
CVE-2025-23048-POC
Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Pattern recognition for hosts, services, and content

Login Area Finder: scans host/s for login panels

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

Metasploit module for massive Denial of Service using #Bluekeep vector.


Generates lists of live hosts and URLs for targeting, automating the usage of MassDNS, Masscan and nmap to filter out unreachable hosts and gather…

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

This repository hosts PoC exploits for vulnerabilities I've discovered, provided for education and to highlight the importance of system security.

Materials for CVE-2024-30052.

Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or…

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets,…

Log4Shell (CVE-2021-44228) docker lab

A cheatsheet for exploiting server-side SVG processors.

Exploit for CVE-2024-3273, supports single and multiple hosts

Detection script for telnetd CVE-2026-32746 that probes remote hosts to identify vulnerable LINEMODE support via TCP connection, generating detection…