
auth-bypass-CVE-2025-40554
Proof-of-concept exploit for CVE-2025-40554, an authentication bypass in SolarWinds Web Help Desk. Includes Nuclei template and Python exploit for…

Proof-of-concept exploit for CVE-2025-40554, an authentication bypass in SolarWinds Web Help Desk. Includes Nuclei template and Python exploit for…

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

Cobalt Strike HTTPS beaconing over Microsoft Graph API

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

A PoC exploit for CVE-2020-13945 - Apache APISIX Remote Code Execution (RCE)

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Fingerprint OpenAI-compatible LLMs from tokenizer and behavior signals.

CVE-2022-24112_POC

Alibab-Nacos-Unauthorized-Reset PWD

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…