
Bug-Bounty-Arsenal-v.3
Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

The only open-source tool to analyze vulnerabilities and configuration issues with running docker container(s) and docker networks.

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

Proof-of-concept exploit for CVE-2020-24572 targeting authenticated remote command execution via a misconfigured web console in RaspAP 2.5.

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

Proof-of-concept exploit for CVE-2018-11759 demonstrating Apache mod_jk access bypass via specially crafted requests to bypass reverse proxy…

Axigen WebAdmin Improper Access Control Vulnerability