
CVE-2022-24112
Apache APISIX batch-requests RCE(CVE-2022-24112)

Apache APISIX batch-requests RCE(CVE-2022-24112)

SAML v2.0 bindings in Java using JAXB

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Write-up and proof-of-concept for CVE-2026-94609, an authentik privilege-escalation flaw letting users with add_user_to_group join superuser groups…

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by…

PlaceOS authentication service and API gatekeeper.

Cryptographically signed delegation receipts for AI agents. Define exactly what an AI can and can't do — signed, verifiable, tamper-proof.

Zero-knowledge privacy platform for confidential API key management, encrypted vault, and secure chat. Built on Oasis Sapphire TEEs

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable…

PHP 8.4+ security library (mirror)

Alibab-Nacos-Unauthorized-Reset PWD

CVE-2026-31816 - Budibase Authentication Bypass to RCE

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)