
CVE-2025-66204
Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

CTF lab and exploit toolkit for CVE-2026-29000, a pac4j-jwt JWE authentication bypass. Includes vulnerable Flask target, token forging library,…

Proof-of-concept exploit for CVE-2025-58434, demonstrating unauthenticated account takeover in Flowise via leaked password reset tokens. Includes…

Local lab simulating CVE-2026-29000 JWT/JWE authentication bypass in pac4j-jwt. Provides login, token forging, and dashboard APIs for practicing web…

CVE-2026-5229: Form Notify Auth Bypass via LINE OAuth Callback (CVSS 9.8)


Docker-based lab demonstrating CVE-2026-44338 authentication bypass in PraisonAI's legacy Flask API. Includes vulnerable and patched services with…


Python verification script for CVE-2026-41940, an authentication bypass in cPanel & WHM, enabling authorized defensive validation and patching…

Exploitation de CVE-2022-26923


Research on CrushFTP AS2 authentication bypass allowing unauthenticated admin access. Includes PoC scripts, detection rules, and technical analysis…

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

Demonstrates CVE-2025-22235 Spring Boot authentication bypass via EndpointRequest.to() misconfiguration. Includes environment setup, reproduction…

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 authentication bypass via middleware WAF evasion. Designed for security…

Academic exploit implementation for CVE-2018-10933, a libssh authentication bypass vulnerability, with a detailed report and Shodan search…

Pre-authenticated remote code execution exploit for Telerik Report Server (CVE-2024-4358/CVE-2024-1800) with authentication bypass and…

Proof-of-concept exploit for CVE-2023-46449: IDOR in Sourcecodester inventory management system v1.0 password change function enabling remote account…