


SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

CVE-2026-27174 - An unauthenticated remote code execution via the admin panel's PHP console feature

Detection for CVE-2025-40602

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading…

A unified console to perform the "kill chain" stages of attacks.

Scans a list of IPs to detect vulnerable H2 database consoles, identifying web pages and checking access restrictions for CVE-2021-42392.

A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.

Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature…