
FreeRDP
FreeRDP is a free remote desktop protocol library and clients

FreeRDP is a free remote desktop protocol library and clients

WireGuard-based zero-trust access platform providing secure, peer-to-peer remote access with granular policy controls, SSO authentication, and audit…

Zero-click authentication bypass exploit for Android ADB Wireless Debugging (CVE-2026-0073). Provides interactive shell, command execution, and…

CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…

Silent;Call — Pre-authentication remote root on Cisco CUCM 15.x (CVSS 10.0)

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

Disclosure of CVE-2020-24030: weak token expiration in ForLogic Qualiex enabling remote privilege escalation and sensitive data access through token…

Proof-of-concept exploit for authentication bypass in Senior Rubiweb 6.2.34, enabling admin access to sensitive information via crafted URLs.

Unauthenticated administrator takeover exploit for CVE-2026-66012 using MCP missing authorization to exfiltrate credentials and achieve remote code…

CVE Reproduction: cve-2024-0012_9474-panos_authbypass_reproduction

CVE-2026-55584 — phpSysInfo IP Allowlist Bypass

Exploit for BUK-TS authentication bypass and remote code execution, with steps to intercept responses and manipulate userid to gain unauthorized…

Vulnerability: Logic flow weakness in Remote Access and Mobile Access

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

CVE-2026-23813 — AOS-CX pre-auth bypass via nginx regex. Detection script, bypass demo, config-disclosure PoC, and IDS rules.

POCs to demonstrate CVE-2026-42167 in ProFTPD

Educational Docker lab demonstrating CVE-2026-39987, a pre-auth RCE via WebSocket authentication bypass in marimo, with exploit script and patch…