
Log-4j-scanner
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Integer overflow in Oniguruma

Poc of SSRF for Request-Baskets (CVE-2023-27163)

Tool to discover paths in web applications

Python PoC exploiting CVE-2026-27739 in Angular SSR: header injection via prototype pollution and SSRF chaining to AWS IMDS/GCP metadata for…

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

CVE-2026-42945 Nginx Rift

CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

Proof-of-concept exploit for CVE-2022-36163, a format string vulnerability in pdftoroff hovacui 1.1.0 PDF reader, demonstrating local…

ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory…

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

Batch vulnerability scanner that integrates FOFA to discover and test Apache APISIX Dashboard instances for CVE-2021-45232 unauthorized access.

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

WPQA < 5.5 - Unauthenticated Private Message Disclosure

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Liner's chat component, allowing attackers to tamper with other users'…

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1