
CVE-2026-44351-poc
Proof-of-concept for CVE-2026-44351, an authentication bypass in fast-jwt <6.2.4 where an empty HMAC key lets attackers forge arbitrary JWTs accepted…

Proof-of-concept for CVE-2026-44351, an authentication bypass in fast-jwt <6.2.4 where an empty HMAC key lets attackers forge arbitrary JWTs accepted…

A static + runtime security scanner for MCP (Model Context Protocol) servers

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

批量检测Spring Cloud Gateway 远程代码执行漏洞 Spring_Cloud_Gateway_RCE_POC-CVE-2022-22947

Exploit for CVE-2022-22947: remote code execution in Spring Cloud Gateway via crafted requests to the Actuator endpoint. Includes Python script and…

Proof-of-concept for CVE-2025-30144: JWT issuer validation bypass in fast-jwt library allowing attackers to forge tokens with array-based iss claims.

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

détection des attaques sql/xss sur API web avec IA

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.

Scan codebases and GCP projects for exposed API credentials

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…


Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

A fast, simple, recursive content discovery tool written in Rust.