
cve-2026-15748
Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Course repository for PowerShell for Pentesters Course

Finds CSP report urls and tests to see if they are vulnerable to log4j

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

Finds public elite anonymity proxies and concurrently tests them

A network data locater using credentials obtained during penetration tests

Azure mindmap for penetration tests

Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

OpenSSL CVE-2014-0160 Heartbleed vulnerability test

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…



Barcha is your Swiss‑Army knife for SQL Injection reconnaissance 🔍. Written in Go, it automates: Shodan enumeration of SSL hosts 🕵️♂️ Liveness &…

Unified network toolkit for Linux — Python 3 + PySide6

🔍 Next.js RCE Scanner (CVE-2025-55182) - Automated vulnerability scanner using Zoomeye search engine. Discovers targets via dorks and tests for…

This C# tool sprays for admin access over the entire domain

Test CIDR blocks for CVE-2014-0160/Heartbleed

Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.