
WSGoat
The vulnerable application that will teach you how to hack WebSockets

The vulnerable application that will teach you how to hack WebSockets

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

Default signature for Jaeles Scanner

a lightweight, flexible and novel open source poc verification framework

PoC exposing a critical IndexedDB vulnerability that enables a disk flooding attack by exploiting the lack of restrictions.

Automation for javascript recon in bug bounty.

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Hands-on vulnerability management case study: how Wazuh flagged a real SSRF (CVE-2025-68616) in WeasyPrint, and how I reproduced and patched it.

Gospider - Fast web spider written in Go

Burp Plugin to Bypass WAFs through the insertion of Junk Data

This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it…

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

Learn how I found my first two CVEs by pure accident.

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Tests your WAF with +160 payloads