
ALPC-Enumerator
A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC

Asynchronous scanner and exploit tool for CVE-2025-5777 (CitrixBleed 2). Detects memory leaks in NetScaler ADC/Gateway, parses sensitive data like…

WordPress WP-Advanced-Search <= 3.3.9 - Unauthenticated SQL Injection

Emat: An email scraper that will scrape any website for Gmail, Yahoo, Hotmail and government email accounts.

Memory disclosure vulnerability in Citrix NetScaler ADC and Gateway when configured as a Gateway (VPN virtual server, ICA proxy, CVPN, RDP Proxy).

CrushFTP CVE-2025-31161 Exploit Tool 🔓

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Demonstration of CVE-2024-32002 exploitation with a Python-based proof-of-concept for vulnerability analysis and security testing.

Detection-only PoC for CVE-2026-21440 in AdonisJS BodyParser. Fingerprints AdonisJS indicators, probes upload endpoints via GET, and outputs…

Automated scanner and exploiter for CVE-2024-13513 in Oliver POS WordPress plugin, checking vulnerable installations and changing password-reset…

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847.

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

LFI Tikit eMarketing v6.8.3.0 (CVE-2023-49031)

Blind SQL Injection to RCE in a PHP open source application