
pfsense-security-research
Authenticated Arbitrary File Read in pfSense 2.8.0 via Diagnostics Web Interface (CVE-2025-53392)

Authenticated Arbitrary File Read in pfSense 2.8.0 via Diagnostics Web Interface (CVE-2025-53392)

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

Poc for CVE-2023-22515

CVE Reproduction: cve-2025-24472-fortinet_authbypass_reproduction

Improper Access Control in Mysterium Node before v1.36.0

Gigamon Unauth RCE (CVE-2026-36848)

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 |…

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and…

Citrix Sharefile vulnerability check and fast research details


VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

CVE-2019-16097-batch

Passive security checker for CVE-2026-48908 affecting SP Page Builder.