
CVE-2024-50477
Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

Proof-of-concept exploit for CVE-2023-27350 authentication bypass in PaperCut MF/NG, allowing unauthenticated interaction with vulnerable print…

Proof-of-concept for CVE-2020-24030: weak token expiration in ForLogic Qualiex v1/v3 enabling remote unauthenticated privilege escalation and…

Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated…

CVE-2023-47564

Accessibility by AllAccessible <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Update

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

User Toolkit <= 1.2.3 - Authenticated (Subscriber+) Authentication Bypass

CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass

SQL injection exploit for ABO.CMS 5.8 that bypasses authentication via the tb_login parameter, granting unauthenticated admin panel access. Includes…

PoC for CVE-2023-32749 affecting Pydio Cells

Proof-of-concept exploit for CVE-2024-10924, an authentication bypass vulnerability in the Really Simple Security WordPress plugin, enabling MFA…

Bypass for Symantec Endpoint Protection's Client User Interface Password

1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover

Proof-of-concept exploit for CVE-2023-27350 in PaperCut NG; exploits SetupCompleted access-control flaw to bypass authentication and execute code as…

Python exploit for CVE-2024-10924 that bypasses Two-Factor Authentication in the Really Simple SSL WordPress plugin, enabling unauthorized…