
CVE-2026-71206-PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)
Tools for managing user identities, authentication, authorization, and access controls within systems and networks.

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

Low-memory graphdb with Bolt+tls support, at-rest encryption & vectors designed for local replica graph use cases.

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

Generates least-privilege AWS IAM policies based on resource ARNs and access levels, automating secure policy creation for cloud infrastructure.

The Symfony PHP framework

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Installable Claude Skills providing expert-level compliance guidance for 30+ frameworks including ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF,…

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

A modern git based age-encrypted secrets manager for teams.

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

PoC exploit for critical Budibase auth bypass: unanchored webhook regex lets attackers append ?/webhooks/trigger, reach protected APIs, and chain…

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

Home to the Signal Protocol as well as other cryptographic primitives which make Signal possible.

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

Squid Web Proxy Cache - Source Code

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…