
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692

Confluence Unauthorized Administrator User Addition Exploitation Script

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

Exploit for CVE-2025-23369: SAML authentication bypass in GitHub Enterprise Server via libxml2 quirks, enabling unauthorized access.

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

POC of CVE-2022-36537

CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC

cve-2022-23131

libssh CVE-2018-10933

Exploit for the CVE-2024-5806

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access…

POCs to demonstrate CVE-2026-42167 in ProFTPD

Confluence Unauthorized Administrator User Addition Exploitation Script

Reproduction environment for CVE-2025-29927, demonstrating Next.js middleware authorization bypass via the x-middleware-subrequest header. Includes…

Progress OpenEdge Authentication Bypass