
OpenHunterAI
Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

Exploit script for CVE-2021-41773 (Apache Path Traversal) with Docker setup and multi-target scanning via URL or list.

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

Check for LDAP protections regarding the relay of NTLM authentication

KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration,…

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

Pentester-focused Docker registry tool to enumerate and pull images

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

CVE-2026-33340: Critical SSRF in lollms-webui /api/proxy - Unauthenticated arbitrary request forgery (CVSS 9.1)

AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual…

CVE2PoC is a tool that helps penetration testers, bug hunters, and security researchers quickly find public exploits or PoCs related to a CVE ID

Proof-of-concept exploit for FoxCMS v1.2.5 remote code execution via the index.html component, with FOFA dork for target discovery.

Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence