
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

A fast, simple, recursive content discovery tool written in Rust.

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

REST/JSON API to the Burp Suite security tool.


Executable security regression testing for agentic applications and MCP-integrated systems.

Burp extension for wordpress security scanning

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR