
scanner-for-CVE-2025-55182-vulnerability
CVE-2025-55182 Detector. Find which of your GitHub repositories are exposed to the critical React/Next.js RCE vulnerability and generate a clean…

CVE-2025-55182 Detector. Find which of your GitHub repositories are exposed to the critical React/Next.js RCE vulnerability and generate a clean…

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.

Jbin will gather all the URLs from the website and then it will try to expose the secret data from them such as API keys, API secrets, API tokens and…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Steganographic online codec allows you to hide a password encrypted message within the images & photos using AES encryption algorithm with a 256-bit…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

A library for detecting known secrets across many web frameworks

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Tool to scan for secret files on HTTP servers

Audits ASP.NET applications for pre-published machine keys to detect ViewState deserialization vulnerabilities and insecure forms authentication…

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

Proof-of-concept exploit for CVE-2022-23529, demonstrating RCE in vulnerable JWT libraries via malicious HMAC secret objects.

CVE-2025-59390 and ThreadLocalRandom Inverse

List of regex for scraping secret API keys and juicy information.

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

Auerswald VoIP System Secret Backdoors -PoC