
CVE-2026-65540
Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

AI-powered bug bounty hunting toolkit that works with or without subscription.

A wrapper around grep, to help you grep for things

Web vulnerability scanner written in Python3

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

Burp extension scanner for CRLF injection and HTTP desync attacks, using mutated probes, WAF false-positive checks, and optional…

Rust-powered HTTP Request Smuggling Scanner.

A Burp Extension designed to identify argument injection vulnerabilities.

Adobe Experience Manager Childlist Selector - Cross-Site Scripting

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

The Clickjacking Exploit Detector uses webpage scanning techniques to identify potential vulnerabilities and provide analysis of those elements.

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Python-based web crawler and SQL injection vulnerability scanner using dork queries. Supports proxy and automated scanning for security testing.