
PwnCity
Insecure TeamCity CI environment for hands-on penetration testing training: reconnaissance, credential theft, privilege escalation, and lateral…

Insecure TeamCity CI environment for hands-on penetration testing training: reconnaissance, credential theft, privilege escalation, and lateral…
Burp extension for wordpress security scanning

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

A Test API for testing the POC against CVE-2022-1388

This script exploits the CVE-2024-40094 vulnerability in graphql-java

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

PortSwigger Burp Plugin for the Log4j (CVE-2021-44228)

Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

PoC de CVE-2026-35616: control de acceso indebido en FortiClient EMS.

CVE-2025-55182 testing toolkit with Postman collection, cURL examples, and F5 WAF signature validation for vulnerability assessment and protection…

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

This experimetal fuzzer is meant to be used for API in-memory fuzzing.