
parameth
This tool can be used to brute discover GET and POST parameters

Optiva-Framework 🔎 Web Application Scanner🕵️

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

Quickly generate context-specific wordlists for content discovery from lists of URLs or paths

Cloudflare Bypass tools | PentestCore

DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

🕵️♂️ All-in-one OSINT tool for analysing any website

Detection artifact for CVE-2026-2699 Progress ShareFile authentication bypass. Sends GET to /ConfigService/Admin.aspx to check vulnerability.

An Instagram Open Source Intelligence Tool - Archive

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

Proof-of-concept exploit for CVE-2017-8295, a WordPress password reset vulnerability allowing attackers to obtain reset links without authentication,…

Using google to scan sites for "ShellShock" (CVE-2014-6271)

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

Proof-of-concept exploit for CVE-2024-22411 targeting the Avo admin panel. Demonstrates vulnerability exploitation in Ruby-based web applications.

a lightweight, flexible and novel open source poc verification framework