
langflow-cors-scanner
Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

MDE/MDI Defender setup for Ludus

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536,…

ngxray — nginx config security scanner

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536,…

CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr

PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials,…

MAL-011: Log4J Misconfiguration Allows Malicious JavaScript in Red Hat AMQ

BeHat Configuration file leaking

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.

Proof-of-concept exploit for CVE-2020-5410 targeting Spring Cloud Config directory traversal vulnerability to access sensitive configuration files.

New Found 0-days!
