
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

This skill helps Claude write secure code and prevent common vulnerabilities.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

Vulnerability Assessment Scanner with Report Generation

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Proof-of-concept demonstrating a SQL injection vulnerability in Bookea-tu-Mesa with vulnerable code analysis and a prepared statement fix.

AI-powered bug bounty hunting toolkit that works with or without subscription.