
mitmproxy2swagger
Automagically reverse-engineer REST APIs via capturing traffic

Automagically reverse-engineer REST APIs via capturing traffic

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

An implementation of a vulnerable MCP server using mcp-go

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

4gaBoards < 3.3.9 - User Information Disclosure

Fingerprint OpenAI-compatible LLMs from tokenizer and behavior signals.

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

EU focused compliance MCP server

Collection's of Tech Talk that are presented by me :)

Cross-cloud S3-compatible object storage CLI to list, export, and download buckets across AWS, Aliyun, Tencent, Huawei and more, with anonymous…

OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass

Report summary and local proof-of-concept script demonstrating CVE-2026-103440, a PageTriage API disclosure of suppressed reviewer usernames on…

The simple PoC of CVE-2023-27587

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API