
cve-2025-29927-nextjs
Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

Proof-of-concept for time-based blind SQL injection in a PHP admin panel. Demonstrates exploitation via unsanitized GET parameter, with mitigation…

Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload…

Exploit for CVE-2020-29204 targeting XXL-JOB distributed task scheduling framework, demonstrating remote code execution via unauthenticated access to…

Proof-of-concept exploit for CVE-2024-34832: directory traversal in CubeCart admin panel leading to remote code execution via crafted `_g` parameter…

CSRF vulnerability PoC and remediation guide for employee deactivation in an admin panel. Includes CVSS scoring, attack reproduction steps, and…

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

Exploit for SQL injection in WordPress Video Gallery plugin (version 2.3.6) via orderby parameter, enabling unauthenticated database extraction.

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

Python exploit for CVE-2026-55579, an unauthenticated RCE in Pheditor via hardcoded default credentials. Executes commands and uploads files through…

PHP-based CTF engine for hosting capture-the-flag competitions with arbitrary challenges, scoreboards, hints, team management, and admin console.…

Open-source ransomware simulator with AES-256 file encryption, system lockdown, and multi-threaded encryption. Includes a web admin interface for key…

Curated RDP Wireshark captures illustrating Kerberos, NTLM, smartcard, NLA, Restricted Admin, Credential Guard, RD Gateway, and clipboard redirection…

⚡ Create infinite UAC prompts forcing a user to run as admin ⚡

Rust proof-of-concept that exploits an authentication bypass in DVR/NVR devices to dump admin credentials via vulnerable login endpoints.

Simulates camera permission phishing attacks for security awareness training, featuring realistic templates, an admin dashboard, and real-time alerts…

Exploit for CVE-2023-22515 in Atlassian Confluence that creates a new admin user and deploys a web-based shell plugin for command execution on the…