
GPON
Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor…

Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor…
Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻

A curated list of resources related to Industrial Control System (ICS) security.

pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

Shodan Dorks

CVE-2025-49844 (RediShell)

:poodle: Poodle (Padding Oracle On Downgraded Legacy Encryption) attack CVE-2014-3566 :poodle:

Spring4Shell - Spring Core RCE - CVE-2022-22965

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Audits GitLab projects against the CIS GitLab Benchmark via read-only API checks, generating JSON reports on compliance and hardening recommendations.

Black-box security evaluation of five ISP cable modem/router gateways, analyzing firmware images and documenting 35+ vulnerabilities including…

POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal

Red portatil de reconocimiento inteligente con IA offline

Educational lab environment with a proof-of-concept exploit for CVE-2025-49844 (RediShell), a critical use-after-free in Redis Lua interpreter,…

A PoC for CVE 2023-20198