
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool

Vulnerabilities I've reported to the Apache Software Foundation: 46 CVEs across 15 projects

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

Full Firefox chain: CVE-2026-2796 wasm type confusion -> content-process RCE, plus CVE-2026-2768 parent-process escape analysis (both fixed in…

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)

Fuzzing Framework for Modules in Apache HTTPD Server

Automatically run and save ffuf scans for multiple IPs

Advisory: CVE-2026-38361 multiple DoS vulnerabilities (CWE-400/CWE-670) in dash-uploader (Python/PyPI)

A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

Proof-of-concept demonstrating command injection via shell() expansion in parameter defaults of Intake catalogs, with exploit YAML and reproduction…

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.

Analysis and PoC for CVE-2025-14174 - ANGLE Metal OOB write (iOS Safari, macOS Chrome)

The Ultimate Information Gathering Toolkit


reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…