
EITS-Portal-Exploit-CVE-2026-31367-PoC
PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable…

Proof-of-concept exploit for CVE-2021-44103 demonstrating vertical privilege escalation in Konga API Gateway 0.14.9, allowing authenticated users to…

Proof-of-concept exploit for CVE-2021-45232, an unauthorized access vulnerability in Apache APISIX Dashboard allowing export/import of admin…

Proof-of-concept exploit for CVE-2026-8181: unauthenticated admin impersonation via incorrect password in Basic Authentication header, enabling REST…

CVE-2026-28767 disclosure: missing authentication on Gardyn Home Kit cloud API admin notifications endpoint, exposing internal system data and…

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

Exploit for Apache ShenYu admin authentication bypass (CVE-2021-37580), allowing unauthorized access to the admin console.

PoC exploit for Apache APISIX CVE-2022-24112, using batch-requests plugin to bypass Admin API IP restriction and execute remote commands via a…