
CVE-2024-7593
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker…

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker…

Unauthenticated SQL injection exploit for ABO.CMS 5.8 enabling login bypass and database takeover via the tb_login parameter.

Exam Matrix <= 1.5 - Unauthenticated Privilege Escalation

Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

Proof-of-concept for CVE-2023-37755: hardcoded admin credentials (admin/admin) in i-doit Pro 25 and below, enabling unauthorized admin login via the…

Simple Dashboard <= 2.0 - Unauthenticated Privilege Escalation

Animation Addons for Elementor Pro <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

Python script that tests PAN-OS devices for CVE-2025-0108 authentication bypass by sending crafted HTTP requests and analyzing responses.

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

CWE-287: Improper Authentication in parse-community parse-server

Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass

PoC, Dockerfile playground and root cause from patch diff analysis.

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).