
Blackash-CVE-2025-4322
CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.


WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment


eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

CVE-2025-65427: Missing rate limiting in Dbit N300 T1 Pro router login API allows brute-force attacks

Public Disclosure


CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631