
CVE-2020-27747
Possible Account Takeover | Brute Force Ability

Possible Account Takeover | Brute Force Ability
Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240

Python3 exploit for CVE-2018-15473 that enumerates valid usernames on OpenSSH servers via timing-based authentication analysis.

Lack of Rate Limiting in Sylius v2.0.2

Powershell Script to build token for CVE-2019-1619

Patch for CVE-2024-10449: replaces vulnerable loginAction.php with a hardened version that requires database configuration for secure authentication.

CVE-2023-1665 - Twake App

OWA Password Sprayer

It is possible to enumerate valid usernames on the login page.

MS-NRPC (Microsoft NetLogon Remote Protocol)/CVE-2020-1472

Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)

automated password spraying tool

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass

Vulnerability in GNU InetUtils telnetd Enables Remote Root Access

CVE-2026-67276 MikroTik RouterOS SSH Authentication Bypass Exploit

Keycloak: Unauthorized organization registration via improper invitation token validation