
hackerone-reports
Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting /…

Subdomain and target enumeration tool built for offensive security testing

ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.

Master script for web reconnaissance

Technical Reference to multiple relay techniques

Powerful Visual Subdomain Enumeration at the Click of a Mouse

PAVELOW Exploit Toolbox is a BASH script that corresponds with your KALI distro to better help your vulnerability hunting and exploiting proccess…

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Multi-functional Web Recon & Vulnerability Scanner Tool


Proof of concept script to check if the site is vulnerable to CVE-2023-35078

This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine…

NetLogic is an advanced network analysis and cybersecurity toolkit for traffic inspection, packet analysis, and threat detection

This repository contains the Proof of Concept (PoC) exploit script for CVE-2026-45156

An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the…

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…