
CVE-2026-8793
Technical CVE write-up detailing missing brute-force protection in a web admin login form, with PoC reproduction, attack-chain context, and…

Technical CVE write-up detailing missing brute-force protection in a web admin login form, with PoC reproduction, attack-chain context, and…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Automated exploit for CVE-2025-48932, an unauthenticated blind SQLi in Invision Community <= 4.7.20, with database enumeration, credential dumping,…

Fast WordPress default credential checker: uses common username/password pairs to detect weak admin accounts.

Multithreaded WordPress brute-force tool that tests admin credentials against a list of sites using configurable threads, timeouts, and verbose…

Proof-of-concept for CVE-2023-37755: hardcoded admin credentials (admin/admin) in i-doit Pro 25 and below, enabling unauthorized admin login via the…

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

Exploit for CVE-2021-27651: bypasses Pega Infinity password reset flow to reset any user's password, enabling admin login and subsequent remote code…

Python exploit for CVE-2020-1472 (Zerologon) that checks, exploits, and restores domain controller machine account passwords, enabling DCSync and…

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

Proof-of-concept exploit for CVE-2024-29868, demonstrating weak PRNG-based recovery token cracking to achieve admin account takeover in Apache…

Proof-of-concept exploit for CVE-2024-57698 disclosing admin MD5 password hash via unauthenticated access to the /user/list endpoint in ModernWMS…

Exploit tool for CVE-2026-8181 targeting Burst Statistics WordPress plugin. Automates authentication bypass, user enumeration, admin account…

ARMember Premium <= 7.3.1 Full Admin Account Takeover

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

Automated PoC exploit for CVE-2026-27886 in Strapi CMS. Performs email enumeration, password reset token exfiltration, and full admin account…

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…