
commix
Automated All-in-One OS Command Injection Exploitation Tool

Automated All-in-One OS Command Injection Exploitation Tool

Oracle OID LDAP Server Privileges Management Exploit

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Automatic SQL injection and database takeover tool

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

Proof-of-concept exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset endpoint. Forges an admin session for full…

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

Orbis is an full spectrum automated external attack surface intelligent toolkit.

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

PoC exploit for CVE-2026-15038 in InfiniteWP Client WordPress plugin: bypasses authentication on Multisite, binds attacker RSA key, escalates to…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…