
CVE-2026-33032
One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

CVE-2026-39154, Stored XSS in CometChat JS SDK

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

This skill helps Claude write secure code and prevent common vulnerabilities.

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…