
terrapod-PoC
PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthenticated access to Superset instances for…

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

Optiva-Framework 🔎 Web Application Scanner🕵️

Disrupt WAF by abusing SSL/TLS Ciphers


NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

A penetration testing tool for finding file upload bugs (NDSS 2020)

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…