
super-secret-finder
Automated secret matching plugin for Burp Suite that detects exposed API keys, tokens, and credentials in HTTP requests and responses for security…

Automated secret matching plugin for Burp Suite that detects exposed API keys, tokens, and credentials in HTTP requests and responses for security…

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

CVE-2026-32646 disclosure detailing missing authentication on Gardyn Home Kit administrative device management API endpoint, enabling unauthenticated…

Detailed disclosure of CVE-2026-25197: Authorization bypass via IDOR in Gardyn Home Kit cloud API, exposing PII and camera images of 134K+ users…

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Liner's chat component, allowing attackers to tamper with other users'…

Proof-of-concept exploit for CVE-2026-44595 demonstrating unauthorized user enumeration via missing authorization checks in YAMCS IAM API endpoints.

Advisory detailing an unauthenticated REST API information disclosure vulnerability in tiaudit, including impact, attack vector, and vendor fix…

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

High-performance web fuzzer for content discovery, virtual host enumeration, and parameter fuzzing. Supports recursive scanning, multi-wordlist…

Self-hosted API to parse, filter, and query the latest CVEs from cve.mitre.org by keyword and year, enabling real-time vulnerability intelligence.

A fast, simple, recursive content discovery tool written in Rust.

An easy-to-use and lightweight API wrapper for Censys APIs.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Automated OSINT and reconnaissance framework for Postman that discovers API endpoints, secrets, and sensitive data across workspaces, collections,…

A python3 script searching for secret on swaggerhub