
CVE-2025-56311
CSRF vulnerability in FD602GW-DX-R410 router allows remote attackers to reboot the device via a crafted POST request to /boaform/admin/formReboot…

CSRF vulnerability in FD602GW-DX-R410 router allows remote attackers to reboot the device via a crafted POST request to /boaform/admin/formReboot…

CTF challenge exploiting CVE-2025-0184 DOCX SSRF vulnerability to access internal admin service and retrieve a flag. Includes exploit generator and…

This script checks if an HP iLO server is vulnerable and can add an admin user

Admin interface for monitoring Spring Boot applications with health checks, metrics, log management, JMX interaction, and thread dump viewing.

CVE-2023-39144 disclosure: cleartext password exposure in Element55 Maketime appliance admin pages, enabling privilege escalation via…

Authentication bypass exploit for CVE-2022-40684 targeting FortiOS, FortiProxy, and FortiSwitchManager. Checks vulnerability and overwrites admin SSH…

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker…

CSRF vulnerability PoC and remediation guide for employee deactivation in an admin panel. Includes CVSS scoring, attack reproduction steps, and…

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

Proof-of-concept exploit for CVE-2024-22411 targeting the Avo admin panel. Demonstrates vulnerability exploitation in Ruby-based web applications.

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

Proof-of-concept exploit for CVE-2024-23733: Incorrect Access Control in Software AG webMethods Integration Server 10.15.0 allowing remote attackers…

Proof-of-concept for CVE-2023-37755: hardcoded admin credentials (admin/admin) in i-doit Pro 25 and below, enabling unauthorized admin login via the…

Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI

🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker…

Documentation of CVE-2026-30081, a high-severity cleartext transmission vulnerability in Quantum Networks QN-I-470 router firmware 6.1.1.B1, allowing…

Root-cause analysis and safety-gated verification tool for CVE-2025-0324, a privilege-escalation flaw in AXIS OS VAPIX allowing any authenticated…

Exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt allowing attackers to forge admin tokens using only the public key.