
wp2shell-PoC
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

AI-powered threat intelligence platform for automated CVE/ransomware monitoring, domain surveillance, data leak detection, and incident response with…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

Content hijacking proof-of-concept using Flash, PDF and Silverlight

Grafana Unauthorized arbitrary file reading vulnerability

baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.


High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

CVE-2023-24055 PoC (KeePass 2.5x)

DNS-based data exfiltration testing tool with bidirectional transfer, web UI, and client script for detecting blind RCE/XXE vulnerabilities in…

The Outlook HTML Leak Test Project

smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares

Exploiting CVE-2021-44228 in vCenter for remote code execution and more.


Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…