
CVE-2023-36899
Reproduction environment and exploit tool for CVE-2023-36899, demonstrating ASP.NET Framework cookieless session authentication bypass and IIS app…

Reproduction environment and exploit tool for CVE-2023-36899, demonstrating ASP.NET Framework cookieless session authentication bypass and IIS app…

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

Community-maintained security checklist for Model Context Protocol (MCP) deployments. Covers authentication, input validation, prompt injection, tool…

Tool for exploiting MS14-068 Kerberos vulnerability to escalate privileges in Windows Active Directory domains.

Automated tool for bypassing authentication and deploying backdoors on ZKSoftware ZMM100 fingerprint access control devices via Telnet, with database…

Exploit tool for CVE-2022-23131, an unsafe session storage vulnerability in Zabbix frontend enabling privilege escalation via SAML SSO authentication…

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

A new open-source tool to quickly audit SAP permissions.

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

Interactive exploitation tool for CVE-2026-41940, a critical pre-auth authentication bypass in cPanel & WHM via CRLF injection. Designed for…

Web-based tool for adding shadow users with SHA-512 password hashing and auto-aging detection, featuring multiple write fallback methods for system…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit

A simple and secure command-line tool for managing TOTP-based two-factor authentication codes.

Python-based WordPress author enumeration and login brute-force tool for penetration testing.

Exploit tool for CVE-2023-2437 targeting UserPro <= 5.1.1 authentication bypass, allowing attackers to gain admin access and create new…