
CVE-2022-1040
This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication

This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication

A flexible, composable authorization framework for Kit (inspired by Action Policy)

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

This Proof‑of‑Concept demonstrates a **Local Privilege Escalation** vulnerability in GNU inetutils `telnetd`. `telnetd` improperly passes…

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

Exploit for CVE-2026-7731 targeting cloud-native identity gateways by refracting JWT temporal validation to escalate privileges from admin:false to…

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token…

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

Exploit for CVE-2018-0114: re-signs JWT tokens by embedding an attacker-controlled public key in the JWS header, bypassing authentication in…

Responsible disclosure of unpatched vulnerability in FluentCRM by WPManageNinja

Proof-of-concept exploit for CVE-2017-8295, demonstrating unauthorized password reset in WordPress 4.7.4 by intercepting the reset link without prior…

Vertical Privilege Escalation via Session Storage by Amjad Ali (CVE-2023-43317)

Accessibility by AllAccessible <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Update

Repository contains description for CVE-2023-35794 discovered by Dodge Industrial Team for Dodge OPTIFY platfrom.

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

Authentication, authorization, traceability and auditability for SSH accesses.

HardeningKitty - Checks and hardens your Windows configuration

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW