
ADCSDevilCOM
A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using…

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using…

OAuth Request Crafter

Modifed ver of the original exploit to save some times on password reseting for unprivileged user

Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor…

Exploit script for CVE-2024-1708 and CVE-2024-1709 in ConnectWise ScreenConnect, enabling authentication bypass and remote code execution with user…

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction

Authentication Bypass for FreeScout End-User Portal

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token…

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

Functional exploit for CVE-2025-29927, a critical Next.js middleware authorization bypass. Sends crafted HTTP requests with the…

POCs to demonstrate CVE-2026-42167 in ProFTPD

WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)

CVE-2025-29927 Proof of Concept

a plugin that protects your wp site from the CVE-2017-8295 vulnerability

POC for CVE-2026-30950 which allows session hijacking in AutoGpt