
CVE-2023-43339-CMSmadesimple-Reflected-XSS---Installation
CMSmadesimple 2.2.18 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload…

CMSmadesimple 2.2.18 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload…

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header…

Proof of concept for unauthenticated sensitive data disclosure affecting the wp-import-export WordPress plugin (CVE-2022-0236)

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Proof-of-concept demonstrating command injection via shell() expansion in parameter defaults of Intake catalogs, with exploit YAML and reproduction…

PoC for CVE-2022-28281 a Mozilla Firefox Out of bounds write.

A cheatsheet for exploiting server-side SVG processors.

Like curl, but it gets past Anubis and Cloudflare bot-walls.

Analysis and PoC for CVE-2025-14174 - ANGLE Metal OOB write (iOS Safari, macOS Chrome)

This script is intended to automate your reconnaissance process in an organized fashion

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB…

Evolution CMS 3.2.3 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload…

A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more!

Exploit and detect tools for CVE-2020-0688

Script to perform automatic initial web and vulnerability recon

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA