
CVE-2025-48932-Invision-Community-SQLi-Exploit
Automated exploit for CVE-2025-48932, an unauthenticated blind SQLi in Invision Community <= 4.7.20, with database enumeration, credential dumping,…

Automated exploit for CVE-2025-48932, an unauthenticated blind SQLi in Invision Community <= 4.7.20, with database enumeration, credential dumping,…

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

ARMember Premium <= 7.3.1 Full Admin Account Takeover

Automated PoC exploit for CVE-2026-27886 in Strapi CMS. Performs email enumeration, password reset token exfiltration, and full admin account…

Exploit for JumpServer CVE-2023-42820 that resets admin password and chains with CVE-2023-42819 to achieve remote code execution on affected versions.

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

Proof-of-concept exploit for CVE-2025-1738 demonstrating cleartext admin password exposure in Trivision NC227WF cameras via unauthenticated local…

Exploit tool for CVE-2026-8181 targeting Burst Statistics WordPress plugin. Automates authentication bypass, user enumeration, admin account…

Python PoC exploit for CVE-2023-6329 authentication bypass in Control iD iDSecure. Reconstructs admin credentials via predictable password derivation…

Exploit for CVE-2021-27651: bypasses Pega Infinity password reset flow to reset any user's password, enabling admin login and subsequent remote code…

Scans and exploits LiteSpeed Cache privilege escalation (CVE-2024-28000) by identifying vulnerable versions, leaking hashes via debug logs, and…

Proof-of-concept exploit for CVE-2024-29868, demonstrating weak PRNG-based recovery token cracking to achieve admin account takeover in Apache…

Go-based exploit for CVE-2023-6875 that intercepts admin password reset emails, logs in, and uploads a web shell to the target server.

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

Go-based brute-force tool exploiting Bludit bruteforce mitigation bypass (CVE-2019-17240) for automated password cracking against admin login pages.