
ClaimJumper
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

📜 Scrape targeted wordlists for password cracking using CSS selectors

A friend of SQLmap which will do what you always expected from SQLmap.

Curated collection of web attack payloads for XSS, SQLi, command injection, and more. Includes fuzzing lists, password wordlists, and CTF-sourced…

Multi-threaded JWT brute-force cracker in C that recovers secret keys from HS256/HS384/HS512 tokens for security testing. Supports custom alphabet,…

Automated exploitation framework for Grafana directory traversal (CVE-2021-43798) with multi-plugin brute-force, batch scanning, credential…

Time-based blind SQL injection toolkit for CVE-2025-4396 with standard and binary-search extraction scripts, plus automated WordPress 6.8+ hash…

Proof-of-concept exploit for a time-based blind SQL injection in the Relevanssi WordPress plugin, featuring comma-less payloads and CASE WHEN logic…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

Self-hosted collaborative password manager with AES-256 encryption, LDAP/AD integration, role-based access control, REST API, and Docker deployment…

Server-side encrypted, self-destructing link service for secure sharing of passwords, documents, and messages. Includes API, password generator, and…

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

A cli for cracking, testing vulnerabilities on Json Web Token(JWT)

There is a SQL injection vulnerability in the backend of Ruoyi v4.8.3

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…