
yakit
All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

A collaborative web exploitation framework.

ISF(Industrial Control System Exploitation Framework),a exploitation framework based on Python

Tool to help exploit XXE vulnerabilities

Advisories, proof of concept files and exploits that have been made public by @pedrib.

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

A collection of exploits for different VoIP products.

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.


XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

PoC for Foxit Reader CVE-2018-14442

ZIP File Raider - Burp Extension for ZIP File Payload Testing

A Python3 module to assist in fuzzing web applications

Generic Scanner for Apache log4j RCE CVE-2021-44228

Lightweight scanner and Nuclei templates for identifying React and Next.js deserialization RCEs (CVE-2025-55182 / CVE-2025-66478).

Reproduces aiohttp CWE-444 request smuggling via rejected WebSocket upgrades, with Python/Rust payloads and Docker lab demonstrating proxy…
