
suds
Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

An intentionally designed broken web application based on REST API.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

Http request smuggling vulnerability scanner

Exploit for CVE-2021-30180 targeting Apache Dubbo RPC framework, enabling remote code execution via crafted RPC requests in vulnerable versions.

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Go client to communicate with Chaos DB API.

A coverage-guided REST API fuzzer developed on top of LibAFL

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

MAPS cloud scanner and response parser for Microsoft Defender research.

Collaborative application security testing between humans and agents via CLI and MCP