
parsec-cloud
Open source Dropbox-like file sharing with full client encryption !

Open source Dropbox-like file sharing with full client encryption !

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable…

Reproduction environment for CVE-2025-29927, demonstrating Next.js middleware authorization bypass via the x-middleware-subrequest header. Includes…

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

CVE-2025-64446

Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

vulnerable-nextjs-14-CVE-2025-29927

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

do not use. vulnerable

Minimal Java web application to reproduce CVE-2022-32532, an Apache Shiro RegExPatternMatcher authentication bypass via newline characters in URLs.

Exploit module for Apache JSPWiki CVE-2019-10077, targeting a Java-based wiki platform with JAAS authentication and access control. Enables…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…