
CORStest
A simple CORS misconfiguration scanner

A simple CORS misconfiguration scanner

A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

Proof-of-concept and analysis for CVE-2020-1947, a YAML deserialization remote code execution vulnerability in Apache ShardingSphere UI, including…

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.

A specialized vulnerability scanner designed to detect CVE-2024-38526, the Polyfill.io Supply Chain Attack, helping organizations identify and…

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

Solar Appscreener XXE

CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr

This repository contains **research and analysis** related to CVE-2025-29927. It demonstrates safe, controlled testing approaches for a path…

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure