
puppet-os-hardening
This puppet module provides numerous security-related configurations, providing all-round base protection.

This puppet module provides numerous security-related configurations, providing all-round base protection.

Non-destructive detector for unauthenticated RCE in BeyondTrust Remote Support and PRA, chaining argument injection and PostgreSQL escape bypass to…

Offline Java tool that scans jars and versions to determine exposure to seven netty-codec-http2 CVEs, recommending the single patched version that…

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.

Non-destructive PostgreSQL vulnerability checker for CVE-2026-6471. Audits server version and REPLICATION privileges to identify exposure to logical…

Mass exploit for CVE-2026-82329, an unauthenticated authentication bypass in JFrog Artifactory. Supports single-target and batch scanning with…

Non-intrusive detector for SonicWall SMA 1000 exposure to CVE-2026-83548/-83549 (version/patch-state check; no exploitation)

Exploit for CVE-2026-63077, an unauthenticated RCE in JetBrains TeamCity via deserialization. Supports mass scanning, multi-threading, and…

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your…

Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Non-destructive security assessment tool for CVE-2026-73296, checking authentication boundaries on exposed Mobile MCP HTTP servers (ports 8020/8021)…

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.

CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers…

ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…