
santa
A binary and file access authorization system for macOS.

A binary and file access authorization system for macOS.

Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9…

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Multiple exploits for Monitorr

F5 BIG-IP iControl REST身份验证绕过漏洞

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

Python exploit for CVE-2026-41940, a critical CRLF injection in cPanel/WHM cpsrvd that bypasses authentication and 2FA, granting root-level access…

Powertek PDU身份绕过

OAuth 2.0 client library for Kit applications supporting authorization code, PKCE, client credentials, and refresh token flows with built-in provider…

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

CVE-2025-31161

Exploit for CVE-2024-4040 affecting CrushFTP server in all versions before 10.7.1 and 11.1.0 on all platforms