
CVE-2018-25031
Python-based proof-of-concept script demonstrating CVE-2018-25031 XSS vulnerability in Swagger UI using Selenium for automated detection across…

Python-based proof-of-concept script demonstrating CVE-2018-25031 XSS vulnerability in Swagger UI using Selenium for automated detection across…

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

OWASP Autonomous Penetration Testing Standard

OWASP Honeypot, Automated Deception Framework.

Open source tooling to stop ICS phishing (malicious calendar invites)

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

A command-line tool to check if passwords have been exposed in data breaches using the Have I Been Pwned (HIBP) API.

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

A script that automatically submits files to Hybrid Analysis (API)

CVE-2020-9483 OR CVE-2020-13921

CVE-2025-55182 and CVE-2025-66478

Java library providing XSS escaping and filtering services (XSSAPI, XSSFilter) to sanitize user-submitted content and prevent cross-site scripting…

CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs

Operational security controls with forensic guarantees

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations