
CVE-2026-46587
Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data…

Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data…


Open-source MITM proxy to intercept, inspect, and mock network traffic.

PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape

find sensitive data leaking from ServiceNow instances.

Reproducer for CVE-2026-46453 — Apache Camel camel-elasticsearch-rest-client unprefixed-header injection (operation/query override via inbound HTTP…


A fast WordPress plugin enumeration tool

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

Professional extension of sqlmap project

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

Official Elastic Skills


An HTTP toolkit for security research.

Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.