
CVE-2026-55040
Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Python exploit for Veeam Backup Enterprise Manager authentication bypass (CVE-2024-29849) with SAML assertion injection, callback server, and…

Authentication bypass exploit for cPanel/WHM CVE-2026-41940 using CRLF injection to gain root WHM access. Features version detection, proxy support,…

Proof-of-concept exploit for CVE-2023-2986, an authentication bypass in Abandoned Cart Lite for WooCommerce, allowing account takeover via cart ID…

Python PoC for CVE-2024-36042 authentication bypass in Silverpeas < 6.3.5. Features version detection, multi-threaded user enumeration, message…

Proof-of-concept exploit for CVE-2026-44595 demonstrating unauthorized user enumeration via missing authorization checks in YAMCS IAM API endpoints.

Forti CVE-2022-40684 enumeration script built in Rust

Automated auth bypass exploit for CVE-2025-0316 targeting WordPress WP Directorybox Manager. Features user enumeration, proxy support,…

Python-based WordPress author enumeration and login brute-force tool for penetration testing.

Exploit for Keycloak CVE-2026-18963 enabling unauthenticated account takeover via reset-credentials bypass. Includes safe detection, non-destructive…