
OA-tongda-RCE
Office Anywhere网络智能办公系统

Office Anywhere网络智能办公系统

cve-2022-23131 zabbix-saml-bypass-exp

CVE-2025-29927 Proof of Concept

Veeam Backup Enterprise Manager Authentication Bypass (CVE-2024-29849)

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using…

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Python-based framework for generating Golden SAML tokens, Kerberos tickets, and Azure Access Tokens to exploit federated identity systems and…

An Android HW Attestation demo

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Exploit for Keycloak CVE-2026-18963 enabling unauthenticated account takeover via reset-credentials bypass. Includes safe detection, non-destructive…

Openfire Console Authentication Bypass Vulnerability with RCE plugin

Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit

Proof-of-concept exploit for CVE-2021-24085: CSRF-based elevation of privilege in Microsoft Exchange Server via msExchEcpCanary token forgery,…

Proof-of-concept exploit for authentication bypass in ConnectWise ScreenConnect, enabling addition of administrative user as first step to Remote…

C exploit for CVE-2021-3560, an authentication bypass in polkit enabling unprivileged users to create a privileged account via DBus, with a detailed…

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

ProxyToken (CVE-2021-33766) : An Authentication Bypass in Microsoft Exchange Server POC exploit