
CVE-2024-50488
Token Login <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation

Token Login <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

CVE-2021-40903

NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

CVE-2020-26061 - ClickStudios Passwordstate Password Reset Portal

Quietly Insights <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

Minterpress <= 1.0.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

User Toolkit <= 1.2.3 - Authenticated (Subscriber+) Authentication Bypass

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

Apache ShenYu 管理员认证绕过

Exploit script for CVE-2022-40684, an authentication bypass in Fortinet FortiOS, allowing unauthorized access to the admin interface.

Python exploit for CVE-2024-10924 that bypasses Two-Factor Authentication in the Really Simple SSL WordPress plugin, enabling unauthorized…

CVE-2023-47564

CVE-2021-44270

SQL injection exploit for ABO.CMS 5.8 that bypasses authentication via the tb_login parameter, granting unauthenticated admin panel access. Includes…

1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover

Accessibility by AllAccessible <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Update

Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0