
sarenka
OSINT tool - gets data from services like shodan, censys etc. in one app

OSINT tool - gets data from services like shodan, censys etc. in one app

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

NotebookLM on steroids — purpose-built for security researchers.

Static analysis scanner for CVE-2020-11023 XSS vulnerabilities in JavaScript. Detects vulnerable jQuery versions and dangerous DOM manipulation…

Bug's feed is a local hosted portal where you can search for the latest news, videos, CVEs, vulnerabilities...

A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.

【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day…

A Telegram Mass Surveillance Bot in Python

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

CVE-2015-6668, relacionada con el plugin WP Job Manager para WordPress (versiones ≤ 0.7.25).

Proof-of-concept exploits for CVE-2024-41453 and CVE-2024-41454 demonstrating stored XSS and malicious file upload vulnerabilities in ProcessMaker 4…

WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证