
CVE-2025-2563
The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

Proof-of-concept demonstrating a stored XSS vulnerability in Juzaweb CMS v5.0.0 via the banner ads HTML field, leading to arbitrary script execution…

Demo app to exploit CVE-2025-29927: NextJS middleware bypass via proxy-injected headers for unauthorized /admin access. Includes vulnerable app and…

Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Proof-of-concept exploit for CVE-2026-20131, a pre-authentication RCE in Cisco Catalyst SD-WAN Controller and Manager, enabling admin access and…

Proof-of-concept for SQL injection vulnerability in SourceCodester Human Resource Management System 1.0, enabling unauthenticated admin login via…

Exploit for CVE-2023-22518 in Atlassian Confluence. Provides a detailed walkthrough of the vulnerability, including environment setup, root cause…

Proof-of-concept exploit for CVE-2024-27956: SQL injection in WordPress leading to admin account creation and remote code execution. Written in…

Proof-of-concept for reflected XSS in Cudy LT400 web interface, demonstrating session cookie theft and admin takeover via crafted requests.

Go-based brute-force tool exploiting Bludit bruteforce mitigation bypass (CVE-2019-17240) for automated password cracking against admin login pages.

Exploit for CVE-2025-10352. Admin account creation on Melis Platform Framework

Exploit for CVE-2026-2406 targeting Terrminus Authentication Gateways, using temporal dispersion to bypass fingerprinting and behavioral AI,…

Go-based exploit for CVE-2025-31161 targeting crushFTP, enabling remote admin account creation via crafted HTTP requests.

Python exploit for CrushFTP CVE-2025-54309 XML race condition vulnerability. Creates admin user via concurrent requests with configurable payload…

Technical analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence allowing…

Step-by-step exploit walkthrough for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Server and Data Center,…

Detailed analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Data Center…