
opa
Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Repository for CVE-2023-4800 vulnerability.

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

A tool to scan Kubernetes cluster for risky permissions

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Workaround guide for CVE-2022-41923 privilege management vulnerability in Grails Spring Security Core plugin, providing patched filter definitions…

Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)

This skill helps Claude write secure code and prevent common vulnerabilities.

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

Python proof-of-concept for LDAP anonymous bind privilege escalation, simulating insecure ACLs to create admin users via unauthenticated LDAP binds.

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

Critical vulnerability in next.js : Bypass middleware authentication

Missing Authorization in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100