
vulnhuntr
Zero shot vulnerability discovery using LLMs

Zero shot vulnerability discovery using LLMs

Go-based exploit for CVE-2024-34102, an XXE vulnerability in Adobe Commerce leading to remote code execution. Supports single and batch URL scanning…

Exploitation CVE-2024-34102

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

A Go-based wrapper for the KNOXSS API to automate XSS vulnerability testing.

A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.

Control Web Panel (CWP) vulnerability scenario related to CVE-2026-57517

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

This is a simple python tool to automatically deface webdav vulnerable websites.

SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

CRLFMap is a tool to find HTTP Splitting vulnerabilities

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

Exploits Kerberos reflection via Unicode normalization in Windows Active Directory to relay authentication to ADCS and MSSQL, enabling…