
misfortune-cookie
Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

Exploit tool for CVE-2026-45833 in ChromaDB, enabling malicious model generation, reconnaissance, and data exfiltration from target collections via…

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Nuclei template for detecting and exploiting unauthenticated remote code execution in OpenCode via crafted HTTP requests.

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

Proof-of-concept exploit for CVE-2021-40438, an Apache HTTP Server mod_proxy vulnerability allowing request forwarding to arbitrary origins, with a…

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

Rust-based DNS enumeration and subdomain discovery tool for reconnaissance and penetration testing security assessments.

OSCP-legal network recon orchestrator for port discovery, service classification, and enum-only plugin dispatch across HTTP, SMB, FTP, SNMP, SSH, and…

Take a list of domains and probe for working HTTP and HTTPS servers

PoSh BloodHound Dog Whisperer

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Metasploit auxiliary module that identifies Emby Media Server version and exploits CVE-2020-26948 SSRF vulnerability to scan internal network…

CVE-2022-41741/742 Nginx Vulnerability Scanner

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

Multi-threaded router fingerprinting tool that identifies web-exposed network devices by analyzing HTTP responses, headers, and favicon hashes for…

Detects and identifies content management systems (CMS) used by web applications through HTTP response analysis and known signatures, aiding in…