
CVE-2026-71203-PoC
PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

A coverage-guided REST API fuzzer developed on top of LibAFL

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

The simple PoC of CVE-2023-27587

Denial of Service exploit for Microsoft HoloLens Device Portal via repeated API pairing requests, causing CPU overload and system unresponsiveness.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Checklist of the most important security countermeasures when designing, testing, and releasing your API

The easiest, and most secure way to access and protect all of your infrastructure.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

List of API's for gathering information about phone numbers, addresses, domains etc

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS