
CVE-2022-26923
Detailed technical write-up and proof-of-concept for CVE-2022-26923, an Active Directory Certificate Services privilege escalation vulnerability,…

Detailed technical write-up and proof-of-concept for CVE-2022-26923, an Active Directory Certificate Services privilege escalation vulnerability,…

Reproduces CVE-2025-0108 path confusion vulnerability in Nginx/Apache stacks. Includes a vulnerable PoC and a patched implementation demonstrating…

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162030) in Copilot, involving user ID switching that could lead to…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162029) in Copilot, enabling unauthorized account access via user ID…

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

Advisory detailing CVE-2025-56221, an authentication rate-limiting flaw in Ascertia SigningHub allowing brute-force attacks, with affected versions…

Documents an OTP verification bypass vulnerability in Ascertia SigningHub, allowing attackers to brute-force OTP codes and impersonate mobile…

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162028) in Copilot, enabling unauthorized account access via user ID…

Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation

Proof-of-concept for CVE-2026-31282: Totara LMS login page access control bypass enabling unauthenticated brute-force credential attacks. Includes…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162026) in Copilot, enabling unauthorized account access via user ID…

Security advisory for CVE-2025-4172025: an authentication bypass vulnerability in Copilot enabling unauthorized account access, session hijacking,…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162025) in Copilot, including impact analysis, affected versions, and…

Security advisory detailing a critical authentication vulnerability in Copilot where user IDs are switched, enabling unauthorized account access and…

Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…