
Pegasus-Pentest-Arsenal
A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Automated JWT security testing tool that exploits known CVEs, tampers with payloads, performs JKU/X5U injection, key confusion attacks, and verifies…

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

📜 Scrape targeted wordlists for password cracking using CSS selectors

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

An implementation of a vulnerable MCP server using mcp-go

Gogs service Exploit and get the root user

CVE-2025-8110 Specifically for the Silentium box on HTB.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool