
git-all-secrets
A tool to capture all the git secrets by leveraging multiple open source git searching tools

A tool to capture all the git secrets by leveraging multiple open source git searching tools

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS),…

CVE-2026-25632 — Fix Unsafe JSON Deserialization Leading to Remote Code Execution

Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

AI-powered assistant for penetration testers that generates payloads, analyzes code, performs reconnaissance, and executes command-line actions to…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.


Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

PoC: identify silent security patches before CVE

CVE-2017-12615 - Apache Tomcat Remote Code Execution (RCE)

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

Critical use-after-free vulnerability discovered in Tinyproxy

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.

CVE For Pterodactyl (For Study and Education)