
carbon-identity-framework
Core framework for identity and access management, providing authentication, authorization, and identity governance capabilities for enterprise…

Core framework for identity and access management, providing authentication, authorization, and identity governance capabilities for enterprise…


Overlay network protocol giving AI agents permanent addresses, authenticated encrypted tunnels, and a trust model over UDP. Includes NAT traversal,…

Exploit script for CVE-2024-1708 and CVE-2024-1709 in ConnectWise ScreenConnect, enabling authentication bypass and remote code execution with user…

Exploit for Keycloak CVE-2026-18963 enabling unauthenticated account takeover via reset-credentials bypass. Includes safe detection, non-destructive…

An Android HW Attestation demo

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

Exploit for CVE-2024-0012 and CVE-2024-9474 targeting authentication bypass and authenticated command injection in Palo Alto PAN-OS management web…

[CVE-2020-6287] SAP NetWeaver AS JAVA (LM Configuration Wizard) Authentication Bypass (Create Simple & Administrator Java User)

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9…

ksmbd CVEs: CVE-2026-31717, CVE-2026-68083

Next.js PoC for CVE-2025-29927

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

CVE-2022-36537

CVE-2021-42287/CVE-2021-42278 Exploiter

A PoC exploit for CVE-2018-9995 - DVR Authentication Bypass