
Big-Ass-Data-Broker-Opt-Out-List
Curated, community-maintained directory of data broker opt-out instructions to help individuals remove personal information from people-search sites…

Curated, community-maintained directory of data broker opt-out instructions to help individuals remove personal information from people-search sites…

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Fast passive subdomain enumeration tool.

Online hash checker for Virustotal and other services

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

Fast, accurate subdomain takeover scanner with zero false positives. Detects vulnerable subdomains, collects metadata (IP, CNAME, title, status…

Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

CVE-2026-5513: Bookly <= 27.2 Stored XSS via Cookie (Unauthenticated)

Multithreaded reverse IP lookup tool for discovering domains hosted on the same IP address.

IPGhost is a strong tool for ethical hackers. This tool automatically changes your IP address , making it hard for anyone to track your online…

Just a silly recon tool that uses data from SSL Certificates to find potential host names

Proof of concept demonstrating unauthenticated access to user resumes via directory listing in CodeAstro Online Job Portal, with reproduction steps…

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

Analysis of state-sponsored WhatsApp phishing infrastructure with real-time QR hijacking and device surveillance

A proof of concept demonstrating how to use the Hinge dating app as a C2.