
CVE-2024-48415
Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

A program for testing WAF functionality

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

AzureGoat : A Damn Vulnerable Azure Infrastructure

GCPGoat : A Damn Vulnerable GCP Infrastructure

A Security Tool for Enumerating WebSockets

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Apache Real Time Logs Analyzer System

Advanced HTTP fingerprinting PoC

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Web vulnerability scanner written in Python3

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.