
CVE-2024-5326-Poc
Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

POC of CVE-2022-36537

Exploit script for CrushFTP authentication bypass (CVE-2025-2825) using crafted Authorization header and CrushAuth cookie to gain unauthorized access.

AdForest <= 6.0.9 - Authentication Bypass to Admin

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Boundary enables identity-based access management for dynamic infrastructure.

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

TeamCity CVE-2023-42793 exploit written in Rust

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

PoC | NextJS Middleware 15.2.2 - Authorization Bypass

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.

PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes…

CVE-2025-29927: Next.js Middleware Bypass Vulnerability

Wechat Social login <= 1.3.0 - Authentication Bypass

JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie

GNU telnetd service from GNU InetUtils authentication-bypass

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…