
FinalRecon
Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Real-time GitHub monitoring tool that searches for exposed API keys, tokens, and credentials across multiple services using regex-based detection…

Research artifact repository containing fuzzing corpora (liblnk, tcpdump, vim), a Telegram privacy vulnerability report, and supporting scripts for…

Automated VirusTotal hunting report generator with scheduled delivery via email, Slack, Telegram, or Microsoft Teams. Supports CLI and JSON output…

Exploit Win10Pcap Driver to enable some Privilege in our process token ( local Privilege escalation )

C-based proof-of-concept for blind SQL injection in XWiki REST API (CVE-2025-32429). Detects WAF interference, iterates boolean and time-based…

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

Proof-of-concept exploit for CVE-2023-3047 SQL injection vulnerability in TMT Lockcell. Demonstrates manual exploitation using cURL and Burp Suite to…

Proof-of-concept exploit for a buffer overflow vulnerability in Tenda routers. Sends crafted unauthenticated POST requests to trigger a crash and…

C-based proof-of-concept exploit for CVE-2025-7753, a time-based SQL injection in Online Appointment Booking System 1.0. Uses libcurl for HTTP…

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

Proof-of-concept exploit script for CVE-2017-7679, an Apache Struts remote code execution vulnerability, demonstrating exploitation for security…

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

Proof-of-concept exploit for CVE-2026-70559, shared via Telegram, demonstrating exploitation of the underlying vulnerability.

Automated vulnerability scanner that detects exposed BeHat configuration files and sends Telegram notifications. Ideal for bug bounty hunters and…

Frida-based proof-of-concept demonstrating authentication bypass in Telegram Android by hooking SharedConfig.checkPasscode to always return true,…

Automated vulnerability scanner for CVE-2023-28121 that checks a list of targets concurrently and delivers results via Telegram notifications.

Detailed analysis and PoC for CVE-2025-67887/86 RCE in 1C-Bitrix Translate module, including exploit chain, CVSS scoring, and mitigation…