
CVE-2026-49097
PoC reproducer demonstrating HTTP header injection in Apache Camel camel-irc (CVE-2026-49097) that allows message redirection and information…

PoC reproducer demonstrating HTTP header injection in Apache Camel camel-irc (CVE-2026-49097) that allows message redirection and information…

Non-destructive WordPress exposure scanner and authorized PoC exploit tool for CVE-2026-63030/CVE-2026-60137. Features version fingerprinting, blind…

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

Detailed CVE-2026-39938 vulnerability report for Cacti ≤1.2.30, demonstrating unauthenticated LFI chained to OS command injection RCE with PoC, root…

🧬 Extract and analyze contributors info from git repos

Unauthenticated remote code execution exploit for Vehicle Management System in PHP via unrestricted file upload in newdriver.php and newvehicle.php,…

Proof-of-concept exploit for a path injection vulnerability in OpenPLC-v3 enabling arbitrary file read via unsanitized command-line arguments,…

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Hunt for AI coding artifacts containing secrets.

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

CVE-2025-13339 disclosure for unauthenticated arbitrary file read vulnerability in Hippoo Mobile App for WooCommerce plugin via path traversal in…

Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server…

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Nuclei template for detecting CVE-2025-53690 deserialization vulnerability in Sitecore XM/XP, enabling automated version fingerprinting and…

Proof-of-concept for CVE-2024-43018: SQL injection in Piwigo 13.8.0 via unsanitized max_level and min_register parameters, enabling information…

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github