
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool

Automated All-in-One OS Command Injection Exploitation Tool

File upload vulnerability scanner and exploitation tool.

XSS payloads designed to turn alert(1) into P1

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.


This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)

Social Network Tabs Wordpress Plugin Vulnerability - CVE-2018-20555


Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

CVE-2023-7028

A standalone Blind XSS Script.


PoC for CVE-2022-24342: account takeover via CSRF in GitHub authentication