
Tools for managing user identities, authentication, authorization, and access controls within systems and networks.


QuantumLock is an open-source, quantum-resistant Bitcoin protocol designed to protect digital assets from future quantum computing threats. Featuring…

Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Oracle OID LDAP Server Privileges Management Exploit

ksmbd CVEs: CVE-2026-31717, CVE-2026-68083

Exploit for CVE-2024-4040 affecting CrushFTP server in all versions before 10.7.1 and 11.1.0 on all platforms

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

Confluence Unauthorized Administrator User Addition Exploitation Script

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

Open source solutions for SOC2, GDPR, and ISO27001

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…