Skip to content
View kevin-mizu's full-sized avatar
💭
🔎
💭
🔎

Sponsors

@e2llm

Block or report kevin-mizu

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Original Proof-of-Concepts for React2Shell CVE-2025-55182

JavaScript 947 106 Updated Dec 5, 2025

This is a "skill" for claude to use FFUF.

Python 81 4 Updated Oct 16, 2025

🚀 Caido releases, wiki and roadmap

Shell 1,997 92 Updated Dec 11, 2025

Disclosures of bugs and vulnerabilities reported by Hacktron.

15 1 Updated Aug 25, 2025

Cybersecurity AI (CAI), the framework for AI Security

Python 6,433 875 Updated Dec 19, 2025

AI-powered assistant that integrates seamlessly with Caido

TypeScript 48 8 Updated Nov 10, 2025

A DNS rebinding attack framework.

JavaScript 1,232 156 Updated Dec 4, 2025

403Bypasser is a simple plugin that lets you bypass 403 status code by transforming HTTP requests with custom templates.

TypeScript 97 14 Updated Aug 13, 2025

Real-Time JavaScript reverse engineering and debugging suite - Burp Suite, but for JavaScript

JavaScript 17 2 Updated Jul 23, 2025

A cross-platform tool to find traces of old SIDs remaining in LDAP objects of the Active Directory

Go 26 2 Updated Jun 29, 2025

A fast application to create and manage dynamic content and routes with an administration panel and a secure API

JavaScript 6 1 Updated Nov 24, 2025

This repository is a one-stop shop for diving deep into the fascinating world of mXSS (mutations caused by browser quirks in HTML parsing). providing a curated list of examples that showcase unexpe…

HTML 24 4 Updated Feb 25, 2025

A cross platform library to write offensive and defensive security tools in Go

Go 130 6 Updated Nov 21, 2025

Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.

Python 223 15 Updated Jul 24, 2025

Replaces every class in a JAR file with a malicious one

Python 3 Updated Mar 11, 2025

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR / APK applications.

Java 234 21 Updated Dec 9, 2025

Easily create and share Proof of Concepts in HTML, JavaScript, etc. with custom headers, all via query parameters

Vue 14 1 Updated Oct 1, 2025

Some tips for Bug Bounty using LibreOffice

HTML 55 6 Updated Feb 28, 2025

Extract GraphQL operations from javascript

JavaScript 23 2 Updated Nov 27, 2025

Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable SSRF candidates.

Go 699 52 Updated Dec 19, 2023

A web based OSINT ressource and tool

TypeScript 186 15 Updated Apr 6, 2025

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Shell 25 Updated Oct 28, 2024

A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.

Python 118 11 Updated Jun 25, 2025

This Chromium extension scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains are resolvable.

JavaScript 68 18 Updated Jan 8, 2025

A collection of scripts for assessing Microsoft Azure security

PowerShell 2,291 336 Updated Oct 29, 2025

Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit

Python 82 13 Updated Oct 7, 2024

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocke…

HTML 527 82 Updated Dec 18, 2025
Python 233 61 Updated Sep 27, 2024
Next