
CVE-2025-59528-PoC
PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB
WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

An on-path blackbox network traffic security testing tool

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi