
CVE-2024-10924
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass

PowerShell script to enumerate Azure Active Directory access permissions, including role assignments, service principals, and privileged access…

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without…

Python PoC for CVE-2024-36042 authentication bypass in Silverpeas < 6.3.5. Features version detection, multi-threaded user enumeration, message…

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

Repository for CVE-2023-4800 vulnerability.

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Python exploit for CVE-2022-36537, an authentication bypass in ZK Framework affecting R1Soft Server Backup Manager, allowing retrieval of web context…

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

POC of CVE-2022-36537

An implementation of a vulnerable MCP server using mcp-go

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…