
Grid-Mobile
Grid: Private Location Sharing mobile app for iOS/Android. E2EE with Matrix.

Grid: Private Location Sharing mobile app for iOS/Android. E2EE with Matrix.

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…


Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without…

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

Owa Valid Login Checker

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

Simple Secure Keeper for Secrets

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.


This repository discloses a server-side authorization bypass in Instagram, which allowed unauthenticated access to private timelines; it seems likely…

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.


Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams