
gf
A wrapper around grep, to help you grep for things

A wrapper around grep, to help you grep for things

Documenting the internals of Fingerprint Pro's commercial agent, not the open-source FingerprintJS library

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Mind-Maps of Several Things

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

NCC Code Navigator

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the…

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

Detailed CVE-2024-55187 advisory with proof-of-concept for a remote code execution vulnerability in phpIpam, exploiting path poisoning and PHAR file…

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

Disclosure for CVE-2025-13339

Python script to detect CVE-2018-16858 vulnerability in target systems, enabling rapid identification and assessment of this specific security flaw.