
CVE-2026-41940
Automated exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM, allowing unauthorized administrative access to vulnerable servers.

Automated exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM, allowing unauthorized administrative access to vulnerable servers.

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Authentication bypass exploit for CVE-2026-32746 targeting legacy Telnet servers, with defensive guidance and Go-based implementation for authorized…

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

Python script to exploit the OWASSRF + TabShell chain on vulnerable Microsoft Exchange servers, leveraging Kerberos authentication for command…

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

UnboundID LDAP SDK for Java

Proof-of-concept exploit for CVE-2026-50338: cross-issuer authentication bypass in Spring Cloud Azure B2C resource servers. Demonstrates token…

Python-based TLS session reuse exploit tester that checks for authentication bypass vulnerabilities in misconfigured servers requiring client…

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

🔐 Lightweight CLI utility designed to synchronize SSH public keys from remote URLs into local authorized_keys files

Proof-of-concept exploit for CVE-2023-27350 authentication bypass in PaperCut MF/NG, allowing unauthenticated interaction with vulnerable print…

Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and…

🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

Authentication, authorization, traceability and auditability for SSH accesses.