
cve-2026-32699-facturascripts-nick-bypass
Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

Minimal Java web application to reproduce CVE-2022-32532, an Apache Shiro RegExPatternMatcher authentication bypass via newline characters in URLs.

Reproduction environment for CVE-2025-29927, demonstrating Next.js middleware authorization bypass via the x-middleware-subrequest header. Includes…

Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)

NSE plugin for Nmap that scans a DotNetNuke (DNN) web application for an Administration Authentication Bypass vulnerability (CVE-2015-2794, EDB-ID:…

Authorization Bypass in Next.js Middleware

Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.

A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

Exploit module for Apache JSPWiki CVE-2019-10077, targeting a Java-based wiki platform with JAAS authentication and access control. Enables…

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For…

Authorization Bypass in Next.js Middleware