
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool

Automated All-in-One OS Command Injection Exploitation Tool

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Like curl, but it gets past Anubis and Cloudflare bot-walls.

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…