
TheDoc
Automates SQL injection exploitation with SQLMAP, crawls for vulnerabilities, extracts database credentials, finds admin login pages, and cracks…

Automates SQL injection exploitation with SQLMAP, crawls for vulnerabilities, extracts database credentials, finds admin login pages, and cracks…

Go-based proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML authentication bypass. Enables unauthorized admin access by forging SAML…

WooCommerce Payments: Unauthorized Admin Access Exploit

Proof-of-concept exploit for CVE-2023-3460 enabling unauthorized admin access in Ultimate Member WordPress plugin versions below 2.6.7. Intended for…

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

Keycloak admin API allows low privilege users to use administrative functions

Exploit for CVE-2023-22515 in Atlassian Confluence that creates a new admin user and deploys a web-based shell plugin for command execution on the…

Proof-of-concept exploit for Progress WhatsUp Gold SQL injection authentication bypass (CVE-2024-6670). Includes root cause analysis and automated…

Proof-of-concept exploit for CVE-2026-20127, a pre-auth RCE in Cisco SD-WAN Manager/Controller enabling admin access and network configuration…

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

Proof-of-concept exploit for CVE-2019-16097 in Harbor, enabling attacker admin account creation and malicious image upload. For authorized security…

Moodle (< 3.6.2, < 3.5.4, < 3.4.7, < 3.1.16) XSS PoC for Privilege Escalation (Student to Admin)

Proof-of-concept exploit for CVE-2021-26121: Server-Side Template Injection in CS-Cart <=4.12.x allowing shop admin to achieve remote code execution…

Automatic Mass Tool for check and exploiting vulnerability in CVE-2023-3076 - MStore API < 3.9.9 - Unauthenticated Privilege Escalation (Mass Add…

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

CVE-2022-31245: RCE and domain admin privilege escalation for Mailcow