
gowitness
🔍 gowitness - a golang, web screenshot utility using Chrome Headless

🔍 gowitness - a golang, web screenshot utility using Chrome Headless

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

A customizable HTTP/HTTPS proxy library for Go supporting regular forwarding, CONNECT tunneling, MITM TLS interception, and programmatic…

Automated RCE exploit for Joomla JCE (CVE-2026-48907) with interactive shell, batch command execution, file download, and proxy support for…

Authorized WordPress XSS-to-RCE scanner with concurrent multi-target XSS reflection and version fingerprint detection, plus optional exploitation…

Node.js library for streaming files as HTTP responses with support for partial content, conditional requests, and configurable caching headers.…

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across…

HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.

AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool

Defensive exposure assessment tool for identifying externally accessible cPanel, WHM, and Webmail management interfaces related to CVE-2026-41940.

Non-destructive exposure survey tool for assessing PAN-OS User-ID Authentication Portal surfaces related to CVE-2026-0300, performing safe HTTP(S)…

This is a proactive tool for security auditing. For your GitHub repository, you’ll want a description that highlights its safety (non-intrusive) and…

A utility for detecting webpage inputs and conducting XSS scans.

A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.

Insecure Temp File Reuse in extract_zipped_paths()

UnauthScout is an OSINT (Open Source Intelligence) tool developed in Bash for passive exploration of assets on version control platforms (GitLab and…

Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.