
CVE-2026-19478-PoC
Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Reproducer that exploits credential vending before location validation in Apache Polaris Iceberg REST, proving cross-tenant cloud reads and bucket…


A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.


PlaceOS authentication service and API gatekeeper.

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.



