
area51
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

Burp extension for wordpress security scanning

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Standalone authorized universal HTTP PoC for CVE-2026-75157

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

Simple JMX RMI scanning tool

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

CVE-2023-23752 nuclei template