
PENTEST-LAB
Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

OWA Password Sprayer

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

an impacket-dependent script exploiting CVE-2019-1040

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)


SpringBlade框架JWT认证的漏洞检测工具

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.


A small PoC for the Keycloak vulnerability CVE-2023-0264

Exploit code for CVE-2026-55040, it can create auth header for any validate account.

Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.

WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation

The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.

CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports.…