
CVE-2022-23131
CVE-2022-23131 Zabbix Server SAML authentication exploit

CVE-2022-23131 Zabbix Server SAML authentication exploit

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

CVE-2026-54121(CertiGhost) without MachineAccountQuota POC

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

Zabbix Frontend Authentication Bypass Vulnerability

Technical analysis and advisory for CVE-2026-51119, a privilege escalation in Invixium IXM WEB allowing authenticated low-privilege users to create…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Vulnerability details and exploit for CVE-2021-3754

Hands-on security lab demonstrating CVE-2023-22515 — Atlassian Confluence Authentication Bypass using a simulated vulnerable environment.

PoC | NextJS Middleware 15.2.2 - Authorization Bypass

Fix without disabling Print Spooler

Provides community notes and an optional temporary hook to guard against CVE-2026-29204, a WHMCS client area addonId ownership vulnerability, with…

Jenkins plugin providing script approval workflows and Groovy sandboxing to enforce secure script execution, with ACL-aware permission checks and…

Bypass for Symantec Endpoint Protection's Client User Interface Password

Proof-of-concept exploit for CVE-2023-27350 in PaperCut NG; exploits SetupCompleted access-control flaw to bypass authentication and execute code as…

https://medium.com/@mnqazi/cve-2023-4696-account-takeover-due-to-improper-handling-of-jwt-tokens-in-memos-v0-13-2-13104e1412f3