
Pegasus-Pentest-Arsenal
A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.


HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from…


Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

The only open-source tool to analyze vulnerabilities and configuration issues with running docker container(s) and docker networks.

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

Proof of concept showing how to exploit the CVE-2018-11759

Axigen WebAdmin Improper Access Control Vulnerability