
CVE-2025-51867
Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

Proof-of-concept for CVE-2025-3855, an IDOR vulnerability in RISE Ultimate Project Manager & CRM that allows authenticated users to modify other…

Modular OSINT framework for harvesting data from open sources and search engines. Supports DNS enumeration, social network scraping, and web API mode…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Finds internet-exposed resources in an AWS account

High-performance network scanner for large-scale IP and port scanning with service identification, embedded device detection, and vulnerability…

Rapid HTML grepping tool for recursively searching web pages by element type, headers, and content to locate login pages, tokens, vulnerable code,…

In-depth attack surface mapping and asset discovery

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

Automated AWS subdomain takeover detection tool using Terraform and serverless functions. Scans DNS records for dangling CNAMEs and alerts on…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…


Automated path traversal and local file read exploit for SolarWinds Serv-U (CVE-2024-28995) with version detection, default and custom path testing,…