
teleport
The easiest, and most secure way to access and protect all of your infrastructure.

The easiest, and most secure way to access and protect all of your infrastructure.

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

Advisory and benign PoC for OS command injection in an nmap MCP server, with duplicate CVE tracking, detection guidance, and mitigation.

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Detailed advisory for CVE-2025-56219, a rate-limiting flaw in Ascertia SigningHub's Add User API, enabling automated user creation and denial of…

Pivotable Reverse WhoIs / PDNS Fusion with Registrant Tracking & Alerting plus API for automated queries (JSON/CSV/TXT)

Damn Vulnerable MCP Server

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Automatic SQL injection and database takeover tool

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit