
oauth-scan
Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

Keycloak admin API allows low privilege users to use administrative functions

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

POC of CVE-2022-36537

Zero-Trust SSH CA

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

🔐 Lightweight CLI utility designed to synchronize SSH public keys from remote URLs into local authorized_keys files

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具

CVE-2022-36537

CVE-2021-42287/CVE-2021-42278 Exploiter

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

Dahua IPC/VTH/VTO devices auth bypass exploit

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.