
CVE-2026-71206-PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

COFF file (BOF) for managing Kerberos tickets.


Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

listmonk’s Session Persistence After Password Reset and Password Change

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.


Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

A small PoC for the Keycloak vulnerability CVE-2023-0264

Post-Exploitation EVTX Analyzer for BloodHound Mapping

An issue was discovered on TP-Link TL-WR840N. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…

SwiftNIO SSH is a programmatic implementation of SSH using SwiftNIO

Zabbix - SAML SSO Authentication Bypass

CVE-2025-8517: Session Fixation in Vvveb CMS v1.0.6.1