
cve-2026-32699-facturascripts-nick-bypass
Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt. Forges JWT tokens to gain admin access to protected endpoints.

Proof of Concept for CVE-2025-31161 / CVE-2025-2825

CVE-2021-37580的poc

cve-2022-23131

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

Docker-based lab for CVE-2024-27198 TeamCity authentication bypass. Includes exploit reproduction, IoC hunting with Sigma/Suricata rules, and…

Python POC, Exploit for CVE-2026-29000

CVE-2025-41646 - Critical Authentication bypass

CVE-2025-31161

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Python proof-of-concept for LDAP anonymous bind privilege escalation, simulating insecure ACLs to create admin users via unauthenticated LDAP binds.

CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing

Exploit for CVE-2024-47533, a critical authentication bypass in Cobbler XML-RPC API, granting unauthenticated admin access for educational security…

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to…

Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287