
CVE-2023-49314
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through…

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through…

.json and .yaml files used to exploit CVE-2018-25031

CVE-2023-35813 is a proof-of-concept used to determine if an instance of Sitecore is vulnerable by analyzing a server Response Header for…

Tries to exploit a WordPress vulnerability (CVE-2018-6389) which can be used to cause a Denial of Service.

A XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary…

Dumb Fuzzer used to find CVE-2010-1411

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

「🔑」A tool used to hunt down API key leaks in JS files and pages

Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.

This Python script can be used to bypass IP source restrictions using HTTP headers.

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

The Web Exploit Detector is a Node.js application used to detect possible infections, malicious code and suspicious files in web hosting environments

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

Open Redirect Finder is an automation tool used to detect open redirect vulnerabilities on a URL.