
BirDuster
A multi threaded Python script designed to brute force directories and files names on webservers.

A multi threaded Python script designed to brute force directories and files names on webservers.


A curated library of security prompts for AI-assisted security testing, threat modeling, and educational exercises.


The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

批量url检测Spring-Cloud-Gateway-CVE-2022-22947

Lab report analyzing CVE-2025-68613 expression injection in n8n, demonstrating sandbox escape via crafted payloads to access sensitive server files,…

Remote detection tool for OWASP Core Rule Set version and paranoia level on ModSecurity WAFs, aiding security posture assessment.

This script exploits the CVE-2024-40094 vulnerability in graphql-java

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

Security research & exploitation analysis of CVE-2025-55182 (React) — CVSS + OWASP Top 10 mapping