
Pegasus-Pentest-Arsenal
A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

The code for personally reproducing the corresponding vulnerability

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100