
vulnerable-nextjs-14-CVE-2025-29927
vulnerable-nextjs-14-CVE-2025-29927

vulnerable-nextjs-14-CVE-2025-29927

Exploit for CVE-2018-0114: re-signs JWT tokens by embedding an attacker-controlled public key in the JWS header, bypassing authentication in…

CVE-2025-31161

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update

Open-source identity and access management solution providing authentication, user federation, single sign-on, and fine-grained authorization for…

Authentication Bypass for FreeScout End-User Portal

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

https://medium.com/@mnqazi/cve-2023-4696-account-takeover-due-to-improper-handling-of-jwt-tokens-in-memos-v0-13-2-13104e1412f3

Bypass for Symantec Endpoint Protection's Client User Interface Password

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

Authorization library enforcing ACL, RBAC, ABAC, and custom access-control models with RESTful matching and policy management APIs for applications…

CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.

Open Source Identity and Access Management For Modern Applications and Services

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

GNU telnetd service from GNU InetUtils authentication-bypass