
permission-manager
Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Exploitation of an authorization bypass vulnerability in the SureTriggers plugin for WordPress versions <= 1.0.78, allowing unauthenticated attackers…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Proof-of-concept exploit for authentication bypass in Senior Rubiweb 6.2.34, enabling admin access to sensitive information via crafted URLs.

Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update

Exploit for CVE-2025-27580: A predictable token vulnerability in NIH BRICS through 14.0.0-67 allows unauthenticated users with a Common Access Card…

Proof-of-concept exploit for CVE-2024-30896, a privilege escalation vulnerability in InfluxDB allowing allAccess token holders to gain operator-level…

A JWT based API for managing users and issuing JWT tokens

Jenkins plugin providing script approval workflows and Groovy sandboxing to enforce secure script execution, with ACL-aware permission checks and…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

CyberArk Conjur automatically secures secrets used by privileged users and machine identities

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

This script exploits the CVE-2024-0204 vulnerability in Fortra GoAnywhere MFT, allowing the creation of unauthorized administrative users, for…

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

Import Users From CSV with Meta 1.15 - Unauthorised Authenticated Users Export

POC for CVE-2026-30950 which allows session hijacking in AutoGpt

API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…