
CVE-2023-48795
Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…


Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…


Retrieve AD accounts description and search for password in it

Check for LDAP protections regarding the relay of NTLM authentication

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Source Code Management Attack Toolkit

The most exhaustive list of reliable DNS resolvers.

Filter and deduplicate large URL lists by removing static extensions, unwanted keywords, IDs, language variants, and parameters, producing clean…

A tool to query for the existence of pre-windows 2000 computer objects.

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

A tool for pointesters to find candies in SharePoint

A list of awesome penetration testing tools and resources.

C# Tool to interact with MS Exchange based on MS docs

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)