
Galaxy-Bugbounty-Checklist
Tips and Tutorials for Bug Bounty and also Penetration Tests.

Tips and Tutorials for Bug Bounty and also Penetration Tests.

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting /…

XSS payloads designed to turn alert(1) into P1

Database firewall written in Go

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.

Master script for web reconnaissance

Powerful Visual Subdomain Enumeration at the Click of a Mouse

PAVELOW Exploit Toolbox is a BASH script that corresponds with your KALI distro to better help your vulnerability hunting and exploiting proccess…

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Multi-functional Web Recon & Vulnerability Scanner Tool

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

WordPress Privilege Escalation Checker

Public advisory for CVE-2025-65640: Stored XSS vulnerability in Globe Document Intelligence.

CVE-2026-14856 TastyIgniter v4.3.0

