
terrapod-PoC
PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthenticated access to Superset instances for…

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

Optiva-Framework 🔎 Web Application Scanner🕵️

Disrupt WAF by abusing SSL/TLS Ciphers

scavenger : is a multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as…


Local file inclusion exploitation tool

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.