
kratos
API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…

API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…

A JWT based API for managing users and issuing JWT tokens

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

Python proof-of-concept for LDAP anonymous bind privilege escalation, simulating insecure ACLs to create admin users via unauthenticated LDAP binds.

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

A new open-source tool to quickly audit SAP permissions.

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Bastillion gives you a clean, browser-based way to manage SSH access across all your systems—like a bastion host with a friendly dashboard.

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

POCs to demonstrate CVE-2026-42167 in ProFTPD

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

Jenkins plugin providing script approval workflows and Groovy sandboxing to enforce secure script execution, with ACL-aware permission checks and…

Proof-of-concept exploit for authentication bypass in Senior Rubiweb 6.2.34, enabling admin access to sensitive information via crafted URLs.

Proof-of-concept exploit for an authorization flaw in Open WebUI that lets low-privileged users edit and delete other members' channel messages via…

POC for CVE-2026-30950 which allows session hijacking in AutoGpt

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW