#1Tools for testing, exploiting, and securing web applications and APIs.
Kitploit recommended

CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).

Blind SQL Injection Tool with Golang

🗒️ A [work-in-progress] collection for interview questions for Information Security roles

Exploit for the Post-Auth RCE vulnerability in Pulse Secure Connect

PoC and scanner for CVE-2024-23897 targeting Jenkins <= 2.441 & LTS 2.426.2. Supports single targets, CIDR ranges, file reading, and CLI command…

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

A POC exploit for CVE-2024-5836 and CVE-2024-6778, allowing for a sandbox escape from a Chrome extension.

Exploit for CVE-2018-3191 targeting Oracle WebLogic Server via T3 protocol, enabling unauthenticated remote code execution with JNDI payload…


Weblogic CVE-2019-2725 CVE-2019-2729 Getshell 命令执行

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…


WebLogic vulnerability exploration from beginner to expert.

This tool is based on regex with effective standards for detecting phishing sites in real time using certstream and can also detect punycode (IDNA)…

Patcher utility that bypasses CryptoQuant premium tier restrictions to unlock advanced analytics and real-time data access, with a Python GUI for…

CVE-2022-1388 F5 BIG-IP RCE 批量检测

proxylogon exploit - CVE-2021-26857