
keyhacks
Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Project Wycheproof tests crypto libraries against known attacks.

Penetration tests guide based on OWASP including test cases, resources and examples.

Tips and Tutorials for Bug Bounty and also Penetration Tests.

Automating situational awareness for cloud penetration tests.

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and…

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

CVE-2018-25031 tests

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no…

Docker container implementing tests for CVE-2016-2107 - LuckyNegative20

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

A python script that tests for an exploitable instance of CVE-2018-1235.

This tool tests WordPress installations for XML-RPC authentication vulnerabilities.

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…