
django-DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Interactive password profiler that generates targeted wordlists by gathering personal details about a user, used for penetration testing and forensic…

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

Python Exploit for CVE: 2018-9276

Demonstrates user enumeration in FormaLMS via response discrepancy on the /lostpwd endpoint, enabling unauthenticated username discovery for targeted…

A lightweight CLI tool to interactively search and access your KeePassXC database entries using fzf. Fast, secure, and terminal-centric.

Exploit for CVE-2025-2304

Exploit for CVE-2024-46987

Small PoC to automate exploitation of CVE-2025-63406.

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)

Python script for SSH username enumeration using timing-based analysis to identify valid accounts on a target server.