
kiterunner
High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Damn Vulnerable C# Application (API)

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

Vulnerability Assessment Scanner with Report Generation

A Test API for testing the POC against CVE-2022-1388

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…