
GrafXploit
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…

Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…

Daily-updated JSON repository of NVD/CVE vulnerability data, enabling easy retrieval and git-based exploration of CVE modification history for…

Async mass-checker for authorized internal testing of CVE-2026-2631 exposure.

CVE-2019-0708-Msf-验证

chrome extension to detect next.js sites vulnerable to CVE-2025-55182 (react2shell)

Proof of concept demonstrating unauthenticated access to user resumes via directory listing in CodeAstro Online Job Portal, with reproduction steps…

Proof-of-concept for absolute path disclosure in Veno File Manager 4.4.9 via an unauthenticated GET request to a debug script, revealing the server's…

CVEHub of CVE-2023-1498 and CVE-2023-1500

Proof-of-concept exploit for CVE-2026-37064: unauthenticated user enumeration in Veno File Manager 4.4.9 via crafted POST request to…

Proof-of-concept exploit for CVE-2026-37070: an authenticated attacker can read arbitrary uploaded files in Veno File Manager 4.4.9 via a crafted GET…

The modern, high-speed successor to nsec3walker. A specialized NSEC3 forensics engine built in Go for rapid zone harvesting and automated hash…

Proof-of-concept exploit for GitLab stored XSS (CVE-2022-1175) enabling personal access token theft and account takeover via malicious issue comments.

Python-based scanner to detect CVE-2014-6271 (Shellshock) vulnerability in CGI-enabled servers, using Google search to discover potential targets.

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

Detection-only PoC for CVE-2026-21440 in AdonisJS BodyParser. Fingerprints AdonisJS indicators, probes upload endpoints via GET, and outputs…

A Python tool leveraging Shodan and Scapy to identify and exploit Windows systems vulnerable to CVE-2024-38063, enabling targeted Denial of Service…

AlienTec-Recon-Tool

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…