
CVE-2019-9053
Python exploit for CVE-2019-9053 targeting a SQL injection vulnerability in CMS Made Simple. Automates time-based blind SQLi to extract admin…

Python exploit for CVE-2019-9053 targeting a SQL injection vulnerability in CMS Made Simple. Automates time-based blind SQLi to extract admin…

Alat ini mendeteksi potensi kerentanan React2Shell (CVE-2025-55182) dalam proyek React dengan memeriksa: - File `package.json` dan file lock untuk…

Prevent PHP vulnerabilities similar to CVE-2016-10033 and CVE-2016-10045.

There were no proper POCs for CVE-2023-30533 so I made one. (Reported by Vsevolod Kokorin)

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

struts1 CVE-2014-0114 classLoader manipulation vulnerability patch

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)

nodejsscan is a static security code scanner for Node.js applications.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

SQL / SQLI tokenizer parser analyzer

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.

patches for SNYK-JS-JQUERY-565129, SNYK-JS-JQUERY-567880, CVE-2020-1102, CVE-2020-11023, includes the patches for SNYK-JS-JQUERY-174006,…

CVE-2021-44228

A static analysis security vulnerability scanner for Ruby on Rails applications