
CVE-2026-64849.yaml
Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

CVE-2023-26083-Mali-InfoLeak-PoC

CVE-2026-25049

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.


The detection of internal security controls at a company

CVE-2022-23779 is a security vulnerability in Zoho ManageEngine Desktop Central ,Testing for CVE-2022-23779 using curl

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.

Microsoft Network Service Fingerprinting Tool

API Scraper Agent for Web API's

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.


PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

Unauthenticated Arbitrary File Read via Absolute Path