
RAWR
Rapid Assessment of Web Resources

Rapid Assessment of Web Resources
Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

CMSmadesimple 2.2.18 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)

An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown…

PoC for CVE-2022-28281 a Mozilla Firefox Out of bounds write.

An XSS exploitation command-line interface and payload generator.

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

Like curl, but it gets past Anubis and Cloudflare bot-walls.

Fuzzing Framework for Modules in Apache HTTPD Server

Full Firefox chain: CVE-2026-2796 wasm type confusion -> content-process RCE, plus CVE-2026-2768 parent-process escape analysis (both fixed in…

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header…

Exploit for Apache NiFi CVE-2023-34468, targeting a vulnerability in versions 1.21.0 and earlier to demonstrate data access and system compromise.

A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

Domain Parser for IPAddress.com Reverse IP Lookup

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.
