
boa-cve-2009-4496-analysis
Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.

Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A workflow to gather responsible disclosure emails from a given host(s).


Extraction of iMessage Data via XSS

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

Maltego transform to detect the OpenSSL Heartbleed vulnerability (CVE-2014-0160)

CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server…

GUI Shodan-powered scanner to identify n8n instances exposed to CVE-2025-68613 (version range 0.211.0–1.122.0)

Check a list of Pterodactyl panels for vulnerabilities from a file.

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

A list of web application security

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.

Social Network Tabs Wordpress Plugin Vulnerability - CVE-2018-20555