
Exploit-for-CVE-2024-46987
Exploit for CVE-2024-46987

Exploit for CVE-2024-46987

Educational Docker lab demonstrating Telnet NEW-ENVIRON username injection (CVE-2026-24061) with a Python client and vulnerable server for isolated…

Proof-of-concept exploit for CVE-2020-9496 (Apache OFBiz) with nuclei template integration and step-by-step vulnerable environment setup for security…

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

Setting up POC for CVE-2021-26084

An LDAP injection vulnerability exists in org.yamcs.security.LdapAuthModule. The username parameter is inserted directly into LDAP search filters…

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

Exploit systems using older WinRAR without knowing their username (unlike other projects)

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

SSH username enumeration exploit targeting OpenSSH 2.3 through 7.7 (CVE-2018-15473). Enumerates valid users individually or from a wordlist via a…

Check if a username is valid on the SSH server by attempting an authentication. The server response will indicate whether the username exists.

Security Advisory: Unauthenticated Stored Cross-Site Scripting Leading To Administrator Account Takeover (openclaw-dashboard)