
TheTimeMachine
Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

An implementation of a vulnerable MCP server using mcp-go

🔍 Next.js RCE Scanner (CVE-2025-55182) - Automated vulnerability scanner using Zoomeye search engine. Discovers targets via dorks and tests for…

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.


Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

DifuseHQ Kalmia CMS version 0.2.0 is vulnerable to user enumeration through distinguishable error responses in the /kal-api/auth/jwt/create…

Proof-of-Concept (PoC) for CVE-2025-62168 👾

Advanced RCE exploitation toolkit for React Server Components vulnerabilities. Features multiple pre-built payloads, Shodan integration for target…

Identify Nginx-ui version and check if it's vulnerable to CVE-2024-22198

CVE-2023-46988: ONLYOFFICE Path Traversal Exploit