
the-bastion
Authentication, authorization, traceability and auditability for SSH accesses.

Authentication, authorization, traceability and auditability for SSH accesses.

Veeam Backup Enterprise Manager Authentication Bypass (CVE-2024-29849)

This is a small proof of concept for CVE-2024-41958

Proof of concept for the vulnerability CVE-2018-19410

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Self-hosted identity management platform providing WebAuthn passkeys, OAuth2/OIDC SSO, SSH key distribution, RADIUS and LDAP integration for modern…

Secure CLI password manager (Argon2id + AES-256-GCM)

Bash PoC for Fortinet Auth Bypass - CVE-2022-40684

A remote code execution vulnerability exists in the iControl REST API feature of F5's BIG-IP product. An unauthenticated, remote attacker can exploit…

Proof-of-concept exploit for CVE-2025-29927 that adds x-middleware-subrequest to bypass Next.js middleware authentication checks.

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

Demonstrates CVE-2022-31692 Spring Security authorization bypass with a minimal Java exploit, enabling security researchers to test and understand…

PoC for CVE-2025-29556 creating Security Officer accounts on ExaGrid EX10 backup appliances via a low-privilege API session, enabling privilege…

FreeRDP is a free remote desktop protocol library and clients

A small, auditable, terminating, deterministic micro-policy engine

Technical documentation and proof-of-concept for CVE-2025-20343, a high-severity denial-of-service vulnerability in Cisco ISE allowing…

Repository for CVE-2023-4800 vulnerability.