
vulmap
Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Web Filter External Enumeration Tool (WebFEET)

WordPress security scanner that enumerates vulnerable plugins, themes, and users to identify misconfigurations and known vulnerabilities for…

Detection for CVE-2025-47812

An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.

Modern tactical exploitation toolkit.

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Detection for CVE-2024-57378

XSS scanner that detects Cross-Site Scripting vulnerabilities in website by injecting malicious scripts

Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own personal use, and…

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

Next generation web scanner

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to…

WPScan rewritten in Python + some WPSeku ideas

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners