
CVE-2026-23813
CVE-2026-23813 — AOS-CX pre-auth bypass via nginx regex. Detection script, bypass demo, config-disclosure PoC, and IDS rules.

CVE-2026-23813 — AOS-CX pre-auth bypass via nginx regex. Detection script, bypass demo, config-disclosure PoC, and IDS rules.

Docker-based lab for CVE-2024-27198 TeamCity authentication bypass. Includes exploit reproduction, IoC hunting with Sigma/Suricata rules, and…

Exploit for Dahua IPC/VTH/VTO devices that bypasses identity authentication by sending crafted malicious packets, allowing unauthorized access.

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

Exploit script for CVE-2022-23131 that bypasses Zabbix SSO authentication by forging JWT tokens, enabling unauthorized admin access to the monitoring…

DLL Injection tool to unlock guest VMs

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

CVE-2021-34646 PoC

Privacy-first password manager with local storage and bring-your-own-cloud sync across Google Drive, Microsoft OneDrive, and Dropbox. Your…

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

CyberArk Conjur automatically secures secrets used by privileged users and machine identities

Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using…

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Exploits CVE-2026-39987 pre-auth RCE in Marimo <0.23.0 by connecting to the unauthenticated /terminal/ws WebSocket. Supports arbitrary command…

Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update