
vault
A tool for secrets management, encryption as a service, and privileged access management

A tool for secrets management, encryption as a service, and privileged access management

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

An LDAP injection vulnerability exists in org.yamcs.security.LdapAuthModule. The username parameter is inserted directly into LDAP search filters…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Proof-of-concept for SQL injection in CodeAstro Simple Attendance Management System 1.0, demonstrating authentication bypass via crafted username…

A lightweight CLI tool to interactively search and access your KeePassXC database entries using fzf. Fast, secure, and terminal-centric.

Username Enumeration in Trivision NC-227WF

Python script for SSH username enumeration using timing-based analysis to identify valid accounts on a target server.

Authentication bypass exploit for Joomla CVE-2023-23752 that leaks administrator credentials and MySQL configuration from vulnerable versions…

Username enumeration and password spraying tool aimed at Microsoft O365.

Apache OfBiz vulns

Proof-of-concept for Active Directory username enumeration vulnerability in Hyland OnBase via login endpoint response differences, enabling…

OpenSSH 2.3 < 7.7 - Username Enumeration

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

Grafana Bruteforce tool

OpenSSH Username Enumeration - CVE-2016-6210