


Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287

The easiest, and most secure way to access and protect all of your infrastructure.

Redacted cPanel/WHM authentication bypass analysis and authorized checker

CVE-2018-10933 very simple POC


This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

fork of the popular jsch library

An implementation of a vulnerable MCP server using mcp-go

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Pull Request-like Review/Approval flow for database queries. For compliant but smooth Engineering access to production.

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Simple Secure Keeper for Secrets

CVE-2026-20896 Gitea Docker X-WEBAUTH-USER auth bypass checker

Unauthenticated administrator takeover exploit for CVE-2026-66012 using MCP missing authorization to exfiltrate credentials and achieve remote code…

Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

Critical vulnerability in next.js : Bypass middleware authentication