
reconix
Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.


Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

A fast WordPress plugin enumeration tool

Chrome v8 1Day Exploit by István Kurucsai

Academic purposes only. Attack against Salesforce lightning with guest privilege.

POC for Veeam Backup and Replication CVE-2023-27532

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

public exploits


Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit


Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

SonicWall SSL-VPN RCE

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)