
FreakVulnChecker
This script check if your list of server is accepting Export cipher suites and could be vulnerable to CVE-2015-0204

This script check if your list of server is accepting Export cipher suites and could be vulnerable to CVE-2015-0204

PoC toolkit that unpacks router firmware, decrypts device secrets, forges JWT tokens, and exploits CVE-2026-71960/71961 to take over Cudy WR3000 mesh…

Formalizing np1sec using Tamarin and other FM (see https://github.com/equalitie/np1sec)

CVE-2019-14222: Default Certificate in Alfresco Community

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

ROCA: Infineon RSA key vulnerability

Vulnerability Assessment and Auditing Framework for all the Crypto Implementations.

Independent IoT security research, vulnerability disclosures, and PoCs focusing on firmware analysis, hardware interfaces, and cryptographic flaws.

hands on investigation of the heartbleed vulnerability (CVE-2014-0160).

Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)

Parallel SSH service discovery and security auditor that scans any port, validates SSH banners, and audits authentication methods, weak cryptography,…

Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350]

Java-based tester for CVE-2022-21449 ECDSA signature verification vulnerability. Checks JVM for the Psychic Signatures bug and reports vulnerable or…

This Python PoC script detects the Heartbleed vulnerability (CVE-2014-0160) by performing a TLS handshake with heartbeat extension and sending a…

Multi-language PoC (Python · Go · JS · C) and technical documentation for CVE-2025-63353, a critical predictable-default-PSK vulnerability in…

This repo describes a vulnerability affecting the QR code based pairing process of the eWeLink IoT devices (CVE-2020-12702).

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…