
deptrust
CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

Scanner and proof-of-concept exploit for Log4j RCE (CVE-2021-44228). Creates a vulnerable application and runs the exploit with a netcat listener.

Bash script to detect Log4j (CVE-2021-44228) exploitable systems by scanning running Java processes for vulnerable log4j-core components without…

Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool

Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

REC Exploit is a Python-based security testing tool that automates detection of potential RCE conditions in web applications under authorized…

Automated scanner for CVE-2025-55182 RCE in Next.js with 8 WAF bypass techniques, custom command execution, and test-only detection mode for…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

A collection of custom security tools for quick needs.

Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

a security scanner for custom LLM applications

Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time…

Concurrent web directory and file brute-forcing tool that performs HEAD requests against a target URL using a wordlist, with support for custom…

Automate NMAP Scans and Generate Custom Nessus Policies Automatically

Automate NMAP Scans and Generate Custom Nessus Policies Automatically

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

Command-line scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…