
CVE-2024-45409
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit

Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory…

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

CVE-2019-19033 description and scripts to check the vulnerability in Jalios JCMS 10 (Authentication Bypass)

This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their…

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

Exploit for CVE-2025-27580: A predictable token vulnerability in NIH BRICS through 14.0.0-67 allows unauthenticated users with a Common Access Card…

Exploit for CVE-2024-48322 targeting RunCodes instances. Retrieves user passwords via email inbox after authentication bypass, requiring only any…

Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…

pam_pkcs11 Bugfix

Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…