
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection
POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Finding Ethereum nodes which are vulnerable to RPC-attacks

Proof-of-concept demonstrating a power analysis side-channel attack against a vulnerable RSA implementation on Arduino (Atmega328P), with detailed…

Go package that checks if RSA keys are vulnerable to ROCA / CVE-2017-15361

Research tool for studying vulnerable cryptographic key generation (brainwallet, PRNG, milksad, LCG, xorshift)

The PQC Network Scanner is a quantum‑focused network assessment tool that scans TLS/SSL certificates across enterprise environments to identify…

Private keys vulnerable to Debian OpenSSL bug (CVE-2008-0166)

Private keys generated with vulnerable keypair versions (CVE-2021-41117)

Detects CVE-2024-3596 in RADIUS/UDP traffic by analyzing MD5 collisions in Access-Request packets, helping administrators identify vulnerable…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

Demonstrates a timing side-channel in Kyber KEM decapsulation using a vulnerable C server and Python attack script, measuring ciphertext rejection…

Demonstrates AES-GCM nonce-reuse exploitation by collecting same-nonce ciphertexts, leading to GHASH key leakage, message forgery, and key recovery…

Proof-of-concept exploit for CVE-2024-22894, demonstrating 3DES-encrypted root password extraction from Alpha Innotec/Novelan heatpump firmware,…

Simple PowerShell script to check whether a computer is using an Infineon TPM chip that is vulnerable to CVE-2017-15361.

This script check if your list of server is accepting Export cipher suites and could be vulnerable to CVE-2015-0204