
SpoofcheckSelfTest
Web application that lets you test if your domain is vulnerable to email spoofing

Web application that lets you test if your domain is vulnerable to email spoofing

Exploit module for Apache JSPWiki CVE-2019-10077, targeting a Java-based wiki platform with JAAS authentication and access control. Enables…

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

Exploit for CVE-2022-24716 in Icinga Web 2, allowing unauthenticated file disclosure of configuration files containing database credentials.

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

Open Source Cloud Native Application Protection Platform (CNAPP)

Automated Tor-based shared web hosting server with PHP multi-version support, email routing, auto-scaling Tor instances, and built-in security…

Automated PHP configuration auditor that scans php.ini for security misconfigurations, supports CLI and web modes, and outputs results in text, HTML,…

OWASP Thick Client Application Security Verification Standard

Web interface for the nftables firewall on Linux, written in Go. The apply undoes itself after 120 seconds unless you confirm it — you cannot lock…

HikvisionExploiter - это Python утилита созданная для автоматизации сканирования и проверки прямого доступа к сети камер Hikvision, нацеленная на…

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

A web version of the bash scripts wrote for Check Point CVE-2026-50751 and CVE-2026-50752. This uses a local server to scan and make changes using…

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…