
HTTPSignatures
A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

Radamsa fuzzer extension for Burp Suite

BurpSuite Standard/Private Collaborator Library

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

批量url检测Spring-Cloud-Gateway-CVE-2022-22947

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

CVE-2018-25031 tests

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具

OAuth Request Crafter

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

CVE-2026-9198利用代码