
terrapod-PoC
PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthenticated access to Superset instances for…

A fast DOM based XSS vulnerability scanner with simplicity.

Burp plugin which supports in finding privilege escalation vulnerabilities

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

A penetration testing tool for finding file upload bugs (NDSS 2020)

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

Disrupt WAF by abusing SSL/TLS Ciphers
