
CVE-2023-51467-EXPLOIT
A PoC exploit for CVE-2023-51467 - Apache OFBiz Authentication Bypass

A PoC exploit for CVE-2023-51467 - Apache OFBiz Authentication Bypass

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to…

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

Proof-of-concept exploit for CVE-2024-41107 targeting SAML authentication bypass in Apache CloudStack versions 4.5.0–4.18.2.1 and 4.19.0.0–4.19.0.2.

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

CVE-2025-29927 lab

Fortinet announced two closely related authentication‑bypass vulnerabilities on 9 December 2025. Both flaws involve improper verification of…

Technical analysis and PoC of CVE-2026-52824: default APP_SECRET in the Kimai Docker image enabling unauthenticated login link forgery. Affects <=…

Reproduction of cve-2024-1708-connectwise_rce_reproduction

this is a modified POC of rz1027 for CVE-2026-20896

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP

A PoC exploit for CVE-2024-27198 - JetBrains TeamCity Authentication Bypass

Demonstrates CVE-2026-11116 SNMPv3 authentication bypass caused by guessable default EngineIDs, with a Python pysnmp simulation and guidance for…

Reproduces CVE-2026-5050 with a simulated Flask LDAP server and exploit script, demonstrating blind LDAP injection via unescaped filters to bypass…

CVE-2026-34348 - Draft or TODO