
argumentinjectionhammer
一个用于识别参数注入漏洞的 Burp 扩展。

一个用于识别参数注入漏洞的 Burp 扩展。

BlueKeep scanner supporting NLA

用于分发侦察和漏洞扫描工作负载的无服务器 AWS 解决方案。通过 Web UI 提交任务;EC2 worker 执行使用 Nmap 等工具的自定义 Python 脚本。

NMAP Vulnerability Scanning Scripts

Pcap importer for Burp

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

CGI Print ENV leaking

Citrix Netscaler ADC & Gateway v13.1-50.23 - 越界内存读取

这是一个被多位安全研究人员用来查找开放重定向漏洞的工具。

Laravel Ignition 在启用调试模式时包含一个跨站脚本(XSS)漏洞。

This tool is used to find php info page

This tool is used to find shell history leaking

SOUND4 Impact/Pulse/First/Eco <=2.x - 信息泄露

A BASH Script to automate the installation of the most popular bug bounty tools

攻击者可以在元素属性中放置包含可执行 JavaScript 的 HTML。该标记不会被转义,从而导致任意标记被注入到文档中。

Zimbra Collaboration (ZCS) 任意文件上传漏洞

4.2.3 之前的 Popup Builder WordPress 插件未能阻止普通访客更新现有弹窗并在其中注入原始 JavaScript,这可能导致存储型 XSS 攻击。

Detection for CVE-2025-11371