
CVE-2022-32532
Apache Shiro CVE-2022-32532

Apache Shiro CVE-2022-32532

CVE-2025-60188 Atarim Plugin Exploit

PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)

A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.

A small, auditable, terminating, deterministic micro-policy engine

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

Bash PoC for Fortinet Auth Bypass - CVE-2022-40684

Proof-of-concept exploit for OctoberCMS authentication bypass (CVE-2021-32648), demonstrating unauthorized access and providing a working PoC for…

Automated exploit for CVE-2026-27944 in Nginx UI: downloads and decrypts backups, extracts secrets, and creates rogue admin accounts for full…

Authorization Bypass in Next.js Middleware

CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]

A new open-source tool to quickly audit SAP permissions.

IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery

Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account…

Exploit for CVE-2020-3952 in vCenter 6.7 https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/

Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth

Package ldapserver implements LDAP Server

[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass