


A python3 script searching for secret on swaggerhub

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

Unofficial api for cve.mitre.org

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

Corelight Sensor API command-line client

A small, auditable, terminating, deterministic micro-policy engine

An implementation of a vulnerable MCP server using mcp-go

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Burp Plugin for Secret Matching


CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)


Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

The code for personally reproducing the corresponding vulnerability