
CVE-2021-39409
Admin account registration in Online Student Rate System

Admin account registration in Online Student Rate System

Possible Account Takeover | Brute Force Ability

Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240

Exploit for CVE-2021-29441 targeting Alibaba Nacos to add unauthorized accounts, enabling authentication bypass and unauthorized access.

Python script that tests PAN-OS devices for CVE-2025-0108 authentication bypass by sending crafted HTTP requests and analyzing responses.

Exploit for CVE-2026-18963, a critical unauthenticated account takeover in Keycloak's reset-credentials flow, chaining two bugs to bypass email…

🔴 CVE-2026-22794 - Appsmith Password Reset Account Takeover via Origin Header Injection | PoC Exploit + Nuclei Template

Exploits Kerberos reflection via Unicode normalization in Windows Active Directory to relay authentication to ADCS and MSSQL, enabling…

Proof-of-concept exploit for CVE-2026-7567, an authentication bypass in WordPress Temporary Login Plugin <= 1.0.0, enabling account takeover. For…

Technical analysis and proof-of-concept for CVE-2026-21858, an authentication bypass and RCE in n8n, demonstrating LFI, session forgery, and full…

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass in cPanel & WHM, enabling unauthenticated access to the control panel.

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt via nested PlainJWT with alg:none inside a JWE container.

Proof-of-concept for SQL injection in CodeAstro Simple Attendance Management System 1.0, demonstrating authentication bypass via crafted username…

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt via JWE-wrapped unsigned JWT, enabling privilege escalation.

Proof-of-concept exploit for CVE-2026-6274, an authentication bypass in Redline WR3200 routers allowing unauthorized password change via static…

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

Proof-of-concept for SQL injection authentication bypass in Simple Content Management System PHP, allowing unauthenticated attackers to gain admin…