
CVE-2025-1739
0day PoC for CVE-2025-1739

0day PoC for CVE-2025-1739

Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…

Redacted cPanel/WHM authentication bypass analysis and authorized checker

The goal of Axiom is to provide a completely anonymous, decentralized, and censorship-resistant social media platform. To make this possible, the…

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

CVE-2026-35616

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

Improved Metasploit module for CVE-2013-6117 (Dahua DVR authentication bypass)

Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation

CrushFTP AS2 Authentication Bypass

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

Wechat Social login <= 1.3.0 - Authentication Bypass

Proof-of-concept exploit for CVE-2025-40554, an authentication bypass in SolarWinds Web Help Desk. Includes Nuclei template and Python exploit for…

Exploit for Dahua IPC/VTH/VTO devices that bypasses identity authentication by sending crafted malicious packets, allowing unauthorized access.

Exploit for CVE-2024-48322 targeting RunCodes instances. Retrieves user passwords via email inbox after authentication bypass, requiring only any…