
Tools for managing user identities, authentication, authorization, and access controls within systems and networks.


Next js middlewareauth Bypass

Para verificar si tu entorno podría ser vulnerable al CVE-2025-29810, necesitamos hacer algunas comprobaciones básicas, como: Versión del sistema…


Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

Local-first encrypted password manager for logins, notes, and API keys, using a SQLite vault sealed with Argon2id and XChaCha20-Poly1305; no cloud or…

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Oracle OID LDAP Server Privileges Management Exploit

ksmbd CVEs: CVE-2026-31717, CVE-2026-68083

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Exploit for CVE-2024-4040 affecting CrushFTP server in all versions before 10.7.1 and 11.1.0 on all platforms

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

Confluence Unauthorized Administrator User Addition Exploitation Script

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

Open source solutions for SOC2, GDPR, and ISO27001