Skip to content
View SaFiSec's full-sized avatar
🎯
Focusing
🎯
Focusing
  • Ethical Hacker | Bug Bounty Hunter
  • internet

Block or report SaFiSec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Burp Extension written in Jython to hunt for common vulnerabilities found in websites. Developed by Gaurav Narwani to help people find vulnerabilities and teach how to exploit them.

Python 252 54 Updated Apr 27, 2020

🛡️ Privacy & Security Audit for Linux Desktops — 390+ checks, 42 sections, zero dependencies, pure Bash. AI-powered fixes with --ai flag.

Shell 8 1 Updated Apr 9, 2026

Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own personal use, and occassionally public released

Python 146 24 Updated Dec 18, 2025

An IIS short filename enumeration tool

Go 1,139 113 Updated Nov 25, 2024

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

JavaScript 2,334 218 Updated Nov 29, 2024

Find XSS payloads that actually work by filtering them based on real-world constraints instead of blind payload spraying.

JavaScript 200 75 Updated Mar 8, 2026

ProjectDiscovery's Open Source Tool Manager

Go 1,094 94 Updated Jan 5, 2026

Self-hosted bug bounty programs that are "scammy" or unethical

173 22 Updated Feb 10, 2026

Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities bef…

TypeScript 37,883 4,044 Updated Apr 9, 2026

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Java 1,142 554 Updated Apr 26, 2024

🔐 Chrome Extension - Detect hardcoded tokens, API keys & secrets in JavaScript files

JavaScript 40 9 Updated Dec 15, 2025

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Python 2,428 262 Updated Dec 7, 2025

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Python 1 Updated Dec 12, 2025

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Python 18 6 Updated Dec 12, 2025

Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation

JavaScript 1 Updated Dec 11, 2025

Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation

JavaScript 80 28 Updated Dec 11, 2025

Original Proof-of-Concepts for React2Shell CVE-2025-55182

JavaScript 1,036 107 Updated Dec 5, 2025

HackerOne Platform Documentation

JavaScript 1 Updated Jan 27, 2022

Google Aiza API Scanner

Python 1 Updated Jun 15, 2025

🍺 The missing package manager for macOS (or Linux)

Ruby 47,444 11,073 Updated Apr 10, 2026

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

1 Updated Jul 23, 2025

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

7 6 Updated Jul 23, 2025

Extract JavaScript source trees from Sourcemap files

Go 1,308 129 Updated Mar 22, 2024

Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime

JavaScript 2,995 405 Updated Mar 28, 2026

Config files for my GitHub profile.

6 1 Updated Nov 25, 2024

Playwright MCP server

TypeScript 30,581 2,488 Updated Apr 9, 2026
Next