
disclosure-check
Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.

Demonstrates an unauthenticated enumeration vulnerability in a public certificate lookup endpoint, exposing personal data such as CPF and RG.…

Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A workflow to gather responsible disclosure emails from a given host(s).

🔵 Threat analysis writeup for Follina (CVE-2022-30190) — Microsoft MSDT RCE zero-day exploited in the wild. Covers static analysis, VirusTotal,…

Modern CLI for exploring vulnerability data with powerful search, filtering, and analysis capabilities.

This repository documents the process of identifying, analyzing, and gathering Open Source Intelligence (OSINT) on a specific security vulnerability…

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

Extraction of iMessage Data via XSS

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

Step-by-step SOC analyst walkthrough for investigating and remediating CVE-2024-3400 (PAN-OS command injection). Covers detection, log analysis,…

Osqery extension HP BIOS WMI

Maltego transform to detect the OpenSSL Heartbleed vulnerability (CVE-2014-0160)

CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server…

Detecting vulnerabilities like CVE-2024-0762, particularly in UEFI firmware, is quite challenging due to the low-level nature

GUI Shodan-powered scanner to identify n8n instances exposed to CVE-2025-68613 (version range 0.211.0–1.122.0)