
yLog4j
PortSwigger Burp Plugin for the Log4j (CVE-2021-44228)

PortSwigger Burp Plugin for the Log4j (CVE-2021-44228)

The code for personally reproducing the corresponding vulnerability

Exploit script for CVE-2021-4191 that enumerates GitLab users via the GraphQL API, useful for security assessments and validating exposure.

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam


Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more