


Python exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Includes Shodan and FOFA dorks for vulnerable instance discovery.

Perform With Massive Authentication Bypass (Wordpress Mstore-API)

Demonstrates a critical JWT signing key predictability vulnerability in PowerJob Server, allowing offline key derivation and token forgery for admin…

Pure Java SSH client/server library implementing SSH-2 protocol with support for multiple ciphers, key exchanges, authentication methods, SFTP, SCP,…

Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

Advisory and technical analysis of CVE-2026-15469, a hard-coded RSA-512 mesh group private key in TP-Link Deco routers, including root cause, impact,…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

CyberArk Security Audit

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

A tool that implements the Golden SAML attack

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

The great CrackMapExec tool compiled for Windows