
CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

PoC, Dockerfile playground and root cause from patch diff analysis.

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

Docker-based lab for reproducing Keycloak CVE-2026-18963, including vulnerable version setup, realm seeding, and source-level workflow analysis with…

The vulnerable application that will teach you how to hack WebSockets

Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass

Proof-of-concept for CVE-2026-23009 demonstrating unauthenticated DICOM image injection into vulnerable PACS servers using pynetdicom, with a…

Python PoC demonstrating CVE-2026-22002 VNC authentication bypass by forcing protocol version downgrade to RFB 3.3, including a simulated vulnerable…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

CVE-2012-2122 - MySQL Authentication Bypass

Pre-built vulnerable CrushFTP 10.8.0 binary for authorized penetration testing of CVE-2025-31161, an unauthenticated authentication bypass…

Proof-of-concept exploit for CVE-2026-49757 demonstrating OAuth2/OIDC account takeover via email-based user matching in AshAuthentication, with…

Proof-of-concept detection tool for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520, CVE-2026-10523).…

genesisQL-sqli-CVE-2026-36826

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

Proof-of-concept exploit for CVE-2026-29198: NoSQL injection in Rocket.Chat OAuth2 authentication, enabling privilege escalation in vulnerable…

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass