
WordPressMassExploiter
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Technical advisory detailing an authenticated path traversal vulnerability in Grav CMS's Twig media_directory() function, enabling arbitrary…

An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

VulDB advisory: jshERP authenticated /user/info IDOR and password-digest replay after CVE-2025-60800

Demonstrates a critical JWT signing key predictability vulnerability in PowerJob Server, allowing offline key derivation and token forgery for admin…

Burp Suite extension for spoofing IP addresses in HTTP requests, enabling testing of server-side IP restrictions and bypassing IP-based access…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Proof-of-concept exploit for CVE-2025-9974 targeting Nokia Beacon routers, demonstrating the vulnerability and providing a basis for security testing…

CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security…

Curated repository of security advisories and vulnerability disclosures researched and reported by the author, including CVE-2025-70336, a stored XSS…

Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

Exploit for CVE-2023-39361 in Cacti, a network graphing solution, demonstrating SQL injection vulnerability for educational and security testing…

Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

Browser resource exhaustion payload that crashes target systems via memory, GPU, audio, and rendering overload. Designed for authorized security…