
CVE-2025-14340
PoC for CVE-2025-14340: Admin account takeover in Payara Server

PoC for CVE-2025-14340: Admin account takeover in Payara Server

Meetup <= 0.1 - Authentication Bypass via Account Takeover

Proof-of-concept exploit for an unauthenticated OTP password reset vulnerability in WordPress, enabling attackers to reset a victim's password…

Proof-of-concept exploit for CVE-2025-9485 demonstrating authentication bypass via unsigned JWT (alg: none) in a WordPress-like OAuth flow. Includes…

Proof-of-concept exploit for CVE-2025-12028 demonstrating CSRF-based OAuth token theft in WordPress IndieAuth plugin, enabling unauthorized API…

Proof-of-concept exploit for CVE-2022-23131, an SSO authentication bypass vulnerability in Zabbix. Allows unauthorized access to Zabbix frontend.

ARMember < 3.4.8 - Unauthenticated Admin Account Takeover

Applications that reproduce CVE-2021-22119

PoC exploit for CVE-2024-8682, enabling unauthenticated user registration on JNews WordPress themes via crafted AJAX requests.

CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Generates a signed session cookie to gain unauthorized admin access.

Online Discussion Forum Site 1.0 - Account Takeover

Vulnerability check script for CVE-2024-37393 (SecurEnvoy MFA 9.4.513)

eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion

Proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML SSO authentication bypass vulnerability. Includes environment setup and a Go-based checker…

CVE-2019-14830

Proof-of-concept exploit for CVE-2023-47504 targeting Elementor WordPress plugin. Requires subscriber credentials and wp-config.php access to delete…

An implementation of CVE-2015-3306