
CryptoLyzer
Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Testing TLS/SSL encryption anywhere on any port

A list of web application security

Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350]

Dahua CVE-2026-29114

A library for detecting known secrets across many web frameworks

HikCentral Professional - Pre-Auth License ActiveCode Leak

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

CVE-2019-14222: Default Certificate in Alfresco Community

Checks for tpm vulnerabilities

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

Penetration tests guide based on OWASP including test cases, resources and examples.

A checker (site and tool) for CVE-2014-0160

[CVE-2019-14615] iGPU Leak: An Information Leakage Vulnerability on Intel Integrated GPU

A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber