
CVE-2026-39275
CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS

CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

Exploit scanner for CVE-2025-25347, an unauthenticated RCE in QingLong Panel, allowing arbitrary command execution and full server takeover.

Proof-of-concept exploit for CVE-2025-6264 in Velociraptor, demonstrating privilege escalation via missing permission checks to redirect clients to a…

Python-based scanner that tests WordPress sites for CVE-2025-4606, a privilege escalation vulnerability in the Sala theme allowing unauthenticated…

Proof-of-concept exploit for CVE-2025-58434, demonstrating unauthenticated account takeover in Flowise via leaked password reset tokens. Includes…

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

CVE-2020-13654 - XWiki Platform < 12.8 - Stored XSS → CSRF → Account Takeover

PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials,…

Detailed CVE-2024-55187 advisory with proof-of-concept for a remote code execution vulnerability in phpIpam, exploiting path poisoning and PHAR file…

CVE disclosure for stored cross-site scripting (XSS) in SWISH Prolog up to v2.2.0, enabling arbitrary code execution and account takeover via crafted…

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Proof-of-concept exploit for CVE-2024-44000 demonstrating unauthorized account takeover in LiteSpeed. Intended for educational security research and…