
CVE-2024-30270-PoC
The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

Fixed exploit for CVE-2022-46169 targeting a web application vulnerability, enabling authenticated remote code execution for penetration testing and…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

TCP tunneling over HTTP/HTTPS for web application servers

An open-source self-hosted purple team management web application.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

Bypass exploit for CVE-2019-16759 targeting a specific web application vulnerability, enabling unauthorized access or privilege escalation during…

PHP-based exploit for CVE-2020-23342, designed to be run in a Docker container for local testing of a specific web application vulnerability.

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

Six Degrees of Domain Admin

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Webshell, Virtual Private Server (VPS) and cPanel Database

Proof-of-concept exploit for CVE-2024-0195, a critical code injection vulnerability in SpiderFlow 0.4.3 enabling remote code execution via the…

Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!