
CVE-2026-36959
Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the…

Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the…

Root-cause analysis and safety-gated verification tool for CVE-2025-0324, a privilege-escalation flaw in AXIS OS VAPIX allowing any authenticated…

Exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt allowing attackers to forge admin tokens using only the public key.

Proof-of-concept exploit for CVE-2026-21721 that escalates privileges to admin on affected dashboards, requiring a valid Editor account.

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

WPBF - a multithreaded WP brute forcer

Security Advisory for CVE-2026-51564

Security Advisory for CVE-2026-51565

Docker-based vulnerable WordPress lab with Python exploit demonstrating pre-auth route confusion and SQL injection chain (CVE-2026-63030 +…

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.

Browser-based MCP CTF — OAuth token confusion and session isolation failure (CVE-2025-49596 pattern). DevTools only.

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Proof-of-concept for CVE-2020-24029: unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege…

CVE-2024-45264

TP-LINK Multiple HTML Injection Vulnerabilities