
WPSniper
CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.
An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

Reflected XSS via search GET Parameter in Phoca Download

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

Damn Small XSS Scanner

Damn Small SQLi Scanner

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

Proof-of-concept exploit for CVE-2026-37070: an authenticated attacker can read arbitrary uploaded files in Veno File Manager 4.4.9 via a crafted GET…

Proof-of-concept for absolute path disclosure in Veno File Manager 4.4.9 via an unauthenticated GET request to a debug script, revealing the server's…

Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…

Proof-of-concept exploit for unauthenticated reflected XSS in MapTiler Tileserver-php v2.0 via the 'layer' GET parameter, enabling arbitrary HTML/JS…

SQL Injection Vulnerability Scanner made with Python