
route-detect
Find authentication (authn) and authorization (authz) security bugs in web application routes.

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Local Authentication Bypass Vulnerability in Reolink Desktop Application

OWA Password Sprayer

Exploit for GitLab account takeover via CVE-2023-7028, demonstrating password reset bypass by injecting attacker email to receive reset token.

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

an impacket-dependent script exploiting CVE-2019-1040

PoC for CVE-2019-12476, a Windows authentication bypass in ManageEngine ADSelfService Plus that provides an unauthenticated SYSTEM shell via crafted…

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

Proof-of-concept exploit for CVE-2024-4040, a server-side template injection in CrushFTP allowing unauthenticated file read, authentication bypass,…

Exploit code for CVE-2026-55040, it can create auth header for any validate account.

Exploit for Dahua camera authentication bypass (CVE-2021-33045) using mitmproxy to intercept and modify login requests to /RPC2_Login.

SpringBlade框架JWT认证的漏洞检测工具

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

A small PoC for the Keycloak vulnerability CVE-2023-0264

Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.