
fleet
Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

Python scripts for inventorying GeoServer WFS endpoints and verifying time-based SQL injection vulnerabilities in PostGIS/GeoTools, with a dedicated…

Go CLI that inventories HTTPS endpoints negotiating HTTP/2 via ALPN to identify systems requiring CVE-2023-44487 mitigation review. Non-exploitative,…

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Proof-of-concept checker for CVE-2025-10951, an unauthenticated path traversal in ml-logger, validating arbitrary file read via /glob and /stream…

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Bash-based proof-of-concept tester for CVE-2026-23550. Checks WordPress modular connector login endpoints for admin cookie issuance and verifies…

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

🔍 Recon notes organizer for bug bounty hunters and CTF players — subdomains, ports, endpoints, vulns, all in one place.

Proof-of-concept for CVE-2026-37197: Server-Side Request Forgery (SSRF) in NukeViet CMS v4.5.07 admin remote upload, enabling internal network…

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

CVE-2026-44277

Automated XSS validation pipeline for CVE-2020-3580 with Shodan-based discovery, scope matching, and approval-gated canary testing for Cisco ASA/FTD…

Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could…