
mongoaudit
🔥 A powerful MongoDB auditing and pentesting tool 🔥

🔥 A powerful MongoDB auditing and pentesting tool 🔥

AD Enum is a pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesses with kerberos.

VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Scanner: CVE-2026-41091/45498 Microsoft Defender LPE/DoS — Python scanner for Windows Defender privilege escalation (CISA KEV)

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

🔪 :octocat: Leak git repositories from misconfigured websites

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Open-source cloud security platform that discovers attack paths, identifies misconfigurations, visualizes IAM access, and provides step-by-step…

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian

A tool to hunt for publicly accessible DigitalOcean Spaces

Prommetrix can obtain relevant information from the instances of 'Node Exporter' executed by 'Prometheus'.

An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0…

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

A Cloudflare resolver that works