
Cve-2026-27944-Tools-Exploit
Suka suka lah

Suka suka lah

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…


An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

This vulnerability allows an attacker to bypass the credentials brute-force prevention mechanism of the Embedded Web Server (interface) of more than…

CVE-2023-24055 PoC (KeePass 2.5x)

bypass all stages of the password reset flow

A vulnerability can allow an attacker to guess the automatically generated development mode secret token.

CVE-2020-25749

lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…

Automated Linux evil maid attack