
CVE-2025-3248
Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Python proof-of-concept for CVE-2025-11740; triggers the vulnerability to verify exposure and support remediation in authorized security tests.

Proof-of-concept exploit for CVE-2026-72898 in Metabase, with technical reproduction steps and usage guidance for validating the vulnerability during…

Course repository for PowerShell for Pentesters Course

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and…

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege


LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

Specify targets and run sets of tools against them


This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.

A collection of selenium tests that might aid it takeover of a selenium node

AI Smart Contract Security Analysis and PoC Generation Framework

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…