
CVE-2026-6145
User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter

User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter

CVE-2021-46075 - A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access…

CVE-2021-46075 - A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access…

Proof-of-concept for a stored XSS vulnerability in Hotel and Tourism Reservation System 1.0, demonstrating unauthenticated injection and admin…

CVE-2020-14008 - ManageEngine Applications Manager RCE

Proof of concept demonstrating unauthenticated access to critical admin functions in Smart Parking System 1.0, allowing account creation, data…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…

Proof-of-concept demonstrating a stored XSS vulnerability in Juzaweb CMS v5.0.0 via the banner ads HTML field, leading to arbitrary script execution…

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM (HTML Injection)

Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the…

Detection artifact generator that verifies cPanel/WHM authentication bypass (CVE-2026-41940) and demonstrates RCE via CRLF injection, targeting WHM…

Proof-of-concept for stored XSS in SourceCodester CET Automated Grading System 1.0, demonstrating unauthenticated payload injection via student…

Proof-of-concept exploit for stored XSS (CWE-79) in a PHP coaching management system, demonstrating session hijacking and privilege escalation from…

Proof-of-concept exploit for CVE-2026-7394, a SQL injection vulnerability in SourceCodester Pizzafy Ecommerce System 1.0. Demonstrates authenticated…

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…