
awscanner
Finds internet-exposed resources in an AWS account

Finds internet-exposed resources in an AWS account

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

CVE-2023-28432 POC

ActiveMQ系列漏洞探测利用工具,包括ActiveMQ 默认口令漏洞及ActiveMQ任意文件写入漏洞(CVE-2016-3088),支持批量探测利用。

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Service-Now Article Bruteforcer

CVE-2021-40875: Tools to Inspect Gurock Testrail Servers for Vulnerabilities related to CVE-2021-40875.

CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server


POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure

CVE-2023-28432 MinIO敏感信息泄露检测脚本

TEM FLEX-1080/FLEX-1085 1.6.0 log log.cgi Information Disclosure

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)

mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

Apache Kylin API Unauthorized Access