
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

just record for myself

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

Python proof-of-concept exploit for CVE-2025-32375 in BentoML, demonstrating and validating the vulnerability against affected deployments.

OPNsense Root RCE (CVE-2026-57155)

Proof-of-concept exploit for CVE-2025-2563, demonstrating the vulnerability and providing reproduction steps for security researchers.

Detailed analysis of CVE-2025-7461, a SQL injection vulnerability in Modern Bag E-commerce System, including root cause, affected code, and…

Web vulnerability scanner written in Python3

AI-powered bug bounty hunting toolkit that works with or without subscription.

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Unauthenticated RCE in Open Web Analytics version <1.7.4

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Nmap script to detect VMware vCenter Server CVE-2021-21972 RCE vulnerability by probing the uploadova endpoint and checking for vulnerable response.

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2