
CVE-2026-75431_PowerJob_jwt_key_predictable
Demonstrates a critical JWT signing key predictability vulnerability in PowerJob Server, allowing offline key derivation and token forgery for admin…

Demonstrates a critical JWT signing key predictability vulnerability in PowerJob Server, allowing offline key derivation and token forgery for admin…

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

Validates injected sessions from the CVE-2026-41940 cPanel/WHM authentication bypass exploit, testing endpoints to distinguish patched servers from…

Audit and incident response tool for CVE-2026-41940 vulnerability

Inspect, debug, and visually test Model Context Protocol (MCP) servers from a web UI, CLI, or TUI, with tool/resource exploration, request logging,…

Python script to exploit the OWASSRF + TabShell chain on vulnerable Microsoft Exchange servers, leveraging Kerberos authentication for command…

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

Proof-of-concept exploit for CVE-2019-0217, a race condition in Apache HTTP Server's mod_auth_digest allowing authentication bypass. Includes…

Exploit for CVE-2023-7028 - GitLab CE/EE

Scans target to see if its vulnerable to CVE-2025-31161

Schneider Electric PowerChute Serial Shutdown vulnerability.

Python3 exploit for CVE-2018-15473 that enumerates valid usernames on OpenSSH servers via timing-based authentication analysis.

Proof-of-concept exploit for CVE-2024-28987 targeting SolarWinds Web Help Desk hardcoded credential vulnerability. Automates exploitation via URL…

Exploit for CrushFTP SSTI vulnerability (CVE-2024-4040) enabling unauthenticated file read, authentication bypass, and remote code execution on…

Academic exploit implementation for CVE-2018-10933, a libssh authentication bypass vulnerability, with a detailed report and Shodan search…

🔐 Lightweight CLI utility designed to synchronize SSH public keys from remote URLs into local authorized_keys files

Research on CrushFTP AS2 authentication bypass allowing unauthenticated admin access. Includes PoC scripts, detection rules, and technical analysis…

Zero-Knowledge Credential Sharing