
PoC-in-GitHub
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
Tools for testing, exploiting, and securing web applications and APIs.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

Undetected version of the Playwright testing and automation library.

💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

halo cms plugin 1-request rce from a url, PoC + exploit chain

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

An open source threat modeling tool from OWASP

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Exploits Apache HTTP Server CVE-2021-42013 for path traversal and CGI-based remote code execution during penetration testing.


A visual no-code/code-free web crawler/spider易采集:一个可视化浏览器自动化测试/数据采集/网页爬虫软件,可以无代码图形化的设计和执行爬虫任务。别名:ServiceWrapper面向Web应用的智能化服务封装系统。

Intentionally vulnerable PHP/MariaDB web application for practicing common web security vulnerabilities across multiple difficulty levels in a legal,…

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…