
CVE-2026-18963
Nuclei template to discover exposed Keycloak reset-credentials endpoints across multiple paths, aiding validation of CVE-2026-18963 exposure.

Nuclei template to discover exposed Keycloak reset-credentials endpoints across multiple paths, aiding validation of CVE-2026-18963 exposure.

Proof-of-concept demonstrating SSRF and LFI in Metabase versions < 0.40.5 (CVE-2021-41277), including internal network scanning and access to cloud…

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

Detection-only PoC for CVE-2026-21440 in AdonisJS BodyParser. Fingerprints AdonisJS indicators, probes upload endpoints via GET, and outputs…

OSINT tool that finds domains, subdomains, directories, endpoints and files for a given seed URL.

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Exploit for Grafana LFI vulnerability CVE-2021-43798 enabling unauthorized file reading via path traversal in plugin endpoints.

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Automated reconnaissance and information-gathering tool for penetration testing, designed to enumerate subdomains, endpoints, and network services.

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Find endpoints on GitHub.

Golang PoC exploit for CVE-2025-12139 targeting the Integrate Google Drive WordPress plugin. Extracts sensitive OAuth credentials (Client ID, Secret,…

Proof-of-concept for CVE-2026-37197: Server-Side Request Forgery (SSRF) in NukeViet CMS v4.5.07 admin remote upload, enabling internal network…

Proof-of-concept for CVE-2025-66698: authentication bypass in Veda v5.4.8 via empty ticket parameter, enabling enumeration of users, policies, and…