
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Python proof-of-concept exploit for CVE-2025-32375 in BentoML, demonstrating and validating the vulnerability against affected deployments.

Detailed analysis of CVE-2025-7461, a SQL injection vulnerability in Modern Bag E-commerce System, including root cause, affected code, and…

A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.

A vulnerability scanner that detects CVE-2021-21980 vulnerabilities.

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)

Web vulnerability scanner written in Python3

A proof of concept for Joomla's CVE-2015-8562 vulnerability (Object Injection RCE)

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package. Demonstrates exploitation of improper…

This repository contains combined exploits for two vulnerabilities in Moodle, a widely used open-source learning management system (LMS)


CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Nmap script to detect VMware vCenter Server CVE-2021-21972 RCE vulnerability by probing the uploadova endpoint and checking for vulnerable response.

Highly configurable script for dictionary/spray attacks against online web applications.

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.