
CVE-2023-22515-POC
Proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Confluence Server and Data Center, enabling…

Proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Confluence Server and Data Center, enabling…

CVE-2023-28121 - WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation [ Mass Add Admin User ]

Proof-of-concept exploit for CVE-2022-1421, a CSRF vulnerability in Discy WordPress theme allowing admin settings modification via crafted AJAX…

Proof-of-concept exploit for CVE-2025-2304, a mass assignment vulnerability in Camaleon CMS < 2.9.1 allowing authenticated privilege escalation to…

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the…

Python proof-of-concept for authenticated remote code execution in PandoraFMS 7.0-NG 742, enabling admin users to upload malicious PHP and obtain a…

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

Authenticated remote code execution exploit for Zen Cart via SQL injection in admin module editing. Proof-of-concept for CVE-2021-3291.

Exploit and scanner for CVE-2023-3460, a WordPress Ultimate Member plugin privilege escalation vulnerability allowing unauthenticated admin account…

Stored XSS via User-Agent in Admin Order View in PhocaCart

Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…