
CVE-2026-19478
Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into…

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

Scanner: CVE-2026-3854 GitHub Enterprise Server Pre-auth RCE via Push Option Injection — Python checker (CISA KEV)

Modern tactical exploitation toolkit.


A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

Adobe Experience Manager (AEM) hacking toolkit

Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own personal use, and…

Rust-powered HTTP Request Smuggling Scanner.