
KingOfBugBountyTips
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

Python API wrapper and command-line client for the tools hosted on spyse.com.

Passive subdomain discovery tool that aggregates results from multiple online sources via CLI, supporting stdin/stdout, JSONL output, and API key…

Torito React2Shell Scanner & Exploit Tool (CVE-2025-55182 / 66478)

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

Nodesub is a command-line tool for finding subdomains in bug bounty programs

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…