
keyguard
Scan codebases and GCP projects for exposed API credentials

Scan codebases and GCP projects for exposed API credentials

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

PoC for https://nvd.nist.gov/vuln/detail/CVE-2022-4361

Public reference for CVE-2025-56643 – Wiki.js 2.5.307 JWT Session Vulnerability

This script audits ServiceNow AI Agents for vulnerabilities like CVE-2025-12420, governance gaps, and compliance risks. Powered by CYBERDUDEBIVASH –…

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

A wrapper of voku/anti-xss for Laravel

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

PoC exploit for critical Budibase auth bypass: unanchored webhook regex lets attackers append ?/webhooks/trigger, reach protected APIs, and chain…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

CrowdStrike Feed Management System. CrowdFMS is a framework for automating collection and processing of samples from VirusTotal, by leveraging the…

Ingress NGINX Controller for Kubernetes

rabl 0.8.6 + fix for CVE-2014-4671

PowerShell Module for managing Microsoft Defender Advanced Threat Protection

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

List of API's for gathering information about phone numbers, addresses, domains etc