
CVE-2026-64849.yaml
Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Scan for and exploit CVE-2024-24919 in Check Point Security Gateways, an unauthenticated arbitrary file read that can expose credentials and lead to…

AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability…


This script automates SQL injection testing using SQLMap with AI-powered decision making.

CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…

Rust-powered HTTP Request Smuggling Scanner.

Mass scanner for Joomla Helix3 CVE-2026-49049 that uploads PHP test payloads via com_ajax and detects executed (RCE) or raw PHP responses.

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

A Burp Extension designed to identify argument injection vulnerabilities.

BlueKeep scanner supporting NLA

Detection for CVE-2025-11371

Detection for CVE-2025-61882 & CVE-2025-61884

Web application that lets you test if your domain is vulnerable to email spoofing

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.