
CVE-2026-30251
Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda…

Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda…

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery…

Burp Suite extension for decoding Ethereum JSON-RPC calls and smart contract interactions, supporting multiple chains and automatic ABI retrieval.

Nuclei template to discover exposed Keycloak reset-credentials endpoints across multiple paths, aiding validation of CVE-2026-18963 exposure.

Automated scanner for CVE-2021-44228 (Log4Shell) that tests single or multiple web targets for the vulnerability using remote callback servers.

Exploit for CVE-2026-25890, a path-based authorization bypass in FileBrowser <= v2.57.0, allowing authenticated low-privileged users to read, upload,…

Proof-of-concept demonstrating authenticated numeric SQL injection in ChurchCRM before 6.7.2, enabling logic manipulation to bypass WHERE clauses and…

Proof-of-concept exploit for CVE-2025-52970, allowing security researchers to test single or multiple target URLs for the vulnerability.

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

Educational lab demonstrating JavaScript expression sandbox escape techniques and patch evolution through multiple vulnerable sandbox versions, with…

Python-based exploit scanner for CVE-2021-41773, allowing single-target or batch scanning to detect vulnerable Apache servers.

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

WordPress mass scanner for detecting CVE-2026-1405 exposure.

Automates CAPTCHA solving with multimodal AI models (GPT-4o, Gemini) and Selenium, supporting text, audio, slider puzzles, and reCAPTCHA v2 via a…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

WordPress security scanner that fingerprints versions, detects reflected XSS across multiple targets concurrently, and supports an authenticated…

CVE-2018-7600 POC (Drupal RCE)

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…