
Potato
Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

The vulnerable application that will teach you how to hack WebSockets

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

Authorization library enforcing ACL, RBAC, ABAC, and custom access-control models with RESTful matching and policy management APIs for applications…

Some scripts to abuse kerberos using Powershell

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

Clone of w1.fi hostap.git - NOTE: This is not the main development location and pull requests for this repository are ignored. See the upstream…

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9

Windows protocol library, including SMB and RPC implementations, among others.

Analysis of a logic vulnerability in the macOS SSH client leading to client passphrase exposure to a local attacker

CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login

Exploit for GitLab CVE-2023-7028: password reset bypass via dual email verification, allowing unauthorized account takeover. Includes affected…

PoC for login with password hash in STARFACE