
React2Shell-Scanner
Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

An API hooking framework for intercepting and monitoring Windows applications

CVE-2018-25031 tests

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

SQL Injection in 3CX CRM Integration

Zap Extension for collaboration in Faraday

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Spring Cloud Gateway repository demonstrating CVE-2022-22947 exploitation for API security testing and vulnerability analysis.

Global API Integrity Assessor

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Martian is a library for building custom HTTP/S proxies

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

SSRF plugin for burp Automates SSRF Detection in all of the Request