
joomla_CVE-2023-23752
Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

CVE-2024-46627 - Incorrect access control in BECN DATAGERRY v2.2 allows attackers to > execute arbitrary commands via crafted web requests.

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The easiest, and most secure way to access and protect all of your infrastructure.

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

Your gateway to OWASP. Discover, engage, and help shape the future!

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…