
CVE-2025-29927
Proof-of-concept exploit for CVE-2025-29927, demonstrating authentication bypass in Next.js middleware via the x-middleware-subrequest header, with…

Proof-of-concept exploit for CVE-2025-29927, demonstrating authentication bypass in Next.js middleware via the x-middleware-subrequest header, with…

YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action

pam_pkcs11 Bugfix

Exploit for CVE-2021-29156

Proof-of-concept exploit for CVE-2025-29927 that adds x-middleware-subrequest to bypass Next.js middleware authentication checks.

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

Discource POC

WordPress CVE-2024-10924 Exploit for Really Simple Security plugin

WebUI for AAA

Technical documentation and proof-of-concept for CVE-2025-20343, a high-severity denial-of-service vulnerability in Cisco ISE allowing…

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

Proof-of-concept exploit for CVE-2024-47533, an unauthenticated authentication bypass in Cobbler's XMLRPC API leading to remote code execution via…

Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI

LibSSH authentification bypass

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.

Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0

CVE-2025-31161

Fix without disabling Print Spooler