
kerberoast
Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…

Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…

SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)

Python script to exploit the OWASSRF + TabShell chain on vulnerable Microsoft Exchange servers, leveraging Kerberos authentication for command…

Proof-of-concept exploit for CVE-2026-49757 demonstrating OAuth2/OIDC account takeover via email-based user matching in AshAuthentication, with…

Python exploit that tests domain controllers for Zerologon (CVE-2020-1472) and resets the vulnerable machine account password through Netlogon…

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it…

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

Pre-built vulnerable CrushFTP 10.8.0 binary for authorized penetration testing of CVE-2025-31161, an unauthenticated authentication bypass…

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing attack to inject a sudo user and gain root shell on vulnerable…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Proof-of-concept exploit for PaperCut CVE-2023-27350, chaining authentication bypass with built-in scripting abuse to achieve remote code execution…

Python script to detect FortiOS authentication bypass (CVE-2024-55591) by probing WebSocket connections to the management interface, identifying…

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

Python exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Includes Shodan and FOFA dorks for vulnerable instance discovery.

A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-saml