
Spring4Shell-POC
Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit

Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

Proof-of-concept exploit for Microsoft Exchange Server Remote Code Execution via ACL bypass, privilege escalation, and arbitrary file write…

(deprecated) Android application vulnerability analysis and Android pentest tool

A webshell framework for penetration testers.

Python-based XSS vulnerability scanner with support for POST/GET requests, parameter injection in cookies/referer/user-agent, and multiple encoding…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

CVE-2018-13379

Discover hidden debugging parameters and uncover web application secrets

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

This extension will help you to detect GET/POST based XSS vulnerability in any website easily

Web app authorisation coverage scanning

Django application that performs SAST and Malware Analysis for Android APKs

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

CVE-2017-12149 jboss反序列化 可回显

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…