
w3af
Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI)

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

The tool helps in quickly identifying vulnerabilities by examining a comprehensive list of potential paths on a website, making it useful for…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Multi-platform Python webshell providing remote shell access on web servers with command history, file upload/download, and directory traversal…

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

An interactive, self-hosted XSS training platform with 33 progressively harder challenges

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

The tool helps in quickly identifying vulnerabilities by examining a comprehensive list of potential paths on a website, making it useful for…

A PHP Based Tool That Helps You To Manage All Your Backdoored Websites Efficiently.

This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help…

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw…

The tool helps in quickly identifying vulnerabilities by examining a comprehensive list of potential paths on a website, making it useful for…

Python script to test CVE-2022-44149 router vulnerability via authenticated payload delivery to the web interface, with logging for security…

An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the…