
kcatcher
Catch what's lurking in your Kafka clusters.

Catch what's lurking in your Kafka clusters.

This repository discloses a server-side authorization bypass in Instagram, which allowed unauthenticated access to private timelines; it seems likely…

Enumerate the permissions associated with AWS credential set

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

Multiple exploits for Monitorr