
CVE-2022-40684
Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).

Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).

PoC exploit for CVE-2026-15038 in InfiniteWP Client WordPress plugin: bypasses authentication on Multisite, binds attacker RSA key, escalates to…

CVE-2026-5415 WP Captcha PRO Authenticated Authentication Bypass Exploit

Proof-of-Concept checker/exploit for MantisBT SOAP auth bypass (CVE-2026-30849 / GHSA-phrq-pc6r-f6gh)


Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Proof of concept for CVE-2017-6640 as burp extension

SAP Netweaver Login Bruteforcer.

Exploit for CVE-2022-22845 - Unauthenticated Admin Takeover On QXIP SIPCAPTURE Homer-App up to 1.4.27

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

Rocket.Chat OAuth2 NoSQL Injection

Pega Infinity Password Reset

PoC for CVE-2025-14340: Admin account takeover in Payara Server

Meetup <= 0.1 - Authentication Bypass via Account Takeover

ARMember < 3.4.8 - Unauthenticated Admin Account Takeover