
CVE-2026-21017-LDAP-Anonymous-Bind-Privilege-Escalation
Python proof-of-concept for LDAP anonymous bind privilege escalation, simulating insecure ACLs to create admin users via unauthenticated LDAP binds.

Python proof-of-concept for LDAP anonymous bind privilege escalation, simulating insecure ACLs to create admin users via unauthenticated LDAP binds.

This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their…

Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php

Alibab-Nacos-Unauthorized-Reset PWD

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

a plugin that protects your wp site from the CVE-2017-8295 vulnerability

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

Login/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options Update

WP Quick Setup <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin/Theme Installation

Square <= 2.0.0 - Missing Authorization via activate_plugin

HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update

Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)

Fix without disabling Print Spooler

Proof-of-concept exploit for CVE-2023-31704: Incorrect access control in Sourcecodester Online Computer and Laptop Store 1.0 allows remote privilege…