
yakit
All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…
Tools for testing, exploiting, and securing web applications and APIs.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Web path scanner

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

CVE-2025-54424: 1Panel TLS client cert bypass enables RCE via forged CN 'panel_client' using a bundled scanning and exploitation tool. Affected: <=…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Model Context Protocol server for autonomous vulnerability discovery

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

OPNsense GUI, API and systems backend


PoCs and exploits for CVEs discovered by NebuSec.

A filter list that hides website features which use Generative AI & content labeled as AI Generated.

XML Security Library