
SwaggerSpy
Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Automagically reverse-engineer REST APIs via capturing traffic


AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation


CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

Open Source Vulnerability Management Platform

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…
