
CVE-2026-20079
Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain


IBM Langflow Unauthenticated RCE via Auto-Login Bypass


Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.


PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)


RCE for WingFTP v4.7.3

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…