
bloodyAD
LDAP-based Active Directory privilege escalation framework supporting pass-the-hash, pass-the-ticket, and certificate authentication for automated…

LDAP-based Active Directory privilege escalation framework supporting pass-the-hash, pass-the-ticket, and certificate authentication for automated…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Testing tool for the Mikrotrick exploit (CVE-2026-67276)

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

Generates detection artifacts to verify cPanel/WHM authentication bypass vulnerability (CVE-2026-41940) and tests targets for exposure.

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

Python helper to scan Fortinet web management for CVE-2026-24858 SSO authentication bypass and optionally send explicit payloads with user…

Batch scanner for CVE-2026-24061 Telnet authentication bypass, with port liveness checks and automated payload attempts for authorized penetration…

A scanner for the FortiNet vulnerability CVE-2025-64446

A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability

PoC exploit for CVE-2025-0108 - PAN-OS Authentication Bypass

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

A Scanner for CVE-2024-1709 - ConnectWise SecureConnect Authentication Bypass Vulnerability

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing attack to inject a sudo user and gain root shell on vulnerable…

automated password spraying tool

🔥 A powerful MongoDB auditing and pentesting tool 🔥