
CVE-2025-22710
Proof-of-concept exploit for CVE-2025-22710, a blind SQL injection vulnerability in the Smart Manager WordPress plugin (<=8.50.0). Includes technical…

Proof-of-concept exploit for CVE-2025-22710, a blind SQL injection vulnerability in the Smart Manager WordPress plugin (<=8.50.0). Includes technical…

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

CVE-2026-44680 exploit framework for MikroORM SQL injection. Detects and exploits JSON path injection vulnerabilities with UNION-based and blind data…

Java classpath enumeration, focussed on CVE-2014-0043 for Apache Wicket 6.x

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Use IDA PRO HexRays decompiler with OpenAI(ChatGPT) to find possible vulnerabilities in binaries

Extract URLs, paths, secrets, and other interesting bits from JavaScript

A tool to hunt for credentials in github wild AKA git*hunt

🧬 Extract and analyze contributors info from git repos

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.

Code viewer and searcher for manual code review. Features multi-instance file browsing, inline note keeper, and grep-like search to assist security…

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

Command-line tool for fast searching of GitHub repositories, users, and commits to gather open-source intelligence and code-related information.

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation