
cve-2026-15748
Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Scans WordPress sites for WP Time Capsule plugin CVE-2024-8856, detecting versions below 1.22.22 and logging vulnerable targets to a file.

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into…

This Repositories contains list of One Liners with Descriptions and Installation requirements

WPScan rewritten in Python + some WPSeku ideas

Login Area Finder: scans host/s for login panels

Arachni's Web User Interface.

Nmap scripts to detect exchange 0-day (CVE-2022-41082) vulnerability

A research tool designed to check for OpenSSL CVE-2014-0160 vulnerability

Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 Cross Site Scripting (XSS) Vulnerability

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session

A scanning suite to find servers affected by the log4shell flaw (CVE-2021-44228) with example to test it

Proof of concept for unauthenticated sensitive data disclosure affecting the wp-import-export WordPress plugin (CVE-2022-0236)