
CVE-2026-34910-PoC
CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.


SAML2 Burp Extension

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

A documentation and tracking project with the goal of making package management systems more secure.

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

RumbleTalk Live Group Chat <= 6.1.9 - Missing Authorization via handleRequest

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

CyberArk Security Audit

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…