
CVE-2026-5430
Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account…

Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account…

This PoC is for educational and authorized security testing purposes only. Do NOT use against systems you don't own.

Original security research and proof-of-concept for CVE-2026-29145, an Apache Tomcat OCSP authentication bypass vulnerability, including technical…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthenticated access to Superset instances for…

Exploit for CVE-2025-31161 with Python and C implementations, allowing authorized penetration testers to manipulate user accounts on target hosts.

listmonk’s Session Persistence After Password Reset and Password Change

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

Provides library functionality for FIDO2, including communication with a device over USB or NFC.

A simple super fast django reusable app that blocks people from brute forcing login attempts

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Proof-of-concept exploit demonstrating a GitHub OAuth token-stealing vulnerability via crafted developer workflow triggers, enabling unauthorized…

Proof-of-concept exploit for CVE-2024-8698 targeting Keycloak SAML authentication bypass. Demonstrates vulnerability exploitation in identity…

Proof-of-concept exploit for CVE-2026-73313, an MFA bypass in XenForo's passkey TFA provider allowing account takeover after password compromise.

Vulnerability Research

Demonstrates a critical JWT signing key predictability vulnerability in PowerJob Server, allowing offline key derivation and token forgery for admin…

Detection artifact for CVE-2026-2699 Progress ShareFile authentication bypass. Sends GET to /ConfigService/Admin.aspx to check vulnerability.

Proof-of-concept exploit for TYPO3 v7.6.15 unencrypted login request vulnerability (CVE-2017-6370), demonstrating plaintext credential exposure over…

CVE-2026-41940: detect and exploit cpanel vuln