
CVE-2026-41940
Mass authentication bypass exploit for CVE-2026-41940 with single-target and batch scanning modes. Automates password-based bypass testing across…

Mass authentication bypass exploit for CVE-2026-41940 with single-target and batch scanning modes. Automates password-based bypass testing across…

CVE-2025-40554 Exploitation


Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Open-source vulnerability scanner with automated network discovery, CVE-based detection, CVSS scoring, risk dashboards, remote agents via gRPC, and a…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

A fast, simple, recursive content discovery tool written in Rust.

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

The simple PoC of CVE-2023-27587

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.