
CVE-2026-8809
Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

The ultimate WinRM shell for hacking/pentesting

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

A tool that implements the Golden SAML attack

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

C# tool for Kerberos protocol manipulation, enabling ticket requests, delegation (S4U), kerberoasting, AS-REP roasting, and golden/silver ticket…

Proof-of-concept exploit for CVE-2024-29855, an authentication bypass in Veeam Recovery Orchestrator. Includes JWT token spraying and technical root…

A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-saml

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

Proof-of-concept exploits for Apache OfBiz vulnerabilities (CVE-2024-32113, CVE-2024-36104, CVE-2024-38856) demonstrating remote code execution and…

Proof-of-concept for CVE-2026-23009 demonstrating unauthenticated DICOM image injection into vulnerable PACS servers using pynetdicom, with a…

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

Exploit for authentication bypass in WP Time Capsule plugin (<1.21.16). Steals admin cookie and uploads webshell.

IBM Langflow Unauthenticated RCE via Auto-Login Bypass