
ci_fuzz
Command Injection Web Fuzzer Script for mitmproxy

Command Injection Web Fuzzer Script for mitmproxy

Python exploit for CVE-2019-5096, a use-after-free vulnerability in GoAhead web server's upload handler, causing denial of service via double-free.

Mass exploiter for CVE-2020-6308 with multi-worker support, enabling automated exploitation of vulnerable SAP NetWeaver systems.

A structure-aware JSON fuzzer

Proof-of-concept exploit for CVE-2017-9096 demonstrating XML External Entity (XXE) injection in iText PDF library via malicious XMP metadata and form…

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

Exploit for CVE-2008-2019 bypassing audio captcha in Simple Machines Forum 1.1.4 using hamming distance and levenshtein distance to compare PCM audio…

Proof-of-concept exploit for CVE-2026-3909, a Chromium Skia out-of-bounds vulnerability, with patches and crash analysis for reliable triggering in…

CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI

Simple python script to fuzz site for CVE-2017-9805

Um script automatizado melhorando o exploit do cve-2011-0762 postado no exploit-db

Proof-of-concept exploit for CVE-2025-51495, an integer overflow in Mongoose WebSocket's mg_ws_cb function leading to out-of-bounds memory access and…

The Offensive Manual Web Application Penetration Testing Framework.

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

ZIP File Raider - Burp Extension for ZIP File Payload Testing

clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability…

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.