
CVE-2026-9090-poc
PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

Proof-of-concept for CVE-2026-23009 demonstrating unauthenticated DICOM image injection into vulnerable PACS servers using pynetdicom, with a…

Exploit for authentication bypass in WP Time Capsule plugin (<1.21.16). Steals admin cookie and uploads webshell.

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

Exploit tool for CVE-2018-10933 libSSH authentication bypass, enabling remote shell access without credentials using Python scripts and optional fake…

Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)

Proof-of-concept exploit for CVE-2024-29855, an authentication bypass in Veeam Recovery Orchestrator. Includes JWT token spraying and technical root…

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

RingCentral Communications 1.5 - 1.6.8 - Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify Function

Exploit script for CVE-2025-68860 targeting WordPress Mobile Builder plugin. Generates forged JWT tokens using a hardcoded secret to authenticate as…

WordPress Mobile builder Plugin <= 1.4.2 is vulnerable to a high priority Broken Authentication

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

Quentn WP <= 1.2.8 - Unauthenticated Privilege Escalation

Proof-of-concept exploit for CrushFTP authentication bypass (CVE-2025-31161) enabling unauthenticated user impersonation, administrative actions, and…

Animation Addons for Elementor Pro <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation