
Wordpress-Vulnerability-Identification-Scripts
Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

Automates Domain Name System (DNS) zone transfer testing. Checks for CVE-1999-0532 by automatically finding a given domains nameservers, and tests…

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

Full automation check for CVE-2025-14847 MonogBleed- Finds origin IP and tests for exploit.

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Find web directories without bruteforce

MSDAT: Microsoft SQL Database Attacking Tool

Course repository for PowerShell for Pentesters Course

OpenSSL CVE-2014-0160 Heartbleed vulnerability test

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Unified network toolkit for Linux — Python 3 + PySide6

This C# tool sprays for admin access over the entire domain

This script can be used to check if a Bluetooth device is vulnerable to CVE-2025-36911.

Safely test Arista NGFW for information disclosure

Test CIDR blocks for CVE-2014-0160/Heartbleed