
hackbox
Multi-function web security assessment tool combining XSS, SSRF, SQL injection testing, subdomain enumeration, Whois lookup, CORS and AWS S3…

Multi-function web security assessment tool combining XSS, SSRF, SQL injection testing, subdomain enumeration, Whois lookup, CORS and AWS S3…

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Web application firewall testing tool with 344+ attack payloads, auto WAF detection, bypass techniques, and full reconnaissance including DNS,…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Multi-CVE exploit tool for Kubernetes ingress-nginx, enabling remote code execution via auth-url, auth-tls-match-cn, and mirror UID injections with…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

React2Shell Exploitation Tool (CVE-2025-55182)

Proof-of-concept exploit for CVE-2021-38647 (OMIGOD), an unauthenticated remote code execution vulnerability in the OMI agent commonly deployed on…