
CVE-2025-492030
Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker…

Fix for CVE-2018-15473

Proof-of-concept for CVE-2018-0114, demonstrating unauthenticated remote token re-signing vulnerability in versions before 0.11.0.

Exploit for CVE-2024-2257: bypasses password policy on Digisol DG-GR1321 routers via crafted HTTP request, enabling unauthorized access for…

Golang implementation of CVE-2019-17662 TinyVNC Arbitrary File Read leading to Authentication Bypass Exploit

Python script using Impacket to test for the Zerologon vulnerability (CVE-2020-1472) by attempting Netlogon authentication bypass against domain…

Exploit for CVE-2024-10924, a critical authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1). Allows…

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

bypass SAML authentication on GitHub Enterprise

Test tool for CVE-2020-1472

Python script to test domain controllers for CVE-2020-1472 (Zerologon) using Impacket. Performs Netlogon authentication bypass detection with minimal…

Animation Addons for Elementor Pro <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

Mitel MiCollab 企业协作平台 任意文件读取漏洞(CVE-2024-41713)由于Mitel MiCollab软件的 NuPoint 统一消息 (NPM) 组件中存在身份验证绕过漏洞,并且输入验证不足,未经身份验证的远程攻击者可利用该漏洞执行路径遍历攻击,成功利用可能导致未授权访问、破…

CVE-2024-37085 unauthenticated shell upload to full administrator on domain-joined esxi hypervisors.

Python script for SSH username enumeration using timing-based analysis to identify valid accounts on a target server.

Proof-of-concept for CVE-2025-30144: JWT issuer validation bypass in fast-jwt library allowing attackers to forge tokens with array-based iss claims.
