
CVE-2026-34048
Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and…

Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and…

The Single Sign-On Multi-Factor portal for web apps. OpenID Certified™ and Post-Quantum Cryptography Ready.

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

Open-source tool to bypass windows and linux passwords from bootable usb

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Zero-knowledge privacy platform for confidential API key management, encrypted vault, and secure chat. Built on Oasis Sapphire TEEs

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Vulnerability details and exploit for CVE-2021-3754

A free, secure and open source app for Android to manage your 2-step verification tokens.

Zero-click authentication bypass exploit for Android ADB Wireless Debugging (CVE-2026-0073). Provides interactive shell, command execution, and…

LG On Screen Phone authentication bypass PoC (CVE-2014-8757)

Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass

An Android HW Attestation demo

0-Click RCE Android Adb TLS Wireless Debugging