
sss3
Automated S3 bucket security scanner that tests domain lists for publicly accessible buckets with listing permissions, exporting results for cloud…

Automated S3 bucket security scanner that tests domain lists for publicly accessible buckets with listing permissions, exporting results for cloud…

Automatic SSTI detection tool with interactive interface

Repository for the Smartphone Pentest Framework (SPF)

Security research project on fuzzing libpng with OSS-Fuzz. Includes seed corpus analysis, custom read/write fuzzers, and a proof-of-concept exploit…

Framework for penetration testing. The software can identify everything from cross-site scripting to SQL injection. Developers can also use this…

OSS-Fuzz - continuous fuzzing for open source software.

Proof-of-concept exploit for CVE-2020-4276, targeting a specific vulnerability in affected software for security testing and validation.

Curated guide to IoT penetration testing hardware and software tools for 2025, covering Bluetooth, Zigbee, Z-Wave, WiFi, RFID, automotive, and…

Collection of shellcode and proof-of-concept exploits for known vulnerabilities, intended for local testing and verifying software or network…

Proof-of-concept exploit for CVE-2024-35315, demonstrating local privilege escalation in Mitel Collab software. Intended for security testing and…

Proof-of-concept exploit for CVE-2018-4411, demonstrating a specific vulnerability in Apple software. Intended for security testing and educational…

Open-source simulation framework for developing, testing, and debugging unmodified software for multi-node embedded and IoT systems, supporting ARM,…

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

An SDN penetration testing toolkit

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

OWASP Thick Client Application Security Verification Standard

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

Proof-of-concept exploit for CVE-2018-6892 targeting a buffer overflow vulnerability in CloudMe software. Demonstrates exploitation technique for…