
CVE-2023-31704
Proof-of-concept exploit for CVE-2023-31704: Incorrect access control in Sourcecodester Online Computer and Laptop Store 1.0 allows remote privilege…

Proof-of-concept exploit for CVE-2023-31704: Incorrect access control in Sourcecodester Online Computer and Laptop Store 1.0 allows remote privilege…

Documentation for CVE-2024-56116: a Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allowing remote attackers to create an…

Macally WIFISD2

Bypass bludit mitigation login form and upload malicious to call a rev shell

Proof-of-concept for CVE-2020-24030: weak token expiration in ForLogic Qualiex v1/v3 enabling remote unauthenticated privilege escalation and…

Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

Vertical Privilege Escalation via Session Storage by Amjad Ali (CVE-2023-43317)

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

Token Login <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation

Bypass for Symantec Endpoint Protection's Client User Interface Password

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

Proof-of-concept exploit for CVE-2023-27350 in PaperCut NG; exploits SetupCompleted access-control flaw to bypass authentication and execute code as…

PoC for CVE-2023-32749 affecting Pydio Cells

Minterpress <= 1.0.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

Quietly Insights <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

Accessibility by AllAccessible <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Update

Agency Toolkit <= 1.0.23 - Missing Authorization to Unauthenticated Arbitrary Options Update

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162030) in Copilot, involving user ID switching that could lead to…