
CVE-2026-21858
Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

Collection of tools to use with Azure Applications

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

Proof-of-concept exploit for CrushFTP authentication bypass (CVE-2025-2825) enabling unauthorized access and data breach simulation.

Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…


RCE for WingFTP v4.7.3

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

CVE-2025-49113 exploit

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…