
CVE-2017-12635
Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

A deep dive into CVE-2025-49706 — the SharePoint spoofing flaw now exploited in the wild for stealthy web shell deployment and privilege escalation.

Exploit for CVE-2022-21661 targeting Elementor WordPress plugin, enabling SQL injection-based privilege escalation and data extraction.

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified…

Proof-of-concept exploit for CVE-2026-12793, an unauthenticated privilege escalation in WordPress JetFormBuilder up to 3.6.2 that creates…

Python PoC scanner and exploit for CVE-2026-13355, an unauthenticated admin privilege escalation in Meta Box AIO WordPress plugins, with FOFA mass…

Python PoC for CVE-2026-12793 in JetFormBuilder <= 3.6.2: unauthenticated privilege escalation leading to plugin upload and remote code execution,…

Docker-based WordPress lab reproducing CVE-2026-60137 and CVE-2026-63030 pre-auth RCE, with a Python PoC exploit for SQLi, privilege escalation, and…

Python detection tool that fingerprints ACF Extended forms on WordPress and checks for publicly exposed role fields indicating CVE-2026-80467…

Detection tooling for CVE-2026-5118, an unauthenticated privilege escalation in Divi Form Builder <= 5.1.2, identifying affected WordPress…

Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

Defensive notes on CVE-2022-24637 in Open Web Analytics before 1.7.4, covering unauthenticated information disclosure, privilege escalation impact,…

Exploit for MinIO privilege escalation vulnerability CVE-2021-43858, allowing unauthorized access to cloud storage. Written in Go, run with 'go run…

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

Automated exploit and mass scanner for CVE-2026-5118, an unauthenticated privilege escalation in WordPress Divi Form Builder <=5.1.2, enabling admin…

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…