
in-toto
Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

CyberArk Conjur automatically secures secrets used by privileged users and machine identities

Review Access - kubectl plugin to show an access matrix for k8s server resources

DLL Injection tool to unlock guest VMs

An open-source framework for verifiably private AI inference

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit

Simple Secure Keeper for Secrets

cve-2022-23131

Zero-Trust SSH CA

Proof-of-concept exploit for GNU Inetutils telnetd authentication bypass (CVE-2026-24061) with Docker lab setup and Go PoC. Exploits NEW-ENVIRON…

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

ManageEngine Service Desk Plus 10.0 Privilaged account Hijacking

Authentication bypass exploit for CVE-2026-32746 targeting legacy Telnet servers, with defensive guidance and Go-based implementation for authorized…

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

CVE Reproduction: cve-2024-0012_9474-panos_authbypass_reproduction