Researcher
cve_2026_34621_advanced. A sophisticated, cross-platform exploit generator for **CVE-2026-34621** – a critical prototype pollution vulnerability in Adobe Acrobat and Reader that leads to sandbox escape and arbitrary code execution on Windows and macOS.
13SSRF-to-RCE-Scanner. IT is advanced Python-based security tool designed to automate the detection and exploitation of SSRF (Server-Side Request Forgery) and RCE (Remote Code Execution) vulnerabilities in web application email input fields. This tool follows a systematic methodology to escalate from SSRF detection to full RCE exploitation with minimal false positives.
4CVE-2026-27944. CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption
4cve-2026-41940-tool. A comprehensive Python utility to **detect**, **scan in bulk**, and **exploit** the critical authentication bypass vulnerability (CVE-2026-41940) in cPanel & WHM and WP Squared.
4IIS-Bug-Bounty-Hunter-v2. A comprehensive security assessment tool for finding vulnerabilities in Microsoft IIS servers. Designed for bug bounty hunters, penetration testers, and security researchers.
2worm-ai-port-dominator. Advanced All-in-One Penetration Testing Framework for Stealth Port Scanning, Service Detection, Port Manipulation, and Vulnerability Assessment
2PyGuard-Obfuscator. 🛡️ PyGuard: Advanced Python Obfuscator & EXE Compiler
2CVE-2025-41244. CVE-2025-41244 is a critical local privilege escalation vulnerability in VMware Aria Operations and VMware Tools
2CVE-2026-22730-Scanner. CVE-2026-22730 Scanner & Exploit – Spring AI MariaDB Vector Store SQL Injection ,A professional security assessment tool for CVE-2026-22730 – a critical SQL injection vulnerability discovered in Spring AI's MariaDB vector store.
2CVE-2026-3228. CVE-2026-3228 - NextScripts WordPress Plugin Stored XSS Scanner & Exploit
2-nginxui_discover. Nginx UI Discovery Scanner - CVE-2026-27944 Version Detector
2DeepRecon. 🕸️ Advanced subdomain & JavaScript recon pipeline — Katana, Wayback, GAU, and more. Built by @NULL200OK.
1pyro-central.github.io. HTML
1rce_upload_always. 🧩 RCE Upload‑Always – LFI + Automated Polyglot Upload Automated Remote Code Execution via LFI & File Upload – with Double Encryption (AES‑256 + XOR) & Key Rotation
1PyScript-to-GUI. A powerful, zero-dependency Python tool that instantly transforms your Command-Line Interface (CLI) scripts into clean, functional Graphical User Interfaces (GUI).
1NULL200OK.
1openclaw_scanner. OpenClaw Discovery Scanner (Enhanced)
1ai_sentinel_enterprise.py. 🔥 AI-SENTINEL v4.0 - Advanced Web Security Scanner
1network-security-auditor-plus. A modular, **asynchronous** network security auditing tool for internal infrastructure assessments. It discovers live hosts, performs port scanning with banner grabbing, measures network distance (hops), maps vulnerabilities to CVEs (via local DB or NVD API), includes optional exploitation modules for default credentials.
1ai_bypass403_pro. AI-Powered 403 Bypass Tester – An intelligent, adaptive tool for security professionals to test and bypass 403 forbidden pages using smart strategies and extensive payloads. Automatically fingerprints servers, selects optimal attack vectors (path manipulation, headers, HTTP methods, protocol evasion), and generates detailed reports.
1IBO-ATTACKS.github.io. HTML
1rsrc.php. CSS
1hacker0x01.github.io. HTML
1threatlocker. HTML
1network-security-auditor. A modular, **asynchronous** network security auditing tool for internal infrastructure assessments
1NULL200OK.py. # 🔍 NULL200OK - Advanced Subdomain Scanner Professional subdomain discovery tool with passive/active reconnaissance. ## Features - Passive enumeration (SSL certificates, DNS records) - Active scanning with smart permutations - DNS brute-forcing - Multi-threaded scanning - Results export to TXT
1OpenClaw-Indirect-Prompt-Injection. OpenClaw Indirect Prompt Injection Security Assessment Tool
1login. HTML
1