
LoHongCam-CVE-2021-33044
Python exploit for Dahua device authentication bypass (CVE-2021-33044). Sends crafted malicious data packets to bypass login and gain unauthorized…

Python exploit for Dahua device authentication bypass (CVE-2021-33044). Sends crafted malicious data packets to bypass login and gain unauthorized…

Exploit for CVE-2020-3952 in vCenter 6.7

Exploit for CVE-2020-3952 in vCenter 6.7 https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

SecureCivic is a citizen-built, open source identity verification platform designed for SSA adoption. It replaces private data brokers with a secure,…

A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor…

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

The Secure CommsOS™ for mission-critical operations

The Symfony PHP framework

The next generation encrypted file sharing project

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Exploit PoC for CVE-2026-82329, an authentication bypass in JFrog Artifactory. Demonstrates forging JWT tokens to gain admin access and create a…

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

Proof-of-concept exploit for CVE-2026-11102 demonstrating OAuth2 implicit grant fragment hijacking via unvalidated redirect_uri, leading to access…

a plugin that protects your wp site from the CVE-2017-8295 vulnerability