burpsuite extension for check unauthorized vulnerability
-
Updated
Oct 7, 2020 - Python
burpsuite extension for check unauthorized vulnerability
Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit
Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarded. Authorized testing only.
A Python script to extract the list of users of a GiTea instance, unauthenticated or authenticated.
🚨 CVE-2023-45866 - BlueDucky Implementation (Using DuckyScripy). it establish an encrypted connection and inject keystrokes without user authorization. The vulnerability was discovered by Marc Newlin of SkySafe. it affects multiple operating systems including Android, Linux, macOS and iOS.
Unauthenticated PHP Object Injection to RCE in WP Activity Log <= 5.6.3.1 (CVE-2026-54806)
Kumpulan Exploit Wordpress Plugins + Tools + and cara penggunaannya
Perform With Massive Openfire Unauthenticated Users
wp2shell - WordPress CVE-2026-63030 Exploit & Scanner
Critical RCE vulnerability (CVSS 9.3) in Weaver E-cology platform versions prior to build 20260312. Unauthenticated remote code execution via exposed debug endpoint at /papi/esearch/data/devops/dubboApi/debug/method. Comprehensive analysis, proof-of-concept, and detection guidance included.
Atlassian Confluence (CVE-2022-26134) - Unauthenticated OGNL injection vulnerability (RCE).
CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell verification. For authorized security testing only.
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
Python scripts to find ADCS servers on a network without any credentials.
CVE-2026-12940 — Langflow OSS <=1.10.1 unauthenticated RCE via MCP stdio environment-variable injection (SHELLOPTS/PS4). Author PoC + source analysis + lab.
A light & organized Python module built with the sole purpose of extracting a Twitter user-object while conforming to Tweepy standards, all without using Twitter's authenticated API.
CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution. No dependencies.
CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.
CVE-2026-95675 · POC
To associate your repository with the unauthenticated topic, visit your repo's landing page and select "manage topics."