
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

FOSSBilling CVE-2026-53647 & CVE-2026-53646 PoC — Unauthenticated API key disclosure & password reset token reuse

Python Hacking Tool for Hackers And Spammers


SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Using this script, you can enumerate Usernames and passwords of Nosql(mongodb) injecion vulnerable web applications.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

a very fast brute force webshell password tool