- Argentina
- https://www.linkedin.com/in/nullfuzz/
Highlights
Lists (20)
Sort Name ascending (A-Z)
Stars
- All languages
- ASP
- ASP.NET
- Assembly
- Batchfile
- BlitzBasic
- C
- C#
- C++
- CSS
- CoffeeScript
- Crystal
- Dart
- Dockerfile
- Emacs Lisp
- Erlang
- Go
- HCL
- HTML
- Hack
- Haskell
- Inno Setup
- Java
- JavaScript
- Jupyter Notebook
- Kotlin
- Lua
- Makefile
- Markdown
- Nim
- Objective-C
- PHP
- Pascal
- Perl
- PowerShell
- Python
- QML
- Raku
- Rich Text Format
- Roff
- Ruby
- Rust
- SCSS
- Scilab
- Shell
- Smarty
- Solidity
- Svelte
- TypeScript
- Vue
- XSLT
- YARA
EVA is an AI-assisted penetration testing agent that enhances offensive security workflows by providing structured attack guidance, contextual analysis, and multi-backend AI integration.
A free open source IT asset/license management system
The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World
Scan websites for exposed Supabase JWTs, enumerate accessible tables, and detect sensitive data exposure automatically.
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.
Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation
Generates millions of keyword-based password mutations in seconds.
One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.
CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface
Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.
A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications
Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets
This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter
Open-source AI agents for penetration testing
Debug, evaluate, and monitor your LLM applications, RAG systems, and agentic workflows with comprehensive tracing, automated evaluations, and production-ready dashboards.
Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
🛜 ESPectre 👻 - Motion detection system based on Wi-Fi spectre analysis (CSI), with Home Assistant integration.
Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound




