
darwis-taxii
A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

A small, auditable, terminating, deterministic micro-policy engine

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

Synapse: Matrix homeserver written in Python/Twisted.

List of regex for scraping secret API keys and juicy information.

A wrapper of voku/anti-xss for Laravel

List of API's for gathering information about phone numbers, addresses, domains etc

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Proof-of-concept exploit for CVE-2021-44103 demonstrating vertical privilege escalation in Konga API Gateway 0.14.9, allowing authenticated users to…

HTTP proxy bridge for security testing of remote MCP servers, allowing standard HTTP tools to send JSON-RPC messages and manage sessions.

Denial of Service exploit for Microsoft HoloLens Device Portal via repeated API pairing requests, causing CPU overload and system unresponsiveness.

Community curated list of nuclei templates for finding "unknown" security vulnerabilities.

Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via…

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

4gaBoards < 3.3.9 - User Information Disclosure

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

A PoC exploit for CVE-2020-13945 - Apache APISIX Remote Code Execution (RCE)