
CVE-2026-64849.yaml
Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

Course repository for PowerShell for Pentesters Course

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

The detection of internal security controls at a company

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

CVE-2026-25049

Test for CVE-2000-0649, and return an IP address if vulnerable

Script fo testing CVE-2000-0649 for Apache and MS IIS servers

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.


CVE-2023-26083-Mali-InfoLeak-PoC

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

