
katana
A next-generation crawling and spidering framework.

A next-generation crawling and spidering framework.

The official exploit for rConfig 3.9.2 Post-auth Remote Code Execution CVE-2019-16663

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

Python proof-of-concept for CVE-2026-33032 that inspects nginx status and configs, then demonstrates unauthorized config write with reload to deploy…

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Multiple exploits for Monitorr

Remote vulnerability scanner for CVE-2025-24514, an ingress-nginx auth-url injection leading to NGINX config manipulation and potential RCE.…

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API…

New Found 0-days!

CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6

Bulk vulnerability scanner for CVE-2023-23752 that extracts configuration data from vulnerable Joomla instances.

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

MAL-011: Log4J Misconfiguration Allows Malicious JavaScript in Red Hat AMQ

PoC for CVE-2026-8023: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2024-51442 write up and example config file

CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr