


Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

PoC for CVE-2025-14340: Admin account takeover in Payara Server

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

PoC for CVE-2022-24342: account takeover via CSRF in GitHub authentication

PoC + vulnerability details for CVE-2022-25262 / JetBrains Hub single-click SAML response takeover

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

PoC exploit for CVE-2026-15038 in InfiniteWP Client WordPress plugin: bypasses authentication on Multisite, binds attacker RSA key, escalates to…

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover

Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak…

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)