
w3af
Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

Automatic SSTI detection tool with interactive interface

Python-based exploit for CVE-2017-8056 targeting XML-RPC denial-of-service vulnerability in web applications.

Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)

Exploit for CVE-2018-7600, a critical remote code execution vulnerability in Drupal core. Enables automated exploitation of unpatched Drupal sites…


Exploit for PrestaShop bockwishlist module 2.1.0 SQLi (CVE-2022-31101)

Proof-of-concept exploit for CVE-2021-25837 targeting Ethermint, demonstrating a critical vulnerability in Ethereum-compatible blockchain nodes.

Proof-of-concept exploit for an open redirect vulnerability (CVE-2023-33405) in BlogEngine.NET CMS versions 3.3.8.0 and earlier, demonstrating…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…


Proof-of-Concept exploit (SQLI BookingPress before 1.0.11)

Proof-of-concept exploit for CVE-2022-44268, an arbitrary file read vulnerability in ImageMagick, enabling local file disclosure via crafted PNG…

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…