
CVE-2026-41940-analysis
Technical analysis of the cPanel/WHM auth bypass

Technical analysis of the cPanel/WHM auth bypass

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

Python exploit script for CVE-2024-1709, an authentication bypass vulnerability in ConnectWise ScreenConnect. Adds a new administrative user to the…

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions including, 6.0.12. This is due to the plugin not properly…

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password…

PoC of the CVE-2026-29000

CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass

Exploit script for CVE-2022-23131 that bypasses Zabbix SSO authentication by forging JWT tokens, enabling unauthorized admin access to the monitoring…

Exploit script for CVE-2022-40684, an authentication bypass in Fortinet FortiOS, allowing unauthorized access to the admin interface.

A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Temporary WordPress plugin requiring authentication for the Core REST Batch API endpoint to mitigate the wp2shell vulnerability chain…

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

Proof-of-concept exploit for CVE-2025-29927, demonstrating authentication bypass in Next.js middleware via the x-middleware-subrequest header, with…

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

FreeRDP is a free remote desktop protocol library and clients