
naabu
A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…

A next-generation crawling and spidering framework.

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Python proof-of-concept for CVE-2026-33032 that inspects nginx status and configs, then demonstrates unauthorized config write with reload to deploy…

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

Cisco Email Security Appliance: Remote Code Execution - RCE from config file

Windows post-exploitation reconnaissance agent that collects system info, privileges, patches, defenses, network config, credentials, and persistence…

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

Security advisory detailing broken access control in UZ801/ES-U3TS MifiService web API, allowing unauthenticated data extraction, config…

Proof-of-concept exploit for CVE-2026-42281, an unauthenticated SSRF in MagicMirror² ≤ 2.35.0, enabling config exfiltration, cloud metadata probing,…

Scans internet-exposed cPanel/WHM instances for CVE-2026-41940 authentication bypass, probing HTTPS on port 2087 and matching response markers to…

Exploit for CVE-2026-31431, a Linux kernel AF_ALG AEAD page-cache write vulnerability enabling unprivileged arbitrary 4-byte writes to readable files…

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…