
CVE-2026-19478-PoC
Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Open Source Vulnerability Management Platform

POC for utilizing wikipedia API for Command and Control

provides a Firewall Manager API designed to centralize and streamline the management of firewall configurations

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The easiest, and most secure way to access and protect all of your infrastructure.

Ingress NGINX Controller for Kubernetes

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…

Automagically reverse-engineer REST APIs via capturing traffic

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

OPNsense GUI, API and systems backend

Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…

Kubernetes policy engine with OPA-based admission control, mutation, and audit for enforcing security and compliance configurations.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)