
RISE-Ultimate_Project_Manager_e_CRM
CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

Http request smuggling vulnerability scanner

A modern vulnerable web app

Research on GraphQL from an AppSec point of view.

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Proof-of-concept exploit for CVE-2026-26012, demonstrating an authenticated organization collection permissions bypass and cipher enumeration in…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

A fast WordPress plugin enumeration tool

Open-source adversary emulation for AI agents and MCP servers.

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations