
CVE-2026-71206-PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…


SwiftNIO SSH is a programmatic implementation of SSH using SwiftNIO


Post-Exploitation EVTX Analyzer for BloodHound Mapping

listmonk’s Session Persistence After Password Reset and Password Change

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

Public reference for CVE-2025-56643 – Wiki.js 2.5.307 JWT Session Vulnerability

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Apache Tomcat - Session fixation via rewrite valve

CVE-2025-8517: Session Fixation in Vvveb CMS v1.0.6.1

An issue was discovered on TP-Link TL-WR840N. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…