
CVE-2023-20198-Exploit
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI

Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI

NSE plugin for Nmap that scans a DotNetNuke (DNN) web application for an Administration Authentication Bypass vulnerability (CVE-2015-2794, EDB-ID:…

Web app authorisation coverage scanning

The Symfony PHP framework


Authorization Bypass in Next.js Middleware

Next.js PoC for CVE-2025-29927

Bypass del MFA en WordPress con el plugin Really Simple Security instalado entre las versiones 9.0.0 – 9.1.1.1.

CVE Reproduction: cve-2024-0012_9474-panos_authbypass_reproduction

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

Python script for CVE-2024-0012 / CVE-2024-9474 exploit


The full repo of all the labs available as part of the benchmark

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

CVE-2024-55215


CVE-2025-64446

Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.