
CVE-2026-23550
Bash exploit for CVE-2026-23550 that triggers unauthenticated WordPress admin login via crafted REST API request to Modular Connector's…

Bash exploit for CVE-2026-23550 that triggers unauthenticated WordPress admin login via crafted REST API request to Modular Connector's…

Python proof-of-concept exploit for CVE-2026-7458, an unauthenticated authentication bypass in PickPlugins User Verification WordPress plugin via…

Exploit code for CVE-2026-55040, it can create auth header for any validate account.

PoC exploit for CVE-2026-15038 in InfiniteWP Client WordPress plugin: bypasses authentication on Multisite, binds attacker RSA key, escalates to…

CVE-2025-29927: Next.js Middleware Exploit

SAP Netweaver Login Bruteforcer.

OWA Password Sprayer

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

listmonk’s Session Persistence After Password Reset and Password Change

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Vulnerability check script for CVE-2024-37393 (SecurEnvoy MFA 9.4.513)

The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.


PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)