
CVE-2026-71518
Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

PoC exploit for critical Budibase auth bypass: unanchored webhook regex lets attackers append ?/webhooks/trigger, reach protected APIs, and chain…

An Android HW Attestation demo

Exploits CVE-2026-39987 pre-auth RCE in Marimo <0.23.0 by connecting to the unauthenticated /terminal/ws WebSocket. Supports arbitrary command…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

In-memory token vault BOF for Cobalt Strike


Burp Suite Extension useful to verify OAUTHv2 and OpenID security

A framework for creating smart cards (ICC-based cards with contacts).

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote memory…

In-depth ldap enumeration utility

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).