
CVE-2026-44848-PoC
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Automated HTTP Request Repeating With Burp Suite

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Type-safe HTTP client library for Android and Java, enabling REST API communication with annotation-based request configuration and converter support.

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

Node.js SDK for capturing and replaying API calls made to/from your service

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

This script exploits the CVE-2024-40094 vulnerability in graphql-java

Type-safe HTTP client for Android and Java with annotation-based API binding, converter support, and integration with OkHttp for network…

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.