
CVE-2025-3248
Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Python proof-of-concept for CVE-2025-11740; triggers the vulnerability to verify exposure and support remediation in authorized security tests.

Proof-of-concept exploit for CVE-2026-72898 in Metabase, with technical reproduction steps and usage guidance for validating the vulnerability during…

UT based automated fuzz driver generation

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and…

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

Plugin For BurpSuite (Pentester)

This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.

CLI tool for the Horizon3.ai API

Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)

AI Smart Contract Security Analysis and PoC Generation Framework

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Project Wycheproof tests crypto libraries against known attacks.

Script to update Windows Recovery Environment to patch against CVE-2022-41099

CVE-2014-2630 exploit for xglance-bin

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…


Docker container implementing tests for CVE-2016-2107 - LuckyNegative20