
dj
Extracts dynamically loaded JavaScript files by statically analyzing website HTML and JS, detecting webpack chunks, import() lazy loading, and source…

Extracts dynamically loaded JavaScript files by statically analyzing website HTML and JS, detecting webpack chunks, import() lazy loading, and source…

Self-hosted scraping engine — bypasses any JS challenge & captcha: Cloudflare, Turnstile, reCAPTCHA, hCaptcha, GeeTest. FlareSolverr & Byparr…

CVE-2026-39154, Stored XSS in CometChat JS SDK

A standalone Blind XSS Script.

A powerfull websites compiler/obfuscator for optimization or intellectual property protection purposes.

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

POC for PDF JS' CVE-2024-4367 vuln

JS Job Manager < 1.1.9 - Unauthenticated Arbitrary Plugin Installation/Activation

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

PoC Exploit CVE-2018-6389

Regular expression matching for URL's. Maintained, safe, and browser-friendly version of url-regex. Resolves CVE-2020-7661 for Node.js servers.

Detailed analysis of CVE-2024-28397, a sandbox escape vulnerability in js2py enabling RCE via Python object traversal. Includes code analysis, PoC,…

CVE-2022-23861: Multiple Stored Cross-Site Scripting in YSoft SafeQ

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

Technical documentation and proof-of-concept for CVE-2025-63700, an OAuth authentication bypass vulnerability in Clerk-js 5.88.0 allowing…

Haraj Script 3.7 - Authenticated Stored XSS

Safari XSS (CVE-2017-7038) https://support.apple.com/en-us/HT207923