
CVE-2025-42957-SAP-S-4HANA-Under-Siege
CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full…

CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full…

Python PoC for CVE-2026-8181, a critical authentication bypass in Burst Statistics WordPress plugin. Includes exploit automation, bulk scanning, and…

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

Automated exploit and mass scanner for CVE-2026-5118, an unauthenticated privilege escalation in WordPress Divi Form Builder <=5.1.2, enabling admin…

Proof-of-concept exploit for CVE-2026-7654 targeting PHP object injection in Admin Columns WordPress plugin to achieve remote code execution.

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

Exploit for CVE-2021-26855 (ProxyLogon) targeting Microsoft Exchange. Creates a new admin user and establishes a reverse shell for post-exploitation…

Proof-of-concept exploit for CVE-2024-55591, enabling unauthenticated WebSocket CLI access to FortiOS devices, with interactive shell and admin…

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…

Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

Exploit for CVE-2025-10352. Admin account creation on Melis Platform Framework

Exploit for CVE-2026-2406 targeting Terrminus Authentication Gateways, using temporal dispersion to bypass fingerprinting and behavioral AI,…

Python exploit for CrushFTP CVE-2025-54309 XML race condition vulnerability. Creates admin user via concurrent requests with configurable payload…

Technical analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence allowing…