
askWAM
Ask the Web Account Manager (WAM) for Entra ID tokens

Ask the Web Account Manager (WAM) for Entra ID tokens

JFrog Artifactory 预认证全链 RCE 复现项目(CVE-2026-42018 / CVE-2026-65616 / CVE-2026-65615):完整攻击链报告、7.146.7 Docker 复现交付物(EXP / 部署 / 基线验证 / payload 样本 / 恢复工具)

cPanel & WHM - Authentication Bypass via Session-File CRLF Injection

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Exploit PoC for CVE-2026-41940, a cPanel & WHM authentication bypass via CRLF injection. Includes mass scanning, post-exploitation actions, and an…

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…

cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

In-memory token vault BOF for Cobalt Strike

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

A C# utility for interacting with SCOM

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…