
djangohunter
Tool designed to help identify incorrectly configured Django applications that are exposing sensitive information.

Tool designed to help identify incorrectly configured Django applications that are exposing sensitive information.

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Retrieve AD accounts description and search for password in it


Standalone PoC for unauthenticated RTMP publish in SRS media servers; verifies the vulnerability, supports HTTP API side-channel check, and enables…

VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)

A script to detect if xz is vulnerable - CVE-2024-3094

CVE-2021-36934 PowerShell Fix

Simple ansible playbook to patch mysql servers against CVE-2016-6662

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536,…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

patch-manager

Bash script to detect vulnerable XZ Utils versions (CVE-2024-3094) and downgrade to a safe release, supporting multiple Linux distributions and…

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

mjml-app v3.0.4 & 3.1.0-beta RCE exploit

Detection and remediation for CVE-2021-3438 with Powershell