
security-research
Security Research

Security Research

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

Git All the Payloads! A collection of web attack payloads.

A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and…

A collection of web pages vulnerable to SQL injection flaws

Web shell scanner and analyzer.

Local F5 BIG-IP script that scans for Indicators of Compromise (IoCs) related to CVE-2020-5902, checking logs, files, and system integrity to detect…

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

This project is now part of @mitmproxy.

Burp Suite extension for extracting metadata from files

Proof-of-concept demonstrating a hardlink path traversal in the tar npm package, allowing overwrite of files outside the extraction directory via…

Web-based project management interface for penetration testing and bug bounty workflows, automating port scanning with Nmap/Masscan and subdomain…

Unrestricted File Upload DoS Vulnerability discovered in MediaCrush thru 1.0.1(CVE-2025-61506)

Documentation of CVE-2025-56223, a denial-of-service vulnerability in Ascertia SigningHub's Upload Document API, allowing unrestricted file uploads…

Documentation of CVE-2025-66838: a rate-limiting vulnerability in ARIS file upload API allowing authenticated remote attackers to cause denial of…

A flaw was found in pki-core. Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows…

Proof-of-concept exploit for Grafana 8.x arbitrary file read vulnerability (CVE-2021-43798), allowing retrieval of sensitive files via crafted URL.