
feroxbuster
A fast, simple, recursive content discovery tool written in Rust.

A fast, simple, recursive content discovery tool written in Rust.


GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Automagically reverse-engineer REST APIs via capturing traffic

A python3 script searching for secret on swaggerhub

An easy-to-use and lightweight API wrapper for Censys APIs.

Burp Plugin for Secret Matching

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Unofficial api for cve.mitre.org

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Liner's chat component, allowing attackers to tamper with other users'…

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…