
CVE-2026-55040
Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

Proof-of-concept exploit for FortiOS authentication bypass (CVE-2024-55591) that allows unauthenticated access to system logs via WebSocket on…

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

Exploit for VMWare Workspace ONE Access chaining five CVEs for unauthenticated remote code execution via JDBC injection and privilege escalation.

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

POC of CVE-2022-36537

Exploit for the CVE-2024-5806

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

CVE-2025-60188 Atarim Plugin Exploit

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

An implementation of a vulnerable MCP server using mcp-go

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

CVE-2022-36537

Multiple exploits for Monitorr

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass