
nuguard
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

POC of CVE-2026-51031 for arbitrary local file read

An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions

方便实用的CVE-2026-39363利用工具

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1


Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint…

**CVE-2024-28987** is a critical vulnerability in SolarWinds Web Help Desk (WHD) that allows remote attackers to access sensitive ticket information…

PoC for CVE-2026-53629, blind SQL injection in the GLPI history log filter

CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

BOF-based tool to extract browser cookies and credentials from Chrome, Edge, and Firefox via handle duplication and fileless download, with offline…

Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Easy peasy file uploads

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.