
sdk
Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.
Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

Docker lab reproducing CVE-2026-10795: UpdraftPlus UpdraftCentral authentication bypass chained to plugin installation for RCE. Includes…

Exploit for CVE-2026-7731 targeting cloud-native identity gateways by refracting JWT temporal validation to escalate privileges from admin:false to…

Python exploit for CVE-2022-36537, an authentication bypass in ZK Framework affecting R1Soft Server Backup Manager, allowing retrieval of web context…

Exploit for CVE-2018-0114: re-signs JWT tokens by embedding an attacker-controlled public key in the JWS header, bypassing authentication in…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4"

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

Responsible disclosure of unpatched vulnerability in FluentCRM by WPManageNinja

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

Java SDK for integrating with Amazon Web Services, providing secure API access to S3, DynamoDB, EC2, and more, with built-in authentication,…

Java client providing fluent DSL access to Kubernetes and OpenShift REST APIs for managing cloud-native infrastructure, pods, services, and…

CVE-2025-60188 Atarim Plugin Exploit

Polkit D-Bus Authentication Bypass Exploit

WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)

Custom Content Types and Fields plugin for WordPress

CVE-2026-55584 — phpSysInfo IP Allowlist Bypass