
Strapi-CVE-2019-1881
Proof of concept for Strapi CVE-2019-18818 - Unauthenticated Password Reset Vulnerability / Privilege Escalation

Proof of concept for Strapi CVE-2019-18818 - Unauthenticated Password Reset Vulnerability / Privilege Escalation

PoC for CVE-2021-34646

An issue in Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

PoC for testing if a target is vulnerable to RCE

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass vulnerability. Enables session hijacking and unauthorized admin access.

Proof-of-concept CSRF exploit for Casdoor's `/api/set-password` endpoint (CVE-2023-34927), enabling unauthorized password changes via cross-site POST…

CVE-2025-7892

CVE-2025-8517 proof-of-concept demonstrating session fixation in Vvveb CMS v1.0.6.1, enabling full administrative account takeover via arbitrary…

Proof-of-concept exploit for CVE-2025-22963, a CSRF vulnerability in Teedy v1.11 allowing account takeover via user information change endpoint.

LiquidPoll – Advanced Polls for Creators and Brands <= 3.3.68 - Missing Authorization via activate_addon

Exploit for CVE-2020-15367: brute-force authentication attack against Venki Supravizio BPM 10.1.2 login page, leveraging user enumeration to gain…

CVE-2021-42665 - SQL Injection authentication bypass vulnerability in the Engineers online portal system.

LifterLMS <= 3.34.5 - Unauthenticated Options Import

CVE-2025-29927: Next.js Middleware Exploit

Proof-of-concept exploit for CVE-2020-29667 targeting insufficient session expiration and a hardcoded cookie value in Lan ATMService M3 ATM…

Unauthenticated SQL injection exploit for ABO.CMS 5.8 enabling login bypass and database takeover via the tb_login parameter.

Bludit 3.9.2 auth bruteforce bypass

Exploit for CVE-2024-2257: bypasses password policy on Digisol DG-GR1321 routers via crafted HTTP request, enabling unauthorized access for…