
webstor
Enumerates all websites across an organization's networks via DNS zone transfers and masscan, stores responses, and enables querying for known…

Enumerates all websites across an organization's networks via DNS zone transfers and masscan, stores responses, and enables querying for known…

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

Fast, accurate subdomain takeover scanner with zero false positives. Detects vulnerable subdomains, collects metadata (IP, CNAME, title, status…

Safely detect whether a UniFi OS Server is vulnerable to CVE-2026-34908

Accurately fingerprint and detect vulnerable (and patched!) versions of Netscaler / Citrix ADC to CVE-2023-3519

This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.

A simple scanner for identifying vulnerable cups-browsed instances on your network

IBM Maximo Asset Management is vulnerable to Information Disclosure via XXE Vulnerability (CVE-2020-4463)

WordPress security scanner that enumerates vulnerable plugins, themes, and users to identify misconfigurations and known vulnerabilities for…

Python exploit script for CVE-2021-26855 (Microsoft Exchange Server SSRF) with integrated ZoomEye dork for mass scanning and detection of vulnerable…

Proof-of-concept scanner that checks hosts for CVE-2021-41773 Apache path traversal vulnerability, reporting vulnerable or not vulnerable status.

The script checks Jenkins endpoints for CVE-2024-43044 by retrieving the Jenkins version from the innstance and comparing it against known vulnerable…

OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team,…

Detection artifact generator for CVE-2026-20253 Splunk Pre-Auth RCE. Probes the PostgreSQL Sidecar Service endpoint to identify vulnerable Splunk…

Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)

Scanner for Zyxel products which are potentially vulnerable due to an undocumented user account (CVE-2020-29583)

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

Quickly identifies servers vulnerable to OpenSSH 'regreSSHion' (CVE-2024-6387).