
turbo-intruder
High-speed Burp Suite extension for sending large volumes of HTTP requests with a custom stack, Python-based attack configuration, and advanced…

High-speed Burp Suite extension for sending large volumes of HTTP requests with a custom stack, Python-based attack configuration, and advanced…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

DHCP exhaustion script written in python using scapy network library

A fork and successor of the Sulley Fuzzing Framework

Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows…

Nuclei templates and exploit resources for CRLF based desync attacks

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…


Proof-of-concept exploit for CVE-2026-8461, generating a crafted AVI file that triggers a crash in unpatched ffmpeg versions.


Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

Proof-of-concept for CVE-2026-9256, a heap buffer overflow in NGINX's ngx_http_rewrite_module. Demonstrates worker crash and denial of service via…

Go-based exploit tool for CVE-2026-42945 (nginx HTTP/2) with detection, crash probing, command execution, and reverse shell capabilities for…

CVE-2026-35333: strongSwan RADIUS attribute iterator infinite loop PoC

This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66…

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI