
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Automated testing to find logic and performance bugs in database systems

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Automatic SQL injection and database takeover tool

Exploit CVE-2025-14847 (MongoBleed) to disclose sensitive heap memory from MongoDB servers. Python-based scanner with detailed vulnerability reports…

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

The easiest, and most secure way to access and protect all of your infrastructure.

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

Exploits chained WordPress REST API SQL injection to enumerate databases and dump tables, with UNION-based, parallel boolean-blind, and time-based…

Exploit framework for Discuz! X5.0 authentication bypass (CVE-2026-49952) enabling unauthenticated database backup access via UC_KEY token reuse.…

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

CVE-2026-23479 Redis Use-After-Free vulnerability detection tool

Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…