
CVE-2026-20217
Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

Never forget where you inject.

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

Plugin For BurpSuite (Pentester)

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。

The CSRF Exploit Generator allows users to generate a CSRF exploit form with configurable parameters.


Template repository for Faraday security platform, providing reusable vulnerability scanning and exploitation templates for automated penetration…

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

The WASM Based Security Toolkit for the Web First Paradigm


The all-in-one browser extension for offensive security professionals 🛠

MagicArch is a comprehensive post-installation script built with Ansible, designed to transform a basic Arch Linux installation into a fully equipped…

Python framework for IT security tools

Vulnerability scanner based on vulners.com search API

Multi-Thread Vulnerability Verify Framework