
sqlmap-ai
此脚本使用 SQLMap 并通过 AI 驱动的决策来自动化 SQL 注入测试。

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

🎯 针对受 CVE-2025-53770 影响的 SharePoint 服务器的漏洞扫描器。检测使用 ToolPane.aspx 与精心构造的 base64+gzip 负载进行的不安全反序列化。🛡️ 由 Ahmed Tamer 开发。

用于基于 CRLF 的 desync 攻击的 Nuclei 模板和漏洞利用资源

WordPress Core 预认证 RCE — 批量路由混淆 + SQL 注入

CVE-2026-56164 是一个影响本地部署的 Microsoft SharePoint Server 的严重缺失身份验证漏洞。它允许未经认证的远程攻击者通过网络提升权限。

Palo Alto - CVE-2026-0300 exploit

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

基于 Rust 的 HTTP 请求走私扫描器。

针对 CVE-2026-31431 ("Copy Fail") — Linux 内核 algif_aead 本地权限提升 (LPE) 的防御性检测与缓解工具。不包含漏洞利用代码。

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

针对 21 个端点验证 Google Maps API 密钥,揭示暴露的服务及其 PoC URL,支持代理,并提供安静模式以进行聚焦审计。

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

用于检测 WP2Shell 预认证 RCE 链暴露风险的 WordPress CVE-2026-63030 和 CVE-2026-60137 安全工具。

用于通过HTTP头和非破坏性登录表单探测验证PHP CVE-2026-17543暴露情况的安全PowerShell验证器。

WordPress All-in-One Exploit Framework — 检测器、扫描器、枚举器、漏洞利用、权限提升。来自 2026-08 波次的 10 个 CVE,包括 CVE-2026-63030 (wp2shell)。