
hexstrike-ai
MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

AI-native security testing platform integrating 100+ tools with agentic orchestration, role-based testing, MCP-native tools, C2 capabilities, and…

autonomous red teaming platform; multi-agent offensive-security meta-harness

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞…

Public repository for improvements to the EXTRABACON exploit

Compile Go and C# programs into WASM-sandboxed native executables with polymorphic output, ghost profiling, and transparent Win32/macOS API bridging…

Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

WebKit NavigateEvent.canIntercept SOP bypass via cross-port interception — iOS 26.3.1 BSI (CVE-2026-20643)

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

An API hooking framework for intercepting and monitoring Windows applications

Proof-of-concept exploit for a Java gadget chain in the Mojarra library, demonstrating deserialization vulnerability exploitation for versions 2.3…

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

Intercept, inspect, and manipulate net.tcp-based WCF traffic with TLS and NTLM support. Decodes binary SOAP to XML for logging or HTTP proxy relay,…

Proof-of-concept exploit for CVE-2020-15999, a heap-buffer-overflow in Chrome's FreeType font rendering via crafted SBIX table, with ASAN crash…

Automated exploit for CVE-2025-66034, chaining path traversal and XML injection in fontTools varLib to achieve unauthenticated remote code execution…