
Flowise-CVE-2025-58434-Chain-59528
FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE.…

FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE.…

Exploit and scanner for CVE-2026-24061, a telnetd authentication bypass that grants root shell via crafted USER environment variable. Includes Docker…

Docker-based exploit environment for CVE-2012-2122 MySQL/MariaDB authentication bypass vulnerability. Demonstrates password comparison flaw allowing…

Dockerized exploit environment for CVE-2024-10924, an authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1)…

Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

PoC, Dockerfile playground and root cause from patch diff analysis.

This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.

This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.

Exploit for Red Hat / GlusterFS CVE-2018-1088 & CVE-2018-1112, featured @ DEFCON 26, Las Vegas!

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Local lab simulating CVE-2026-29000 JWT/JWE authentication bypass in pac4j-jwt. Provides login, token forging, and dashboard APIs for practicing web…

Proof-of-concept exploit for CVE-2022-4361, a reflected XSS vulnerability in Keycloak's OIDC authentication flow, with Docker-based test environment…

Proof-of-concept exploit for CVE-2019-0217, a race condition in Apache HTTP Server's mod_auth_digest allowing authentication bypass. Includes…

this is a modified POC of rz1027 for CVE-2026-20896

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

Pre-built vulnerable CrushFTP 10.8.0 binary for authorized penetration testing of CVE-2025-31161, an unauthenticated authentication bypass…

Vulnerability in GNU InetUtils telnetd Enables Remote Root Access