
CVE-2020-7378
Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

Exploit script for CVE-2017-7921 targeting vulnerable IP cameras. Retrieves admin credentials via config decryption and enables automated snapshot…

Exploit tool for CVE-2023-2437 targeting UserPro <= 5.1.1 authentication bypass, allowing attackers to gain admin access and create new…

Exploit script for CVE-2025-3102 targeting SureTriggers WordPress plugin (≤ v1.0.78). Detects vulnerable versions, exploits via REST API, and creates…

Proof-of-concept for CVE-2022-45599: PHP type juggling vulnerability in Aztech WMB250AC router login.php allowing admin authentication bypass via…

Python exploit for CVE-2019-19609 targeting Strapi CMS 3.0.0-beta.17.4. Resets admin password and executes remote commands via JWT token manipulation.

Proof-of-concept exploit for CVE-2024-57698 disclosing admin MD5 password hash via unauthenticated access to the /user/list endpoint in ModernWMS…

Proof-of-concept for CVE-2023-37755: hardcoded admin credentials (admin/admin) in i-doit Pro 25 and below, enabling unauthorized admin login via the…

Hicip IP admin password reset script using CVE-2020-9529. This is made for educational purposes only of course.

Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

Unauthenticated Privilege Escalation to Administrator via Role Form Field

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…