
macOS-enterprise-privileges
This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.

🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For…

Exploit module for Apache JSPWiki CVE-2019-10077, targeting a Java-based wiki platform with JAAS authentication and access control. Enables…

Minimal Java web application to reproduce CVE-2022-32532, an Apache Shiro RegExPatternMatcher authentication bypass via newline characters in URLs.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

NSE plugin for Nmap that scans a DotNetNuke (DNN) web application for an Administration Authentication Bypass vulnerability (CVE-2015-2794, EDB-ID:…

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

Open source Dropbox-like file sharing with full client encryption !

A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692

Reproduction environment for CVE-2025-29927, demonstrating Next.js middleware authorization bypass via the x-middleware-subrequest header. Includes…