
CVE-2025-70829
An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…

Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation

CVE-2025-40554 Exploitation

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

Scripts to detect and exploit CVE-2024-9014 OAuth2 authentication bypass in pgAdmin 4, including vulnerability checking and OAuth2 configuration…

CrushFTP CVE-2025-31161 Exploit Tool 🔓

A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.

proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198

Python exploit for CVE-2025-31161, an authentication bypass in CrushFTP. Retrieves user lists via crafted CrushAuth and AWS4-HMAC-SHA256 headers.…

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

CVE Reproduction: cve-2025-24472-fortinet_authbypass_reproduction

Proof-of-concept exploit for CVE-2025-22963, a CSRF vulnerability in Teedy v1.11 allowing account takeover via user information change endpoint.

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

Proof-of-concept exploit for CVE-2020-1958, an LDAP injection vulnerability in Apache Druid 0.17.0, enabling user enumeration and LDAP attribute…

CVE-2026-67276 MikroTik RouterOS SSH Authentication Bypass Exploit

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

Authentication Bypass PoC for CVE-2025-2825 – Exploiting CrushFTP 10.x