
Gitlab-CVE-2026-19478
Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Executable security regression testing for agentic applications and MCP-integrated systems.

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Burp extension for wordpress security scanning


Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

A fast, simple, recursive content discovery tool written in Rust.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

REST/JSON API to the Burp Suite security tool.