


Official Kali Linux tool to check all urls of a domain for SQL injections :)

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

BoB Web Application Security Project

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…

Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate…

Woeful is a tool that lets web apps to safely and securely connect to the outside internet without a complex backend.

Multi-threaded HTTP/2 request flood tool targeting Apache Tomcat 10.1.10-10.1.39 using malformed priority headers for DoS stability testing. Strictly…

Proof-of-concept exploit for CVE-2020-0601 (Windows CryptoAPI spoofing) that generates rogue CA certificates to intercept HTTPS traffic, with…

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

Proof-of-Concept (PoC) for CVE-2025-62168 👾

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

Multi-threaded URL enumeration/content-discovery tool in Python.

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

RscScan: Professional cross-platform vulnerability scanner for Next.js Server Actions (CVE-2025-55182). Detects critical RCE flaws with…

WordPress Sites Vulnerability Checker for CVE-2020-35489 - "Educational Use Only"

Proof of Concept (POC) for the CVE-2025-25296 vulnerability affecting Label Studio versions prior to 1.16.0

Docker container for CVE-2016-10033 (PHPMailer remote code execution) used for practicing exploitation in a controlled lab environment.