
BurpSuite-For-Pentester
This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Interactive exploitation tool for CVE-2026-41940, a critical pre-auth authentication bypass in cPanel & WHM via CRLF injection. Designed for…

PoC exploit for CVE-2025-69985: authentication bypass leading to RCE in FUXA SCADA ≤1.2.8. Includes a modular Python exploit with interactive shell,…

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

Detailed analysis and PoC exploit for CVE-2025-2825, an authentication bypass in CrushFTP. Includes nuclei templates, multi-threaded scanner, and…

Python exploit script for CVE-2025-41646, an authentication bypass in RevPi Webstatus <= 2.4.5. Supports single/mass exploitation, proxy, silent…

Exploit module for Apache JSPWiki CVE-2019-10077, targeting a Java-based wiki platform with JAAS authentication and access control. Enables…

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

CVE-2026-0257 - PAN-OS

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

A free, secure and open source app for Android to manage your 2-step verification tokens.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Automated HTTP Request Repeating With Burp Suite

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).