
CVE-2026-27886-check
Detect whether a Strapi instance is vulnerable to CVE-2026-27886 (unauthenticated boolean-oracle exfiltration of administrator secrets).

Detect whether a Strapi instance is vulnerable to CVE-2026-27886 (unauthenticated boolean-oracle exfiltration of administrator secrets).

Unauthenticated administrator takeover exploit for CVE-2026-66012 using MCP missing authorization to exfiltrate credentials and achieve remote code…


PoC for CVE-2025-14340: Admin account takeover in Payara Server

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

Proof-of-concept for reflected XSS in Cudy LT400 web interface, demonstrating session cookie theft and admin takeover via crafted requests.

Proof-of-concept for CVE-2025-14221: Stored XSS in SourceCodester Online Banking System 1.0 via unsanitized First Name field, enabling session…

Critical vulnerability report detailing zero-day Remote Debugging Port exposure in Discord macOS client leading to account takeover, spyware, worm…

Proof-of-concept exploit demonstrating unauthenticated CSRF-based account takeover via reflected DOM-XSS in BigTreeCMS v4.4.14 admin panel.

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Proof-of-concept for CVE-2021-39377, a SQL injection vulnerability in openSIS 8.0 via the username parameter, enabling database takeover through…

Proof-of-concept exploit for reflected XSS in Trend Micro Deep Discovery Inspector 3.8, enabling CSRF bypass and admin account takeover via…

Proof-of-concept for CVE-2024-40492: stored XSS vulnerability in heartbeat.chat leading to account takeover. Includes reproduction steps and impact…

Proof-of-concept for reflected XSS in Cudy LT400 web interface, demonstrating session cookie theft and admin takeover via crafted requests.

Proof-of-concept for reflected XSS in Cudy LT400 web interface, demonstrating session cookie theft and admin takeover via crafted requests.

Proof-of-concept exploit for CVE-2026-7567, an authentication bypass in WordPress Temporary Login Plugin <= 1.0.0, enabling account takeover. For…

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

Proof-of-concept exploit for CVE-2026-18963, a critical Keycloak reset-credentials bypass enabling unauthenticated account takeover. Includes lab…