
sqlmap-ai
This script automates SQL injection testing using SQLMap with AI-powered decision making.

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Advisory and information hub for the Next.js middleware authorization bypass CVE-2025-29927, including a link to technical analysis and details.

A CSRF POC for Updating the Profile of a Hospital leading to Account Takeover

Public advisory landing page documenting CVE-2026-54520, a high-severity path traversal vulnerability in ai-agent-automation's workflow executor,…

CVE-2025-67875 - ChurchCRM has stored XSS via Person Property Assignment Leading to Admin Session Hijacking

Demonstrates an unauthenticated enumeration vulnerability in a public certificate lookup endpoint, exposing personal data such as CPF and RG.…

CVE-2022-28454

Disclosure of a SQL injection vulnerability in ScienceLogic web platform (index.em7) affecting versions prior to 12.1.1, with mitigation guidance and…

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

A critical Cross-Site Request Forgery (CSRF) vulnerability in Sell Done Storefront v.1.0. Discovered by B. Sibhi

Proof-of-concept exploit for CVE-2024-24135, a cross-site scripting vulnerability in Product Inventory with Export to Excel. Demonstrates the XSS…

Python-based web reconnaissance tool that extracts site metadata, DNS records, subdomains, firewall names, technologies, and certificate details for…

g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure

Proof-of-concept exploit for CVE-2022-29361, demonstrating client-side desync to XSS in Werkzeug. Tested on Chromium.

Proof-of-concept demonstrating authenticated numeric SQL injection in ChurchCRM before 6.7.2, enabling logic manipulation to bypass WHERE clauses and…