
oauth-scan
Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

fork of the popular jsch library

Exploit for CVE-2020-3952 in vCenter 6.7 https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…


A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.

Apache Shiro CVE-2022-32532

Discource POC

Utility to derive the shared secret on a JitBit Helpdesk install which can be used for authentication bypass (CVE-2017-18486)

Exploit for CVE-2020-3952 in vCenter 6.7


ProxyToken (CVE-2021-33766) : An Authentication Bypass in Microsoft Exchange Server POC exploit


POC for CVE-2026-30950 which allows session hijacking in AutoGpt

Exploit for CVE-2022-46169

Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and…