
CVE-2021-36460
Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

Simulates a Matter commissioning code brute-force attack (CVE-2026-23005) using Python to demonstrate missing rate limiting and lockout on 8-digit…

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

Exploit the Redash weak secret key vulnerability (GHSA-g8xr-f424-h2rv) to generate password reset links for any user, enabling account takeover…

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

Proof-of-concept exploit for CVE-2024-10508: unauthenticated privilege escalation via password recovery bypass in RegistrationMagic WordPress plugin…

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

ARMember Premium <= 7.3.1 Full Admin Account Takeover

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak…

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

Public Disclosure

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

Python exploit for CVE-2023-7028, abusing GitLab password reset poisoning to take over accounts including administrators via crafted email requests.

Proof-of-concept exploit for CVE-2023-34732 demonstrating authenticated function abuse in Flytxt NEON-dX to brute-force and reset user passwords,…