
CVE-2024-46278-teedy_1.11_account-takeover
【Teedy 1.11】Account Takeover via XSS

【Teedy 1.11】Account Takeover via XSS

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials,…

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

Possible Account Takeover | Brute Force Ability

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Unauthenticated CSRF Account TakeOver in BigTreeCMS v4.4.14

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

LiteSpeed Unauthorized Account Takeover

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover

Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…