
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

Reproducer for CVE-2026-46456: Apache Camel camel-aws2-sqs inbound message-attribute header injection enabling downstream producer steering and RCE…

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

Reproducer for CVE-2026-46455 demonstrating Apache Camel camel-keycloak authentication bypass via missing TokenVerifier.IS_ACTIVE check, allowing…

Reproducer for CVE-2026-46726 demonstrating WebSocket header injection in Apache Camel camel-vertx-websocket enabling SSRF and property-placeholder…

Reproducer for CVE-2026-49099 demonstrating SOQL injection via HTTP header override in Apache Camel camel-salesforce, with mock Salesforce backend…

Proof-of-concept reproducing CVE-2026-48206 header injection in Apache Camel camel-jira, demonstrating authorization bypass via user-controlled…

PoC reproducer for CVE-2026-53913 demonstrating a fail-open authentication bypass in Apache Camel's camel-keycloak, leading to unauthenticated RCE…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Multi-architecture Docker toolkit for penetration testing with preconfigured tools for web, network, mobile, API, OSINT, and forensics. Features…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

The Swiss Army knife for automated Web Application Testing

Unauthenticated remote code execution exploit for CVE-2025-24893 targeting Linux XWiki, delivering a reverse shell for authorized penetration testing…

CLI tool for automated detection of server-side and client-side template injection vulnerabilities across 44 template engines in 8 programming…

Automatic SSTI detection tool with interactive interface

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…