
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Offline MongoDB analysis tool detecting CVE-2025-14847 exploitation via log correlation, assert count analysis, and FTDC spike detection. Supports…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A new open-source tool to quickly audit SAP permissions.

Educational research tool demonstrating CVE-2025-14847 memory disclosure in MongoDB's BSON decompression. Simulates bounds-checking failures and…

Automated tool for bypassing authentication and deploying backdoors on ZKSoftware ZMM100 fingerprint access control devices via Telnet, with database…

Python decryption tool for SSCMS CMS encrypted database configurations and user passwords using a hardcoded DES key and IV.

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

The easiest, and most secure way to access and protect all of your infrastructure.

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

Proof-of-concept exploits for CVE-2026-42167, a SQL injection vulnerability in ProFTPD's mod_sql logging pipeline enabling unauthenticated SQL…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Exploit framework for Discuz! X5.0 authentication bypass (CVE-2026-49952) enabling unauthenticated database backup access via UC_KEY token reuse.…

Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402