
CVE-2025-55462
Technical documentation and proof-of-concept for CVE-2025-55462, a CORS misconfiguration in Eramba v3.26.0 allowing cross-origin authentication…

Technical documentation and proof-of-concept for CVE-2025-55462, a CORS misconfiguration in Eramba v3.26.0 allowing cross-origin authentication…

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…


Isolated educational lab simulating CVE-2025-4679 OAuth credential exposure. Learn offensive and defensive security through hands-on exercises,…

Documents a high-severity ExaGrid EX10 MailConfiguration API access control flaw that leaks plaintext SMTP credentials to authenticated operators,…

Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

High-performance Java RPC and microservices framework with service discovery, traffic management, observability, and built-in security for building…

Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

Denial of Service exploit for Microsoft HoloLens Device Portal via repeated API pairing requests, causing CPU overload and system unresponsiveness.

Cross-cloud S3-compatible object storage CLI to list, export, and download buckets across AWS, Aliyun, Tencent, Huawei and more, with anonymous…

The one shot API attacker tool - finds the API url from the given root simulate the automated attacks

Synapse: Matrix homeserver written in Python/Twisted.

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

Ingress NGINX Controller for Kubernetes

CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs

The Shadow Daemon web application firewall server

EU focused compliance MCP server