
CVE-2023-22515
Detailed analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Data Center…

Detailed analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Data Center…

Proof-of-concept exploit for CVE-2023-40000 targeting WordPress LiteSpeed Cache plugin versions < 5.7.0.1. Supports check and attack modes, with XSS…

Python exploit for CVE-2022-32199, enabling authenticated admin users to delete arbitrary files on ScriptCase <= 9.9.008 via directory traversal.

Proof-of-concept exploit for CVE-2024-27956, a SQL injection in ValvePress Automatic WordPress plugin. Creates admin user and enables remote code…

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

AdForest <= 6.0.9 - Authentication Bypass to Admin

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password…

Python exploit script for CVE-2021-22911 targeting Rocket.Chat admin password reset via unauthenticated user registration. Automates exploitation…

Proof-of-concept for CVE-2020-24033: Cross-Site Request Forgery on fs.com S3900 24T4S switch allows unauthenticated admin account creation via…

Exploit script for CVE-2022-23131 that bypasses Zabbix SSO authentication by forging JWT tokens, enabling unauthorized admin access to the monitoring…

Proof-of-concept exploit for reflected XSS in Trend Micro Deep Discovery Inspector 3.8, enabling CSRF bypass and admin account takeover via…

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session…

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

Automated exploit script for CVE-2023-42793 targeting TeamCity, enabling token manipulation and admin user creation for penetration testing.

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…

Proof-of-concept exploit for CVE-2026-20131, a pre-authentication RCE in Cisco Catalyst SD-WAN Controller and Manager, enabling admin access and…

Proof-of-concept demonstrating stored XSS in Appsmith Table Widget leading to vertical privilege escalation and full admin takeover via XSS-to-CSRF…

Exploits Zabbix SQL injection (CVE-2024-42327) to extract admin session and execute commands via API, achieving reverse shell.