
CVE-2025-3248
Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and…

Finds CSP report urls and tests to see if they are vulnerable to log4j

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

Plugin For BurpSuite (Pentester)


Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)

WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…


Finds public elite anonymity proxies and concurrently tests them

SSLScan tests SSL/TLS enabled services to discover supported cipher suites

Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…