-
-
NextSploit Public
Forked from AnonKryptiQuz/NextSploitNextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
Python UpdatedApr 12, 2025 -
BlindBrute Public
Forked from c3llkn1ght/BlindBruteA blind SQL injection brute forcer
Python MIT License UpdatedNov 30, 2024 -
urlfinder Public
Forked from projectdiscovery/urlfinderA high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.
Go MIT License UpdatedNov 27, 2024 -
loxs Public
Forked from coffinxp/loxsbest tool for finding SQLi,CRLF,XSS,LFi,OpenRedirect
-
-
ShadowDumper Public
Forked from Offensive-Panda/ShadowDumperShadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advanced techniques to dump memory, allowing to access sensitive daβ¦
C++ MIT License UpdatedNov 19, 2024 -
sj Public
Forked from BishopFox/sjA tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.
Go MIT License UpdatedNov 15, 2024 -
URLFetcherApp Public
Forked from gh-ost00/URLFetcherAppFetch urls/hidden file on domain target
-
-
trivy Public
Forked from aquasecurity/trivyFind vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Go Apache License 2.0 UpdatedOct 30, 2024 -
CVE-2024-27954 Public
Forked from gh-ost00/CVE-2024-27954Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities
Python UpdatedOct 29, 2024 -
Rest_API_Exploit Public
Forked from gh-ost00/Rest_API_ExploitCORS Exploit POC for WordPress REST API
HTML UpdatedOct 27, 2024 -
cherrybomb Public
Forked from blst-security/cherrybombStop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.
Rust Apache License 2.0 UpdatedOct 25, 2024 -
JS-Scanner Public
Forked from gh-ost00/JS-ScannerThe powerfull Extract and Scanner Javascript urls xD
Python UpdatedOct 25, 2024 -
SSTImap Public
Forked from vladko312/SSTImapAutomatic SSTI detection tool with interactive interface
Python GNU General Public License v3.0 UpdatedOct 14, 2024 -
Nuclei_templates2024 Public
nuclei templates for bug bounty #by.Ghost
-
crlfuzz Public
Forked from dwisiswant0/crlfuzzA fast tool to scan CRLF vulnerability written in Go
Go MIT License UpdatedOct 3, 2024 -
ghauri Public
Forked from r0oth3x49/ghauriAn advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
Python MIT License UpdatedOct 3, 2024 -
CVE-2024-28987-POC Public
Forked from gh-ost00/CVE-2024-28987-POCWeb Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)
Python UpdatedSep 5, 2024 -
CVE-2024-1071-SQL-Injection Public
Forked from gh-ost00/CVE-2024-1071-SQL-InjectionProof of concept : CVE-2024-1071: WordPress Vulnerability Exploited
Python UpdatedAug 30, 2024 -
CVE-2024-4577-RCE Public
Forked from gh-ost00/CVE-2024-4577-RCEPHP CGI Argument Injection (CVE-2024-4577) RCE
Python UpdatedAug 20, 2024 -
exploit-writing-for-oswe Public
Forked from rizemon/exploit-writing-for-osweTips on how to write exploit scripts (faster!)
UpdatedJul 15, 2024 -
kiterunner Public
Forked from assetnote/kiterunnerContextual Content Discovery Tool
Go GNU Affero General Public License v3.0 UpdatedApr 29, 2024 -
CRLF-Injection-Scanner Public
Forked from MichaelStott/CRLF-Injection-ScannerCommand line tool for testing CRLF injection on a list of domains.
Python UpdatedApr 14, 2024 -
p0wny-shell Public
Forked from flozz/p0wny-shellSingle-file PHP shell
PHP Do What The F*ck You Want To Public License UpdatedFeb 16, 2024 -
vulnerability-Checklist Public
Forked from Az0x7/vulnerability-ChecklistThis repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter
UpdatedFeb 10, 2024 -
client-side-prototype-pollution Public
Forked from BlackFan/client-side-prototype-pollutionPrototype Pollution and useful Script Gadgets
UpdatedJan 27, 2024 -
-
BobTheSmuggler Public
Forked from TheCyb3rAlpha/BobTheSmuggler"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would compress your binary (EXE/DLL) into 7z/zip file forβ¦
Python MIT License UpdatedJan 16, 2024