
nextjs-middleware-exploit
Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.

Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.


Python3 exploit for CVE-2018-15473 that enumerates valid usernames on OpenSSH servers via timing-based authentication analysis.

Python script that tests PAN-OS devices for CVE-2025-0108 authentication bypass by sending crafted HTTP requests and analyzing responses.

Possible Account Takeover | Brute Force Ability

Powershell Script to build token for CVE-2019-1619

Proof-of-concept demonstrating lack of rate limiting on the Sylius v2.0.2 login endpoint, enabling unrestricted automated authentication attempts.

Educational demo of CVE-2022-21449 Java ECDSA signature bypass using real and fake JWT tokens to illustrate the vulnerability and its impact on…

Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

Schneider Electric PowerChute Serial Shutdown vulnerability.

Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)

This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.

SSH man-in-the-middle tool

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

Framework for Man-In-The-Middle attacks

Enumerate valid users within Microsoft Teams and OneDrive with clean output.

PoC Exploit for CVE-2018-8820