
TokenTactics
Azure JWT Token Manipulation Toolset

Azure JWT Token Manipulation Toolset

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Password attacks and MFA validation against various endpoints in Azure and Office 365

CVE-2020-13941: Abusing UNC Paths in Windows Environments in Apache Solr

Fortinet FortiClientEMS improper access control

Validates injected sessions from the CVE-2026-41940 cPanel/WHM authentication bypass exploit, testing endpoints to distinguish patched servers from…

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

Proof-of-concept for CVE-2025-66698: authentication bypass in Veda v5.4.8 via empty ticket parameter, enabling enumeration of users, policies, and…

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

Enumerate information from NTLM authentication enabled web endpoints 🔎

A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.