Skip to content
View nullfuzz-pentest's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report nullfuzz-pentest

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Proof of Concept for CVE-2026-23745: Arbitrary File Overwrite vulnerability in node-tar (versions < 7.5.3).

JavaScript 21 3 Updated Jan 17, 2026

Vulnerable app with examples showing how to not use secrets

Java 5 1 Updated Jan 11, 2026

批量检测CVE-2020-5902

Python 2 Updated Jul 10, 2020

The open source coding agent.

TypeScript 98,847 9,368 Updated Feb 6, 2026

EVA is an AI-assisted penetration testing agent that enhances offensive security workflows by providing structured attack guidance, contextual analysis, and multi-backend AI integration.

Python 301 58 Updated Jan 22, 2026

A free open source IT asset/license management system

PHP 13,369 3,745 Updated Feb 5, 2026

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

Shell 154 10 Updated Dec 31, 2025

Scan websites for exposed Supabase JWTs, enumerate accessible tables, and detect sensitive data exposure automatically.

Python 116 12 Updated Dec 29, 2025

Tool for mass testing ZeroLogon vulnerability CVE-2020-1472

Python 3 1 Updated Sep 30, 2022

WiFi Penetration Testing & Auditing Tool

Python 707 67 Updated Apr 28, 2025
JavaScript 927 164 Updated Dec 26, 2025

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

Go 410 83 Updated Dec 16, 2025

Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation

JavaScript 75 24 Updated Dec 11, 2025

A Windows Named Pipe Multi-tool / Proxy

C++ 286 20 Updated Dec 7, 2025

Generates millions of keyword-based password mutations in seconds.

Python 1,403 170 Updated Jun 8, 2025

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

JavaScript 403 66 Updated Dec 12, 2025

CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface

Python 11 6 Updated Dec 5, 2025

Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.

JavaScript 61 15 Updated Dec 9, 2025

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

Python 114 18 Updated Dec 10, 2025

Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets

Python 133 21 Updated Jan 21, 2025

This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter

3,223 747 Updated Feb 10, 2024

Open-source AI hackers to find and fix your app’s vulnerabilities.

Python 19,809 2,080 Updated Feb 4, 2026

A Repository to Track Anti-Forensic Techniques

118 10 Updated Mar 8, 2023

IRC application written in Rust

Rust 3,719 148 Updated Feb 6, 2026

Debug, evaluate, and monitor your LLM applications, RAG systems, and agentic workflows with comprehensive tracing, automated evaluations, and production-ready dashboards.

Python 17,659 1,341 Updated Feb 6, 2026

AI-Powered Dark Web OSINT Tool

Python 4,100 780 Updated Jan 17, 2026

Easy SSH servers in Golang

Go 4,082 483 Updated Jan 27, 2025

Chrome Dump Password

Python 11 4 Updated Nov 17, 2025
Next