
vcenter_saml_login
A tool to extract the IdP cert from vCenter backups and log in as Administrator

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Polkit D-Bus Authentication Bypass Exploit

Office Anywhere网络智能办公系统

Veeam Backup Enterprise Manager Authentication Bypass (CVE-2024-29849)

Docker setup for CVE-2026-24061

WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass


Ivanti Neurons for ITSM (On Premise) exploits

PoC for CVE-2025-29556 creating Security Officer accounts on ExaGrid EX10 backup appliances via a low-privilege API session, enabling privilege…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Exploit PoC for CVE-2026-41940, a cPanel & WHM authentication bypass via CRLF injection. Includes mass scanning, post-exploitation actions, and an…

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…