
x8-Burp
Hidden parameters discovery suite

Hidden parameters discovery suite

Automated Google Dorking tool for OSINT reconnaissance, vulnerability discovery, and information gathering via advanced search operators and targeted…

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

Fast CLI tool to scan websites, sitemaps, and URL lists for broken links, with concurrent workers, coverage reporting, and multiple output formats.

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

German OWASP Day conference site & presentation archive

Searching for virtual hosts among non-resolvable domains

Fetches JavaScript files quickly and comprehensively.

Searcher for cross-site leaks (XS-Leaks)

A CodeQL workshop covering CVE-2021-21380

Vulnerability scanner for Spring4Shell (CVE-2022-22965)

Mass scanner for Log4j CVE-2021-44228 vulnerability with Python-based detection and exploit capabilities for automated security testing.

Proof-of-concept exploit for an unauthenticated root authentication bypass in Proxmox VE 7.0-8.0.3, intended for authorized security testing and…

Proof-of-concept for CVE-2026-19516, demonstrating session spoofing and SSRF in Grafana MCP. Intended for authorized security research and education…

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

YZMCMS v3.7最新版xss漏洞 CVE-2018-8078

A nice web-crawler written in Bash that will look for login pages/admin-panels for you on any given website.

Proof-of-concept for Chrome V8 zero-day CVE-2026-85046, providing educational exploit code and setup instructions for authorized security research in…