
pwndb
Search for leaked credentials

A tool for generating reverse shell payloads on the fly.

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).


Extract URLs, paths, secrets, and other interesting bits from JavaScript

Command-line scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

Extracts secrets (passwords, API keys, tokens) from WARC web archives using Gitleaks rules. Supports HTTP, S3, local files, and compressed archives…

Manage x509 certificates on PIV-enabled YubiKeys, generate keys and certificate requests, and sign or verify git commits and files.

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

CVE-2025-55182复现环境及RCE回显poc

Command-line scanner for detecting and exploiting CVE-2025-55182 (RCE) in Next.js React Server Components. Supports batch scanning from domain lists…

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

Bash-based scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

Extracts structured Cyber Threat Intelligence (CTI) from PDF, DOCX, and TXT documents using LLMs. Generates MITRE ATT&CK attack flows, detection…

A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.

Advanced Network Interface Management and Monitoring

A command line security audit tool for Amazon Web Services

A Command Line based python tool for exploit Zero-Day vulnerability in MSDT (Microsoft Support Diagnostic Tool) also know as 'Follina' CVE-2022-30190.