
wonitor
fast, zero config web endpoint change monitor

fast, zero config web endpoint change monitor

A next-generation crawling and spidering framework.

Stage two containers

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Automated data harvesting tool for extracting sensitive information (backups, clones, address books) from web servers via targeted scanning and…

BeHat Configuration file leaking

Python proof-of-concept for CVE-2026-33032 that inspects nginx status and configs, then demonstrates unauthorized config write with reload to deploy…

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

Security advisory detailing broken access control in UZ801/ES-U3TS MifiService web API, allowing unauthenticated data extraction, config…

⚙️ NGINX config generator on steroids 💉

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…

ngxray — nginx config security scanner

Detect Citrix ADC SAML action or SAML iDP Profile config vulnerable to CVE-2020-8300 using Citrix ADC NITRO API

Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.

Bits generated while analyzing CVE-2019-6340 Drupal RESTful RCE

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")