
burpcommander
Ruby command-line interface to Burp Suite's REST API

Ruby command-line interface to Burp Suite's REST API

Collaborative application security testing between humans and agents via CLI and MCP

CyberArk Security Audit

find sensitive data leaking from ServiceNow instances.

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Simple JMX RMI scanning tool

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

SQL Injection in 3CX CRM Integration

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

Application scanning component of purpleteam

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Automatic SQL injection and database takeover tool

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…