
WPSniper
CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.
Valid JQuery that profiles the system and returns info to the server in a fake analytics GET request

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

Detection-only PoC for CVE-2026-21440 in AdonisJS BodyParser. Fingerprints AdonisJS indicators, probes upload endpoints via GET, and outputs…

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

Get Fine Grained Password Policy

Subdomain takeover vulnerability checker

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Enemies Of Symfony - Debug mode Symfony looter

Proof-of-concept exploit for CVE-2022-22954, a server-side template injection in VMware Workspace ONE Access Freemarker, enabling remote code…

Fast Golang Tool To Get Cname For Domains and Subdomain

Azure mindmap for penetration tests

Tool for mass testing ZeroLogon vulnerability CVE-2020-1472

Proof-of-concept exploit for CVE-2022-22954, a Freemarker server-side template injection in VMware Workspace ONE Access, with a one-line GET request…

CVE-2025-10035_GoAnywhere Get RCE

POC for VMWARE CVE-2022-22954