
CVE-2023-2732
Perform With Massive Authentication Bypass (Wordpress Mstore-API)

Perform With Massive Authentication Bypass (Wordpress Mstore-API)

CVE-2012-2122 - MySQL Authentication Bypass

genesisQL-sqli-CVE-2026-36826

Proof-of-concept exploit for CVE-2015-7755 targeting Juniper ScreenOS backdoor authentication bypass via SSH with hardcoded root credentials.

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Quentn WP <= 1.2.8 - Unauthenticated Privilege Escalation

CrushFTP CVE-2025-31161 Exploit Tool 🔓

Relais 2FA <= 1.0 - Authentication Bypass

JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 Implementation

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

Proof-of-concept for CVE-2026-31282: Totara LMS login page access control bypass enabling unauthenticated brute-force credential attacks. Includes…

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login


Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…

CVE-2024-55374