
cve-2026-15748
Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into…

This Repositories contains list of One Liners with Descriptions and Installation requirements

Passive security checker for CVE-2026-48908 affecting SP Page Builder.


An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines.

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

cPanel Scanner is a fast, multi-threaded tool written in Go for detecting cPanel services across IP ranges, CIDR blocks, or target lists. Perfect for…

Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…


List of regex for scraping secret API keys and juicy information.

Make URL path combinations using a wordlist

Real-world infosec wordlists, updated regularly