


Next generation web scanner

SSRF (Server Side Request Forgery) testing resources

Collection of quality safety articles. Awesome articles.

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Metlo is an open-source API security platform.

Network, recon and offensive-security tool for Linux.

DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it

Modern alternative to dirbuster/dirb

A collection of useful links for Pentesters

A collection oneliner scripts for bug bounty

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)

xpath is a fast, multi-technique XPath injection scanner written in Nim. It focuses on practical detection, response comparison, visible extraction,…

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…