
reconftw
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…


A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

Disrupt WAF by abusing SSL/TLS Ciphers

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

A penetration testing tool for finding file upload bugs (NDSS 2020)

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

Optiva-Framework 🔎 Web Application Scanner🕵️

Burp plugin which supports in finding privilege escalation vulnerabilities

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

A fast DOM based XSS vulnerability scanner with simplicity.

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…