
CVE-2019-11043
php-fpm+Nginx RCE

php-fpm+Nginx RCE

parsing search results from startpage search engine (based on google.com results)

Check list of URLs against Log4j vulnerability CVE-2021-44228

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

Drupal CVE-2024-45440

Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

Proof-of-concept exploit for CVE-2020-3187 targeting Cisco ASA/FTD session password disclosure via crafted HTTP cookie header.

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

Ghazi is a BurpSuite Plugins For Testing various PayLoads Like "XSS,SQLi,SSTI,SSRF,RCE and LFI" through Different tabs , Where Each Tab Will Replace…

Get information client with getdatareport (Plugin)

Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…

Detection-only PoC for CVE-2026-21440 in AdonisJS BodyParser. Fingerprints AdonisJS indicators, probes upload endpoints via GET, and outputs…

Damn Small SQLi Scanner

Damn Small XSS Scanner

Automated System Hardening Framework

Enemies Of Symfony - Debug mode Symfony looter