
CVE-2024-5324
Login/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options Update

Login/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options Update

Pedalo Connector <= 2.0.5 - Authentication Bypass to Administrator

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions including, 6.0.12. This is due to the plugin not properly…

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token…

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

AdForest <= 6.0.9 - Authentication Bypass to Admin

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password…

Change the algorithm RS256(asymmetric) to HS256(symmetric) - POC (CVE-2016-10555)

WP Quick Setup <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin/Theme Installation

A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update

Password Strength Evaluator is a tool to evaluate the strength of passwords and provide recommendations to improve their security.

CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options…

Exploit for CVE-2025-27580: A predictable token vulnerability in NIH BRICS through 14.0.0-67 allows unauthenticated users with a Common Access Card…

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

Bypass bludit mitigation login form and upload malicious to call a rev shell