
By-Poloss..-..CVE-2026-19125
Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).

Audit and incident response tool for CVE-2026-41940 vulnerability

Local-first encrypted password vault for Android with Master Password access, Recovery Key support, Autofill integration, and portable encrypted…

Burp Suite extension to perform Kerberos authentication

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

Authentication Bypass Vulnerability Apache OFBiz < 18.12.10.

An LDAP based Active Directory user and group enumeration tool

Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb

Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.

Proof of Concept Utilities Developed to Research NTLM Relaying Attacks Targeting ADFS