
WSGoat
The vulnerable application that will teach you how to hack WebSockets

The vulnerable application that will teach you how to hack WebSockets

Authorization library enforcing ACL, RBAC, ABAC, and custom access-control models with RESTful matching and policy management APIs for applications…

Windows protocol library, including SMB and RPC implementations, among others.

Clone of w1.fi hostap.git - NOTE: This is not the main development location and pull requests for this repository are ignored. See the upstream…

Some scripts to abuse kerberos using Powershell

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

Analysis of a logic vulnerability in the macOS SSH client leading to client passphrase exposure to a local attacker

Exploit for GitLab CVE-2023-7028: password reset bypass via dual email verification, allowing unauthorized account takeover. Includes affected…

A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9

CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

PoC for login with password hash in STARFACE

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.