
CVE-2024-31114
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

Extends BloodHound to collect and ingest Active Directory relationships from macOS hosts, including logged-in users, admin groups, SSH/VNC/AppleEvent…

Go-based proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML authentication bypass. Enables unauthorized admin access by forging SAML…

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

Proof-of-concept exploit for CVE-2019-16097 in Harbor, enabling attacker admin account creation and malicious image upload. For authorized security…

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

Proof-of-concept exploit for CVE-2021-36394 in Moodle, enabling admin password takeover and remote code execution via custom PHP functions.

PoC and exploit for CVE-2022-40684, an authentication bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager management interfaces, enabling…

Unauthenticated SQL injection and arbitrary file upload exploit chain for FreePBX 16, achieving remote code execution via admin creation and webshell…

Proof-of-concept exploit for CVE-2020-25223 (Sophos UTM web admin pre-auth RCE) that delivers a reverse shell. Includes post-exploitation notes and…

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

Proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Confluence Server and Data Center, enabling…

CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

Exploit for CVE-2023-41362, a remote code execution vulnerability in MyBB Admin Control Panel, allowing authenticated attackers to execute arbitrary…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

WAC RCE - CVE-2026-26119 Windows Admin Center authenticated RCE via WinREST/PowerShell invokeCommand.