


A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

A Test API for testing the POC against CVE-2022-1388

Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

This script exploits the CVE-2024-40094 vulnerability in graphql-java

[CVE-2016-4014] SAP Netweaver AS JAVA UDDI Component XML External Entity (XXE)

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Zap Extension for collaboration in Faraday

Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.
