
CVE-2026-8181
CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Multi-source subdomain enumeration tool with 50+ collection modules, DNS brute-force, passive DNS analysis, certificate transparency, search engine…

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE.…

Offensive MSSQL toolkit written in Python, based off SQLRecon

Proof-of-concept exploit for CVE-2025-6264 in Velociraptor, demonstrating privilege escalation via missing permission checks to redirect clients to a…

Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.

Automated Recon for Pentesting & Bug Bounty

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

CVE-2025-31161


CVE-2025-58434 Flowise <= 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025-59528 lowiseAI Custom MCP…

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

CVE-2020-13654 - XWiki Platform < 12.8 - Stored XSS → CSRF → Account Takeover