
Pegasus-Pentest-Arsenal
A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

FAST WEB APPLICATION VULNERABILITY SCANNER written in python3

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Python-based scanner that detects debug mode misconfigurations in web applications using multiple HTTP methods and fingerprinting techniques to…

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

Proof of concept showing how to exploit the CVE-2018-11759

CVE-2023-25202: Insecure file upload mechanism

CVE-2025-68428 Proof of Concept

Drag and Drop Multiple File Uploader PRO - Contact Form 7 v5.0.6.1 Path Traversal (CVE-2023-1112)

Next.js Middleware Authorization Bypass


Confluence Broken Access Control

WP Full Stripe Free <= 8.4.3 - Missing Authorization

CVE-2025-31651 PoC


Tiny File Manager v2.4.7 and below are vulnerable to Cross Site Scripting

Axigen WebAdmin Improper Access Control Vulnerability