
stylesmuggler-ioc-toolkit
StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells,…

StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells,…

Python exploit for CVE-2015-1579 targeting WordPress Slider Revolution <= 4.1.4, allowing remote file disclosure. Usage: python3 xpl.py --url=target.

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

CVE-2026-41940: detect and exploit cpanel vuln

Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.

Moment.js vuln lab

POC for PDF JS' CVE-2024-4367 vuln

This app is the standard Asp.Net default web app with an old version of the AjaxControlToolkit, put here for those interested in CVE-2015-4670

Nuclei templates for drupal vulns... far from perfect

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

Vuln Apache Struts with splunk

Detection for CVE-2025-61882 & CVE-2025-61884

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

POC for the vuln CVE-2025-22131

https & http

Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002)

PHP CLI script to scan domains for the CVE-2014-0160 (Heartbleed) vulnerability using an external API service.

mitigation script for MS Exchange server vuln