
feroxbuster
A fast, simple, recursive content discovery tool written in Rust.

A fast, simple, recursive content discovery tool written in Rust.

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

Knocker, a knock based access control service for your homelab

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

Advisory and benign PoC for OS command injection in an nmap MCP server, with duplicate CVE tracking, detection guidance, and mitigation.

The simple PoC of CVE-2023-27587

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

PHP 8.4+ security library (mirror)

Enrolled agent can smuggle arbitrary OpenSearch _bulk operations via DataValue.index. GHSA-ff9g-85jq-r3g3. Draft

OAuth 2.0 client library for Kit applications supporting authorization code, PKCE, client credentials, and refresh token flows with built-in provider…

Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.