
XSSFire
A standalone Blind XSS Script.

A standalone Blind XSS Script.

Checks mutual followers between ig accounts (local hosted, use your own session id)

A high-performance automation tool designed to bridge the gap between technical web reconnaissance and executive reporting. Developed by **Adi…

Advisory and technical write-up for CVE-2026-18782, a critical SQL injection in TREX MES web API endpoints enabling auth bypass, data theft, and RCE…

Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

Automatically run and save ffuf scans for multiple IPs

Embed a reverse shell in Notion pages using the Notion API as a proxy, enabling stealthy remote shell sessions with encrypted and authenticated…

Playground to experiment with different behavior on patched/unpatched Kestrel for the CVE-2025-55315 HTTP smuggling vulnerability

MitM attack allowing a malicious interloper to impersonate a legitimate server when a client attempts to connect to it

WPQA < 5.5 - Unauthenticated Private Message Disclosure

强大的内网渗透辅助工具集-让Yasso像风一样 支持rdp,ssh,redis,postgres,mongodb,mssql,mysql,winrm等服务爆破,快速的端口扫描,强大的web指纹识别,各种内置服务的一键利用(包括ssh完全交互式登陆,mssql提权,redis一键利用,mysql数据库…

CVE-2025-33053 Proof Of Concept (PoC)

Collaborative application security testing between humans and agents via CLI and MCP

SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass…

Demonstrates SSRF exploitation via URL parser differential between urllib.parse and requests, including vulnerable service and PoC exploit script.

Technical analysis of CVE-2026-42945 (NGINX Rift), a critical heap buffer overflow in NGINX's rewrite engine caused by a state mismatch between…

Generic wiki/HTML rendering system that converts textual input between syntaxes (wiki, HTML, XHTML). This repository contains a patched version…

Docker-based PoC for Flask CVE-2023-30861, demonstrating session handling vulnerability between Flask and reverse proxy cache servers for security…