
findom-xss
A fast DOM based XSS vulnerability scanner with simplicity.

A fast DOM based XSS vulnerability scanner with simplicity.

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

A penetration testing tool for finding file upload bugs (NDSS 2020)

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthenticated access to Superset instances for…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Disrupt WAF by abusing SSL/TLS Ciphers

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…


Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

Burp plugin which supports in finding privilege escalation vulnerabilities