
evilwaf
evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Burp Extension for collaboration in Faraday

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Automatic SSTI detection tool with interactive interface


This PoC script is designed to verify the presence of CVE-2024-9326, a high SQL Injection vulnerability in PHPGurukul Online Shopping Portal v2.0. It…

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Tests your WAF with +160 payloads

Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2


Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Network Infrastructure Penetration Testing Tool

Web Application Vulnerability Scanner.