
magicRecon
MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

A better version of my xssfinder tool - scans for different types of xss on a list of urls.

Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own personal use, and…

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Check list of URLs against Log4j vulnerability CVE-2021-44228

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially…

This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It…

This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific…

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

A vulnerability was found in PHPgurukul visitor management system 1.0. it has been rated as problemic. Affected by the issue is some unknown…

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths…

Scanner to detect the presence of CVE-2025-55182 & CVE-2025-66478 on targeted web services.

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

Application scanning component of purpleteam

Community curated list of templates for the nuclei engine to find security vulnerabilities.