
s3cXSSer
This extension will help you to detect GET/POST based XSS vulnerability in any website easily

This extension will help you to detect GET/POST based XSS vulnerability in any website easily

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos…

Scanner: CVE-2026-3854 GitHub Enterprise Server Pre-auth RCE via Push Option Injection — Python checker (CISA KEV)

Modern tactical exploitation toolkit.

Recon-Ninja


Nuclei Templates Collection

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…


RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Adobe Experience Manager (AEM) hacking toolkit

🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted…


Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own personal use, and…

CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434…

Rust-powered HTTP Request Smuggling Scanner.

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.