
nginx-mitigate-log4shell
Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script

Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

Scan for misconfigured S3 buckets across S3-compatible APIs!

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

Shell script and Ansible playbook to detect and remediate CVE-2024-3094 in xz-utils by checking package versions, upgrading or downgrading to a…

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

mjml-app v3.0.4 & 3.1.0-beta RCE exploit

Cloud-native Kubernetes cluster inspection tool that detects application misconfigurations, unhealthy components, and node problems using custom OPA,…

Checks a shared hosting environment for CVE-2017-9798

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by…

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.

A drop-in fix for CVE-2023-29689 - SSTI in PyroCMS, via a custom Twig Sandbox implementation

nameko Arbitrary code execution due to YAML deserialization