Unauth IDOR + PII Leak + RCE Mass exploitation scanner for CVE-2026-93399 (CVSS 9.1 Critical) affecting the Bookly — Online Scheduling and Appo…

★ 0 · 2026-09-26
CVE-2026-89055
CRITICAL
CVSS 9.1 CRITICAL CWE-862 Published 2026-09-25 PoCs 1 ★ 0 Last push 2026-09-25 (2 weeks ago)

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product images, logos, and documents — by injecting their IDs into a review that is later trashed and purged. Exploitation requires a public review-form link (a 13-hex formId distributed to customers via e-mail), which exposes the nonce needed to reach the handler without any WordPress account or session.

Show 1 repositories
murrez/CVE-2026-89055

Unauthenticated authorization bypass in Customer Reviews for WooCommerce ≤ 5.120.0: holders of a public /cusrev/{formId}/ review link can POST cr_local_forms_s…

★ 0 · 2026-09-25
CVE-2026-94127
CRITICAL
CVSS 9.3 CRITICAL CWE-122 Published 2026-09-22 PoCs 2 ★ 15 Last push 2026-09-24 (2 weeks, 1 day ago)

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Show 2 repositories
FurkanKAYAPINAR/CVE-2026-94127

CVE-2026-94127

★ 0 · 2026-09-23
CVE-2026-95675
CRITICAL
CVSS 9.3 CRITICAL CWE-78 Published 2026-09-22 PoCs 1 ★ 1 Last push 2026-09-24 (2 weeks, 1 day ago)

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.

Show 1 repositories
d6fault/CVE-2026-95675

CVE-2026-95675 · POC

★ 1 · 2026-09-24
CVE-2026-89274
CRITICAL
CVSS 9.1 CRITICAL CWE-94 Published 2026-09-19 PoCs 3 ★ 3 Last push 2026-09-23 (2 weeks, 2 days ago)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of approved `wprm-comment-rating` comments — without sanitizing or stripping shortcode tokens before execution; the subsequent `wp_strip_all_tags()` and `strip_shortcodes()` calls operate only on the output string after execution has already fully occurred, providing no protection against server-side shortcode invocation. This makes it possible for unauthenticated attackers to execute arbitrary registered WordPress shortcodes server-side on every recipe page render, causing shortcode output — such as attachment captions, private post fields, or other data exposed by installed shortcodes — to be embedded in the page's JSON-LD `reviewBody` metadata and disclosed to all visitors who load the recipe page. Successful exploitation requires the attacker's rated comment to pass the site's comment approval threshold, either via auto-approval or moderator action, before the injected shortcode begins executing on page loads.

Show 3 repositories
murrez/CVE-2026-89274

PoC for CVE-2026-89274: unauthenticated arbitrary shortcode execution in WP Recipe Maker ≤10.8.1 via recipe rating comments (JSON-LD). Python check/exploit/ver…

★ 3 · 2026-09-19
Polosss/By-Poloss..-.CVE-2026-89274

Unauthenticated Arbitrary Shortcode Execution

★ 0 · 2026-09-20
Hassham1/CVE-2026-89274-wp-recipe-maker-poc

CVE-2026-89274 — WP Recipe Maker <= 10.8.1 arbitrary shortcode execution via rating-comment reviewBody (CVSS 9.1): Docker validation lab with vulnerable (10.8.…

★ 0 · 2026-09-23
CVE-2026-90898
CRITICAL
CVSS 9.8 CRITICAL CWE-284, CWE-306 Published 2026-09-14 PoCs 1 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).  transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.

Show 1 repositories
HORKimhab/CVE-2026-90898

CVE-2026-90898 - Draft or TODO

★ 0 · 2026-09-23
CVE-2026-88877
CRITICAL
CVSS 9.3 CRITICAL CWE-639 Published 2026-09-10 PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 3 days ago)

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect annotation. For such Ingresses the provider creates an additional 'sibling' router that matches on the host alone, carries only the RedirectRegex middleware, and still points at the parent router's protected backend service. Because RedirectRegex is not a terminal handler, a request its pattern does not match is forwarded to the backend, and because the redirect pattern only accepts a numeric port while Traefik's host matcher canonicalizes the authority via net.SplitHostPort, a request with a non-numeric or empty port (for example 'Host: www.example.com:x') selects the sibling router, misses the redirect, and is proxied to the protected backend with none of the Ingress's annotation-derived middlewares applied. This discards not only authentication (e.g. BasicAuth) but every annotation-derived middleware, including source-IP allowlisting. Traefik v2 and v3 releases before v3.7.0 are not affected. The issue is fixed in v3.7.12.

Show 1 repositories
CVE-2026-93674
CRITICAL
CVSS 9.8 CRITICAL CWE-94 Published 2026-10-07 PoCs 1 ★ 4 Last push 2026-09-22 (2 weeks, 4 days ago)

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Show 1 repositories
rmhowe425/POC-CVE-2026-93674

POC-CVE-2026-93674 Authenticated Blind command injection proof of concept exploit code

★ 4 · 2026-09-22
CVE-2026-89026
CRITICAL
CVSS 9.3 CRITICAL CWE-321 Published 2026-09-15 PoCs 1 ★ 1 Last push 2026-09-21 (2 weeks, 4 days ago)

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.

Show 1 repositories
AranFarzami/CVE-2026-89026

PoC exploit and scanner for CVE-2026-89026, targeting the Issabel PBXAPI authentication vulnerability

★ 1 · 2026-09-21
CVE-2026-88854
CRITICAL
CVSS 9.3 CRITICAL CWE-89 Published 2026-09-20 PoCs 1 ★ 3 Last push 2026-09-20 (2 weeks, 5 days ago)

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.

Show 1 repositories
murrez/CVE-2026-88854

CVE-2026-88854 — OrdaSoft Joomla Gallery unauth SQLi PoC (check / mass scan / EXTRACTVALUE read)

★ 3 · 2026-09-20
CVE-2026-92229
CRITICAL
CVSS 9.1 CRITICAL CWE-94 Published 2026-09-19 PoCs 1 ★ 5 Last push 2026-09-19 (2 weeks, 6 days ago)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Show 1 repositories
murrez/CVE-2026-92229

CVE-2026-92229 — Forminator ≤1.57.2 unauth shortcode exec (current_url / quiz AJAX). Python 3 PoC.

★ 5 · 2026-09-19
CVE-2026-91843
CRITICAL
CVSS 9.8 CRITICAL CWE-121 Published 2026-09-16 PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Show 1 repositories
HORKimhab/CVE-2026-91843

CVE-2026-91843 - Draft or TODO

★ 0 · 2026-09-18
CVE-2026-87930
CRITICAL
CVSS 9.2 CRITICAL CWE-502 Published 2026-09-09 PoCs 1 ★ 1 Last push 2026-09-17 (3 weeks, 1 day ago)

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.

Show 1 repositories
winrarzipsexploit/CVE-2026-87930

CVE-2026-87930 Joomla Multi-CVE RCE suite — authorized testing only

★ 1 · 2026-09-17
CVE-2026-88899
CRITICAL
CVSS 9.3 CRITICAL CWE-73 Published 2026-09-10 PoCs 1 ★ 0 Last push 2026-09-14 (3 weeks, 4 days ago)

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

Show 1 repositories
uziii2208/CVE-2026-88899

Knowns 0.30.0: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem

★ 0 · 2026-09-14
CVE-2026-87492
CRITICAL
CVSS 9.6 CRITICAL CWE-863 Published 2026-09-09 PoCs 1 ★ 4 Last push 2026-09-13 (3 weeks, 5 days ago)

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Show 1 repositories
valencenavy/IsolatedAnarchy-Public

Public release of CVE-2026-87492 🥷

★ 4 · 2026-09-13
CVE-2026-8732
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-306 Published 2026-05-29 PoCs 6 ★ 8 Last push 2026-09-08 (1 month ago)

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.

Show 6 repositories
p3Nt3st3r-sTAr/CVE-2026-8732-POC
★ 8 · 2026-06-01
zycoder0day/CVE-2026-8732

CVE-2026-8732 | WP Maps Pro <= 6.1.0 | Unauthenticated Privilege Escalation

★ 3 · 2026-05-30
Jenderal92/CVE-2026-8732

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

★ 3 · 2026-05-31
fientix/CVE-2026-8732-PoC

CVE-2026-8732 | WP Maps Pro <= 6.1.0 Unauth Admin Creation

★ 2 · 2026-09-08
xShadow-Here/CVE-2026-8732

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation

★ 1 · 2026-05-30
HORKimhab/CVE-2026-8732

CVE-2026-8732 - Draft (WordPress)

★ 0 · 2026-06-01
CVE-2026-9055
CRITICAL
CVSS 9.8 CRITICAL CWE-269 Published 2026-09-02 PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.

Show 1 repositories
EXEcution-py/CVE-2026-9055
★ 0 · 2026-09-02
CVE-2026-9198
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-94 Published 2026-07-17 PoCs 8 ★ 3 Last push 2026-09-02 (1 month, 1 week ago)

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

Show 8 repositories
0xgh057r3c0n/CVE-2026-9198

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

★ 3 · 2026-07-24
0xdak/CVE-2026-9198_exploit
★ 1 · 2026-07-21
rmhowe425/PoC-CVE-2026-9198

Proof of concept exploit code for CVE-2026-9198

★ 1 · 2026-09-02
ywh-jfellus/CVE-2026-9198

Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass

★ 0 · 2026-07-24
Procjevt/CVE-2026-9198
★ 0 · 2026-08-10
CuteeCat/CVE-2026-9198

CVE-2026-9198利用代码

★ 0 · 2026-08-11
chessalekin/cve-2026-9198_exploit
★ 0 · 2026-08-24
joaovicdev/EXPLOIT-CVE-2026-9198
★ 0 · 2026-08-29
CVE-2026-9586
CRITICAL
CVSS 9.3 CRITICAL CWE-89 Published 2026-07-17 PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Show 1 repositories
HORKimhab/CVE-2026-9586

CVE-2026-9586 - Draft or TODO

★ 0 · 2026-09-02
CVE-2026-9090
CRITICAL
CVSS 9.1 CRITICAL Published 2026-05-28 PoCs 2 ★ 0 Last push 2026-08-15 (1 month, 3 weeks ago)

Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-configured Identity Provider certificate, allowing an attacker to forge assertions signed with an attacker-controlled key.

Show 2 repositories
Kimdir01/CVE-2026-9090-poc

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

★ 0 · 2026-08-15
CVE-2026-9645
CRITICAL
CVSS 9.9 CRITICAL CWE-78 Published 2026-05-28 PoCs 1 ★ 0 Last push 2026-08-09 (2 months ago)

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

Show 1 repositories
0xmhany/CVE-2026-9645-ScadaBR-Analysis

Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.

★ 0 · 2026-08-09
CVE-2026-9082
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-89 Published 2026-05-20 PoCs 12 ★ 23 Last push 2026-08-07 (2 months ago)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

Show 8 of 12 repositories
7h30th3r0n3/CVE-2026-9082-Drupal-PoC

Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module…

★ 23 · 2026-05-21
N45HT/drupal-cve-2026-9082-checker

Drupal CVE-2026-9082 Blind SQL Injection Checker

★ 8 · 2026-05-24
HORKimhab/CVE-2026-9082

CVE-2026-9082 | SA-CORE-2026-004

★ 2 · 2026-05-21
ridhinva/drupal-jsonapi-sqli-scanner

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

★ 2 · 2026-08-07
0xBlackash/CVE-2026-9082

CVE-2026-9082

★ 1 · 2026-06-04
ywh-jfellus/CVE-2026-9082

PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi

★ 1 · 2026-05-21
sourcecode347/CVE-2026-9082-Mass_Scanner

Mass Scanner For Drupal Exploit CVE-2026-9082

★ 1 · 2026-06-16
CVE-2026-9256
CRITICAL
CVSS 9.2 CRITICAL CWE-122 Published 2026-05-22 PoCs 4 ★ 3 Last push 2026-08-01 (2 months, 1 week ago)

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Show 4 repositories
3nou9h/CVE-2026-9256-Poc
★ 3 · 2026-05-28
06-ux/CVE-2026-9256-POC

CVE-2026-9256 Nginx heap buffer overflow POC

★ 1 · 2026-06-03
suominen/CVE-2026-9256

Tracking the nginx CVE-2026-9256 rewrite-module heap overflow

★ 0 · 2026-08-01
CVE-2026-8838
CRITICAL
CVSS 9.3 CRITICAL CWE-94 Published 2026-05-18 PoCs 2 ★ 0 Last push 2026-07-28 (2 months, 1 week ago)

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.

Show 2 repositories
Maxime288/CVE-2026-8838-RCE
★ 0 · 2026-05-19
< Prev Page 2 / 3 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.