
Grafana-Final-Scanner
Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

Proof-of-concept implementation for CVE-2026-33017, demonstrating the vulnerability for authorized security testing and research.

Monitoring centralisé pour instances Nextcloud multiples

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.

Proof-of-concept exploit scripts for CVE-2026-63642 and CVE-2026-63643, SSRF vulnerabilities in MagicMirror²'s Calendar module allowing…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

PHP proof-of-concept for CVE-2026-42613, demonstrating exploitation of the referenced vulnerability.

Proof-of-concept exploit for CVE-2026-13181 affecting Telerik web components, demonstrating remote code execution via crafted requests.

Multi-protocol cryptographic analyzer auditing TLS, SSL, SSH, IKE, DNSSEC, and HTTP security headers. Detects 400+ cipher suites, generates JA3/HASSH…

Python proof-of-concept exploiting CVE-2026-77578, an authenticated path traversal in Xibo CMS that reads arbitrary local files via crafted XML…

Proof-of-concept for CVE-2026-79387, an authenticated SQL injection in PbootCMS user management allowing arbitrary field updates and account takeover.

An open source threat modeling tool from OWASP

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Proof-of-concept for CVE-2026-79303, a critical boolean-blind SQL injection in Kaiten affecting order_by and order_direction parameters, with…