
ncccodenavi
NCC Code Navigator

NCC Code Navigator

Finding exposed secrets and personal data in GitLab

🧬 Extract and analyze contributors info from git repos

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).

PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).

This is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271

Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Tainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read

OWASP Foundation Web Respository

Tool to search secrets in various filetypes.

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.