
CVE-2026-60206
CVE-2026-60206

CVE-2026-60206

TorChat - Secure, private, and anonymous peer-to-peer chat over the Tor network

Authentication Bypass Vulnerability Apache OFBiz < 18.12.10.

CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

CVE-2026-29000 - pac4j-jwt (< 4.5.9 / < 5.7.9 / < 6.3.3) JwtAuthenticator authentication bypass PoC

PoC for CVE-2021-26088 written in PowerShell

Automated CVE-2022-26923 Exploitation (Certifried)

CVE-2026-46376 - FreePBX Unauthenticated UCP Access via Hard-Coded Credentials

CVE-2026-5229: Form Notify Auth Bypass via LINE OAuth Callback (CVSS 9.8)

CVE-2021-29441 - Nacos Authentication Bypass

CVE-2026-46490 — samlify <2.13.0 SAML AttributeValue XML injection -> signed-assertion privilege escalation. Self-contained PoC, verified e2e.

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

An LDAP injection vulnerability exists in org.yamcs.security.LdapAuthModule. The username parameter is inserted directly into LDAP search filters…

Exploitability PoC for CVE-2026-43515 (Apache Tomcat constraint bypass).

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

Reproduction lab for CVE-2025-29927 — Next.js middleware authorization bypass (CVSS 9.1)

Bypass Authentication