
CVE-2022-43959
Bitrix Vulnerability CVE-2022-43959

Bitrix Vulnerability CVE-2022-43959

Notes about attacking Jenkins servers

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github,…

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Vulnerable app with examples showing how to not use secrets

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

Pluggable linting tool to prevent committing credential.

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

A tool to capture all the git secrets by leveraging multiple open source git searching tools

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…