


php-fpm+Nginx RCE

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Deserialization payload generator for a variety of .NET formatters


The all-in-one browser extension for offensive security professionals 🛠

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Swiss army knife Webserver in Golang. Keep simple like the python SimpleHTTPServer but with many features

A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-saml

A Python3 module to assist in fuzzing web applications

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

For pentesters who don't wanna leave their terminals.

StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。

simple urls < 115 - Reflected XSS

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

ZIP File Raider - Burp Extension for ZIP File Payload Testing

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…