
HuntCyberArk
CyberArk Security Audit

CyberArk Security Audit

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Ruby command-line interface to Burp Suite's REST API

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

SQL Injection in 3CX CRM Integration

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Martian is a library for building custom HTTP/S proxies

a Damn Vulnerable Serverless Application

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch

Simple JMX RMI scanning tool

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…