
mzap
⚡️ Multiple target ZAP Scanning

⚡️ Multiple target ZAP Scanning

CVE-2026-9830 Proof of Concept

A Burp Extension designed to identify argument injection vulnerabilities.

Ruby command-line interface to Burp Suite's REST API

Collaborative application security testing between humans and agents via CLI and MCP

CyberArk Security Audit

find sensitive data leaking from ServiceNow instances.

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…


PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Simple JMX RMI scanning tool

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

SQL Injection in 3CX CRM Integration

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.