
watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260
Detection artifact generator that verifies BMC FootPrints instances for pre-authenticated RCE chain (CVE-2025-71257, CVE-2025-71260) by bypassing…

Detection artifact generator that verifies BMC FootPrints instances for pre-authenticated RCE chain (CVE-2025-71257, CVE-2025-71260) by bypassing…

A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.

Java-based scanner that checks IP addresses for CVE-2024-24919 vulnerability, with interactive options to print response data and change target file…

Tool for mass testing ZeroLogon vulnerability CVE-2020-1472

Tool for mass testing ZeroLogon vulnerability CVE-2020-1472

YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228

Concurrent web directory and file brute-forcing tool that performs HEAD requests against a target URL using a wordlist, with support for custom…

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…

Scans WordPress sites for WP Time Capsule plugin CVE-2024-8856, detecting versions below 1.22.22 and logging vulnerable targets to a file.

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code.

Automated scanner for CVE-2019-12102 unauthenticated file upload vulnerability in Kentico CMS. Checks domains, verifies with hash parameter, and…

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

MailPoet Newsletters <= Arbitrary File Upload (exploiter)

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)