
CVE-2025-14340
PoC for CVE-2025-14340: Admin account takeover in Payara Server

PoC for CVE-2025-14340: Admin account takeover in Payara Server

Proof-of-concept exploit for an authentication bypass in HP 1920 Series switches, allowing unauthenticated admin password change via crafted HTTP…

Exploit for CVE-2021-26855 (ProxyLogon) targeting Microsoft Exchange. Creates a new admin user and establishes a reverse shell for post-exploitation…

ARMember < 3.4.8 - Unauthenticated Admin Account Takeover

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated…

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

Proof-of-concept exploit for a mass assignment privilege escalation vulnerability in Camaleon CMS < 2.9.1. Authenticated low-privilege users can…

Proof-of-concept exploit for Mailcow CVE-2022-31138 enabling RCE via perl code injection in Sync Job regex fields, with privilege escalation to…

Proof-of-concept exploit for CVE-2024-55591, enabling unauthenticated WebSocket CLI access to FortiOS devices, with interactive shell and admin…

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

Python PoC exploit for CVE-2023-6329 authentication bypass in Control iD iDSecure. Reconstructs admin credentials via predictable password derivation…

Advanced Custom Fields Extended (ACFE) WordPress Plugin Exploit RCE - Admin Creation

Proof-of-concept exploit for CVE-2022-40684 authentication bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager. Injects SSH keys via…

Docker-based reproduction environment for Apache CouchDB CVE-2017-12635 vertical privilege escalation via JSON parser inconsistency, enabling…

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

Python exploit script for CVE-2024-6624 targeting unauthenticated privilege escalation in the JSON API User WordPress plugin. Automates user…

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

CVE-2021-46075 - A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access…