
macOS-enterprise-privileges
This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Open source Dropbox-like file sharing with full client encryption !

Web app authorisation coverage scanning

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692

Reproduction environment for CVE-2025-29927, demonstrating Next.js middleware authorization bypass via the x-middleware-subrequest header. Includes…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.

Authorization Bypass in Next.js Middleware

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For…

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

Reproduces CVE-2025-29927 middleware authorization bypass in Next.js 14.2.24 and demonstrates exploitation with curl to bypass authentication and…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…