
CVE-2026-19490
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

Exploits Kerberos reflection via Unicode normalization in Windows Active Directory to relay authentication to ADCS and MSSQL, enabling…

cPanel/WHM CVE-2026-41940 CRLF injection auth bypass exploit

Exploit for Cisco Catalyst SD-WAN Controller authentication bypass (CVE-2026-20127) that forges DTLS CHALLENGE_ACK_ACK messages to gain unauthorized…

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

CVE-2026-24858 FortiCloud Single Sign On (SSO) a factory default enabled feature once you register any FortiGate/FortiManager/FortiAnalyzer …

Remote timing attack exploit for Apache mod_auth_digest (CVE-2026-33006) that bypasses Digest authentication via a 33-layer temporal cascade,…

Proof-of-concept exploit for CVE-2026-25253, demonstrating one-click remote code execution in OpenClaw via authentication token theft and cross-site…

Scanner for cPanel & WHM authentication bypass (CVE-2026-41940) that detects vulnerable versions via CRLF injection and session manipulation, with…

Go-based scanner and exploit tool for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports batch scanning, token leakage, and…

Inspect, debug, and visually test Model Context Protocol (MCP) servers from a web UI, CLI, or TUI, with tool/resource exploration, request logging,…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types

Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel

Grafana Bruteforce tool

A python3 multithreaded SSH dictionary attack tool

Python utility that reads accessible gMSA password blobs from Active Directory and extracts plaintext passwords for use in security audits and red…