
CVE-2021-38647
Proof on Concept Exploit for CVE-2021-38647 (OMIGOD)

Proof on Concept Exploit for CVE-2021-38647 (OMIGOD)

Tool to spray AWS Console IAM Logins

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…


PowerShell framework to assess Azure security

Capturing, analysing and responding to cyber attacks

A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654

OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team,…

Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and…

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

Libvirt - Unauthenticated DoS Vulnerability (Exploit & Time Randomization to Thwart It)

Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.

vllm-project vllm version 0.5.2.2 is vulnerable to Denial of Service attacks.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging…

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…