
macOS-enterprise-privileges
This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Bastillion gives you a clean, browser-based way to manage SSH access across all your systems—like a bastion host with a friendly dashboard.

A JWT based API for managing users and issuing JWT tokens

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

Proof-of-concept exploit for an authorization flaw in Open WebUI that lets low-privileged users edit and delete other members' channel messages via…

Python proof-of-concept for LDAP anonymous bind privilege escalation, simulating insecure ACLs to create admin users via unauthenticated LDAP binds.

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Proof-of-concept exploit for authentication bypass in Senior Rubiweb 6.2.34, enabling admin access to sensitive information via crafted URLs.

API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…

CyberArk Conjur automatically secures secrets used by privileged users and machine identities

Technical analysis and advisory for CVE-2026-51119, a privilege escalation in Invixium IXM WEB allowing authenticated low-privilege users to create…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

POC for CVE-2026-30950 which allows session hijacking in AutoGpt

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

POCs to demonstrate CVE-2026-42167 in ProFTPD

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…