
CVE-2026-54121-CertiGhost
CVE-2026-54121(CertiGhost) without MachineAccountQuota POC

CVE-2026-54121(CertiGhost) without MachineAccountQuota POC

OAuth Request Crafter

CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated…

A tool to extract the IdP cert from vCenter backups and log in as Administrator

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using…

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

An open source, self-hosted implementation of the Tailscale control server

Checklist of the most important security countermeasures when designing, testing, and releasing your API

fork of the popular jsch library

Exploits CVE-2026-39987 pre-auth RCE in Marimo <0.23.0 by connecting to the unauthenticated /terminal/ws WebSocket. Supports arbitrary command…

The full repo of all the labs available as part of the benchmark

This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication