
CVE-2021-44228_scanner
Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.

Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.

Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510

:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:

Automated blind-xss search for Burp Suite

Network share sniffer and auto-mounter for crawling remote file systems

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。

This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific…

Nuclei template to detect CVE-2024-24919 by checking for /etc/shadow file leakage, enabling automated vulnerability scanning and security assessment.

Batch vulnerability scanner for CVE-2026-39363 in Vite dev server, exploiting WebSocket origin validation bypass to read arbitrary files via…

Go-based scanner for Apache Tomcat AJP file read/inclusion vulnerability (CVE-2020-1938). Detects and exploits Ghostcat to read arbitrary files or…

Python script to detect WordPress sites vulnerable to CVE-2020-35489 in Contact Form 7, allowing unrestricted file uploads. Scans domains or lists…

Batch verification script for CVE-2021-43798 in Grafana, written in Go, with 48 built-in checks to identify vulnerable instances and download the…

Nuclei template for CVE-2025-30208, exploiting a file read vulnerability in Vite. Includes search queries for Hunter, FOFA, and Shodan to identify…

CVE-2025-3515 WordPress lab for Drag and Drop Multiple File Upload for CF7: Dockerized PoC & Nuclei testing

This repo contains a script to automatically test sites for vulnerability to the Heartbleed Bug (CVE-2014-0160) based on the input file for the urls.

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

Wazuh SCA Linux hardening policy for Copy Fail (CVE-2026-31431)

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…