


🔍 Discover and scan vulnerable Next.js instances to protect your infrastructure from critical RCE vulnerabilities like CVE-2025-55182.

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

PoC of CVE-2025-1974, modified from the world-first PoC~

Mass vulnerability scanner targeting CVE-2024-36401 in GeoServer, using WFS requests to discover feature types and deliver payloads for automated…

Log4j Vulnerability RCE - CVE-2021-44228

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

DotDotPwn - The Directory Traversal Fuzzer

Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC

Automated scanner for CVE-2020-5902 (F5 BIG-IP RCE) using FOFA search engine to discover and exploit vulnerable targets.

This tool can be used to brute discover GET and POST parameters