
CVE-2024-6624
Python exploit script for CVE-2024-6624 targeting unauthenticated privilege escalation in the JSON API User WordPress plugin. Automates user…

Python exploit script for CVE-2024-6624 targeting unauthenticated privilege escalation in the JSON API User WordPress plugin. Automates user…

Python POC, Exploit for CVE-2026-29000

Automated 8-phase exploit for CVE-2026-8732, an unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0. Uses multiprocessing and asyncio to scan…

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

CVE-2021-21735 write-up: ZTE ZXHN H168N V3.5 wizard-page information leak, firmware routing flaw, and the path from exposed PPPoE/WLAN data to full…

The code for personally reproducing the corresponding vulnerability

Proof-of-concept for unauthenticated stored XSS in SourceCodester Inventory System, demonstrating admin session hijacking via crafted registration…

Proof-of-concept exploit for CVE-2025-7771, a Windows kernel driver vulnerability in ThrottleStop.sys enabling arbitrary physical memory read/write…

Lab for the CVE-2024-27198

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Benign proof-of-concept for CVE-2026-36226, a cross-site scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 Admin Dashboard Create…

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

Docker-based lab for CVE-2024-27198 TeamCity authentication bypass. Includes exploit reproduction, IoC hunting with Sigma/Suricata rules, and…

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept