
web-check
🕵️♂️ All-in-one OSINT tool for analysing any website

🕵️♂️ All-in-one OSINT tool for analysing any website

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE…

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Reflected XSS via search GET Parameter in Phoca Download

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

Damn Small XSS Scanner

Damn Small SQLi Scanner

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8